Privacy policy

1. Introduction

UAB “Sekasoft” (hereinafter referred to as “Sekasoft” or “we”) respects your privacy and is committed to protecting personal data in accordance with applicable legislation, including Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and the relevant laws of the Republic of Lithuania.

This Privacy Policy (hereinafter referred to as the “Policy”) explains how Sekasoft collects, uses and stores personal data when you use our website, document management system (DMS) services and mobile applications.

If you have any questions regarding this Policy or the processing of personal data, please contact us at info@sekasoft.com.

2. Key Principles of Personal Data Processing

Sekasoft processes personal data in accordance with the key data protection principles established by the GDPR:

  • Lawfulness, fairness and transparency: We process personal data lawfully, fairly and transparently, relying on a clear legal basis in each case.

  • Purpose limitation: Personal data is collected for specified, explicit and legitimate purposes and is not subsequently processed in a manner incompatible with those purposes. We do not use collected data for other purposes unless we have a lawful basis for doing so and inform you in advance.

  • Data minimisation: We process only personal data that is adequate, relevant and necessary for the purposes stated, and no more than is required.

  • Accuracy: We seek to ensure that personal data is accurate and, where necessary, kept up to date. Inaccurate or outdated data is corrected or deleted.

  • Storage limitation: We retain personal data for no longer than is necessary to achieve the purposes for which it was collected, unless applicable law requires a longer retention period. Once the retention period expires, the data is securely deleted or anonymised.

  • Integrity and confidentiality: We process personal data in a manner that ensures appropriate security. We apply appropriate technical and organisational measures to protect data against unlawful processing, accidental loss, destruction or damage. All personal data processed by us is treated as confidential information and may be accessed only by authorised persons.

3. Personal Data We Collect

3.1. Data You Provide to Us

We collect personal data that you provide directly when using Sekasoft services or contacting us. This information is required so that we can properly fulfil our contractual obligations and comply with applicable legal requirements.

Such data may include your first name, last name, position, company name, contact details (telephone number, email address and address), and other information necessary for entering into or performing a contract or responding to your requests.

When an organisation registers for or uses certain Sekasoft DMS services, including DO365, we may also process service administration information such as the number of users using the application, the implementation partner and the organisation’s tenant URL. Where this information relates to an identifiable individual, it is treated as personal data in accordance with this Policy.

All information you provide must be accurate and correct. If you provide inaccurate information, you must correct it without delay.

If you contact us regarding employment, for example by submitting a CV, we may collect additional information relating to the recruitment process, such as your CV and information about your qualifications. Such data is used solely for recruitment purposes and is processed in accordance with a separate privacy notice.

3.2. Data Collected Automatically

When you use our website or mobile applications, certain data is collected automatically. This may include:

  • Technical and device information: Your device IP address, browser type and version, operating system, device identifiers, login time and duration, and application version. This information is required to ensure the technical operation and security of our services, for example for authentication and error diagnostics.

  • Usage data: Information about how you use our services, including pages viewed, clicks, actions performed within the system, date and time stamps and similar information. We analyse this data in order to improve the functionality of our services and the user experience, for example by monitoring which DMS features are used most frequently.

  • Cookies: We use cookies and similar technologies on our website. Cookies are small text files that, where your consent is required, are stored in your browser memory after you have given your consent. Further information about cookies is provided in Section 7 below.

Some categories of automatically collected data may not constitute personal data because they do not identify you directly. For example, we may collect aggregated statistics about website or application traffic or the amount of content downloaded. Such statistical data is processed in a manner that does not allow a specific individual to be identified.

3.3. Data Received from Third Parties

We generally obtain personal data directly from you. However, in certain cases we may receive data from other sources.

For example, if your employer, which is our customer, identifies you as a contact person when entering into a contract, we may receive your personal data from your employer.

We may also use third-party sources to verify information contained in public registers, for example a company register where this is necessary for entering into a contract.

Any personal data received from external sources is processed under the same conditions and principles as personal data received directly from you.

4. Purposes and Legal Bases for Processing Personal Data

Sekasoft collects and processes your personal data for specific purposes and always relies on at least one lawful basis for processing under the GDPR.

The main purposes for which we process personal data and the relevant legal bases are set out below:

  • Provision of services and performance of contracts: We process your personal data in order to enter into and perform contracts with you or the organisation you represent. This may include providing access to the DMS, administering user accounts and providing customer support. The legal basis for processing is entering into and performing a contract. If you register for our services or use our application, the necessary contact and login data is processed in order to fulfil our contractual obligations to you.

  • Customer support and communication: When you contact us by email, telephone or other channels, we process the information you provide in order to respond to your enquiries, resolve issues and provide technical support. We do this on the basis of our legitimate interest in providing high-quality customer service and maintaining communication with customers.

  • Service improvement and analytics: To improve our products and the user experience, we analyse service usage data. We use Google Analytics and similar analytics tools that collect anonymous and pseudonymous data about users’ interactions with our website or application. Google Analytics cookies may collect information about your device location, demographic information and browsing activity. We use this information in aggregated form to understand user needs. The legal basis for this processing is our legitimate interest in analysing and improving our services. You have the right to object to such processing at any time.

