Privacy Policy


The administrator who manages the website recognises the importance of every individual’s privacy. This document sets out the privacy policy applied by the Administrator (the “Policy”), and this Policy applies to the website managed by the Administrator, which is accessible at the Internet address https://www.ketbilietai.lt, as well as the KETBILIETAI Android and iOS app, and the products and services offered on the website.


For the purposes of this Policy, services include any actions performed by a visitor that they may perform on the website, including, but not limited to, using opportunities to take a driving theory test, register for driving courses, reading published information, writing comments, submitting and receiving any kind of information and/or data.


KEY TERMS USED IN THIS POLICY

ADTAĮ - Law of the Republic of Lithuania on Legal Protection of Personal Data.
Responsible Employee — an employee of the Company who, according to the position and nature of work, has the right to perform specific functions related to Data Processing.
GDPR - Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, which repeals Directive 95/46/EC (General Data Protection Regulation).
Company — the data controller UAB "DrivingEd", legal entity code 302653177.
Employee means a person who has entered into an employment contract, temporary employment contract or voluntary activity contract with the Company.
Data/Personal Data — any information about an identified or identifiable natural person (service recipient); an identifiable natural person is a person who can be directly or indirectly identified, in particular by an identifier such as a name, a personal identification number, location data and an internet identifier, or by one or more characteristics of that natural person's physical, physiological, genetic, mental, economic, cultural or social identity.
Data Recipient — a natural or legal person, government authority, agency or other body to which Personal Data is disclosed, whether or not it is a third party.
Service Recipient — data subject whose Personal data is processed by the Company.
Data Processing means any operation or set of operations performed on personal data by automatic or manual means, such as: collecting, recording, sorting, storing, adapting or changing, reproducing, searching, using, disclosing by transmission, distribution or otherwise making them available, arranging them in the required order or combining them by combining, blocking, erasing or destruction.
Data Processor — a natural or legal person, public authority, agency or other institution that processes Personal Data on behalf of the Company.
Third Party means a natural or legal person, public authority, agency or other institution that is not a Service Recipient, the Company, a data processor, or persons who are authorised to process personal data by the direct authority of the Company or the Data Processor.
Other concepts used in the Policy correspond to the concepts used in GDPR and ADTAĮ.

 

GENERAL PROVISIONS

The purpose of this Policy is to inform Service recipients about the procedure for processing their Data and their storage terms, and to indicate their rights in relation to this data and the Company.
The Company ensures that it complies with the following fundamental principles related to the processing of personal data:
Personal data must be processed in a legal, fair and transparent manner (principle of legality, fairness and transparency);
Personal data must be collected for established, clearly defined and legitimate purposes and not further processed in a manner incompatible with those purposes;
Personal data must be adequate, appropriate and only necessary to achieve the purposes for which they are processed (data minimisation principle);
Personal data must be accurate and updated when necessary; all reasonable measures must be taken to ensure that personal data that are not accurate, taking into account the purposes of their processing, are immediately deleted or corrected (principle of accuracy);
Personal data must be kept in such a form that the identity of the Service Recipient can be determined no longer than is necessary for the purposes for which the personal data is processed;
Personal data must be processed in such a way that adequate security of personal data is ensured through the application of appropriate technical or organizational measures, including protection against unauthorised or illegal data processing and against accidental loss, destruction or damage (principle of integrity and confidentiality);
The Company is responsible for compliance with the above principles and must be able to demonstrate compliance (principle of accountability).
The Company may authorize Data Processors to process the Data under its control, i.e. information technology and electronic communication service providers, advisors, auditors, consultants, security services and other persons who process the data managed by the Company for the established purposes and according to the Company's instructions. The Data Processor's access rights to the Data are terminated upon termination of the personal data processing agreement concluded with the Company, or upon termination of this agreement.

