Privacy Policy
Please read this document carefully, as it presents the most important information about the processing and storage of your personal data when you use the www.judu.lt self-service portal and the m.Ticket, m.Parking and JUDU apps administered by us, visit the www.judu.lt website, and visit the Facebook, Instagram, YouTube or LinkedIn accounts of Municipal Enterprise “Susisiekimo paslaugos”. When collecting and using your data, we comply with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter – the GDPR), the Law on Legal Protection of Personal Data of the Republic of Lithuania, and other legal acts regulating the protection of personal data.
Please note that the terms of use of the m.Ticket, m.Parking and JUDU apps also contain information about the processing of your data when you use these apps.
As this Privacy Policy (hereinafter – the Policy) may change without separate notice, please check it each time you visit the www.judu.lt website and the JUDU app. The latest version of the Policy is available on the website.
For broader information on data processing, please refer to the Personal Data Protection section of the website.
1. WHO ARE WE?
Your personal data is collected, used and stored by:
Municipal Enterprise “Susisiekimo paslaugos” (hereinafter – SĮSP)
Legal entity code: 124644360
Address: Laisvės pr. 10A, 04215 Vilnius
Email address: [email protected]
Telephone number: +370 5 210 70 50
2. WHY AND WHAT DATA DO WE COLLECT ABOUT YOU?
2.1. To create a user account in the customer self-service portal. To use SĮSP services in the customer self-service portal, you must become a registered user. You can do this via the E-Government Gateway or by registering with your email address.
Registration via the E-Government Gateway
When registering via the E-Government Gateway, you will be redirected from the SĮSP website to the E-Government Gateway website, where you will have to select an identification method (via a bank or by using an electronic identification tool). In this case, with your consent, the E-Government Gateway will provide us with the personal data about you that is specified on the E-Government Gateway platform (name, surname, personal identification number, email address, telephone number, date of birth). Please note! When you log in to the self-service portal using your E-Government Gateway account, SĮSP will receive the personal data necessary specifically for ordering a parking permit for residents living in the Vilnius city parking fee zone. If you do not wish to transfer all of this data to us, log in to the self-service portal using your email address and password (registration without the E-Government Gateway).
Registration without any integrations
When registering on the customer self-service platform, you will be asked to enter the following data:
- name and surname (mandatory)
- email address (mandatory)
- password (stored in encrypted form)
What GDPR condition do we rely on when processing your personal data?
For the purpose of entering into and performing a transaction (Article 6(1)(b) of the GDPR).
How long do we store this data?
We store this data for 3 years from the registered user’s last login to the customer self-service portal. After this period, the registered user is notified of the deletion of their account and given a period of 30 calendar days to log in to the customer account so that the storage of the user account can be extended for another 3 years. If the user does not do so within 30 calendar days, the registered user’s account together with all of their data will be removed within 1 month.
2.2. To create a user account in the JUDU app. To use SĮSP services in the JUDU app, you must become a registered user. You can do this by using the “Google” and “Apple” login interfaces or by registering with your email address.
Registration via the “Google” interface
For the purpose of logging in to the App with a “Google” account through the “Google” authentication (OAuth) service, we may receive the following data: name, surname, email address and unique Google account identifier. Profile photo data may be technically accessible through the “Google” authentication service; however, the App does not collect, store or otherwise process such data and does not use it for any purposes.
Registration via the “Apple” interface
For the purpose of logging in to the App with an “Apple” account through the “Sign in with Apple” authentication service, we may receive the following data: name, surname, email address or a private (pseudonymised) email address provided by “Apple”, and a unique Apple user identifier. The email address is used only for account creation and authentication in the JUDU app. The JUDU app does not process any additional Apple account data.
Registration without any integrations
When registering in the JUDU app, you will be asked to enter the following data:
- name and surname (mandatory)
- email address (mandatory)
- password (stored in encrypted form)
What GDPR condition do we rely on when processing your personal data?
Based on your consent (Article 6(1)(a) of the GDPR) and for the purpose of entering into and performing a transaction (Article 6(1)(b) of the GDPR).
