1. Controller
MB UNIQ GROUP, company code 308087387, Perkūnkiemio g. 19, LT-12120 Vilnius, Lithuania, is the controller for personal data processed through the UNIQ WAY website, booking service and corporate portal. Privacy requests: info@uniqway.lt or +370 656 64235.
2. Information we process
- Identity and contact data: passenger/booker name, business email, telephone and authorised-user details.
- Journey data: pickup, destination, date/time, flight number, passengers, luggage, instructions and accessibility or child-seat requests.
- Communication preferences: whether the passenger requested an optional WhatsApp arrival message and the time that consent was recorded.
- Company data: company name/code, address, VAT details, billing contacts, authorised bookers and cost centre.
- Transaction data: price, deposit, payment status, invoice and refund records. Full payment-card details are handled by Stripe and are not stored by us.
- Account and security data: authentication identifiers, login/session information and audit/security records.
- Communications: enquiries, applications, complaints and service messages.
- Technical data: IP address, browser/device information and necessary cookie data where generated by hosting, security or authentication systems.
Please avoid adding sensitive personal information to free-text notes unless genuinely necessary for safe service delivery.
3. Purposes and legal bases
| Purpose | GDPR basis |
|---|---|
| Quote, booking, payment, transport and customer support | Contract or steps requested before contract |
| Optional WhatsApp arrival message for a specific journey | Consent; the passenger may decline, untick the option or withdraw at any time |
| Corporate account administration and authorised bookers | Contract and legitimate interests in controlled business access |
| Invoices, accounting, tax records and legal claims | Legal obligation and legitimate interests |
| Fraud prevention, security, availability and misuse detection | Legitimate interests and legal obligations |
| Optional marketing | Consent, where required; withdrawal is available at any time |
| Non-essential analytics/cookies | Consent |
The WhatsApp option is used only for operational communication about the selected journey. It does not subscribe the passenger to marketing messages.
5. Retention
- Booking and service correspondence: normally up to 3 years after completion, longer where a dispute or legal claim remains active.
- Corporate account records: for the account relationship and normally up to 3 years after closure.
- Accounting, invoice and payment evidence: for the period required by Lithuanian accounting and tax law.
- Unsuccessful corporate applications: normally 12 months.
- Security logs: normally up to 12 months unless an incident requires longer investigation.
- Cookie/consent records: according to the periods described in the Cookie Policy.
Data may be retained longer where required by law, fraud prevention, insurance, litigation or an authority. It is then deleted or anonymised when no longer required.
6. Your rights
Subject to GDPR conditions, you may request access, correction, deletion, restriction, portability, objection and withdrawal of consent. You may also complain to the Lithuanian State Data Protection Inspectorate (VDAI). We may verify identity before responding and normally respond within one month.
Deletion is not absolute where information must be retained for legal, accounting, defence-of-claims or public-authority requirements.
7. Security and accounts
We use access controls, encrypted connections, row-level database security, restricted administrative access and payment providers designed to limit exposure. Public My Way access requires a signed booking-specific link, the secure Stripe return session, or the exact booking-reference and passenger-surname combination. Lookup attempts are rate limited and the public page does not receive payment-card identifiers, internal operational notes or unrestricted database access. No system is completely risk-free. Customers must protect booking references, access links and login credentials, use unique passwords and notify us promptly of suspected unauthorised access.
8. Passengers booked by another person
Corporate bookers and other customers must have authority to provide passenger information and should make this policy available to the passenger. We use that data only for the booking, service, safety, communication and related legal purposes.
9. Updates
We may update this policy when services, providers or legal requirements change. The current version and effective date will remain available on the website.