Privacy policy

Last updated: 23d of July, 2026.

 

1. Introduction 

UAB Refra (“Refra“) is committed to protecting the privacy of individuals and ensuring that personal data is processed in a transparent, lawful and responsible manner.

Refra processes personal data only where necessary for specified business purposes and where a valid legal basis for such processing exists. All processing activities are carried out in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the applicable laws of the Republic of Lithuania and other relevant data protection legislation.

This Privacy Policy explains how Refra collects, uses, stores, shares and protects personal data, as well as the rights available to individuals whose personal data is processed.

This Privacy Policy applies to visitors of the Refra website, customers, prospective customers, business partners, suppliers, job applicants and other individuals who interact with Refra or use its products and services.

 

2. Categories of Personal Data Refra Collects

Refra collects and processes only the personal data that is necessary for defined business purposes. The categories of personal data processed depend on the nature of the relationship with Refra, the services provided and the communication channels used.

Depending on the circumstances, Refra may process the following categories of personal data:

  • Identification data, such as first name and surname.
  • Business contact information, including email address, telephone number, job title, company name and other business-related contact details.
  • Communication data, including correspondence, enquiry details, meeting records and other information provided during business communications.
  • Order, contract and warranty service information, required for order administration, contract performance, technical support, warranty services, repairs and other activities related to the provision of Refra’s products and services.
  • Technical equipment information, where required for diagnostics, technical support, warranty services or fault analysis.
  • Website usage and cookie data, collected to ensure the proper operation and security of the website, analyse website performance and improve the user experience.
  • Recruitment data, including information contained in a curriculum vitae (CV), cover letter or job application, such as education, professional experience, qualifications and any other information voluntarily provided during the recruitment process.

Refra applies the principle of data minimisation and collects only personal data that is relevant and necessary for the purposes for which it is processed.


3. Purposes of Processing

Personal data is processed only for specified, explicit and legitimate purposes.

Refra may process personal data in order to:

  • respond to enquiries and manage ongoing communications;
  • prepare quotations and negotiate, conclude and perform contracts;
  • administer and fulfil orders;
  • provide technical support, warranty services and repair activities;
  • manage relationships with customers, suppliers and business partners;
  • ensure the operation, security and performance of the Refra website;
  • comply with applicable legal and regulatory obligations;
  • establish, exercise or defend legal claims and protect Refra’s legitimate business interests;
  • send marketing communications where consent has been obtained or where otherwise permitted by applicable law;
  • manage recruitment processes, assess candidates’ suitability and communicate regarding employment opportunities.

Refra does not use personal data for automated decision-making or profiling that produces legal effects or similarly significant consequences for individuals.


4. Legal Basis for Processing

Refra processes personal data only where a valid legal basis for such processing exists, as provided for under the General Data Protection Regulation (GDPR).

Depending on the specific circumstances, personal data may be processed on one or more of the following legal bases:

  • Performance of a Contract – where processing is necessary to enter into or perform a contract, administer orders, provide technical support, warranty services or fulfil other contractual obligations.
  • Pre-contractual Steps – where personal data of job applicants is processed in order to take steps at the applicant’s request prior to entering into an employment contract. Where consent is required for specific processing activities, such as retaining application information for future recruitment opportunities, such consent is obtained separately.
  • Compliance with a Legal Obligation – where Refra is required to process personal data in order to comply with applicable legal or regulatory requirements, including accounting, taxation and other statutory obligations.
  • Legitimate Interests – where processing is necessary for the purposes of Refra’s legitimate business interests, including improving customer service, managing relationships with customers and business partners, ensuring the security of its website and systems, or establishing, exercising or defending legal claims.
  • Consent – where applicable legislation requires the individual’s explicit consent, for example when sending marketing communications or using certain categories of cookies.

Where processing is based on consent, consent may be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of any processing carried out prior to its withdrawal.


5. Sharing of Personal Data

Refra does not sell personal data or disclose it to third parties for commercial purposes.

Where necessary for the conduct of its business activities, Refra may share personal data only with recipients who require such information for legitimate business purposes and in accordance with applicable legal requirements.