How long do we store this data?
We store this data for 3 years from the registered user’s last login to the JUDU app. After this period, the registered user is notified of the deletion of their account and given a period of 30 calendar days to log in to the account so that the storage of the user account can be extended for another 3 years. If the user does not do so within 30 calendar days, the registered user’s account together with all of their data will be removed within 1 month.
2.3. For the purpose of using the services offered by the customer self-service portal.
2.3.1. Public transport tickets. This service allows you to add JUDU / Vilniečio cards that you use, assign owners to them, purchase public transport tickets or top up the e-wallet. For this purpose, we collect:
- the card owner’s name (it is not mandatory to provide the real name or surname)
- JUDU / Vilniečio card number
2.3.2. Parking. This section allows you to order vehicle parking services and pay the Daily Fee. For this purpose, we collect:
- name, surname, personal identification number
- residential address
- telephone number, email address
- vehicle data (vehicle make and model (optional information), vehicle registration number, registration certificate number and a copy of this certificate, driving licence number and a copy of this licence)
- data relating to the long-term parking service in a parking fee zone (name, surname, telephone number and email address of the person for whom this service is ordered)
- number of the notice of unpaid Local Fee
2.3.3. For the purpose of informing vehicle drivers about an unpaid Local Fee not paid on time, we collect:
– When you have not registered the vehicle in JUDU self-service and have not specified the registration number of the vehicle you manage:
- the vehicle registration number;
- name, surname, personal identification number;
- email address;
- if you are a representative of a legal entity – your email address and the name of the legal entity.
We obtain this data under data provision agreements concluded with Akcinė bendrovė “Regitra”, State Enterprise Centre of Registers and the State Tax Inspectorate under the Ministry of Finance of the Republic of Lithuania.
– When you (the vehicle driver), wishing to check whether a case of non-payment of the Local Fee has been recorded, complete a special form on the SĮSP website www.judu.lt, we collect the following personal data about you:
- Vehicle identification number (VIN), or
- Vehicle registration number
- Vehicle licence plate number
What GDPR condition do we rely on when processing your personal data?
Processing is necessary for compliance with a legal obligation to which the controller is subject (Article 6(1)(c) of the GDPR), and processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller (Article 6(1)(e) of the GDPR).
How long do we store this data?
When you check whether a case of non-payment of the Local Fee has been recorded, this data is not stored in the SĮSP infrastructure.
When you have not registered the vehicle in JUDU self-service, the data is stored for up to 6 months.
2.3.4. When you (the vehicle driver) create your account through the SĮSP website www.judu.lt or the JUDU app and enable the notification functionality, which allows notices about an unpaid fee to be sent to the email address or telephone number specified by you, the following are collected:
- Vehicle identification number (VIN), or
- Vehicle registration number
- Vehicle licence plate number
- Contact details (email address and/or telephone number)
What GDPR condition do we rely on when processing your personal data?
Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller (Article 6(1)(e) of the GDPR). Your contact details, which you provide in order to receive information about an unpaid Local Fee, are processed on the basis of consent.
How long do we store this data?
Your registration data is stored until the account expires (you may delete the account) or until you withdraw your consent to the processing of contact details for the purpose of providing information.
2.3.5. Within the scope of issuing electronic permits to persons with disabilities, the following data is collected:
- Number of the parking card for a person with a disability
- Vehicle licence plate number to which the person wishes the exception under the Law on Fees to be applied
- Expiry date of the parking card for a person with a disability
- Email address of the person submitting data for the issuance of the permit
What GDPR condition do we rely on when processing your personal data?
Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller (Article 6(1)(e) of the GDPR).
How long do we store this data?
The data required to obtain an electronic permit is stored until the expiry date of the parking card for persons with disabilities.
2.3.6. For the purpose of controlling payment of the Local Fee, we collect:
- photographs showing the vehicle, its licence plate number and parking location.
- geographical (GPS) coordinates of the parking location and the time of the first and second scan
What GDPR condition do we rely on when processing your personal data?
Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller (Article 6(1)(e) of the GDPR).
