I. About this information note and our commitments
I. About this information note and our commitments
This information note is addressed to BT Clients (“Clients” or “BT Clients”) – as defined in section II – and represent the way in which Banca Transilvania S.A. (“Bank”, “BT”, "we") fulfills towards them the obligation of informing regarding the processing of their personal data (personal data, date).
We provide you with this information note according to art. 13-14 of the General Data Protection Regulation (“GDPR”), so that you are transparently informed about the processing that BT carries out on personal data when you become a BT Client, throughout the period you hold this status, as well as for certain periods imposed by law after your status as a BT Client ceases.
This information note is of a general nature and is an integral part of BT Privacy Policies. You can find the Privacy Policy and this general information note both on the BT website (including in the section Privacy Hub from this website), as well as in BT units.
For certain services/products/activities of personal data processing that we perform, we have also prepared specific information notes, which you can find in the section Privacy Hub.
We commit to processing and protecting your personal data in accordance with applicable legal provisions and with the highest standards of security and confidentiality, to respect the fundamental human rights and freedoms in connection with this processing, and to periodically evaluate our activity in this field, to ensure that these rights are always respected.
To guide and support us in our activity in the field of personal data processing and protection, we have appointed a data protection officer (“DPO”). The BT DPO can be contacted by any data subject, at any of the following contact details:
- e-mail address dpo@btrl.ro.
- the BT headquarters in Cluj-Napoca city, Calea Dorobanților, no. 30-36, Cluj county, with the mention: "to the attention of the person responsible for personal data protection"
We commit to periodically reviewing this information note and informing you about any substantial changes made to it, through direct communication means (via the secure messaging service of the Neo BT or BT24 internet banking service - if you use these BT services - or by message to the email address or phone number declared to BT - if you do not use the internet banking service and have declared at least one of these contact details to the bank) and/or indirect means (e.g., by displaying the updated version of the information note in all BT units and on the BT website).
We hereby present who BT is (the data controller), what categories of personal data we process from BT Clients (the data subjects to whom the data processing referred to in this information note relates), for what purposes we use this data, to whom we may disclose or transfer it, how long we keep it, as well as what rights Clients can exercise in connection with this processing.
If you are not familiar with the meaning of various specialized terms used in the GDPR or in the applicable banking legislation, we recommend that you first study section A of BT Privacy Policy.
II. Who is the BT Client
II. Who is the BT Client
In this information note, the data subjects of personal data processing are BT Clients, defined as follows:
„Client BT” or ”Client” is a natural person who belongs to any of the following categories of targeted persons:
- residents/ non-residents, holders of at least one current account opened at the Bank (also called “individual account holder client”) or who rent safety deposit boxes at BT;
- legal or conventional representatives of Clients, natural or legal persons, account holders or who have rented safety deposit boxes;
- persons with operating rights on the accounts of individual or legal entity clients account holders (“authorized on the account”);
- the real beneficiaries of Clients, natural or legal persons holding accounts opened at BT (“real beneficiary”);
- persons entitled to submit bank documents, to withdraw account statements and/or to deposit cash on behalf of and for the account of the individual or legal entity Clients account holders (“delegates”);
- associates/shareholders of BT Clients Corporate clients;
- users of a bank product/service who do not have any of the qualities mentioned above but regularly use some BT products/services (e.g. supplementary card users, managers with guarantee accounts opened at the bank, users of BT meal vouchers, BT Pay users);
- guarantors of any kind of the payment obligations assumed by individual or legal entity Clients account holders;
- persons who sign requests on the bank's dedicated forms to become Clients, but this request is rejected or abandoned (even if these persons are not active BT Clients, we are legally obliged to keep their personal data for a certain period of time);
- legal or conventional successors of those mentioned above.
III. Who is the personal data operator
III. Who is the personal data operator
Banca Transilvania S.A. is a credit institution, Romanian legal entity, registered with the Cluj Trade Registry Office under number J1993004155124, having the unique registration code no. RO5022670 and the following contact details: registered office address - Calea Dorobanților, no. 30-36, Cluj-Napoca, Cluj County, Romania, Tel: 0801 01 0128 (BT) – callable from the Romtelecom network, 0264 30 8028 (BT) – callable from any network, including international, *8028 (BT) – callable from Vodafone and Orange networks, email address: contact@bancatransilvania.ro, BT website: https://.bancatransilvania.ro.
Banca Transilvania S.A. is the parent company of the BT Financial Group.
The provisions of this general information note refer to the personal data processing carried out by BT as a data controller.
As part of certain activities, we process personal data together with other entities, as joint controllers. Find details about this processing in the specific information notes in the section Privacy Hub from the BT website.
