1. Who is the personal data operator, the data subjects, and what are the purposes of the processing
1. Who is the personal data operator, the data subjects, and what are the purposes of the processing
Banca Transilvania, S.A. credit institution with its registered office in Cluj-Napoca, Calea Dorobanților street, no. 30-36, Cluj county, registered at the Trade Register under no. J1993004155124, VAT number RO 5022670, contact phone: 02648028 (hereinafter referred to as “BT”) makes available to its legal entity clients the Internet and Mobile Banking service – BT Go (hereinafter referred to as “BT Go”) according to BT Go Terms and Conditions of Use. In this context, processes as a personal data operator ("personal data"), as further informed to you below.
If you are an individual using BT Go on behalf of one or more BT corporate clients of Banca Transilvania from Romania or Banca Transilvania – Italy Branch (for the functionalities available in BT Go for them), you have the status of user of this service on behalf of the corporate client(s) who have appointed you (hereinafter “client”) and you are a data subject of the personal data processing.
Also, it is a data subject including the account holder client who has contracted/uses BT Go, if they are of the type P.F.A., Individual Enterprise, individual form of practicing liberal professions (hereinafter “individual professional”).
BT will periodically update this notice, without imposing less favorable conditions regarding the processing and protection of personal data. The changes will be communicated to you, and the updated version will be available at any time for consultation in BT Go and also on the BT website, in the Privacy Hub section. BT Go users are always subject to the current version of this notice. If you have any questions or concerns regarding how BT processes personal data, you can contact the data protection officer appointed by BT at dpo@btrl.ro
2. What personal data we process, under what legal grounds, what individual automated decisions we make and what happens if you refuse their processing
2. What personal data we process, under what legal grounds, what individual automated decisions we make and what happens if you refuse their processing
a. What data do we collect when you open the business relationship of the legal entity with the bank through BT Go
At the opening of a business relationship through BT Go mobile for the legal entity you represent, we use remote identification through video means, which involves the processing of data from the identity document, contact data, and biometric data (facial recognition), in accordance with the applicable legislation. Details are presented in Information note regarding the processing of personal data for opening the business relationship with BT through BT Go - legal entities
b. What data do we collect for the identification/authentication of BT Go users
In order to use BT Go, we have the legal obligation to verify your identity, namely to identify you as an authorized user to use this service, according to the obligation imposed on us by the legislation in the field of payment services, which requires us to verify who you are, what you own, and what you know (strong customer authentication).
For identification, we process the following types of personal data, depending on the situation:
- the data from the identity document, pe care va fi necesar să îl fotografiați în anumite situații (acest lucru implică acces la camera foto). Vom compara aceste informații cu cele existente în evidențele băncii.
- the image faces in motion, from the selfie video that we will ask you to take in certain cases (requires access to the camera).
- the biometric data of the face, obtained by biometric comparison of the selfie image with that from the identity document photographed in the BT Go application and/or with the image already existing in the bank's records. We will process this data only if you express your explicit consent, which we will request from you in BT Go before carrying out such processing . Biometric comparison is based on criteria such as the color, size, and tilt of the eyes, the position and distance between the eyes, eyebrows, lips, and nose. In the situation where the score issued by the facial recognition tool is unsatisfactory or if you do not wish to express your consent for the processing of this type of personal data, we can identify you at any BT unit or through the call center, where we will not use biometric data.
- Login ID in BT Go (hereinafter referred to as "user ID")
- phone number declared at the bank
- security code (PIN) set for BT Go
When using the BT Go mobile version, you can choose to use either the PIN for this application that you set, or biometric data (e.g., fingerprint, face-ID from the device you are using) for login. You can also set biometric authentication for the web version of BT Go. If you opt for this login method, BT does not have access to the biometric data, as they are stored on the device you use. BT only obtains the information that the biometric authentication method was validated by your phone.
Special information addressed to BT Go USA users, regarding the processing of personal data necessary for identification through Onfido
U.S. users of BT Go, as defined in the Terms of Use and execution of banking transactions via Internet/Mobile Banking BT Go, should be aware that, in accordance with applicable U.S. legislation for the processing of biometric data, including the Illinois Biometric Information Privacy Act (BIPA), their personal data of this type are processed by Onfido, as detailed in the Onfido Facial Scan and Voice Recording Policy, found at the following link: https://onfido.com/facial-scan-policy-and-release/. If you are a U.S. user of BT Go, by continuing the identification process in the Application as described above, you confirm that you have read, understood, and accept the Onfido Facial Scan and Voice Recording Policy, as well as Onfido Privacy Policy and Onfido Terms and Conditions.
c. What data do we collect to ensure the security of BT Go
In order to protect transactions ordered through BT Go and the information within this platform, we will collect and use DeviceID of the device on which you have the BT Go mobile application installed, others device security identifiers (ex. Instance ID/Device Identifier), including the history of the devices on which you have used BT Go and the generated tokens, the model, the phone manufacturer, and the type of its operating system, to verify that at each login you are still using the same phone with which you registered to use the BT Go application.
