Privacy Policy
Last Updated: September 2025
Effective: This document is effective from the date of publication
🛡 GDPR Compliant

  1. Introduction and Data Controller Identification
    Beacons of Mercy (hereinafter: "the Organization", "we", "our") operates as a data controller under GDPR (General Data Protection Regulation) and international privacy protection laws.
    Data Protection Officer (DPO) Contact Details:
    Email: [email protected]
    Registered Entity: Beacons of Mercy, VšĮ (Public Institution)
    Registration Number: 307453515
    Registered Address: Veiverių g. 9B-1, Vilnius, Lithuania
    Country of Registration: Republic of Lithuania (EU)
  2. Personal Data Collected
    2.1 Data Collected Directly from You
    Identification Details: First name, last name, ID number (in cases required by law)
    Contact Details: Email address, phone number, residential address
    Financial Details: Credit card details (encrypted), bank account details, donation amounts
    Demographic Information: Age, geographic location, religious affiliation (optional)
    Communication: Email correspondence, messages, communication preferences
    2.2 Data Collected Automatically
    Network Data: IP address, estimated geographic location
    Browser Data: Browser type, operating system, resolution
    Usage Data: Pages visited, time spent, navigation patterns
    Cookies: Unique identifiers, user preferences, session information
  3. Legal Basis for Data Processing
    Data processing is based on the following legal bases according to GDPR:
    Article 6(1)(a) – Consent: Newsletter registration, marketing communication
    Article 6(1)(b) – Contract Performance: Processing donations, issuing receipts
    Article 6(1)(c) – Legal Obligation: Reporting to tax authorities and regulation
    Article 6(1)(f) – Legitimate Interest: System security, fraud prevention
    Article 9(2)(d) – Sensitive Data: Only in cases of explicit religious activity
  4. Data Processing Purposes
    Donation Processing: Receiving donations, issuing receipts, financial tracking
    Communication: Activity updates, direct mailing, responding to inquiries
    Regulatory Obligations: Reporting to authorities, money laundering prevention
    Service Improvement: Analytics, user research, development
    Security: Threat identification, fraud prevention, data backup
  5. Information Sharing with Third Parties
    5.1 Data Processors
    Payment Processors: PayPal, Stripe (PCI DSS certified)
    Email Services: Mailchimp, SendGrid
    Cloud Storage: Amazon AWS (with DPA agreements)
    Analytics: Google Analytics (with anonymization)
    5.2 Mandatory Disclosure
    Local tax authorities
    Legal authorities according to legal requirements
    Courts and enforcement authorities
    5.3 International Transfers
    Transfers outside the European Union are made only with appropriate safeguards:
    European Commission adequacy decisions
    Standard Contractual Clauses (SCCs)
    Binding Corporate Rules
  6. Data Subject Rights
    6.1 Your Rights Under GDPR
    Right of Access (Article 15): Receive information about processing of your data
    Right to Rectification (Article 16): Correct incorrect or inaccurate data
    Right to Erasure (Article 17): Delete data under certain conditions
    Right to Restrict Processing (Article 18): Restrict processing under certain circumstances
    Right to Object (Article 21): Object to certain processing
    Right to Data Portability (Article 20): Receive data in a structured format
    Right to Withdraw Consent (Article 7): Withdraw consent at any time
    6.2 Submitting Requests
    To exercise your rights, contact us at: [email protected]
    We will respond to your request within 30 days , with the possibility of extending by an additional 60 days in complex cases.
  7. Information Security
    7.1 Technical Protection Measures
    AES-256 encryption for sensitive information
    SSL/TLS protection for all communication
    Encrypted backups with multi-location storage
    24/7 intrusion detection and monitoring systems
    7.2 Organizational Protection Measures
    Regular staff training on privacy protection
    Limited access policy according to “need to know” principle
    Periodic security audits
    Confidentiality agreements with all employees
  8. Data Retention
    8.1 Retention Periods
    Active Donor Details: As long as account is active + 7 years
    Donation Data: 7 years from donation date (tax requirements)
    Correspondence: 3 years from last correspondence
    Website Usage Data: 25 months (Google Analytics)
    Technical Cookies: Up to 2 years
    8.2 Automatic Deletion
    Our automatic deletion systems operate according to law and automatically delete information at the end of periods.
  9. Data Breach
    In case of data breach:
    We will report to the privacy protection authority within 72 hours
    We will notify you directly if the breach may affect you
    We will take all necessary steps to limit the damage
  10. Policy Updates
    We may update this policy from time to time. Material updates will be communicated with 30 days advance notice via email.
  11. Complaints and Inquiries
    For questions or complaints:
    DPO: [email protected]
    Privacy Protection Authorities: According to country of residence
    EU Data Protection Authorities: According to country of residence
  12. Information Specific to Minors
    We do not knowingly collect information from minors under 16 without parental consent. If such collection is identified — the information will be deleted immediately.
  13. Profiling and Automated Decisions
    We may use profiling for:
    Personalized content adaptation
    Identifying donation preferences
    Fraud prevention
    We do not have automated decision-making that significantly affects your rights.
    This document was prepared in accordance with GDPR requirements and international law.
    Last updated: September 2025