Privacy Policy
Last Updated: September 2025
Effective: This document is effective from the date of publication
🛡 GDPR Compliant
- Introduction and Data Controller Identification
Beacons of Mercy (hereinafter: "the Organization", "we", "our") operates as a data controller under GDPR (General Data Protection Regulation) and international privacy protection laws.
Data Protection Officer (DPO) Contact Details:
Email: [email protected]
Registered Entity: Beacons of Mercy, VšĮ (Public Institution)
Registration Number: 307453515
Registered Address: Veiverių g. 9B-1, Vilnius, Lithuania
Country of Registration: Republic of Lithuania (EU) - Personal Data Collected
2.1 Data Collected Directly from You
Identification Details: First name, last name, ID number (in cases required by law)
Contact Details: Email address, phone number, residential address
Financial Details: Credit card details (encrypted), bank account details, donation amounts
Demographic Information: Age, geographic location, religious affiliation (optional)
Communication: Email correspondence, messages, communication preferences
2.2 Data Collected Automatically
Network Data: IP address, estimated geographic location
Browser Data: Browser type, operating system, resolution
Usage Data: Pages visited, time spent, navigation patterns
Cookies: Unique identifiers, user preferences, session information - Legal Basis for Data Processing
Data processing is based on the following legal bases according to GDPR:
Article 6(1)(a) – Consent: Newsletter registration, marketing communication
Article 6(1)(b) – Contract Performance: Processing donations, issuing receipts
Article 6(1)(c) – Legal Obligation: Reporting to tax authorities and regulation
Article 6(1)(f) – Legitimate Interest: System security, fraud prevention
Article 9(2)(d) – Sensitive Data: Only in cases of explicit religious activity - Data Processing Purposes
Donation Processing: Receiving donations, issuing receipts, financial tracking
Communication: Activity updates, direct mailing, responding to inquiries
Regulatory Obligations: Reporting to authorities, money laundering prevention
Service Improvement: Analytics, user research, development
Security: Threat identification, fraud prevention, data backup - Information Sharing with Third Parties
5.1 Data Processors
Payment Processors: PayPal, Stripe (PCI DSS certified)
Email Services: Mailchimp, SendGrid
Cloud Storage: Amazon AWS (with DPA agreements)
Analytics: Google Analytics (with anonymization)
5.2 Mandatory Disclosure
Local tax authorities
Legal authorities according to legal requirements
Courts and enforcement authorities
5.3 International Transfers
Transfers outside the European Union are made only with appropriate safeguards:
European Commission adequacy decisions
Standard Contractual Clauses (SCCs)
Binding Corporate Rules - Data Subject Rights
6.1 Your Rights Under GDPR
Right of Access (Article 15): Receive information about processing of your data
Right to Rectification (Article 16): Correct incorrect or inaccurate data
Right to Erasure (Article 17): Delete data under certain conditions
Right to Restrict Processing (Article 18): Restrict processing under certain circumstances
Right to Object (Article 21): Object to certain processing
Right to Data Portability (Article 20): Receive data in a structured format
Right to Withdraw Consent (Article 7): Withdraw consent at any time
6.2 Submitting Requests
To exercise your rights, contact us at: [email protected]
We will respond to your request within 30 days , with the possibility of extending by an additional 60 days in complex cases. - Information Security
7.1 Technical Protection Measures
AES-256 encryption for sensitive information
SSL/TLS protection for all communication
Encrypted backups with multi-location storage
24/7 intrusion detection and monitoring systems
7.2 Organizational Protection Measures
Regular staff training on privacy protection
Limited access policy according to “need to know” principle
Periodic security audits
Confidentiality agreements with all employees - Data Retention
8.1 Retention Periods
Active Donor Details: As long as account is active + 7 years
Donation Data: 7 years from donation date (tax requirements)
Correspondence: 3 years from last correspondence
Website Usage Data: 25 months (Google Analytics)
Technical Cookies: Up to 2 years
8.2 Automatic Deletion
Our automatic deletion systems operate according to law and automatically delete information at the end of periods. - Data Breach
In case of data breach:
We will report to the privacy protection authority within 72 hours
We will notify you directly if the breach may affect you
We will take all necessary steps to limit the damage - Policy Updates
We may update this policy from time to time. Material updates will be communicated with 30 days advance notice via email. - Complaints and Inquiries
For questions or complaints:
DPO: [email protected]
Privacy Protection Authorities: According to country of residence
EU Data Protection Authorities: According to country of residence - Information Specific to Minors
We do not knowingly collect information from minors under 16 without parental consent. If such collection is identified — the information will be deleted immediately. - Profiling and Automated Decisions
We may use profiling for:
Personalized content adaptation
Identifying donation preferences
Fraud prevention
We do not have automated decision-making that significantly affects your rights.
This document was prepared in accordance with GDPR requirements and international law.
Last updated: September 2025