Depending on the nature of the services provided, personal data may be shared with:

  • providers of IT systems, cloud services and business software;
  • providers of accounting, auditing, legal or professional advisory services;
  • logistics and transportation service providers;
  • authorised Refra distributors and business partners, where necessary to respond to enquiries, fulfil orders or provide warranty services;
  • payment, financial and insurance service providers;
  • public authorities or regulatory bodies where disclosure is required by law or pursuant to a lawful request.

All service providers and business partners receiving personal data on behalf of Refra are required to implement appropriate safeguards and process personal data only to the extent necessary for the agreed purposes.

Where personal data is transferred outside the European Economic Area (EEA), Refra ensures that such transfers are carried out in accordance with the GDPR and are subject to appropriate safeguards to protect the personal data.


6. Data Retention

Refra retains personal data only for as long as necessary to fulfil the purposes for which it was collected or for as long as required under applicable legal or regulatory requirements.

Retention periods vary depending on the nature of the personal data and the purpose of processing. For example:

  • enquiry and correspondence records are retained for as long as necessary to manage the enquiry and maintain the business relationship;
  • contract, order and accounting records are retained for the periods required by applicable legislation;
  • warranty service and technical support records are retained for as long as necessary to fulfil warranty obligations and to establish, exercise or defend potential legal claims;
  • marketing data is retained until consent is withdrawn or until another legal basis for processing no longer applies;
  • cookie-related information is retained in accordance with the retention period applicable to each individual cookie;
  • recruitment data is retained for the duration of the recruitment process, unless the applicant agrees that the information may be retained for consideration in relation to future employment opportunities.

Once the applicable retention period has expired, personal data is securely deleted, anonymised or otherwise disposed of, unless continued retention is required by law.


7. Cookies

The Refra website uses cookies and similar technologies to ensure the proper functioning of the website, analyse its performance and improve the user experience.

Cookies may be used for the following purposes:

  • ensuring the functionality and security of the website;
  • remembering user preferences and settings;
  • analysing website performance and usage;
  • collecting statistical information on website traffic;
  • measuring the effectiveness of marketing and communication activities, where the user’s consent has been obtained.

Depending on their purpose, the following categories of cookies may be used:

  • Strictly Necessary Cookies, which are essential for the operation of the website and cannot be disabled.
  • Analytics Cookies, which help Refra understand how visitors interact with the website and support continuous improvements to its functionality and performance.
  • Functional Cookies, which remember user preferences and provide an enhanced browsing experience.
  • Marketing Cookies, which are used only where the user has provided consent and help deliver more relevant content and evaluate the effectiveness of marketing activities.

Users may manage or change their cookie preferences at any time through their browser settings or via the cookie management tool available on the Refra website.


8. Your Rights

Under the General Data Protection Regulation (GDPR), individuals are entitled to exercise a number of rights in relation to the processing of their personal data.

Subject to the conditions and limitations set out in applicable legislation, you have the right to:

  • request access to your personal data;
  • request the rectification of inaccurate or incomplete personal data;
  • request the erasure of your personal data where a legal basis for such erasure exists;
  • request the restriction of processing in certain circumstances;
  • object to the processing of your personal data where such processing is based on Refra’s legitimate interests;
  • receive the personal data you have provided in a structured, commonly used and machine-readable format, or request its transfer to another data controller where technically feasible;
  • withdraw your consent at any time where processing is based on consent.

Refra is committed to addressing all enquiries relating to the processing of personal data promptly and transparently. Individuals are therefore encouraged to contact Refra directly before submitting a complaint to a supervisory authority.


9. Information Security

Refra implements appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.

Access to personal data is restricted to employees and authorised service providers who require such access in order to perform their responsibilities. All individuals processing personal data on behalf of Refra are required to comply with confidentiality obligations and applicable data protection requirements.

Refra regularly reviews and updates its security measures, taking into account technological developments, emerging risks and applicable regulatory requirements.


10. Changes to this Privacy Policy

Refra may update this Privacy Policy from time to time to reflect changes in applicable legislation, technological developments or its business operations.

The most recent version of this Privacy Policy will always be published on the Refra website, and the date of the latest update will be indicated at the beginning of this document.

Where required by applicable law, Refra will communicate material changes through appropriate communication channels.


11. Contact Information

If you have any questions regarding this Privacy Policy or wish to exercise your rights in relation to the processing of your personal data, please contact Refra via sales@sienna-crocodile-334307.hostingersite.com