Privacy Policy

SIA “HANSABUSS Latvija”

GENERAL TERMS

  • SIA “HANSABUSS Latvija”, registration No. 40003262339, legal address: Mednieku iela 2, Tukums, LV-3101, contact phone +371 80700002, e-mail address: info@hansalines.lv . By using this contact information or by visiting the legal address of SIA “HANSABUSS Latvija”, questions regarding the processing of personal data may be asked. A request for the exercise of one’s rights may be submitted in accordance with Section 6 of the Privacy Policy, “ACCESS TO PERSONAL DATA AND OTHER CUSTOMER RIGHTS”.
  • The purpose of the SIA “HANSABUSS Latvija” privacy policy (hereinafter – Privacy Policy) is to provide the customer (hereinafter – Customer) with information regarding the processing of personal data, in particular its purposes, scope, protection, and data storage.
  • The Privacy Policy applies to the personal data processing processes of Customers carried out by SIA “HANSABUSS Latvija” (hereinafter – Company), regardless of the form in which the Company receives the Customer’s personal data. The Company is the controller and processor of personal data.
  • The Privacy Policy also applies, among other things, to video surveillance carried out by the Company in the following manner – stationary video cameras located in bus interiors that film only the bus interior.
  • Within the meaning of the Privacy Policy, a Customer is a natural person – a passenger or another person who expresses a wish to use, uses, or could use the public transport services provided by the Company, or a person who has entered into or is preparing to enter into a contract with the Company for the receipt of services.
  • The Privacy Policy has been developed in accordance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council (27 April 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), and other applicable legislation in the field of privacy and data processing.

LEGAL BASIS AND PURPOSE OF DATA PROCESSING

  • The Privacy Policy applies to the Customer personal data processing processes carried out by the Company, and personal data is processed in relation to them on the following legal bases:
    • consent of the data subject, whereby the Customer gives consent to the processing of their personal data for a specific purpose (Article 6(1)(a) of the General Data Protection Regulation);
    • conclusion and performance of a contract where the Customer is a contracting party (Article 6(1)(b) of the General Data Protection Regulation);
    • compliance with a legal obligation applicable to the Company, based on external regulatory enactments (Article 6(1)(c) of the General Data Protection Regulation);
    • performance of a task carried out in the public interest or in the exercise of official authority vested in the Company (Article 6(1)(e) of the General Data Protection Regulation);
    • pursuit of legitimate interests in order to realize the interests and obligations of the Company arising from existing obligations between the Company and Customers or as determined in accordance with regulatory enactments (Article 6(1)(f) of the General Data Protection Regulation).
    • A technical and organizational measure carried out by the Company in the public interest to prevent (including mitigate) corruption risks is the placement of video surveillance equipment in locations where the Company’s authorized employees perform cash transactions (for example, public transport drivers selling single-trip tickets on certain routes). Video surveillance with audio recording as a physical control measure is recommended in the Corruption Prevention and Combating Bureau document “Guidelines on the basic requirements for internal control systems for the prevention of corruption and conflict of interest risks in public person institutions”, issued based on the Cabinet of Ministers Regulation No. 630 of 17 October 2017, “Regulations on the basic requirements for internal control systems for the prevention of corruption and conflict of interest risks in public person institutions”.
  • The Company’s purposes for processing personal data in accordance with its legitimate interests are as follows:
    • to carry out commercial activities by providing passenger transport services;
    • to effectively manage the Company’s commercial management processes, financial and business accounting, and analytics, including customer surveys, their research and analysis, service usage indicators and statistics, preparation of reports, etc.;
    • to perform and manage tasks and obligations assigned by the state and local government, including the granting and administration of fare discounts (granting and monitoring of fare discounts), verification and processing of Customer personal data for the granting and administration of fare discounts;
    • to protect property, including buses involved in the provision of the Company’s services;
    • to protect the vital interests of persons, including life and health;
    • to ensure safety in the relationship between the Customer and the employee, for example, to ensure public order and safety, prevent security threats, and ensure the safe provision of public transport services;
    • to ensure compliance with order in the provision of public transport services in accordance with the requirements of regulatory enactments, for example, to ensure public order, compliance with ticket sales regulations, as well as compliance with public transport usage regulations, including internal work regulations and labor protection requirements;
  • Regarding the processing of data carried out during the video surveillance process in the Company’s buses, several of the aforementioned purposes apply in accordance with the Company’s legitimate interests: to protect the vital interests of persons, including life and health; to prevent illegal actions, corruption, and other high-impact risks; to protect property, including buses involved in the provision of the Company’s services; to ensure safety in the relationship between the Customer and the employee; to ensure compliance with order in the provision of public transport services in accordance with the requirements of regulatory enactments. Consequently, regarding the processing of personal data carried out during the video surveillance process, it is possible to define one common purpose for the Company: ensuring quality control and improving the quality of the services provided by the Company.