Also, we have the legitimate interest and, where applicable, the legal obligation to collect and use address/ IP addresses to the devices you use to connect to BT Go, which also reveals the geographical location from where you carry out the transaction via BT Go. If you refuse to grant us access to this data, you will not be able to use the BT Go service.
At the same time, we use a tool that scans device application list with which you connect to BT Go, to detect if there is malware, including applications of the type that allow remote connection and/or if you use the device for calls while using BT Go. In case such applications/situations or other cases suggesting a compromise of your user accounts in other applications provided by BT are identified, we will block your access to the BT Go user account and/or we will block the use of BT Go on the potentially compromised device. This block is an automated individual decision that we make based on the legal obligations imposed on us.
Not least, we are obliged by the applicable legal provisions in the field of payment services to we monitor transactions to prevent fraud. In case we detect transactions that are suspected of fraud, we may decide to block their processing.
We process this data to protect information from BT Go. If you refuse their processing, you will not be able to use BT Go.
d. What data do we process when you use BT Go
In order to fulfill the legal obligations we have, to provide you with the BT Go service you have contracted for your company and, where applicable, because we have a legitimate interest in preventing fraud and communicating with BT Go users to provide them support and to request their evaluation of the quality of the BT Go service, we use:
-> Data related to accounts, cards and transactions
When you use the different functionalities of BT Go, we will have implicit access to informationregarding: bank accounts (of the legal entity and the payment beneficiaries), balances, transactions ordered through the accounts of the legal entity or related to amounts received in its accounts, including information mentioned in the payment explanations, data about the BT products of the legal entity (including loans held or that you wish to repay, deposits, investments held or made and their history, cards issued/requested for designated card users and details about them). Although this service is dedicated exclusively to corporate clients of Transilvania Bank, and information about corporate entities is not considered personal data, information about clients who are individual professionals has the status of personal data and the bank will treat it in compliance with the applicable legal provisions in this field.
Also, we process your personal data and/or that of other persons, such as individual payment beneficiaries or profesioniindividualized or other such persons mentioned in the payment explanations (e.g. the name you want to insert for the predefined beneficiary, address, IBAN) or whom you define as predefined beneficiaries (name/first and last name, IBAN).
At the same time, for the provision of the Beneficiary Name Display Service (SANB) for the purpose of preventing fraud in the case of initiated interbank payments, if you are a legal entity client of the type indicated above, whose information has the status of personal data, we inform you that these are processed according to the details in Information note regarding the processing of personal data within the Beneficiary Name Display Service (SANB), available on the bank's website, at the following link: https://www.bancatransilvania.ro/information-note-sanb.
Also for prevention of frauds, in the case of intrabank payments initiated from BT Go, BT processes – as an independent operator – the same categories of personal data that are used within SANB, but without the involvement of other participating banks or Transfond. The legal basis for processing personal data is BT's legitimate interest to prevent frauds in the case of intrabank payments (BT-BT). The abbreviated name of the entity, as registered at BT, will be displayed to other BT customers who initiate from a bank application a payment to the entity's account opened at the bank, regardless of whether the payment is completed or not.
When apply/contract a loan online from BT Go, we process your personal data as detailed in Information note on the processing of personal data for obtaining an online BT loan dedicated to legal entities.
If you integrate from BT Go with the FGO invoicing platform and allow access to the provider of this platform including the transaction history from the accounts of the legal entity that you connect to FGO, you assume the obligation to comply with the applicable legal provisions in the field of processing and protection of personal data, including those of informing and, where appropriate, obtaining consent from the data subjects to whom the legal entity has transferred amounts or from whom it has collected amounts within these transactions or whose personal data appear in the explanations of the transactions, considering that these personal data will be disclosed in this way to the FGO provider.
In case of accessing the functionality of investments, certain users will be able to invest on behalf of the legal entity in funds managed by BT Asset Management SAI (BTAM) by signing the intermediation contract with BT, to buy/sell fund units (UF) in the chosen fund, to set, modify or cancel a recurring investment, to view transactions in processing, operation history and balance, to generate portfolio statements and transaction confirmations, details about ex post costs and certificates of held investment accounts. Banca Transilvania will process, as a person authorized by the BTAM operator, as appropriate, the following personal information/data concerning you: name, first name, CNP, BTAM client ID, investment account number, transaction history, balance held in investment funds managed by BTAM, information related to gain/loss and withholding tax.
