1. Who we are
NEO Finance, AB (legal entity code 303225546), with its registered office at Ukmergės st. 126, LT-08100 Vilnius, Lithuania (hereinafter – “NEO Finance”, the “Company”, “we”), is the data controller of personal data referred to in this Information Notice on the processing of personal data (hereinafter – the Notice).
General contacts: tel. +370 700 80075, e-mail [email protected]
Data Protection Officer: [email protected]
2. Why you are receiving this Notice
NEO Finance has entered into an agreement with Witty Global, UAB (legal entity code 305433923) (hereinafter – “Witty”), under which, as of 3 August 2026 (hereinafter – the Transfer Date), NEO Finance takes over the administration of Witty clients’ (hereinafter – the “Clients”, “You”) unclaimed electronic money balances and the related obligation to return such balances, and acquires Witty’s rights related to certain applicable fees.
In order to administer the remaining e-money balances, as of the Transfer Date NEO Finance has received from Witty and processes the personal data of Witty Clients. This Notice explains how NEO Finance processes personal data as an independent data controller. When processing your personal data, we comply with the applicable legal acts in force, including the General Data Protection Regulation (hereinafter – GDPR, the Regulation), the Law on Legal Protection of Personal Data of the Republic of Lithuania, and the requirements of other legal acts governing the security of personal data.
Witty remains responsible for the processing of personal data related to its activities up to the Transfer Date, and for other matters not taken over by NEO Finance under the transfer agreement – for such matters you should contact Witty using the contact details provided by it.
3. Where we obtain your personal data from
We primarily receive your personal data from Witty. After the Transfer Date, we may also obtain or create personal data:
-directly from you, when you contact us, provide instructions for the return of your e-money balance, exercise your rights, or otherwise communicate with us;
-from banks, payment service providers, or other parties involved in returning your e-money balance;
-from public registers, competent authorities, or compliance service providers, where necessary and permitted under applicable legal acts; and
-in our systems, when we record communications, refunds, fee calculations, account reconciliation, and case administration actions.
4. Purposes and legal bases of processing
We process your personal data only for specific purposes related to the contractual requirements for administering and returning the transferred e-money balances and their implementation.
Table: Processing purposes, data categories, legal bases and retention periods
|
No. |
Purpose of processing |
Personal data processed |
Legal basis for data processing |
Data retention period |
|
|
Administration and return of remaining electronic money balances |
First and last name, personal identification number/date of birth or equivalent identifier, client ID, e-mail address and phone number, residential and/or correspondence address, remaining e-money balance, currency, e-money account identifiers, bank account for balance return, refund status, payment dates and related transaction references. |
GDPR Article 6(1)(b) – performance of a contract with the data subject |
10 years after the return of the e- money balance |
|
|
Calculation, write-off, collection, and recovery of applicable fees |
First and last name, personal identification number/date of birth or equivalent identifier, client ID, e-mail address and phone number, residential and/or correspondence address remaining e-money balance, currency, e-money account identifiers, , refund status, payment dates and related transaction references, fee and claim data. |
GDPR Article 6(1)(b) – performance of a contract with the data subject |
10 years after the return of the e- money balance |
|
|
Client identification and verification |
First and last name; personal identification number/date of birth; nationality; copy of identity document and the data contained therein (type, number, issue and expiry data; photograph; signature, if provided in the document); client and e-money account identifiers; results of identification and verification. |
GDPR Article 6(1)(c) – compliance with a legal obligation applicable to the Company under the Law on the Prevention of Money Laundering and Terrorist Financing of the Republic of Lithuania |
8 years from the end of the business relationship (return of the e-money balance) |
|
|
Communication with clients transferred from Witty |
First and last name, client ID, e-money account number, e-mail address, phone number, residential and/or correspondence address, e-money account balance and currency, amount of fees payable, bank account number for balance return, balance return instructions, content of correspondence, content of inquiries and requests, date and time of communication; technical data (if communication takes place by electronic means – IP address, location, device, browser). |
