Marketing assets portal

Privacy Policy

How we handle the personal data of authorized users of the ERGOVENT Marketing assets portal.

1. Who We Are and Scope

ERGOVENT, JSC (registration code 305236840) is the controller of the personal data processed through the ERGOVENT Marketing assets portal (“Portal”). This Privacy Policy explains how we collect, use, protect, and share the personal data of authorized users.

The Portal is not publicly accessible. It is restricted to pre-approved distribution partners, dealers, and commercial representatives, and gives them access to ERGOVENT B2B brand assets, media files, and related services. This Policy applies only to the Portal.

2. Personal Data We Collect

We collect only the data needed to manage account access, verify identity, and deliver brand assets:

  • First name and surname
  • Pre-approved corporate or business email address
  • Represented company name
  • Technical and security data: IP address, browser and device information, session identifiers, authentication events, and login timestamps
  • Portal activity, such as file downloads

Access is granted through pre-approved email addresses using single-use verification codes (One-Time Passcodes, OTP). We do not create or store user passwords.

3. How We Obtain Your Data and Required Fields

We obtain personal data directly from you, from your company, or from an ERGOVENT representative who sponsors or administers your access, and automatically when you use the Portal.

Your name, business email address, company name, authentication data, and essential session and security data are required to provide and protect Portal access. If they are not provided, we cannot create or maintain your access. Any other information we request will be identified as optional.

4. Why We Use Your Data and Our Legal Bases

We process personal data to:

  • verify identity, issue OTP codes, manage authorized access, protect accounts, and prevent misuse;
  • respond to support requests and provide requested brand assets;
  • record downloads, administer asset licences, protect trademarks, and handle legal claims;
  • send service, security, and brand-guideline notices needed for Portal use; and
  • meet our legal obligations.

This processing relies on our legitimate interest in running a secure, restricted partner portal, on performing our agreement with you or your company where relevant, and on complying with the law. We have assessed this processing to be necessary and proportionate and not to override your rights.

We do not run marketing emails, newsletters, targeted advertising, analytics, or cross-site tracking through the Portal.

5. Essential Technologies

The Portal uses only technologies that are strictly necessary to authenticate users, keep sessions secure, prevent abuse, and protect the Portal — for example, session tokens and security identifiers. We do not use them for analytics, advertising, profiling, or cross-site tracking. Depending on the technology, the information is deleted when your session ends or kept only for the period needed for security and access control. Because these technologies are strictly necessary, a cookie consent banner is not required.

6. Who We Share Data With and International Transfers

We do not sell your personal data or disclose it for advertising or unrelated marketing. We share personal data only with:

  • authorized ERGOVENT personnel who need it for their work;
  • hosting, OTP, email delivery, security, and IT support providers acting under contract; and
  • public authorities where disclosure is required by law.

Service providers may use the data only to provide services to ERGOVENT and must protect it under data protection agreements.

Portal personal data is primarily hosted and processed within the European Economic Area (EEA). Where a service provider processes data outside the EEA, we rely on an adequacy decision where one applies, or on approved safeguards such as the European Commission’s Standard Contractual Clauses. You can request more information about these safeguards using the contact details below.

7. How Long We Keep Your Data

We keep personal data only as long as needed:

Data categoryRetention period
Account and contact dataWhile Portal access is active, plus 24 months after deactivation
Authentication and security logs12 months
Download and asset-licence recordsDuration of the business relationship, plus 3 years
One-time passcode (OTP) dataDeleted or made unusable when the code expires
Support correspondence3 years after the request is closed

We may keep specific data longer where the law requires it or where reasonably necessary to handle legal claims. After the applicable period, data is securely deleted or irreversibly anonymized.

8. Security

We use appropriate physical, technical, and organizational measures — including encrypted data transmission (TLS/SSL), restricted administrative access, and passwordless (OTP) authentication — to protect personal data against unauthorized access, loss, misuse, or alteration. No method of electronic storage or transmission is completely secure, so we cannot guarantee absolute security.

9. Your Rights

Subject to applicable law, you may request to:

  • access your personal data;
  • correct inaccurate or outdated data;
  • delete your data (“right to be forgotten”);
  • object to or restrict processing based on our legitimate interests; and
  • receive your data in a portable format where the legal conditions are met.

These rights are not absolute, and we may keep or continue processing data where the law allows or requires it. The Portal does not use automated decision-making or profiling that produces legal or similarly significant effects. Depending on where you live or work, local law may also give you the right to raise a concern with a data protection authority in your country.

To exercise any right, or to revoke access for a departing team member, contact us using the details in Section 12. We may ask for information to verify your identity.

10. Changes to This Policy

We may update this Policy to reflect changes in how the Portal works or in applicable law. We will update the date at the end of this document and, where practicable, notify authorized users of material changes by email or within the Portal before they take effect. A link to the current Policy is provided on the login screen and in your initial access invitation.

11. Your Acknowledgment

Access to the Portal is voluntary. By choosing to request access and use the Portal, you confirm that you have read this Privacy Policy and that you freely accept how your personal data is handled as described here. If you do not agree, please do not use the Portal. Where separate consent is ever required for another activity, we will ask for it separately.

12. Contact Us

For any questions about this Policy, to exercise your rights, or for any information you need about your personal data, please contact us. All requests are handled through the channels below:

ERGOVENT, JSC
Ryternos str. 3A, Biruliškės, Kaunas, LT-54469, Lithuania
Registration code: 305236840
VAT code: LT100012620415
Email: marketing@ergovent.com
Website: www.ergovent.com

You may also contact the regional manager of your ERGOVENT distributor company, who can assist you directly or pass your request to us.

This Privacy Policy was last updated on July 27, 2026. All rights reserved by UAB ERGOVENT.