RECIPIENTS OF PERSONAL DATA

  • The Company processes Customer data using modern technology possibilities, taking into account the Company’s reasonably available organizational, financial, and technical resources, ensuring the confidentiality and appropriate protection of personal data and processing them in accordance with the personal data processing purposes, legal bases, and internal regulatory documents established by the Company.
  • When processing video surveillance data, the Company, as the data controller, ensures that only authorized persons have access to the technical and information resources used for the processing of video surveillance data, and that the processing of video surveillance data is carried out by authorized persons.
  • The Company does not disclose Customer personal data or any information obtained during the provision of services and the term of the contract to third parties, except:
    • if the data must be transferred to the respective third party within the framework of a concluded contract to perform an action necessary for the execution of the contract (for example, to a bank within the framework of settlements to ensure the service);
    • in accordance with the clear and unambiguous consent of the Customer;
    • in accordance with established legal obligations;
    • to persons provided for in external regulatory enactments upon their justified request, in the manner and to the extent specified in external regulatory enactments;
    • in cases specified in external regulatory enactments for the protection of the Company’s legitimate interests, for example, by applying to a court or other state institutions against a person who has infringed upon the Company’s legitimate interests.
  • Personal data may be sent, transferred, or made available to the following recipients, including but not limited to:
    • public authorities, for example, state or municipal police, VSIA “Autotransporta direkcija” (Road Transport Administration);
    • outsourced service providers involved in the service provision process;
    • insurance service providers for the review of insurance cases;
    • Sworn bailiffs, sworn notaries, sworn advocates in the performance of their professional duties;
    • other persons related to the provision of the Company’s services.
  • The Company does not transfer or make Customer data available to recipients outside the European Union or the European Economic Area, or to international organizations.

CATEGORIES OF PERSONAL DATA

  • The Company processes the following personal data of Customers:
    • personal identification data – name, surname, personal identity number, data from an identity document, for example, when reviewing Customer applications;
    • visual identification data of a personalized smart card – name, surname, smart card number, photo, and additional information according to the type of smart card, for example, for the bus driver or inspector to verify that the personalized smart card belongs to the passenger;
    • data from a document certifying a person’s rights – name, surname, status, document expiration date, for example, disability certificate data in cases where it is a document certifying the right to travel and is checked by the bus driver or inspector;
    • personal contact information – address, phone number, e-mail address, for example, in the case of Customer applications and/or complaints, as well as in accordance with a contract in cases where a representative of a legal entity is indicated;
    • video surveillance data – video image, photo fixation, and other data related to the video surveillance process (date and time, route), for example, in cases of requests from state or municipal authorities, in accident and violation situations, as well as during the video control process;
    • special categories of data – Customer health data, including Customer disability data, for example, data submitted by the Customer regarding injuries sustained in a road traffic accident;
    • customer opinion – for example, Customer survey results, Customer feedback, thanks, and complaints.
  • This section of the Privacy Policy lists the most significant types and examples of personal data categories processed by the Company.
  • The Customer uses the Company’s website www.hansalines.lv anonymously, and at the moment interaction with the Company’s website begins, the Company may receive non-identifying information about the Customer as a user. Non-identifying information may include the browser name, computer type, and technical information about the type of connection to the Company’s website.