 

PROCESSING OF DATA OBTAINED BY PROVIDING SERVICES ON THE WEBSITE www.ketbilietai.lt

The Company processes the following personal data of persons registered on the website ketbilietai.lt:
1. Name, surname;
2. Address;
3. Email address;
4. Telephone number;
5. Date of birth;
6. Personal code.


The basis of data processing is consent / performance of the contract.
Data is processed in accordance with Terms of use of the website.
The purpose of data use is the provision of services in accordance with the contract and the administration, monitoring and improvement of the provision of services.
Data is received directly from Service recipients, from the social network Facebook, from the payment system "Paysera LT" UAB and Google.
The data is transferred to IT service providers and driving schools.
Data can be transferred to other Third Parties only at their request and with a legal basis for transfer.

 

DATA PROCESSING FOR DIRECT MARKETING PURPOSES

The Company processes the following Personal data of persons who have given consent:
1. Email address.
2. Name, surname.
2. Legal basis for processing — consent.
3. Data received directly from Service recipients, Facebook and Google.
4. On the website, it is possible to freely choose to agree to receive notifications or not.
Data is transferred to IT service providers.
Data is not transferred to other third parties.

 

Based on a legitimate interest in helping the user to successfully prepare for driving exams, we can send informational messages (e.g. reminders about mandatory documents in the Regitra, changes in the exam procedure). These messages are not considered direct marketing, but are part of the service to help the user achieve their learning objective. The user has the right to refuse such messages at any time in his profile settings or by clicking on the link at the bottom of the email received. Direct marketing offers (newsletters) are sent only with the prior consent of the user. 

 

MANAGEMENT OF DATA COLLECTED BY COOKIES AND OTHER TOOLS (WEB BEACONS).

The data controller uses cookies and other tools (web beacons) in order to improve the quality of browsing the website www.ketbilietai.lt and the services provided on it. These tools collect the following information:
- data about visitors' actions and their browsing habits on the website.
The basis of data processing is Consent.
The data is obtained directly from the data subjects.
The purpose of data use is to ensure a more efficient and high-quality operation of the website, monitoring the flow of visitors and protecting Service recipients from unauthorised use of their login data.
The Company does not use cookies and other tools to collect personal information about users, but certain information processed may be considered personal data.
On the website, it is possible to choose to accept the use of cookies.
Data is transferred to IT service providers.
Data is not transferred to other third parties.

 

INFORMATION PROVIDED TO SERVICE RECIPIENTS

The data managed by the Company is provided to third parties with the consent of the Service recipient or another legal basis for data provision.
Service recipients must provide the following information before processing their Personal Data:

  • Company name, details and contact details;
  • Purposes of data processing;
  • Legal basis for data processing;
  • Contact details of the Data Protection Officer, if applicable;
  • The period of storage of personal data or, if this is not possible, the criteria used to determine that period;
  • The right to request that the Company allow access to the personal data of the Service Recipients and correct or delete them, or limit data processing, or the right to object to Data being processed, as well as the right to Data Portability;
  • The right to submit a complaint to the supervisory authority;
  • If any, recipients of personal data or categories of recipients of personal data;
  • When applicable, about the Company's intention to transfer personal data to a third country or an international organization;
  • When applicable, that there is automated decision-making, including profiling, and, at least in those cases, meaningful information about its rationale, as well as the meaning of such Data Processing and the expected consequences for the Service Recipient.

Information must be presented in a concise, transparent, clear and easily accessible form, in plain language.
Information is provided in writing, by email or other means. At the request of the Service Recipient, information can be provided verbally, but in all cases, information collected about a specific person is provided only after the Service Recipient proves his identity and submits a signed request or a copy thereof.


The obligation to provide information does not apply to the extent that:
1. Providing such information is impossible or would require a disproportionate effort. In such cases, the Company takes appropriate measures to protect the freedoms and legitimate interests of the Service recipient, including public publication of information;
2. The fact of obtaining or disclosing data is clearly established in the legal acts of the EU or the Republic of Lithuania, which establish appropriate measures to protect the legitimate interests of the recipient of the Services;
When personal data must remain confidential, including the established obligation to maintain secrecy.