How long do we store this data?
Data collected during scanning that does not relate to violators (where it is confirmed that the vehicles have paid the applicable fee) is stored for no longer than 24 hours from its collection.
Data collected during scanning about vehicles that stopped in the Local Fee area only briefly or where, at the time of control, you were on your way to a parking meter to make payment, is stored until the end of the working day, when all data is automatically deleted from the E-control equipment (hard disk), i.e. within 24 hours from its collection.
If you or vehicles that are parked next to, but outside, the fee zone are captured in the photograph during scanning, they are irreversibly anonymised automatically by hiding your face and/or vehicle licence plate numbers, automatically (without user intervention) within approximately 2 minutes from the capture of the data.
2.3.7. Service status / History. This section allows you to view the history of services ordered in the customer self-service portal. For this purpose, we collect:
- electronic ticket usage data (JUDU / Vilniečio card number, usage status, ticket type, amount, quantity, route number, location);
- data on ordered vehicle parking services (e.g. long-term parking fee zone, service duration, service activation date, vehicle licence plate number, Daily Fee payment information in the case of an unpaid Local Fee, etc.)
2.3.8. Payments and invoices in the customer self-service portal. This service allows you to view payments you have made for public transport tickets (point 2.2.1) or other customer self-service services. For this purpose, we collect:
- purchase order data (order date, order status, invoice number)
- payment transfer data (payer’s name, surname, order No., payment amount, payment method and transfer date)
If you wish to receive an invoice for purchased transport tickets or vehicle parking, you provide the requested data in the profile settings section of the www.judu.lt self-service portal.
What GDPR condition do we rely on when processing your personal data?
Processing is necessary for compliance with a legal obligation to which the controller is subject (Article 6(1)(c) of the GDPR), and processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller (Article 6(1)(e) of the GDPR).
How long do we store this data?
We store this data for as long as your account is valid. If you decide to delete your account or the automatic account deletion period due to user inactivity expires, your data specified in the public transport, parking, service status / history, payments and invoices sections is stored for as long as required by applicable legal acts.
2.3.9. Payments and invoices in the JUDU app. This service allows you to view payments you have made in the JUDU app. For this purpose, we collect:
- purchase order data (order date, order status, invoice number)
- payment transfer data (payer’s name, surname, order No., payment amount, payment method and transfer date)
- other payment-related data
If you wish to receive an invoice for purchased transport tickets or vehicle parking, you provide the requested data in the profile settings section of the www.judu.lt self-service portal or the JUDU app.
What GDPR condition do we rely on when processing your personal data?
Processing is necessary for compliance with a legal obligation to which the controller is subject (Article 6(1)(c) of the GDPR), and processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller (Article 6(1)(e) of the GDPR).
How long do we store this data?
We store this data for as long as your account is valid. If you decide to delete your account or the automatic account deletion period due to user inactivity expires, your data specified in the public transport, parking, service status / history, payments and invoices sections is stored for as long as required by applicable legal acts.
2.4. For the purpose of informing you about the Company’s services and requesting your opinion (direct marketing).
In order to inform you about the services provided by SĮSP, send newsletters, invitations to participate in surveys and ask for your opinion on the quality of services provided by SĮSP, we collect your email address. Personal data of survey participants is generally not collected; however, in individual surveys, residential addresses, names of workplaces and other data may be collected if they are necessary to achieve the purposes of the specific survey. You will receive information about the Company’s services and invitations to participate in surveys only if you have given your consent, which you may withdraw at any time by clicking the unsubscribe link at the bottom of the newsletter or by another method indicated by the Company.
What GDPR condition do we rely on when processing your personal data?
The basis for processing is your consent (Article 6(1)(a) of the GDPR). You may give or withdraw consent in the Company’s self-service portal or by another method established by the Company.
How long do we store this data?
We store your personal data for 3 years from the date of receipt of consent. 30 calendar days before the end of this period, we will send a notice about the upcoming end of the newsletter subscription and invite you to express your will regarding the extension of the subscription. If you consent to continue the newsletter subscription, your personal data will be stored for another 3 years. If you refuse to extend the subscription or do not respond to the notice received, you will be removed from the list of newsletter subscribers after the end of the 30-calendar-day period.