GDPR Article 6(1)(f) – legitimate interests of the Company in ensuring effective communication with clients when reviewing and responding to their requests and inquiries |
Until the return of the e- money balance |
|
|
Compliance with legal and regulatory obligations (prevention of money laundering, terrorist financing, and fraud) |
First and last name, personal identification number, date of birth, nationality, residential and/or correspondence address, copy of identity document and the data contained therein , client ID, e-money account number, e-money account balance and currency, transaction history (dates, amounts, currencies of transactions performed, payer and payee data, purpose of payment), source of funds, bank account number for the return of funds, purpose and nature of the business relationship, , PEP status, links to politically exposed persons, sanctions screening results, client risk level (classification), risk assessment factors, indicators of unusual or suspicious transactions, results of checks and investigations carried out, explanations and documents provided by the client, content of correspondence, and information submitted to competent authorities. |
GDPR Article 6(1)(c) – compliance with a legal obligation applicable to the Company under the Law on the Prevention of Money Laundering and Terrorist Financing of the Republic of Lithuania |
8 years from the end of the business relationship (return of the e-money balance) |
|
|
Handling of complaints and disputes of clients transferred from Witty |
First and last name, phone number, e-mail address, residential and/or correspondence address; date of complaint, other personal data provided in the complaint and/or necessary to review the complaint, technical data (if the complaint is submitted electronically – IP address, location, device, browser). |
GDPR Article 6(1)(c) – legal obligation applicable to the Company (Resolution No. 03-105 of the Board of the Bank of Lithuania of 6 June 2013) |
3 years after the complaint has been reviewed |
|
|
Call recording (ensuring quality of client service, fraud prevention) |
Incoming and outgoing voice calls and their recordings, call date, time, call duration, caller’s phone number, voice data, other personal data provided during the call (including first and last name, contact details, financial data). |
GDPR Article 6(1)(a) – consent of the data subject |
3 months – recordings intended to ensure the quality of client service |
Not used for marketing. We will not use the transferred data for direct marketing or for offering unrelated products or services, except where you give your consent to such data processing.
5. To whom may your personal data be transferred?
Depending on the basis for data provision, we may transfer your personal data to engaged service providers (data processors) who help us to provide services to you and who therefore need to process your personal data. Engaged data processors process personal data only in accordance with the Data Processing Agreements signed with them, which set out all data processing conditions and security requirements; data processors will process personal data according to our instructions and to the extent we determine, only insofar as necessary to achieve the data processing purposes.
-Providers of information technology services, such as hosting services and other services for the development and maintenance of information systems we use;
-Service providers of anti-money laundering and counter-terrorist financing prevention services, fraud prevention services, and remote identity verification;
-Service providers of data center and infrastructure services (e.g., rental of servers).
Other data recipients to whom the Company transfers personal data process it independently, i.e., they independently determine the purposes and means of data processing. We may transfer your personal data to the following recipients:
-banks, payment service providers, and other financial institutions involved in returning e-money balances;
-other professional service providers (auditors, consultants, notary offices, bailiffs’ offices, persons providing us with legal services, attorneys);
-state authorities to which we are required to provide data (the State Tax Inspectorate under the Ministry of Finance, the Bank of Lithuania, the Financial Crime Investigation Service under the Ministry of the Interior, the police and/or other law enforcement authorities, courts, etc.)
-Witty, where necessary to reconcile transferred records, correct inaccuracies, or resolve matters directly related to balances or assigned claims, or where the request relates to actions prior to the Transfer Date
6. Transfer of data outside the European Economic Area
We do not transfer the personal data referred to in this Notice outside the European Economic Area (EEA).
7. What are your rights?
As a data subject, you have all the rights established by the Regulation.