 

DATA RETENTION PERIODS

The Company applies different personal data storage terms depending on the categories of personal data processed:

  1. The Company applies different personal data storage terms depending on the categories of personal data processed:

     

Purpose of processing personal data

Storage term

Provision of services on the website www.ketbilietai.lt 

2 years after the last login

 

Provision of services on the website www.ketbilietai.lt when money or credits are accumulated in the person's account

2 years after the last login

Data processing for direct marketing purposes

2 years from the last connection to the website or other action in the Ketbilietai.lt system

Processing of data collected by cookies and similar means in order to improve the quality of using the page

The period for which a cookie remains on the computer depends on the type of cookie.

 

Exceptions to the above-mentioned retention periods may be established to the extent that such deviations do not violate the rights of Service recipients, meet legal requirements and are properly documented.
If the Data is used as evidence in a civil, administrative or criminal case or in other cases established by law, the Data may be stored as long as necessary for these Data Processing purposes and destroyed immediately when they are no longer needed.


DATA DESTRUCTION

Destruction is defined as the physical or technical act of rendering the data contained in a document irrecoverable by conventional commercially available means.
Personal data stored in electronic form are destroyed by deleting them without the possibility of recovery.
The employee working on the specific computer where the personal data files are stored is responsible for the destruction of personal data files stored in electronic form.
The employees who administer these systems are responsible for the destruction of the data contained in the Company's databases and IT systems.

 

RIGHTS OF SERVICE RECIPIENTS

The Service Recipient can exercise the following rights:
1. The right to be informed;
2. Right of access;
3. The right to erasure;
4. The right to rectification;
5. The right to restrict data processing;
6. The right to data portability;
7. The right to object to data processing;
8. Rights related to automated decision-making and profiling.

The rights are exercised according to the following procedures for fulfilling the requests of Service recipients, which create better conditions for the necessary actions to be performed within the specified periods.
In a standardized manner, requests for access to Data from Service recipients (hereinafter referred to as data subjects in this policy) are received after they fill out a request to allow access to personal data.
The Company must inform Data Subjects about their rights in a clear, concise, transparent, understandable and easily accessible form, in plain language.

 

GENERAL PROCEDURAL REQUIREMENTS
1. Upon receiving any request, demand or other form of appeal from the data subject, the employees of the Data Controller must first determine the identity of the applicant. To confirm your identity, it is sufficient to submit a copy of your identity document with the application (such documents include a driver's license, passport, personal identity card or other official document with a photo and signature).
2. If the appeal is submitted by a representative of the data subject, the employee must take steps to ensure the right of such person to represent a specific person.
3. After making sure that the request is submitted by an identified person who has the right to do so, the Company's employee must get acquainted with the content of the request and, if the data subject requests, get acquainted with the personal data or delete them.


PROCEDURE — ACCESS TO PERSONAL DATA
The data subject, directly or through a representative, has the right to receive confirmation from the Data Controller as to whether personal data relating to them are being processed, and if such personal data are being processed.
Upon receiving the data subject's request to access their personal data, the Responsible Employee reviews the Data Controller's databases to which he has access, looking for information about the data subject and sends a request to other employees to send the available data.
After receiving information from the employees about the available data, the Responsible Employee provides a copy of the processed personal data or provides access to this data.
The right to receive a copy cannot have a negative impact on the rights and freedoms of others, therefore the Responsible Employee must obscure or remove information related to other natural persons. In addition, the Responsible Employee must ensure that these rights do not adversely affect the rights and freedoms of others, including trade secrets or intellectual property rights.
Together with a copy of the data (or separately if a copy is not provided), the Responsible Employee provides the data subject with the following information:

  • Purposes of data processing;
  • Categories of relevant personal data;
  • Data recipients or categories of data recipients to whom personal data has been or will be disclosed, in particular, data recipients in third countries or international organizations;
  • The period of storage of personal data or, if it is not possible to specify it, the criteria used to determine that period;
  • The right to request the Data Controller to correct or delete personal data or to limit the processing of personal data related to the data subject or to object to such processing;
  • The right to submit a complaint to the State Data Protection Inspectorate as a supervisory authority;
  • When personal data is not collected from the data subject, all available information about its sources;
  • Whether automated decision-making, including profiling, is applied and, at least in those cases, meaningful information about its rationale, as well as the meaning and expected consequences of such data processing for the data subject.

 

When personal data is transferred to a third country or an international organization, the data subject must be informed of the appropriate security measures related to the data transfer or other basis on which such transfer is carried out.
When the data subject submits the request by electronic means, and unless the data subject requests it to be submitted otherwise, the information is provided in a commonly used electronic form.

 

SHARING DATA WITH THIRD PARTIES

In order to ensure the smooth and high-quality provision of Services, analyse the use of the website and the app, optimise advertising campaigns and securely process payments, in certain cases we may share your Personal Data with reliable third-party service providers. We ensure that your data will be transferred to these service providers only to the extent that it is necessary to achieve the stated goals and in compliance with all applicable legal requirements.

Your data may be shared with the following categories of data recipients and for the following purposes:

Google Analytics (Google Ireland Limited): This data is used to analyse website and app traffic, collect user behaviour statistics and improve services. Google Analytics helps us understand how users interact with our services and optimise the user experience. Pseudonymised data is collected, such as IP address (anonymized), device information, browsing history.

Google Ads (Google Ireland Limited): Data (e.g. pseudonymised browsing data related to your interest in our services) can be used to manage and optimise advertising campaigns so that we can show you relevant ads on our and other Google platforms.

"Paysera LT", UAB: These data (e.g. name, surname, payment amount, order information) are transferred for payment processing and execution of financial transactions when you choose to pay through the Paysera system. Paysera acts as a separate data controller for payment processing.

"Montonio Finance" AS: The following data (e.g. name, surname, payment amount, order information) are transmitted for payment processing and execution of financial transactions when you choose to pay through the Montonio system. Montonio Finance AS acts as a separate data controller for processing payments.

Before transferring data to third parties, we make sure that they apply appropriate technical and organizational measures to protect your Personal Data, comply with GDPR and other related legal acts.

 

PROCEDURE — RECTIFICATION AND ERASURE OF DATA
The data subject using the ketbilietai.lt, Android or iOS app has the right to demand that the Data Controller correct or delete personal data relating to them. The request to correct or delete personal data must be sent by the data subject to info@ketbilietai.lt.

Data deletion procedures are more detailed described here.

Depending on the purposes for which the data were processed, the data subject has the right to request that incomplete personal data be supplemented, including by submitting an additional statement.
Upon receiving the data subject's request to get acquainted with their personal data, the Responsible employee sends a request to other employees of the Data Controller to send the available data about the requesting data subject.
After receiving the employees' answers, the Responsible Employee assesses whether there are grounds to delete part or all of the data requested by the data subject to be deleted. If the Responsible Employee determines that such a basis exists, the Responsible Employee deletes the personal data of the data subject from the databases available to them and instructs other employees to delete the personal data of the data subject.
The data subject has the right to demand that the Data Controller delete the personal data relating to them, if this can be justified by one of the following reasons:

  • Personal data are no longer necessary to achieve the purposes for which they were collected or otherwise processed;
  • The data subject withdraws the consent on which the data processing is based, and there is no other legal basis for processing the data;
  • The data subject does not agree to the data processing and there are no overriding legal reasons for processing the data;
  • Personal Data has been processed unlawfully;
  • Personal data must be deleted in accordance with a legal obligation established by European Union or national law.