IV. The purposes for which we process Customers' data
IV. The purposes for which we process Customers' data
As a BT Client, we process your data, depending on the situation, for:
- application of measures regarding customer due diligence for the prevention of money laundering and terrorist financing. Details in specific information note from Privacy Hub;
- solvency assessment, reduction of credit risk, determination of the indebtedness degree of Clients interested in personalized offers related to the bank's credit products or in contracting these types of products (credit risk analysis), including through data processing in the Credit Bureau system. Details in specific information note from Privacy Hub;
- concluding and executing contracts for the products/services offered to BT clients (such as, but not limited to: cards, deposits, loans, internet and mobile banking, BT Pay, SMS Alert); Details about the processing of personal data for certain BT products/services can be found in the specific information notes on Privacy Hub;
- conclusion and execution of contracts for occasional transactions, (see section C point 2 of BT Privacy Policy when you carry out occasional transactions, even if you are also a regular BT client);
- processing/settlement of bank transactions;
- establishment of garnishments, recording the garnished amounts at the disposal of creditors and providing responses regarding these to the enforcement bodies and/or competent authorities, according to the bank's legal obligations;
- reports to the competent authorities, according to the bank's legal obligations (e.g. reports to the National Agency for Fiscal Administration – A.N.A.F., National Bank of Romania – N.B.R. - including to the National Office for Prevention and Control of Money Laundering, Credit Risk Center and Payment Incidents Center within the N.B.R. etc);
- carrying out analyses and keeping records of economic, financial and/or administrative management of the bank;
- administration within internal departments of the services and products offered by the bank, as well as human resource management;
- collection of receivables and debt recovery;
- the legal defense of the bank's rights and interests, the resolution of disputes, investigations or any other petitions/complaints/requests in which the bank is involved;
- performing risk checks on the bank's procedures and processes, as well as carrying out audit or investigation activities, including for the prevention and management of conflicts of interest;
- taking measures/providing information or responses to requests/notifications/complaints of any kind addressed to the bank by any person, including authorities or institutions. For details about the processing of your data, if you have addressed such petitions to the bank, please also study section C point 10 of BT Privacy Policy;
- proof of requests/ agreements/ options regarding certain requested/ discussed/ agreed aspects within telephone calls initiated by Clients or the bank, by recording the discussed aspects and, if applicable, audio recording of telephone conversations or, if applicable, audio-video;
- informing Customers about the products/services held at the bank, for the proper execution of the contractual relationship (carried out, as appropriate, by sending messages of general or particular interest addressed to Customers such as, but not limited to: sending account/card statements, transaction reports, notifications regarding the insertion of garnishments on accounts, notifications about the existence of unauthorized debts or overdue loan payments, notifications about the approaching expiry date of a certain product/service held, notifications about improvements or new facilities offered in connection with the product/service held, about changes to the general business conditions or the general information note regarding the processing of personal data, about the need to update data, etc.);
- transmission of advertising messages/commercial communications to Customers who have expressed their consent for the processing of their personal data for this purpose. For details about the processing of your data, if you have expressed options regarding the processing of your data for advertising purposes at BT, please also study section C point 12 from BT Privacy Policy;
- evaluation/improvement of service quality (requesting/collecting Clients' opinions regarding the quality of services/products/BT employees);
- financial education of Clients;
- carrying out internal analyses (including statistical ones), both regarding products/services, as well as regarding the portfolio and the profile of Clients, conducting market studies, analyses of Clients' opinions regarding the bank's products/services/employees;
- development and testing of BT products/services;
- archiving in physical/electronic format of documents/information, including backup copies;
- performing registry/secretarial services regarding correspondence addressed to the bank and/or sent by it;
- ensuring the security of the IT systems used by BT and the physical spaces where the bank carries out its activity;
- monitoring the security of BT persons/areas/goods and of visitors to BT units/equipment. Details about data processing for this purpose can be found in specific information note regarding video surveillance and in specific information note regarding visits to some BT offices from section Privacy Hub.