-to know about the processing of personal data and right to access the data being processed – to obtain information as to whether we process your personal data and, if such personal data is processed, the right to access your personal data;
-to request the rectification of personal data, if you find that the personal data being processed about you is inaccurate or incorrect;
-to request the restriction of processing actions, except for storage – in cases where, upon reviewing the personal data, it is established that the data is incorrect, incomplete, or inaccurate, or is being processed unlawfully;
-to request the erasure of personal data (“the right to be forgotten”), where the request can be justified by at least one of the reasons specified in Article 17(1) of the Regulation, except where your data must be retained on the basis of legal obligations applicable to the Company or for the establishment, exercise, or defence of legal claims;
-to object to the processing of personal data, where such data is processed or intended to be processed on the basis of a legitimate interest pursued by the Company, including profiling, except where the data is processed for compelling legitimate reasons that override your interests, rights, and freedoms as a data subject, or in order to establish, exercise, or defend legal claims;
-to receive personal data concerning you that you have provided to the Company, processed by automated means and based on consent or a contract, in a commonly used machine-readable format, and to transmit it to another controller (the right to data portability), where technically feasible;
-to object to being subject to a decision based solely on automated processing, including profiling;
-to withdraw your given consent to the processing of personal data at any time by submitting a notice to the Company.
If you believe that the Company’s actions or omissions violate your rights or the requirements of legal acts, you have the right to lodge a complaint with the supervisory authority – the State Data Protection Inspectorate.
You may exercise your rights yourself or through representatives by submitting a free-form request to us. The request may be submitted orally or in writing, in person, by post, or by electronic means (by e-mail to [email protected]). The request must be clear and comprehensive, and must indicate your first and last name, information on which rights and to what extent you wish to exercise, and how you would like to receive the response, and it must be signed. If you submit the request by electronic means, the information will also be provided by electronic means, unless you request otherwise in advance.
When processing your request, we have the right and obligation to verify your identity, which we will always endeavour to establish in the simplest and most convenient way for you. Your request must also contain sufficient information to allow us to reasonably verify your identity. If the request is submitted by an authorised representative, the request must be accompanied by a written power of attorney and information confirming the representative’s identity. If there are reasonable doubts as to the identity of the natural person submitting the request, we have the right to request additional information necessary to confirm your identity.
We endeavour to review your requests and provide information as quickly as possible, but no later than within 30 calendar days of receipt of the request. If, due to certain circumstances/the complexity of the request submitted (if assistance from engaged data processors is required) or due to the number of requests being handled by the Company, the Company is unable to review the request in time, the review period may be extended by up to two months, and we will inform you of this without delay. We will also inform you if we determine that, in contacting us, you have not complied with the procedure set out in this section, indicating the deficiencies. If you do not correct the indicated deficiencies or inform the Company of reasonable grounds why the indicated deficiencies cannot be remedied, we will not review the request.
Requests are reviewed and information and data are provided free of charge; however, in certain cases we have the right either to refuse to exercise your rights (where the request is unfounded, disproportionate, or repetitive), or the provision of information and data may be subject to a fee, taking into account the administrative costs of providing the information or of the notices or actions requested, in accordance with the requirements of legal acts and the rates set by the Company (if there is evident abuse of rights, unreasonably repeated requests for the provision of information, data, extracts, documents, etc.).
8. Automated decision-making
We do not use the personal data referred to in this Notice for making decisions based solely on automated processing, including profiling that could produce legal effects concerning you or similarly significantly affect you.
9. Security of your personal data
We apply technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, such data. Depending on the circumstances, these measures include access control, authentication, encryption or other secure transmission methods, logging, confidentiality obligations, incident management procedures, and regular review of access rights and service providers.
10. Amendments to this Notice
We may update this Notice when the data processing described herein changes or when required by legal acts. We will publish the current version of the Notice here, and, where appropriate, we will inform you directly of any material changes.
If you have any questions about this Notice or the processing of personal data, you may always contact the Company’s Data Protection Officer by e-mail at [email protected].