  • Direct marketing: With your prior consent, we may use your contact details to send newsletters, invitations to events or other information related to our services. The legal basis for processing is your consent. You may withdraw your consent at any time. Each email includes an option to unsubscribe. If you are our customer, in certain cases we may also rely on our legitimate interest to inform you about similar services, while providing an easy way to opt out of such communications.

  • Compliance with legal obligations: We process personal data in order to comply with legal obligations applicable to us. For example, accounting legislation requires us to retain certain financial documents for a specified period. We may also process personal data in response to lawful requests from public authorities or in order to comply with court decisions.

  • Other purposes with your consent: If we intend to process your personal data for other purposes, we will inform you in advance and obtain your consent, for example in relation to non-essential cookies or the publication of customer success stories.

Where processing is based on consent or legitimate interests, you have the right to withdraw your consent or object to the processing at any time, as applicable. Please see Section 11 below.

5. Personal Data Retention

We retain personal data for no longer than is objectively necessary for the purposes for which it was collected, unless applicable law requires or permits a longer retention period.

  • Customer data relating to contractual relationships: We process your contact details and data relating to the performance of a contract for the duration of the contractual relationship. After the contract ends, key data is retained for as long as required by law. Other data relating to the performance of the contract is generally deleted within 2 years after the end of the contract, unless it is required in connection with legal claims.

  • DMS user accounts: We retain your account data for as long as you remain an active user of our DMS. If your account becomes inactive or is deleted, the personal data associated with the account will be deleted or anonymised within a reasonable period, generally within 1 month.

  • Marketing consents: We retain evidence of your consent for as long as the consent remains valid and for a short period after it is withdrawn.

  • Candidate data: If you apply for a position with us, we retain your data for the duration of the recruitment process. The CVs of unsuccessful candidates are generally deleted after the recruitment process has ended, unless we have obtained consent to retain them for longer, in which case they will be retained for no longer than 1 year.

Once the relevant retention periods expire, personal data is securely deleted or anonymised.

6. Disclosure of Personal Data to Third Parties

Sekasoft may disclose your personal data to third parties only in accordance with applicable legal requirements and subject to appropriate data protection safeguards.

We do not transfer or sell your personal data to third parties, except in the circumstances described below:

  • Service providers (data processors): We use trusted third-party service providers that provide infrastructure, hosting, email delivery, data analytics and other services. These providers are given access to personal data only to the extent necessary to provide the relevant service. We impose strict contractual confidentiality and data protection requirements on all such partners.

  • Third-party applications selected by customers or users: Where you or the organisation you represent chooses to connect a Sekasoft service to a third-party application or service, information may be disclosed to that third party as necessary to enable the integration or functionality requested by you. Such third parties process data according to their own terms and privacy practices where they act independently from Sekasoft. You should therefore review the privacy terms applicable to any third-party service you choose to connect.

  • Affiliated group companies: Sekasoft currently has no subsidiaries or affiliated companies to which personal data is routinely transferred. If this changes, personal data may be transferred within the group for internal administrative purposes.

  • Compliance with legal requirements: We may disclose personal data to public authorities or other third parties where required by law or legal proceedings, for example pursuant to a court order. We may also disclose data to law enforcement authorities where necessary. In each case, we disclose only the minimum amount of personal data necessary.

  • Business transactions: In the event of strategic business transactions, such as a merger or acquisition, personal data may be transferred to third parties subject to strict confidentiality requirements.

We may also use or disclose aggregated or anonymised statistical information about the use of our services where such information does not identify any individual. Such information may, for example, be used to analyse service usage, improve our services or describe general usage trends.

International data transfers: As a general rule, your personal data is stored within the European Union (EU) or European Economic Area (EEA). If a transfer outside the EU/EEA is necessary, we will ensure that such transfer complies with Chapter V of the GDPR, for example by using Standard Contractual Clauses.

7. Cookies and Third-Party Analytics Tools

Cookies are small data files that we use on our website to distinguish you from other users and ensure smooth functionality.

  • Strictly necessary cookies: These cookies are essential for the operation of the website, including navigation, login and language settings. Without them, the website would not function properly. We do not require separate consent for their use, as they are used on the basis of our legitimate interest in ensuring website functionality.

  • Analytics and performance cookies: These cookies collect statistical information about website traffic and user activity. We use Google Analytics. These cookies may collect anonymous information about your visits and approximate location. We use analytics cookies only after obtaining your consent, which you may change at any time.

  • Functional cookies: These cookies allow us to remember the choices you make. They are used only with your consent. If you reject these cookies, certain personalised features may not function properly.

  • Advertising and targeting cookies: We currently do not use any third-party advertising cookies for direct marketing purposes.

Further information about the specific cookies we use is available in our Cookie Policy. You may also control cookies through your browser settings.