- fraud prevention;
V. What personal data do we process from Customers
V. What personal data do we process from Customers
BT clients’ personal data categories are processed, as appropriate, as follows:
- identification data: name, first name, pseudonym (if applicable), date and place of birth, personal numeric code (P.N.C.) or another similar unique identification element (e.g. U.I.C. for authorized natural persons or T.I.N. for natural persons practicing liberal professions), other details from the identity card/passport, as well as copies of these documents, signature (handwritten or electronic), citizenship, home address, residence, as well as the address where the Client lives and its legal status;
- contact details: phone number, email address and correspondence, fax;
- financial data (such as, but not limited to transaction data, data relating to payment behavior, data about accounts and financial/banking products, held/made at BT or other financial institutions);
- tax dates (e.g. country of tax residence, tax identification number);
- professional dates (ex. profession, occupation, position, employer's name or nature of own activity, education level, specialization, information about the public office held, if you are a politically exposed person (PEP), quality, holdings and, if applicable, powers of representation held within legal entities);
- information about the family situation (ex. marital status, matrimonial regime, number of dependents, kinship relations, marriage, cohabitation);
- information about the economic and financial situation (ex. data about income, data regarding owned/possessed goods, source of wealth – if you are PEP);
- data about requested/used BT products and services (ex. information about the purpose and nature of the business relationship, the source/destination of funds used within the contractual relationship/transactions, type of products/services, contractual period, other details related to products/services, including for credit products: product type, granting term, granting date, due date, amounts and credits granted, amounts owed, account status, account closing date, credit currency, payment frequency, amount paid, monthly rate, employer's name and address, amounts owed, outstanding amounts, number of overdue installments, due date of the overdue payment, number of days of delay in credit repayment. Data about credit products is processed both in the bank's records and - as the case may be - in the Credit Bureau records and/or in other records/systems of this type);
- the image (contained in identity documents or captured by video surveillance cameras, as well as the image within video recordings);
- voice within conversations and recordings of telephone or audio/video calls (initiated by Clients or by the bank);
- biometric data (ex. facial recognition, used in the framework of remote identification processes through video means, within the methods of unlocking devices on which you have bank applications installed, if you have set methods such as facial recognition or fingerprint-based – in this latter case BT does not have access to biometric data, but only relies on them to allow you to access/use certain BT applications);
- age, for verifying the eligibility to contract certain products/services/offers of the bank (e.g. credit products, products dedicated to minors, etc.);
- opinions, expressed within notifications/complaints/conversations, including phone calls, regarding products/services/bank employees;
- identifiers allocated by BT or by other financial-banking or non-banking institutions, such as, but not limited to: BT client code (BT CIF), transaction references/identifiers, IBAN codes of bank accounts, debit/credit card numbers, contract numbers, identifiers allocated by the bank to Clients classified as "non-residents", formed from a succession of digits relating to the year, month, day of birth and the identity document number, whole or truncated, IP addresses, device identifiers (e.g. mobile phones) and the operating system of the devices used to access mobile banking services/mobile payment applications;
- data regarding the state of health, in case such information is provided to us within the documentation submitted to the bank, results from transactions or if their processing is necessary to prove by the Clients the difficult situation they or their family members are in, especially for granting facilities on credit products;
- information regarding fraudulent activity or potentially fraudulent;
- information regarding the location carrying out certain transactions (implicitly, in the case of performing operations on BT equipment belonging to Banca Transilvania);
- any other personal data belonging to Clients, which are brought to our attention in various contexts by other Clients or by any other persons
VI. What are the sources from which we collect Clients' personal data
VI. What are the sources from which we collect Clients' personal data
As a rule, personal data that we process is collected directly from you (e.g. when you become a BT Client, when you update your data at the bank, perform transactions, apply for certain products, such as credit products, etc.).
Nevertheless, there are situations when data is collected from other sources, from/of:
- other Clients of BT (e.g. authorizing other Clients on their accounts opened at the bank, contracting bank products/services by a Client on behalf of another Client who authorized them in this respect, contracting by employers who are corporate Clients of BT of products/services of the bank for/on behalf of their employees - meal vouchers, collection of salary income in accounts opened at BT, guarantee management accounts etc);
- persons who are not BT clients (e.g. persons who deposit cash amounts into the accounts of BT Clients, persons who send petitions claiming that they use data declared at the bank by BT Clients);
- authorities or public institutions (e.g. the General Directorate for Personal Records – G.D.P.R. – from which we receive current data of the clients' identity documents or of the persons undergoing the steps to become BT clients, which we process for the purpose of client knowledge according to the details in the section Privacy Hub from the site, subsection “Knowing the client”, courts, prosecutor's offices, police, judicial executors, B.N.R., A.N.P.C., A.N.S.P.D.C.P., etc.), notaries, lawyers;
- institutions involved in the field of payment services (e.g. Transfond, S.W.I.F.T, international payment organizations, etc);
- other credit institutions with which Banca Transilvania S.A. has merged (e.g. Volksbank România S.A., Bancpost S.A., OTP Bank România S.A.) or with which it will merge in the future or from which some contracts have been assigned (e.g. Idea::Bank, currently named Salt Bank) or will be assigned in the future;
- other banks/financial institutions, including partner banks and correspondent banks or banks/financial institutions participating in syndicated loans;
- other entities of the BT Financial Group, for determined and legitimate purposes, generally for the proper conduct of financial/economic activity and for fulfilling the legal requirements related to the supervision on the consolidated basis of the BT Group;
- public sources, such as but not limited to: the National Trade Register Office (N.T.R.O.), the National Register of Movable Property Advertising (N.R.M.P.A.), the Office of Cadastre and Real Estate Advertising (O.C.R.E.A.), the court portal (portaljust), the Official Gazette, social media, internet etc.;
- records of the type Credit Bureau, the Credit Risk Central of the National Bank of Romania, in case there is a legal basis and a determined and legitimate purpose for consulting them;
- database providers (e.g. entities authorized to manage databases with persons accused of financing acts of terrorism, publicly exposed persons, providers who aggregate and redistribute data collected from public sources, etc);
- contractual partners of the bank from various fields (e.g. evaluation companies, insurance companies, pension and investment fund management companies);
- debt collection / debt recovery companies (e.g. we can find out the new contact details of Customers from companies that support us in debt recovery activity);
VII. On what legal grounds we process Clients' personal data and what happens if you refuse their processing
VII. On what legal grounds we process Clients' personal data and what happens if you refuse their processing
The legal grounds on which BT processes personal data are, as the case may be:
- the bank's legal obligation (when data processing is necessary for the fulfillment of a legal obligation of the bank);
- conclusion/execution of contracts (processing is necessary for the execution of a contract to which the data subject is a party or to take steps at the request of the data subject prior to entering into a contract);
- the legitimate interest of the bank and/or of some third parties;
- the necessity of processing data for the fulfillment of a task serving a public interest (e.g. the application of measures for customer identification to prevent money laundering and terrorist financing);
- the consent of the data subject.