2.5. For the purpose of personalised advertising on social networks and digital channels.
In order to show you personalised SĮSP advertising on social networks (“Facebook”, “Instagram”, “LinkedIn”) and digital channels (“Google”), we collect and use your email address. Your email address may be transferred to the operators of the respective platforms only for the purpose of creating audiences and displaying personalised advertising, in compliance with the requirements of applicable personal data protection legislation.
What GDPR condition do we rely on when processing your personal data?
The basis for processing is your consent (Article 6(1)(a) of the GDPR). You may withdraw your consent at any time in the SĮSP self-service portal or by another method indicated by the Company. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal of consent.
How long do we store this data?
We store your email address for this purpose for 3 years from the date of receipt of consent or until withdrawal of consent, whichever occurs earlier.
2.6. If you participate in marketing competitions organised by us
We collect your first name, last name, telephone number, email address, and other information specified in the terms and conditions of the relevant competition.
What legal basis under the GDPR do we rely on when processing your personal data?
For the purposes of organising and administering the competition, determining the winner and awarding the prize, we process your personal data on the basis of Article 6(1)(b) of the GDPR, where such processing is necessary to take steps at your request or to fulfil the competition terms and conditions, as well as on other applicable legal bases where relevant.
If, under the terms and conditions of a particular competition, the winner is to be publicly announced, the winner’s personal data (e.g. name, surname, photograph or other information) will be made public based on your separate consent (Article 6(1)(a) of the GDPR).
How long do we retain your personal data?
We retain personal data of competition participants for as long as necessary to organise and administer the competition.
We retain the personal data of the competition winner related to the awarding and transfer of the prize for as long as necessary to complete the transfer of the prize and to fulfil the related legal, accounting and tax obligations, as well as for as long as necessary to establish, exercise or defend potential legal claims. Where applicable legislation establishes specific retention periods, we retain the data for the period prescribed by such legislation.
2.7. If you communicate with us and/or are interested in our activities on social networks
We collect your name and surname, comments you leave under our posts, shares of our posts, data on “like”, “follow” and other reactions by you (including information about when you started following or liked the SĮSP social network account), your photo, messages with attachments that you send to us, the history of communication with us (including the content of messages and the time of their receipt/submission), reviews you leave and SĮSP ratings.
What GDPR condition do we rely on when processing your personal data?
Based on your consent (Article 6(1)(a) of the GDPR). Your clicks on “like”, “follow” and other reactions, i.e. comments, shares, etc., are considered to constitute consent. By contacting us via social networks, you agree to our privacy policy.
How long do we store this data?
Your publicly posted comments, clicks on “like”, “follow” and other reactions, i.e. comments, shares, etc., will be stored and visible to other persons until you withdraw or delete these actions.
Communication with us, i.e. messages and similar data, is stored for 3 years.
2.8. For the purpose of checking and confirming the user account of the customer self-service portal and the JUDU app
When creating a customer self-service user account without the help of the E-Government Gateway, or an account in the JUDU app, an automatic confirmation email with a link is sent to the specified email address. After clicking the link, the personal data described in point 2.1 of this Policy is stored in accordance with the established procedure. If you do not use the confirmation link within 8 hours, all data entered in the registration form is destroyed.
What GDPR condition do we rely on when processing your personal data?
On the basis of our legitimate interest in ensuring that the person registers using their own personal data (Article 6(1)(f) of the GDPR).
How long do we store this data?
The email address is stored for 8 hours while the confirmation link is active. After you activate your account, personal data is stored in accordance with the procedure and terms set out in point 2.1 of this Policy.
2.9. In order to improve our website, ensure its operation, increase its security and adapt its content and form to users’ needs
When you visit the SĮSP website, we automatically collect the following data about you: IP address, operating system, user ID and other information about your activity on our and other websites. We collect and store this information as part of log records or through cookies. For more information about the use of cookies, please read sections 7 and 8 of this Policy.
