This Notice explains what personal data we process when you receive an invitation to one of our events, register for it (through an invitation, a registration link or at the on-site registration desk) and take part in it, why we do so, and what rights you have. It is provided under Articles 13 and 14 of the EU General Data Protection Regulation 2016/679 (GDPR).
1. Who processes your data
Data controller:
UAB „Penkių kontinentų bankinės technologijos“ (BS/2)
Company code: 125592767
Address: Kareivių g. 2, LT-08248 Vilnius, Lithuania
Email: info@bs2.lt
Website: https://www.bs2.lt/
Event management system: https://events.bs2.lt/
Hereinafter "the Organiser", "we".
For any question about the processing of your data, or to exercise your rights, write to info@bs2.lt.
2. Where we get your data
- From you — when you fill in the participation confirmation form, the registration form or the form at the registration desk.
- From our CRM system — if you or your organisation are already among our business contacts (clients, partners, participants of past events). From the CRM we take your name, job title, organisation, country and business contact details in order to send you an invitation and prepare your badge.
- During the event and our mailings — records of event entry, email opens and the use of your QR code (see sections 3.3–3.5).
3. What data we process and why
3.1. Invitation and registration
Data: first and last name, job title, organisation, country, business email address, business phone number, additional information and comments you enter in the form, your answer to the invitation (attending or declining, and the reason), the event, the date and time of registration.
Purposes: registering you, confirming your participation, preparing participant lists and badges, sending you organisational information (confirmations, the programme, your entrance pass, event materials), contacting you about the event.
Legal basis: steps taken at your request to arrange your participation — Art. 6(1)(b) GDPR; the Organiser's legitimate interest in holding events for its business contacts and inviting them — Art. 6(1)(f) GDPR.
3.2. Invitation mailings and their measurement
We send invitations to our events to business contacts in our CRM system. Our emails may contain a small image that shows whether the email was opened, and we record when the link in the invitation is followed. We use this in aggregate to assess our mailings and to avoid unnecessary reminders. We record the time of the open, the type of device or email client and a truncated IP address (its last part removed).
Legal basis: the Organiser's legitimate interest in promoting its events to business contacts — Art. 6(1)(f) GDPR.
You can stop receiving invitations at any time using the unsubscribe link in the invitation email or by writing to info@bs2.lt. We will then send you no further invitations. You can also prevent open tracking by blocking images in your email client.
3.3. Badge, event entry and visits to event areas
Your badge may show your first and last name, job title, organisation, country, participant category and a personal QR code. After you confirm your participation, an entrance pass with the QR code and a picture of your badge may be emailed to you.
At the entrance, our staff scan the QR code. We record the fact and time of entry, and visits to separate event areas (for example, a showroom) where entry to them is recorded by badge.
Purposes: identifying participants, access control, security, attendance records and planning future events.
Legal basis: arranging your participation — Art. 6(1)(b) GDPR; the Organiser's legitimate interest in event security and attendance records — Art. 6(1)(f) GDPR.
3.4. Digital business card behind the QR code
The QR code on your badge opens your digital business card on events.bs2.lt. The card shows your first and last name, job title, organisation, country, business email address and business phone number, and lets the visitor save your contact to their phone (a vCard file).
The card exists to make it easy for participants to exchange business contacts, which is what our events are for.
Please note:
- anyone who scans the QR code on your badge, or who receives the link to the card, can open it;
- the page is not indexed by search engines, and its address contains a random code that cannot be guessed;
- a contact saved by another participant to their phone, or a photo they took of your badge, stays with that person and cannot be deleted by the Organiser;
- we keep statistics of card views (time, device type, truncated IP address); they do not tell us who opened the card and are used in aggregate only.
Legal basis: the legitimate interest of the Organiser and of participants in business networking at the event — Art. 6(1)(f) GDPR. Only business contact details are shown.
If you do not want your card to be available, write to info@bs2.lt — before the event or at any time after it. We will switch the card off and the QR code will no longer open it; you remain registered for the event and we will admit you by other means.
3.5. Planning how we work with participants
To plan our team's time and prepare the event (seating, meetings, materials), we place participants in priority categories based on their job title. For this, the text of the job title — without your name, email address, organisation, country or any other data — may be sent for automatic classification to an artificial intelligence service provider (see section 4). A member of our staff can review and change the result.