When legal provisions require us to process certain data in a certain situation or if your data is necessary for concluding or executing contracts for BT products/services, if you refuse the processing of such data, you will not be able to become/remain BT clients or we will not be able to process the transactions you request from us.
If we process your data based on our legitimate interest or that of third parties, you may object to such processing for reasons related to your particular situation (e.g., if you are a BT Client and do not wish to receive general interest messages or messages requesting you to evaluate the quality of our services/products, we will accommodate your request without affecting the business relationship you have with BT). In some cases, our legitimate interest or that of third parties may outweigh yours, and we will not be able to accommodate the request in which you oppose the processing (e.g., data processing in the Credit Bureau system, if there are no other reasons to accommodate the objection request).
If we process your data based on your consent/agreement, you have the right to withdraw this agreement at any time. However, the withdrawal will not affect the previous processing of your data (e.g. when we process your data based on consent for advertising/marketing purposes you have the right to withdraw this agreement. Withdrawal of marketing consent does not affect your right to become or remain a BT client. However, refusal to have your data processed for advertising purposes will result in the bank not being able to inform you about certain offers/promotions and, consequently, it is possible that in some cases you may not be able to benefit from products/services under promotional conditions).
VIII. To whom can we disclose/transfer Clients' personal data
VIII. To whom can we disclose/transfer Clients' personal data
Personal data that we process of Clients may sometimes be disclosed/transferred by BT, in accordance with the principles of GDPR, based on the applicable legal grounds depending on the situation and only under conditions that ensure their full confidentiality and security.
We commit to respecting fundamental human rights and freedoms in the case of such disclosures, especially the right to the protection of personal data and the right to privacy, and to periodically evaluate our activity in this area to ensure that these rights are always respected.
Find below within this section (* -> ***) details about legal provisions that require us to report/communicate personal data concerning you to certain authorities.
Also, when public authorities/institutions request from us the provision of personal data, we commit that these will be disclosed only if we have a legal obligation or a legitimate interest, only based on clear internal procedures and only with the approval of persons in management positions.
We will provide the authorities only the strictly necessary data and if it is proven that we have made such personal data disclosures in violation of human rights, we commit to remedy the damage caused to the data subjects.