 

When the Data Controller has made personal data public and must delete the personal data, the Responsible Employee, taking into account the available technologies and implementation costs, takes reasonable steps, including technical measures, to inform the data controllers processing the data that the data subject has requested that such data controllers delete the personal data or their copies or duplicates.


GENERAL PROCEDURAL REQUIREMENTS

(Clauses 4 and 5) do not apply if data processing is necessary:

  • In order to exercise the right to freedom of expression and information;
  • In order to comply with a legal obligation established by European Union or national law, which requires the processing of data, or in order to perform a task carried out in the public interest;
  • For reasons of public interest in the field of public health;
  • For archival purposes in the public interest, for scientific or historical research purposes or for statistical purposes, if the stated right may make it impossible or may significantly hinder the achievement of the purposes of that processing; or
  • In order to assert, enforce or defend legal claims.

The responsible employee informs the data subject about the decision to correct or delete the data, and in the event that it is refused or the request is only partially fulfilled, the reasons for such a decision.

 

PROCEDURE — RESTRICTION OF DATA PROCESSING
The responsible employee must take steps to restrict the processing of the data of a specific data subject in any of the following circumstances:
The Data Subject disputes the accuracy of the Data for a period during which the Data Controller can verify the accuracy of the Personal Data;
The processing of the personal data is unlawful and the data subject does not consent to the deletion of the data and instead requests the restriction of its use;
The data controller no longer needs personal data for the purposes of processing, but the data subject needs them in order to assert, establish, exercise or defend legal claims; or
The Data Subject has objected to the Processing of the Data until it is verified whether the legitimate interests of the Data Controller prevail over the interests of the Data Subject.
When Data Processing is restricted, such Personal Data may be processed, with the exception of storage, only with the consent of the data subject or in order to assert, establish, exercise or defend legal claims, or to protect the rights of another natural or legal person, or for reasons of important public interest of the European Union or the Republic of Lithuania.
When it is decided to lift a restriction on Data Processing, the Responsible Employee implementing such a decision must inform the data subject before canceling the restriction to process data.

 

PROCEDURE — REQUEST FOR DATA PORTABILITY
Upon receiving the data subject's request, the responsible employee must contact other employees and collect from them and submit the personal data related to the applicant, which he submitted to the Data Controller in a structured, commonly used and computer-readable format. The responsible employee fulfills such a request only under the following circumstances:
Data processing is based on consent or contract; and
Data is processed by automated means.
In the event that a data subject with the right to Data Portability wishes the Data Controller to transfer personal data directly to another Data Controller, the Data Controller shall assess whether this is technically possible and inform the Data Subject thereof.
The right to Data Portability will not apply when the processing is necessary for the performance of a task carried out in the public interest.
The responsible employee must ensure that the exercise of the right to data portability does not adversely affect the rights and freedoms of others and, accordingly, transfer personal data exclusively related to a specific data subject.

 

PROCEDURE — OBJECTION TO THE PROCESSING OF PERSONAL DATA
The Data Subject has the right, on grounds relating to their particular situation, to object at any time to the processing of personal data relating to them, when such Data Processing is carried out based on the legitimate interest of the Data Controller or a third party as a legal basis for data processing.
When examining the objection, the Responsible Employee assesses whether the Data is processed for significant legitimate reasons that override the interests, rights and freedoms of the data subject, or for the purpose of asserting, enforcing or defending legal claims. In such a case, the objection is rejected and the Responsible Employee provides an answer to the data subject, explaining the reasons for the objection to stop data processing.
When the data subject objects to the processing of the Data for direct marketing purposes, the Responsible Employee must immediately take steps to prevent the Personal Data from being processed for such purposes.
When Personal Data is processed for statistical purposes, the data subject, on grounds relating to their particular situation, has the right not to consent to the processing of Personal Data relating to them, except in cases where data processing is necessary to perform a task carried out for reasons of public interest.

 

20 June 2025