What GDPR condition do we rely on when processing your personal data?
On the basis of legitimate interest (Article 6(1)(f) of the GDPR).
How long do we store this data?
For more information about retention periods, please read sections 7 and 8 of this Policy.
2.10. If you complete our surveys or feedback forms
We process the answers you provide in a survey or feedback form and, if you choose, the contact information you provide (e.g. name, email address, telephone number) in order to assess the quality of services provided by us (e.g. public transport, vehicle parking) and by our other partners, examine your feedback and, if you leave contact details, contact you about the information you provided.
What GDPR condition do we rely on when processing your personal data?
Based on your consent (Article 6(1)(a) of the GDPR). You provide the data voluntarily – if you do not provide it, we will examine the feedback anonymously.
How long do we store this data?
The data is stored for no longer than 3 months from the date of submission, unless legal acts provide for a longer retention period.
2.11. If you submit an application for the issuance of a resident permit under the pilot project for opening shopping centre parking lots to residents.
For this purpose, we collect: name, surname, residential address, telephone number, email address. The data contained in the submitted certificate of declared place of residence is only checked, and a copy of it is not stored.
What GDPR condition do we rely on when processing your personal data?
Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller (Article 6(1)(e) of the GDPR).
How long do we store this data?
The data is stored for the validity period of the permit, unless legal acts provide for a longer retention period.
Please note! We may store your personal data for longer than indicated in this Policy where your data is necessary for compliance with legal obligations applicable to us (e.g. statutory data retention periods or for the establishment, exercise or defence of legal claims).
3. TO WHOM DO WE DISCLOSE YOUR PERSONAL DATA WITHIN AND OUTSIDE THE EEA?
We transfer your personal data only to reliable third parties and only in order to properly implement the purposes of personal data processing. More specifically, your data may be transferred:
Within the EEA:
- UAB “Synopticom” (newsletter sending platform). You can read their privacy policy here.
- “Swedbank”, AB (payment solutions provider). You can read their privacy policy here.
- To our partners providing information technology, customer self-service maintenance, electronic communications, accounting, audit, legal and other services;
- To state supervisory and law enforcement authorities.
Outside the EEA:
- Meta Platforms Ireland Limited (Ireland), Meta Platforms, Inc. (USA) (Facebook and Instagram and analytics tools used). Data is transferred pursuant to an adequacy decision adopted by the European Commission.
- Google Ireland Limited (Ireland), Google LLC (USA) (YouTube and analytics tools used). Data is transferred pursuant to an adequacy decision adopted by the European Commission.
- LinkedIn Ireland Unlimited Company (Ireland), LinkedIn Corporation (USA) (LinkedIn). Data is transferred pursuant to an adequacy decision adopted by the European Commission.
- Microsoft Ireland Operations Limited (Ireland), Microsoft Corporation (USA) (Microsoft Clarity). Data is transferred pursuant to an adequacy decision adopted by the European Commission.
We will provide all of these service providers only with as much of your personal information as is necessary for the specific service.
4. HOW DO WE PROTECT YOUR PERSONAL DATA?
Yes, we take all appropriate measures to protect your information; however, no website, online transaction, computer system, and especially no wireless connection, is completely secure. Although we undertake to make every effort to protect your personal data, we cannot guarantee the absolute security of your personal data transmitted on our website. By transmitting any information, you assume the risks associated with its transmission. Therefore, remember that access to your account is protected by the password you set. Do not disclose your password to anyone! When you have finished using the SĮSP customer self-service portal, log out of it immediately by clicking the “Log out” button. This is especially important when you use a public computer. Once we receive your data, we apply all technical and administrative security measures necessary to protect it against unlawful loss, unauthorised access, unlawful alteration, disclosure or deletion. We grant access to your personal data only to those persons who need it for the purposes described in this Policy.