Categories of recipients to whom we may disclose personal data, as appropriate, are:
- other Clients who have the right and the need to know them;
- other entities within the BT Financial Group;
- companies involved in payment processing (e.g.: Transfond S.A., payment processors);
- financial-banking entities (e.g. participants in payment and interbank communication schemes/systems such as S.W.I.F.T., S.E.P.A., ReGIS, partner banks and correspondent banks, banks or financial institutions participating in syndicated loans);
- international payment organizations (e.g. Visa, Mastercard);
- contractual partners (service providers) used in BT's activity, such as, but not limited to, providers/suppliers of: digital certificate issuance services (for applying qualified/extended electronic signature), services for collecting outstanding debts/claims, IT services (maintenance, implementation, support, cloud), archiving services in physical and/or electronic format, courier services, audit services, card-related services, market study/research services, email/SMS/telephony transmission services, marketing services, other services provided by suppliers to whom BT has outsourced certain financial-banking services, etc);
- insurance companies;
- real estate appraisal companies;
- management companies of pension and investment funds;
- guarantee companies (funds) for various types of credit/deposit products (e.g. F.N.G.C.I.M.M., F.G.D.B. etc.);
- partners of the bank from various fields, whose products/services/events we can promote to BT Clients based on their consent. The updated list with the bank's partners can be found here: https://www.bancatransilvania.ro/partners;
- assignees;
- authorities and national public institutions, such as, but not limited to: the National Bank of Romania (N.B.R.), the National Agency for Fiscal Administration (N.A.F.A.)*, the Ministry of Justice, the Ministry of Internal Affairs (M.I.A.), the General Directorate for Persons Records (G.D.P.R.) to which we send the first name, last name and personal numerical code (CNP) of clients/persons who go through the steps to become BT clients for the validation of these data and for providing additional information from their current identity documents, which we process for the purpose of knowing the clientele according to the details in the section Privacy Hub from the site, subsection “Customer Knowledge”, the National Office for the Prevention and Control of Money Laundering (O.N.P.C.S.B.) **, the National Agency for Cadastre and Real Estate Publicity (A.N.C.P.I.), the National Register of Movable Property Publicity (R.N.P.M.), the Financial Supervisory Authority (A.S.F), including, as the case may be, their territorial units;
- banking institutions or state authorities, including from outside the European Economic Area - in the case of international S.W.I.F.T. transfers or as a result of processing carried out for the purpose of applying F.A.T.C.A. and C.R.S. legislation;
- notaries public, lawyers, bailiffs;
- Credit Risk Center***;
- Credit Bureau and Participants in the Credit Bureau system****;
* disclosure of personal data to A.N.A.F.
According to the provisions of the Tax Procedure Code (Law no. 207/2015), in its capacity as a credit institution, BT has the legal obligation to:
1. Communicate daily to A.N.A.F.:
- the list of natural persons, legal entities or other entities without legal personality who open or close bank or payment accounts at BT, persons who have the right to sign for the opened accounts, persons claiming to act on behalf of the client, the real beneficiaries of the account holders, together with the identification data provided in art. 15 para. (1) of Law no. 129/2019 for preventing and combating money laundering and terrorist financing, as well as for amending and supplementing certain normative acts, with subsequent amendments and completions, or with the unique identification numbers assigned to each person/entity, as appropriate, as well as information regarding the IBAN number and the opening and closing dates for each individual account.
- list of persons who have rented safe deposit boxes, accompanied by the identification data provided in art. 15 para. (1) of Law no. 129/2019, with subsequent amendments and completions, or by the unique identification numbers assigned to each person/entity, as applicable, together with data regarding the termination of rental contracts.
2. Communicate, at the request of A.N.A.F., for each holder subject to the request, all turnovers and/or balances of the bank accounts opened, as well as the information and documents regarding the operations carried out through the respective accounts.
3.Send to A.N.A.F. - on the occasion of the request to open a bank account or rent a safe deposit box - the request for assignment of the tax identification number/registration code, for non-resident individuals who do not have it. The request sent by BT to A.N.A.F. will include the following data of the non-resident: last name, first name, date and place of birth, gender, home address, data and copy of the identity document, tax identification code from the country of residence (if any). BT can also send to A.N.A.F. supporting documents of the information filled in within the request. Based on the transmitted data, the Ministry of Finance assigns the tax identification number or, as the case may be, the tax registration code, registers the respective person for tax purposes and communicates to BT the information regarding the tax registration.
** O.N.P.C.S.B. - In case the conditions for the transmission by BT of some personal data to the National Office for Prevention and Control of Money Laundering are met, according to the legislation for the prevention and combating of money laundering and terrorism financing, these are simultaneously transmitted in the same format also to A.N.A.F.
*** C.R.C. - The Bank has the legal obligation to report to the Credit Risk Center (C.R.C) within the B.N.R. the credit risk information for each debtor who meets the condition to be reported (includes identification data of an individual debtor and transactions in lei and foreign currency through which the Bank is exposed to risk towards that debtor), respectively to have recorded towards this debtor an individual risk, as well as information about detected card frauds.
**** Credit Bureau S.A./participants in the Credit Bureau system - The bank has a legitimate interest in reporting to the Credit Bureau System, to which other Participants also have access (mainly credit institutions and non-bank financial institutions, as associated operators of the bank and the Credit Bureau) the personal data of Clients who have contracted loans, as well as of Clients who have delays in loan repayments of at least 30 days, under certain conditions. The data is also disclosed to these recipients in the case of inquiries into this system, made by the bank in the process of analyzing a loan application or request.
IX. Transfers of Customer Data to Third Countries or International Organizations
IX. Transfers of Customer Data to Third Countries or International Organizations
Some of the contractual partners who provide us with services necessary for the smooth running of our activity and/or their subcontractors are not located in the European Union (E.U.) or the European Economic Area (E.E.A.), but in other countries (“third countries”).