The category is used only inside the Organiser, is never printed on the badge and has no legal effect on you. We do not take decisions based solely on automated processing that produce legal or similarly significant effects for you (Art. 22 GDPR).
Legal basis: the Organiser's legitimate interest in organising the event effectively — Art. 6(1)(f) GDPR.
3.6. Website operation and security
Data: IP address, browser and device information, server logs, cookies (section 7).
Purposes: making the forms work, protecting them against automated and abusive requests, investigating incidents.
Legal basis: the Organiser's legitimate interest in the security of its systems — Art. 6(1)(f) GDPR.
3.7. Special categories of data
Please do not enter information about your health, political opinions, religious beliefs, trade union membership or other special categories of data in the forms. If such information is needed for your participation (for example, accessibility requirements), we will ask for it separately.
4. Who receives your data
To the extent needed for the purposes above, your data may be received by:
- authorised staff of the Organiser;
- co-organisers and partners of the specific event — the participant list (name, job title, organisation, participation status) where needed to run the event;
- the event venue and security staff — for access control;
- badge printing service providers;
- hosting, email and technical support providers processing data on the Organiser's behalf and on its instructions;
- Google Ireland Limited / Google LLC — reCAPTCHA on the registration form (protection against automated requests; processes your IP address and browser information) and Google Fonts (font delivery; receives your IP address);
- GeoJS — a service that detects the country from your IP address, used to preselect the country code in the phone field;
- anyone who scans the QR code on your badge — the data on your digital business card (section 3.4);
- public authorities — where required by law.
We do not sell personal data or share it with third parties for their own marketing.
5. Transfers outside the European Economic Area
Some of the providers listed above (Google LLC, PBC and possibly GeoJS) are located in the United States or may process data outside the EEA. Such transfers rely on the European Commission's adequacy decision (EU–U.S. Data Privacy Framework) for certified companies, or on the Standard Contractual Clauses adopted by the European Commission.
You can request information about the safeguards applied by writing to info@bs2.lt.
6. How long we keep your data
- Registration data and records of your participation — [N] years after the event, for our records, planning future events and defending possible claims.
- Contact data in our CRM system — while the business relationship continues or until you object to its use.
- Email open and business card view records — [N] months.
- Digital business card — available while your badge is valid; it is switched off at your request or when the Organiser revokes the badge.
- A record that you unsubscribed — for as long as needed to make sure we do not invite you again.
When these periods end, the data is deleted or anonymised unless the law requires us to keep it longer.
7. Cookies and data stored in your browser
The forms on events.bs2.lt use:
- invitation form cookies — keep the values you type into the form on your device for up to 30 days, so you do not lose them if you open the page again. This data stays in your browser;
- language cookie — remembers the interface language;
- registration desk device cookie — used only on the Organiser's tablets at the event venue;
- reCAPTCHA cookies (Google) — on the registration form, to protect it against automated requests.
We do not use third-party advertising or analytics cookies. You can delete cookies in your browser settings.
8. Your rights
Where and to the extent provided by the GDPR, you have the right to:
- be informed about and access the data we hold about you;
- have inaccurate or incomplete data corrected;
- have your data erased;
- have the processing restricted;
- receive the data you provided in a machine-readable format;
- object to processing based on legitimate interest (Art. 21 GDPR) — including your digital business card and the job title classification; you can object to receiving invitations at any time, and we will then stop sending them;
- lodge a complaint with a supervisory authority.
To exercise your rights, write to info@bs2.lt. We will reply within one month. We may ask only for the additional information needed to confirm your identity.
The supervisory authority in Lithuania is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), L. Sapiegos g. 17, LT-10312 Vilnius, https://vdai.lrv.lt/. You may also contact the supervisory authority of the country where you live or work.
9. Is providing data mandatory
The fields marked as required in the form are needed to register you and arrange your participation. Without them we cannot register you or prepare your badge and entrance pass. All other fields are optional.
10. Security
We apply organisational and technical measures to protect your data against accidental or unlawful destruction, loss, alteration, disclosure and unauthorised access: access to the system for authorised staff only, encrypted connections, random unguessable links in QR codes and invitations, pages excluded from search engine indexing, and truncated IP addresses in statistics logs.
11. Changes to this Notice
We may update this Notice. The current version is always available in the registration forms on events.bs2.lt; its date is shown at the top.