5. YOUR RIGHTS
Each data subject, i.e. each of you whose data is processed in our activities, has the following rights:
- To know (to be informed) about the processing of your personal data (Articles 12-14 of the GDPR);
- To access your personal data being processed (Article 15 of the GDPR);
To require the rectification of inaccurate personal data relating to you (Article 16 of the GDPR); - To require the erasure of personal data relating to you (“right to be forgotten”) (Article 17 of the GDPR). Please note! You have the right to be forgotten only if this can be justified by one of the following reasons:
- the personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
- you withdraw the consent on which the processing of personal data is based and there is no other basis for processing the data;
- you object to the processing of data pursuant to Article 21(1) of the GDPR and there are no overriding legitimate grounds for processing the data.
- To restrict processing (Article 18 of the GDPR): Please note! You have the right to restrict the processing of your data only when:
- the personal data is inaccurate;
- the processing of personal data is unlawful, but you oppose the erasure of the data;
- the controller no longer needs the personal data for its purpose, but you need it for the establishment, exercise or defence of legal claims;
- you object to the processing of data pursuant to Article 21(1) of the GDPR, if the controller’s legitimate grounds do not override your grounds.
- To transmit your personal data where the processing is based on consent or a contract and the data is processed by automated means (Article 20 of the GDPR);
- To object to the processing of personal data on grounds relating to your particular situation where the data is processed: (i) in the exercise of official authority vested in the controller or for the performance of a task carried out in the public interest, or (ii) where the data is processed for the legitimate interests of the controller or a third party, except where the controller demonstrates that the data is processed for compelling legitimate grounds that override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims (Article 21 of the GDPR);
- If you believe that SĮ “Susisiekimo paslaugos” is unlawfully processing your personal data or is not implementing your rights, you have the right to lodge a complaint with the State Data Protection Inspectorate (L. Sapiegos g. 17, 10312 Vilnius, tel. (8 5) 271 2804, 279 1445, email [email protected]);
- To consult the Data Protection Officer of SĮ “Susisiekimo paslaugos” by email at [email protected].
- If you no longer wish your personal data to be processed for direct marketing purposes or if you have any other request or instruction related to the processing of your personal data, please write to us by email at [email protected]
6. THIRD-PARTY WEBSITES, SERVICES AND PRODUCTS ON OUR WEBSITES
This website may contain third-party banners, links to their websites and services, which we do not control and for which we are not responsible regarding the security and privacy of information collected by third parties. You should read the privacy provisions applicable to the third-party websites and services that you use.
7. COOKIES
This website uses strictly necessary, analytical and marketing cookies, which help display our website and ensure its functionality and convenient navigation. More information about how cookies work can be found on the website www.cookiecentral.com.
Information related to cookies is not used to identify you personally, and we control the collected data. Such cookies may be used for the purposes listed below:
- to ensure the smooth and efficient operation of the website or app;
- to anonymously collect statistical information about how and which posts you viewed;
- to save the settings you selected during and between visits;
- to enable us to collect reliable information on the use of the website and app, allowing us to determine whether the website and app meet users’ needs and to improve them accordingly.
8. HOW TO MANAGE AND DELETE COOKIES
When you use a browser to access the content we provide, you can always configure your browser to accept all cookies, reject all cookies or notify you when a cookie is sent. Each browser is different, so if you do not know how to change cookie settings, check its help menu. Your device’s operating system may include additional cookie controls. If you do not want information to be collected through cookies, use the simple procedure available in most browsers that allows you to refuse the use of cookies. To learn more about how to manage cookies, visit: www.cookiecentral.com.
We do not link the visitor’s IP address and email address with data that allows the visitor to be identified. This means that each visitor’s browsing session will be recorded, but the visitor of the website www.judu.lt will remain anonymous.
Necessary cookies are a condition for using our website. If you refuse these types of cookies, we cannot guarantee how our website will function when you visit it. You can control the use of functional, statistical and advertising (marketing) cookies in the cookie panel installed on the www.judu.lt page by selecting “enable” or “disable” for the relevant cookies.
Our website may also contain links to the websites of other persons, companies or organisations. Please note that we are not responsible for the content of such websites or the privacy principles they apply. Therefore, if you access other websites by clicking a link from our website, you should separately review their privacy policy.