When these partners/their subcontractors or international organizations may have access to the personal data we process, we will only allow the transfer of data when it is strictly necessary and only based on adequacy decisions or, in the absence of these decisions, based on appropriate guarantees provided by the GDPR.
To ensure that these transfers respect human rights, especially the right to the proper protection of personal data wherever it may be processed, we commit ourselves - both before allowing the transfer of data to third countries or international organizations, and throughout the entire period during which the transfer takes place, including when changes occur to the circumstances initially considered - to analyze whether there are risks to the rights and freedoms of the data subjects and to manage them appropriately, including by taking any additional necessary measures, so that the data benefits from the same level of protection that it would have within the EU/EEA.
The European Commission may decide that some third countries, some territories or some sectors in a third country provide an adequate level of protection for personal data. The European Commission has issued adequacy decisions for the following third countries/sectors: Andorra, Argentina, Canada (only commercial companies), Switzerland, the Faroe Islands, Guernsey, Israel, the Isle of Man, Jersey, New Zealand, Uruguay, Japan, the United Kingdom of Great Britain, South Korea. To these countries/sectors (insofar as a contrary decision has not been issued regarding any of them), as well as to other countries that the Commission will recognize in the future as providing an adequate level of protection, transfers of personal data do not require special authorizations and are assimilated to disclosures of personal data to recipients from the EU/EEA. The updated list of third countries for which an adequacy decision has been issued is the one mentioned on the European Commission website.
To any other third country or international organization, we will make transfers of personal data only based on appropriate safeguards permitted by the GDPR, usually those consisting of Standard Contractual Clauses approved by the European Commission which you can find here and, if these guarantees are not sufficient, we will take other additional measures for the proper protection of data.
By way of exception, if BT Clients order through the bank transactions to beneficiaries located in third countries that have not been recognized as having an adequate level of personal data protection, the transfer of data to those countries is based on the provisions of the GDPR according to which: the transfer that is necessary for the performance of a contract between the bank and the Client or for the application of pre-contractual measures adopted at the Client's request or, as the case may be, the transfer that is necessary for the conclusion of a contract or for the performance of a contract concluded in the interest of the data subject.
X. Automated decision-making processes, including profiling
X. Automated decision-making processes, including profiling
In some circumstances, only in compliance with the GDPR provisions, within BT's activity, automated decision-making processes are used, including as a result of profiling.
These are decisions taken by the bank based on automatic processing of personal data, with or without the intervention of a human factor, and which can produce legal effects and/or can affect the data subjects similarly, to a significant extent.
Similar situations are the following:
- for the application of customer knowledge measures in order to prevent and combat money laundering and the financing of terrorism (including for the implementation of international sanctions), according to our legal obligation, we will carry out checks in databases with persons accused of financing acts of terrorism, in international sanctions lists or in warning lists regarding persons with a high risk of fraud. If your data is found in these records, the bank reserves the right to refuse to enter into a business relationship with you or to terminate the contractual relationship. For the same purpose, we will send and receive from the D.G.E.P. data from the identity document of clients/persons who go through the steps to become BT clients. The data received from D.G.E.P. will be recorded or, as the case may be, updated in our records as data from the clients' identity documents. BT will not take any measures likely to produce legal effects or that would significantly similarly affect the clients based solely on the automated processing of data provided by D.G.E.P., unless the provisions of art. 22 of the General Data Protection Regulation (GDPR) are respected.