8. Sekasoft as a Data Processor (DMS Services)

Customers using the Sekasoft DMS may process personal data within the system. In such cases, Sekasoft acts as a data processor, while the customer acts as the data controller within the meaning of the GDPR.

  • Customer content: Your use of our DMS services may involve uploading, entering, storing or otherwise processing documents, files and other content that may contain personal data (“Customer Content”). Sekasoft processes and accesses Customer Content only to the extent necessary to provide, maintain, secure and support the service, to respond to a support request, to comply with the customer’s documented instructions, or where access or disclosure is required by applicable law. Where necessary for service analysis and improvement, information derived from Customer Content may be used only in aggregated or anonymised form that does not identify individuals or customers, unless otherwise agreed with the customer.

  • Data Processing Agreements: We enter into a separate Data Processing Agreement (DPA) with each customer, as required by Article 28 of the GDPR. We undertake to process personal data only in accordance with the customer’s instructions. Sekasoft does not use customer data for its own purposes.

  • Confidentiality: All Sekasoft employees and subcontractors are legally required to maintain confidentiality, and access is granted on a least-privilege basis.

  • Technical and organisational measures: We apply appropriate security measures, including encryption, access controls and backups, in accordance with the ISO/IEC 27001 standard, in order to protect customer data.

  • Sub-processors: We use other data processors for certain parts of our services, for example cloud infrastructure. A new sub-processor may be engaged only with the customer’s consent.

  • Responsibility: We are responsible to the customer for processing personal data in accordance with the requirements of the GDPR.

If you have questions about what personal data is processed in the DMS on behalf of your employer, we recommend that you first contact your employer, who acts as the data controller.

9. Privacy Aspects of Mobile Applications

When using our mobile application, you are protected by the same privacy provisions. Certain aspects specific to the application are set out below:

  • Data collection within the application: Login information is transmitted through a secure connection. The application collects basic usage data on the basis of our legitimate interest in maintaining functionality and security.

  • Access to device functions: The application may request permission to access functions such as the camera or file system, for example when uploading documents. We do not request unnecessary permissions, and you may withdraw permissions at any time through your device settings.

  • Mobile analytics and crash reporting: We may use crash-reporting tools, such as Firebase Crashlytics, which collect anonymous crash reports for the purpose of improving service quality.

  • Push notifications: The application may send notifications about important events using the relevant platform notification service. You may control these notifications through your device settings.

  • Privacy Policy within the application: This Policy is always available in the application settings.

10. Data Security

Sekasoft has implemented appropriate technical and organisational measures to protect personal data in accordance with Article 32 of the GDPR and the ISO/IEC 27001 standard:

  • Encryption: Sensitive information is encrypted when transmitted and stored in our systems using technologies such as HTTPS/TLS.

  • Access control: Access is granted only where necessary and in accordance with role-based access control principles. We apply strong password policies and two-factor authentication.

  • Network and system protection: Servers are protected by firewalls and antivirus software. We are certified in accordance with ISO/IEC 27001.

  • Testing and assessment: We periodically perform internal and external testing, including penetration testing, assess threats and update our systems.

If a personal data breach occurs, we have established procedures in place. We will notify the State Data Protection Inspectorate and, where required, you directly.

11. Your Rights

Data protection legislation gives you the following rights:

  • Right of access: You have the right to obtain information about what personal data we process about you.

  • Right to rectification: You have the right to request that inaccurate or incomplete personal data be corrected.

  • Right to erasure: You have the right to request the deletion of your personal data (“right to be forgotten”) where there are grounds for doing so.

  • Right to restriction of processing: You have the right to request that active processing of your personal data be temporarily restricted.

  • Right to data portability: You have the right to receive your personal data in a machine-readable format and transfer it to another controller.

  • Right to object: You have the right to object to processing where it is based on legitimate interests or carried out for direct marketing purposes.

  • Right to withdraw consent: You may withdraw previously given consent to the processing of personal data at any time.

  • Right not to be subject to automated decision-making: Sekasoft does not make decisions based solely on automated processing.

To exercise these rights, please contact us using the details provided below.

You also have the right to lodge a complaint with the State Data Protection Inspectorate. However, we encourage you to contact us first so that we can seek to resolve the matter.

12. Children’s Privacy

Sekasoft services are intended for business and professional use and are not directed at children. We do not knowingly request or collect personal data directly from children under the age of 18 through our website or services.

Where personal data relating to children is processed within a customer’s DMS environment, Sekasoft processes such data solely on behalf of and in accordance with the instructions of the relevant customer acting as the data controller.

13. Contact Details

If you have any questions or would like to exercise your rights, please contact us:

UAB “Sekasoft”
Address: Savanorių pr. 349, 51480 Kaunas, Lithuania
Email: info@sekasoft.com

We will respond as soon as possible, but no later than within 1 month.

14. Changes to this Privacy Policy

Sekasoft may update this Privacy Policy from time to time.

Material changes will be communicated in advance by publishing a notice on our website or by informing you by email.

If you do not agree with future changes, you have the right to stop using our services. If you continue using the services after the Policy has been updated, we will consider this as acceptance of the revised Policy.