PERSONAL DATA RETENTION PERIOD

  • Customer data is stored in accordance with the retention periods established by the Company in accordance with external regulatory enactments.
  • The retention period for Customer data is determined in accordance with the periods specified in regulatory enactments for ensuring the Company’s legitimate interests or for the performance of contracts.
  • Customer data is stored as long as the Customer or the Company can realize their legitimate interests (for example, by applying to a court).
  • Video surveillance data is stored temporarily at the place of data acquisition or storage in a local video archive. The duration of temporarily stored video surveillance data is up to 3 months for video materials from those video cameras that film bus interiors.
  • If necessary, in order to realize the Company’s legitimate interests (for example, in cases of road traffic accidents, hooliganism, violations of safety and order regulations, etc.), video surveillance data may be extracted for long-term storage on a video storage site. The Company extracts video surveillance data from the local video archive to the video storage site in the following cases:
    • if a request has been received from the State Police or another public authority;
    • if a complaint has been received which the Company, in conjunction with the purpose of video surveillance, has assessed as sufficient for processing such a request;
    • if an event has occurred that automatically informs of signs of a security incident;
    • if a violation of safety or order regulations is detected during video control.
  • After the end of the Customer data retention periods specified in regulatory enactments or the end of legitimate interests, Customer data is deleted. Video materials that, in order to implement the Company’s legitimate interests, have been extracted from the local video archive for storage on a video storage site, are stored for up to 1 year, unless a justification for extending the period has been established.

ACCESS TO PERSONAL DATA AND OTHER CUSTOMER RIGHTS

  • Customer personal data is information of restricted access and is processed in accordance with the personal data processing purposes, legal bases, and regulatory enactments established by the Company.
  • The Customer has the right to submit a data request in the general manner, asking for an explanation of what data about them is being processed and which data needs to be restricted. Such a request will be fulfilled if it is legally justified and technically possible. Other data recipients will also be informed about data restriction requirements.
  • The Customer has the right to receive information about the processing of their personal data, as well as to request the Company to supplement, correct, or delete it, if permissible in accordance with regulatory enactments or the Company’s legitimate interests, and to the extent technically possible. Regarding data obtained as a result of video surveillance, the data cannot be corrected or supplemented, as otherwise it will be considered falsification or distortion of information.
  • The Customer also has the right to withdraw their consent to data processing. Withdrawal of consent does not affect data processing carried out during the time when the Customer’s consent was in force. By withdrawing consent, the processing of data carried out on other legal bases will not be terminated.
  • The Customer may submit a request to the Company regarding the exercise of their rights in the following manner:
    • in writing by sending an official written application to the Company or by submitting it in person at the Company’s legal address at Mednieku iela 2, Tukums, LV-3101, Latvia;
    • by e-mail, by sending an official written application signed with a secure electronic signature and containing a time stamp to the Company’s e-mail address info@hansalines.lv.
  • Upon receiving the Customer’s request for the exercise of their rights, the Company verifies the Customer’s identity, evaluates the request, and fulfills it in accordance with regulatory enactments, to the extent technically possible. The Company sends the response to the Customer by mail or to their e-mail, depending on the method of receiving the response indicated in the letter.
  • A response containing personal data or a response regarding the exercise of one’s rights is provided to the Customer only if the Customer has submitted an official written application and the Customer has been identified in the following manner: for in-person identification, the Customer arrives at the Company’s legal address at Mednieku iela 2, Tukums, LV-3101, Latvia and informs the Company’s representative that they wish to receive personal data and have arrived for in-person identification. The Customer presents an identity document to the Company’s representative.
  • If the Customer has complaints or questions related to the Privacy Policy or the Customer has detected a possible personal data protection violation, the Customer shall contact the Company using the communication channels indicated in the data controller’s contact information, which are specified in Section 1 of the Privacy Policy, “GENERAL TERMS”.
  • The Company responds to every written application from a data subject, including regarding the exercise of their rights, within one month.
  • The Company ensures the fulfillment of data processing and protection requirements in accordance with regulatory enactments and, in the event of a Customer’s objection, performs useful actions to resolve the objection. However, if this is not successful, the Customer has the right to apply to the supervisory authority – the Data State Inspectorate (www.dvi.gov.lv), by submitting a relevant question or complaint.

OTHER TERMS

The Company has the right to make additions to the Privacy Policy, making its current version available to the Customer. The current Privacy Policy is posted on the Company’s website www.hansalines.lv .

The Privacy Policy enters into force on January 2, 2025.