- to protect BT Clients against fraud and for us to properly fulfill our client knowledge obligations, we monitor their transactions and, if we identify suspicious operations (such as unusual payments in terms of frequency, value, including reported against the declared source of funds or the purpose and nature of the business relationship, transactions initiated from different localities within short time intervals that did not allow travel between those locations, transactions whose details raise suspicions of money laundering or financing of terrorism acts, attempts to use BT cards on suspicious websites), we may take measures to block transactions, cards, accounts, making these decisions solely on an automated basis;
- according to legal provisions, granting credit products is conditioned by the existence of a certain degree of indebtedness of the applicants. In determining the eligibility to contract a credit product related to the degree of indebtedness, it will be determined based on automatic criteria, starting from the level of income and expenses recorded by the applicant;
- in order to objectively verify the fulfillment of eligibility conditions for pre-offering and, as the case may be, analyzing a credit application of an applicant – natural or legal person - in most cases a bank scoring application will be used which will analyze data filled in the credit application, information resulting from verifications carried out in the bank's own records and/or those of Credit Bureau S.A. and will issue a score that determines the credit risk and the likelihood of paying the installments on time in the future. To the issued score is added the result of other verifications of the applicant's situation, which will be analyzed by bank employees to determine whether the eligibility conditions established by internal regulations are met. The final decision to approve or reject the credit application is however based on the analysis carried out by the Bank's employees (human intervention). An exception to human intervention is the situations when you request credit products exclusively online. In these cases, we will make the decision to grant the credit or, as the case may be, to reject this application based solely on automated data processing. Making the decision by such means is necessary to quickly analyze the application and conclude the credit contract. However, you are guaranteed the right to request human intervention, that is, the analysis of the credit application by a bank employee, to express your point of view and to contest the exclusively automatic decision;
- for the confirmation of your identity, in the case of opening a remote business relationship, in the case of updating data through online means or for remote identification through video means, certain information of your face (taken from a static or video image) is compared with the photo from the identity document and, if you are already a BT Client, the information extracted based on your face and from the identity document is confronted with those already in the bank's records. Also, within these online processes, your access to the phone number, email address is verified and these are confronted with those already declared at BT (if you are a BT Client). If, following these automated processes, we identify discrepancies, we will carry out checks through our employees and, if necessary, we will ask you to resume the enrollment/update/identification process at a BT unit;
- In the case of BT Clients who have expressed their consent on the dedicated form for their data to be processed for advertising purposes, we will create a profile of them based on certain criteria (e.g. transaction data, age, locality, income range), which we will study automatically to form an opinion about the advertising messages that would be relevant to them. In some cases, this profile will only result in promoting a certain product/service to persons who meet the profile conditions. In other cases, it will mean that only persons who meet the profile criteria can contract/benefit from certain promotional offers. The rest of the Clients can, however, benefit from products/services under standard conditions.
XI. For how long do we keep Clients' personal data
XI. For how long do we keep Clients' personal data
1. The storage period of Client data as a result of the request to establish/conduct a business relationship with the Bank or as a result of the request to use/usage of BT products/services
According to the legal obligation we have, the personal data that we process for the application of client knowledge measures for the prevention of money laundering and terrorist financing, together with all records obtained through the application of these measures, such as the monitoring and verifications carried out by the bank, the supporting documents and transaction records, including the results of any analysis conducted in relation to the client, which determine the client's risk profile, must be kept for 5 years after the termination of the Client's business relationshipaccount holder with the bank.
We have the obligation to keep this data for the indicated period and in case the Client's request to open a business relationship with the bank is rejected or if the Client withdraws it. In this case, the retention period of 5 years will be calculated from the date of the request's rejection or the client's withdrawal, respectively from the date of the occasional transaction.
At the request of the competent authorities, the initial legal period of 5 years mentioned above can be extended, up to a maximum of 10 years from the termination of the business relationship.
Upon the expiration of this legal retention period (initial or extended, as the case may be), the bank will delete or anonymize this data, except in situations where other legal provisions require their continued retention. Other legal provisions that oblige us to retain Clients' data for a longer period are those from:
- The fiscal procedure code, which provides that some of the data processed for the application of customer knowledge measures must also be processed for reporting to A.N.A.F. The legal retention period of these data is 10 years from the termination of the business relationship or from the date of the occasional transaction;
- the financial-accounting legislation provides that accounting documents relevant to financial records and supporting documents, including contracts on the basis of which the accounting entries were made (implicitly also the personal data contained therein) must be kept until 10 years since the end of the financial year in which they were created;
- the national legislation applicable in the field of electronic signature, which obliges providers issuing digital certificates to keep information regarding a qualified certificate for a period of minimum 10 years from the date of its expiry. In cases where Romanian providers we collaborate with in this field process personal data as associated operators with the bank, it is possible that we keep data regarding certificates for this period;
- for Clients whose personal data has been queried in the records of A.N.A.F. (according to the agreement expressed by them), the legal term imposed for keeping the interrogation consent forms (implicitly also for the personal data contained therein) is 8 years;
As for the data that the bank is legally obliged to report to the Credit Risk Center (C.R.C.), the documents containing the credit risk information and the information about reported card frauds (including personal data therein) shall be kept for a period of 7 years.
Regarding the data processed in the Credit Bureau system based on the legitimate interest of the Participants in this system, they are stored at the level of this institution and disclosed to the Participants for 4 years since the date of the last update, cu excepția datelor solicitanților de credit care au renunțat la cererea de credit sau cărora nu li s-a acordat creditul, care sunt stocate și dezvăluite Participanților pentru o perioadă de 6 months.
For all cases in which data/some data is subject to multiple retention periods, the longest of these shall apply. After the expiration of the longest period, the data shall be deleted or anonymized.
2. Retention period for Client data captured by video surveillance cameras
If you visit the bank's units (including office buildings) or BT equipment (ATMs, payment machines), your image is captured by the video surveillance system. Data collected through video surveillance cameras is retained for 30 days, after which it is deleted by an automatic procedure. In specific cases, thoroughly justified, only in compliance with the applicable legal provisions, the retention period of relevant video recordings may be extended up to 6 months from the end of the month in which the images were taken or, if necessary, for a longer period, until the completion of investigations of the incident that made it necessary to extend the storage period. In the case of video images subject to data access requests, the retention periods for the personal data of BT petitioners apply.
