01 · Controller
Who is responsible for your data
Proven Holding, UAB is the controller for this website, general enquiries and the current Proven Companies certification operation.
- Legal entity code
- 308121918
- Register
- Register of Legal Entities of the Republic of Lithuania
- Privacy contact
- info@provencompanies.com
“Proven Companies” and “Proven” refer to the business name and certification brand operated by Proven Holding, UAB. If a separate Irish company later becomes a controller or joint controller, this notice will be updated before that company processes personal data.
02 · Data
Personal data we may use
- Enquiry and business contact data: name, role, business email, telephone number, employer, country and correspondence.
- Applicant and assessment data: legal company name, registration number, website, authorised representative, application answers, supporting evidence and assessment communications.
- Public-source data: information from official company registers and other lawful sources relevant to the applicant business. This may include personal data relating to directors or authorised representatives.
- Certification data: certificate ID, legal company identity, country, activity, issue date, validity, status and an approved company description.
- Technical and analytics data: IP address, browser and device information, requested pages, timestamps, traffic source, consent choice, website interactions, security events and basic server logs. Optional analytics data is collected only with consent.
- Contract and payment administration: customer contact details, contract records, invoices and payment status. We do not intend to publish card details or collect them through this website.
We do not intentionally request special-category personal data. Please do not send health, biometric, political, religious or other sensitive personal information unless we have specifically confirmed that it is necessary and lawful.
03 · Use
Purposes and legal bases
| Purpose | Typical legal basis |
|---|---|
| Responding to an enquiry and considering eligibility | Steps requested before a contract; legitimate interests in operating a B2B enquiry process |
| Assessing an applicant and reviewing supplied or public information | Steps requested before a contract; legitimate interests in conducting a consistent, evidence-based assessment |
| Issuing, administering, renewing, suspending or withdrawing certification | Performance of a contract; legitimate interests in protecting the integrity of certification |
| Publishing and maintaining a verification record | Performance of a contract; legitimate interests in enabling certificate verification and preventing misuse |
| Accounting, legal compliance and dispute handling | Legal obligation; performance of a contract; legitimate interests in establishing or defending legal claims |
| Website security and operational logs | Legitimate interests in providing a secure and reliable service |
| Audience measurement through Google Analytics | Consent |
| Electronic marketing, if introduced | Consent, where consent is legally required |
Where we rely on legitimate interests, we consider the necessity of the processing, the effect on individuals and reasonable safeguards. You may ask us for more information about that assessment.
04 · Sources
Where information comes from
Information may come directly from you, the applicant company, an authorised representative, official company registers, contracted business-information providers and other lawful public sources. If we obtain personal data indirectly, we will provide the information required by law unless a lawful exception applies.
05 · Verification
Public certificate records
A certification record is intended to make a certificate independently verifiable. It may display the certified company’s legal name, company number, country, business activity, certificate ID, issue date, valid-until date, current status and a clearly identified company-supplied description.
Private financial evidence, internal scoring, confidential correspondence and personal contact details will not be published. A named signatory or representative will be shown only where this is necessary, expected for the document and appropriately authorised.
06 · Recipients
Sharing and international transfers
Personal data may be shared only as needed with authorised staff and contracted providers supporting hosting, security, communications, analytics, CRM, assessment data, document production, delivery, accounting, professional advice and payment administration. Website analytics is provided by Google Ireland Limited after consent. Providers must act under appropriate contractual and confidentiality obligations.
If personal data is transferred outside the European Economic Area, we will use an applicable safeguard, such as an adequacy decision or approved standard contractual clauses, and provide further information on request.
07 · Retention
How long information is kept
| Category | Indicative period or criterion |
|---|---|
| General enquiries | Up to 24 months after the last meaningful contact |
| Eligibility and unsuccessful applications | Normally up to 24 months after the decision, unless a longer period is needed for a complaint or legal claim |
| Customer and certification files | For the relationship and afterwards for the period required by contract, tax, accounting and legal-claim rules |
| Public verification record | While active and for a proportionate historical period afterwards, clearly marked as expired, suspended or withdrawn |
| Routine security logs | Normally up to 30 days, unless needed to investigate a security event |
| Google Analytics user and event-level data | Up to 14 months in the Analytics property; aggregate reports may be retained longer |
| Consent record | While consent is relied on and for a limited period needed to demonstrate compliance |
These periods may be shortened or extended where required by law, an active dispute, fraud prevention, security needs or an enforceable legal request. A documented operating retention schedule will apply where it is more specific.
08 · Rights
Your data protection rights
Depending on the circumstances, you may have the right to access, correct, erase or restrict your personal data, object to processing, receive portable data and withdraw consent without affecting earlier lawful processing. Some rights are limited where another lawful ground requires us to keep or use the information.
Certification decisions are intended to include human review. We do not currently make decisions about individuals based solely on automated processing that produce legal or similarly significant effects.
To exercise a right, email info@provencompanies.com. We may need proportionate information to verify your identity and clarify the request. You may complain to the Lithuanian State Data Protection Inspectorate ↗ or, where applicable, to the authority in the country where you live, work or believe an infringement occurred, including the Irish Data Protection Commission ↗.
09 · Security
Security and responsibility
We use proportionate organisational and technical measures intended to protect personal data. No internet service is completely secure, so please use appropriate care and do not send confidential assessment evidence through an ordinary contact form unless we have provided an approved channel.
10 · Cookies
Cookies and similar technologies
The website uses essential browser storage to remember your privacy choice. If you accept analytics, Google Analytics measures visits and website interactions. Analytics remains off when you reject it, and no advertising or remarketing cookies are intentionally used. See the Cookie Policy for the inventory and controls.
11 · Updates
Changes and contact
We will update this notice before material new processing begins, including connection of the CRM, payment provider, assessment suppliers or a separate Irish operating company. The latest revision date will always be shown at the top.
Questions about this notice can be sent to info@provencompanies.com.