Descriptions of cookies used on the SĮ “Susisiekimo paslaugos” website
Necessary cookies
To make the website easier to use, necessary cookies enable core functions such as page navigation and access to secure areas of the website. Without these cookies, the website will not function properly. These cookies do not collect any information for marketing purposes and do not remember where you have been on the internet.
| Name | Provider | Purpose | Expiry | Type |
| _GRECAPTCHA | Google Inc. (Google.com) | used to protect the website from spam and abuse, ensuring that the user is not a robot | 6 months | HTTP |
Functional cookies
Functional cookies allow the website to remember settings and information selected by the user that change or personalise the appearance or behaviour of the website. For example, these cookies may save the selected language, the user’s location or whether the user has already visited the website. These cookies are not used for marketing purposes and do not collect information that would identify the user on other websites.
| Name | Provider | Purpose | Expiry | Type |
| cookie_func | SĮSP | remembers the website functional settings selected by the user, e.g. language, cookie consent | 1 year | HTTP |
| visited | SĮSP | determines whether the user has already visited the website so that content display can be adapted | 1 year | HTTP |
Statistical cookies
Statistical cookies collect information about how visitors use the website. They help website operators understand how often the website is visited, how much time is spent on it, whether users encounter errors, and how they interact with the website content. These cookies collect data anonymously and are intended solely for analysis and improvement of website performance.
| Name | Provider | Purpose | Expiry | Type |
| _ga | Google Inc. (Google Analytics) | collects information about how visitors use the website – number of visitors, traffic sources and page visits; | 2 years | HTTP |
| _ga_11YCZY0BS8 | Google Inc. (Google Analytics) | used to support “Google Analytics” functions and track user actions on the website | 2 years | HTTP |
| _gid | Google, Inc. (Google Analytics) | collects information about user interaction with the website, e.g. which pages were visited | 24 hours | HTTP |
| _clck | Microsoft Corporation (Microsoft Clarity) | stores the “Clarity” user ID and a reference to that ID so that user actions can be tracked across multiple pages | 1 year | HTTP |
| _clsk | Microsoft Corporation (Microsoft Clarity) | combines multiple page views into one “Clarity” session | 1 day | HTTP |
| cookie_3rd_stat | third parties (service providers) | collects statistical information about user activity on the website for analytics purposes | 1 year | HTTP |
Advertising (marketing) cookies
Advertising (marketing) cookies are used to track users across different websites. Their purpose is to provide personalised advertising content based on the user’s browsing habits and interests. They also help assess the effectiveness of advertising campaigns, limit the number of ad impressions and ensure that the user sees advertising relevant to them.
| Name | Provider | Purpose | Expiry | Type |
| _fbp | Meta Platforms, Inc. (Facebook) | used to show personalised advertisements on the “Facebook” platform to users who visited the website. | 3 months | Pixel Tracker |
| cookie_3rd_adv | third parties (service providers) | tracks user behaviour across multiple websites in order to show relevant advertisements | 1 year | Pixel Tracker |
Description of analytics carried out in the JUDU app
SĮSP collects necessary app usage analytics data in order to ensure the quality, security and stable operation of the app, evaluate user experience (UX), identify functional issues and plan app development.
For this purpose, technical Firebase data may be collected (e.g. sessions, app version, operating system version, device model), app usage events describing user actions in the interface (e.g. opened screen, completed route search, started ticket purchase process), and an internal analytics identifier (User ID), which allows sessions of the same user to be linked.
Technical error analysis data necessary for the operation and security of the app (“Firebase Crashlytics”) is processed on the basis of legitimate interest in order to ensure the stable and secure operation of the app and to promptly identify and resolve technical errors.
The app does not duplicate data that is reliably recorded in backend systems (e.g. payments, ticket activations or parking sessions). Analytics data is used only for analysis of app quality, usability and performance. It is not used for advertising, personalised marketing or tracking users in other apps or websites.
9. CONTACT US
Is this Privacy and Cookie Policy unclear? Do you have questions, requests or complaints? Let’s talk about it! Send your enquiries by email to [email protected].
Information updated on 2026-07-03