3. Retention period for Customer data whose marketing options have been expressed
BT Client Data who have given consent to receive advertising messages are processed for this purpose until the consent is withdrawn or, otherwise, until the termination of their status as a BT Client.
4. Period of retention of data of Clients who submitted petitions to the bank (BT petitioning Clients)
To prove that I have received complaints/claims/information requests/measures from you and that I have formulated and sent responses to them, the data related to these petitions will be kept (together with the personal data contained therein) in the case of BT clients, for the duration of their business relationship with the bank plus 3 years (legal prescription period).
Any other personal data processed by BT for other purposes indicated in this Information Note will be kept for the period necessary to fulfill the purposes for which they were collected, to which non-excessive terms may be added, established according to the applicable legal obligations in the field, including but not limited to the provisions regarding archiving, or established internally, according to the legitimate interests of the bank.
XII. What rights do BT clients have regarding the processing of their data
XII. What rights do BT clients have regarding the processing of their data
All BT Clients are guaranteed the rights below regarding their personal data processed by BT.
You should know that we treat these requests with the highest degree of professionalism and their status is periodically brought to the attention of the Bank's management.
Each of the requests is carefully analyzed, the responses to them are documented and, whenever necessary, we take corrective measures to ensure that we respect the rights you have regarding the legal processing and proper protection of your data, which is an essential component of our obligation to respect human rights.
a) the right of access: Clients can obtain from BT confirmation that their personal data are being processed, as well as information regarding the specifics of processing such as: the purpose, categories of personal data processed, recipients of the data, the period for which the data are retained, the existence of the right to rectification, deletion, or restriction of processing. This right allows Clients to obtain a free copy of the processed personal data;
b) the right to rectification: Clients can request BT to modify incorrect data concerning them or, as the case may be, to complete incomplete data;
c) right to erasure (right "to be forgotten"): Clients can request the deletion of their personal data when:
- these are no longer necessary for the purposes for which we collected and process them;
- the consent for the processing of personal data has been withdrawn and BT can no longer process them on other grounds;
- the personal data is processed contrary to the law;
- personal data must be deleted according to relevant legislation;
d) the right to withdraw consent: Clients can withdraw their consent regarding the processing of personal data processed on this legal basis at any time. The withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal;
For withdrawing consent for data processing for advertising purposes you can also use the online form “Do you want marketing or not?” (options for BT clients) and check the option "I do not wish to receive advertising messages";
e) the right of opposition : Clients can object at any time to processing for marketing purposes, as well as processing based on BT's legitimate interest, for reasons related to their specific situation;
f) the right to restriction of processing : Clients can request the restriction of processing their personal data if:
- challenge the accuracy of personal data, for a period that allows us to verify the accuracy of the data in question;
- processing is illegal, and the Client opposes the deletion of personal data, instead requesting the restriction of their use;
- the data is no longer necessary for us but the Client requests them for a legal action;
- in case the Client has objected to the processing, for the time period during which we verify whether BT's legitimate rights as a controller prevail over those of the data subject.
g) the right to data portability : Clients may request, under the law, that the bank provide them with certain personal data in a structured form, commonly used and capable of being read automatically. If Clients wish, BT can transmit the respective data to another entity, if technically possible.
h) rights regarding automated individual decision-making process : as a rule, Customers have the right that their data not be subject to a decision taken exclusively by automated means, including profiling, if this produces legal effects on them or similarly affects them to a significant extent. They have the right to express their point of view, to contest the decision and to request human intervention (the review of the automated decision by a BT employee).
i) the right to file a complaint with the National Supervisory Authority for Personal Data Processing (N.S.A.P.D.P.) : Clients have the right to file a complaint with the Supervisory Authority if they believe their rights have been violated:
National Authority for the Supervision of Personal Data Processing, General Gheorghe Magheru Boulevard 28-30 Sector 1, postal code 010336 Bucharest, Romania, e-mail: anspdcp@dataprotection.ro
For exercising the rights mentioned in points a) – h) above, please use the contact details of the data protection officer designated by BT (DPO BT), sending the request in any of the following ways:
- at the e-mail address dpo@btrl.ro
- filling out the online form available for Clients in the section: ”How to exercise your GDPR rights at BT”, available on Privacy Hub
- by postal mail, to the address in Cluj-Napoca city, Calea Dorobanților street, no. 30-36, Cluj county, with the mention “to the attention of the data protection officer”
Before sending us the request, we recommend you read the instructions in the section ”How to exercise your GDPR rights at BT” available on Privacy Hub.