-> Contact details
Because we have a legitimate interest in providing you support in using BT Go (support) and because we want to know your opinion about this service (service quality evaluation), we will use the contact data you declared to the bank as our client. You have the right to object to such contact. For details, read the section regarding the rights you have in relation to the processing of your personal data.
If you have a sole proprietorship company, we will process its contact data (primary and secondary phone numbers and email addresses) to update them in the bank's records, within the BT Go mobile application.
-> Permissions requested in the context of using the application
When you install the application, you will be asked for permissions to access the status and identity of the phone, as well as to photo camera a dispozitivului, necesarpentru fotografierea actului de identitate in procedul de identificare pentru inregistrarea in BT Go. În funcție de versiunea de Android/iOS a telefonului puteți acorda acces astfel:
- Allow/Deny access
- Allow/Deny/While using the app
- Allow/Deny/Only this time
If you refuse to grant access to the camera you will not be able to register in the BT Go application. After registration, you can withdraw this permission, in which case you will not be able to use the BT Go features that require the use of the camera (e.g. invoice scanning), but you will be able to use other sections of BT Go.
Also, on first login in the application, you will be asked for permission to transmitting of notifications. If you refuse to grant access you will still be able to use the application, but you will no longer benefit from in-app notifications.
To upload invoices, the application will need access to section ofphotos/files of the device.
Other permissions necessary for the use and operation of the application, as established by the operating system provider of the device you are using and for which explicit user consent is not required, are detailed in the "permissions" section of the Play Store/Apple Store/App Gallery for the BT Go application (e.g., permissions to notify you when you do not have an internet connection).
-> Notifications
Through the BT Go mobile banking application, we will send you different types of notifications, depending on the actions you take and the user category you belong to, namely notifications:
- For authentication in the web version of BT Go
- For the authorization of payments made in the internet banking application
- About transactions on the client's account (e.g. receipts, payments, cash deposits/withdrawals at BT machines or at the counter, establishment or lifting of garnishments)
- About products owned by the client (e.g. about credits, deposits, cards)
- About new features/updates of BT Go
- Of general interest for BT Go users
- About offers/promotions (only with activation)
You will be able to enable/disable push notifications as you wish. If you refuse to receive notifications/some types of notifications, you will still be able to use the app, but you will no longer benefit from push alerts, which may make it harder for you to use BT Go (e.g. you will have to access different sections in BT GO to identify operations that require actions from you).
-> Aassistance and support through the BT chatbot Go
Through the BT chatbot Goyou can get quick answers about available features in BT Go or you can chat in real time with a BT consultant. In this context, we process data such as: name, client code BT, type of product or situations a for which solicitati support , the application version, the phone's operating system and the language selected in chat, for identification and support.
3. To whom can we disclose the data as a result of using BT Go
3. To whom can we disclose the data as a result of using BT Go
For individual professional clients, the data about their accounts and transactions in BT Go indirectly identify the natural person representing the individual professional, thus being personal data. We will disclose these data, as applicable, to:
➢ other BT Clients who have the right and need to know them
- BT Go users (all BT Go users are BT Clients) if you have granted other people BT Go user rights on the individual professional accounts opened at BT, we will disclose to these people - within BT Go - the bank data (accounts, transactions, identifiers of the accounts and transactions, etc.) corresponding to the accounts to which you have granted user rights
- BT clients to whom you order payments from BT Go
- When you make transactions through BT Go to accounts of other BT clients, the data related to these transactions (usually, the name of the individual professional, amount, BT account IBAN, payment explanations) will be accessible to the beneficiaries to whom you made the payment.
➢ contractual partners (service providers) used in BT activity
- for identification in BT Go which involves photographing the identity document and/or the face (selfie/video selfie), BT uses the services of the providerOnfido and those of some of its subcontractors, who process, only on behalf of and under the instructions of the bank, the data from the identity document, the image (including that from the video selfie taken in BT Go) and respectively the biometric data of the face, used for identification in BT Go. The data processing will be carried out in some cases also in third countries. The transfer of personal data to these countries is based either on adequacy decisions issued by the European Commission (e.g. in the United Kingdom), or other appropriate safeguards, in accordance with the GDPR mechanisms consisting of Standard Contractual Clauses approved by the European Commission which you can find here: https://eur-lex.europa.eu/legal-content/RO/TXT/PDF/?uri=CELEX:32021D0914
- BT Go allows connection to services offered by the bank's contractual partners (e.g. billing services). If you use these functionalities, the data necessary for the activation/connection/operation of these services is disclosed to these partners (these partners are also BT Clients).
- at your data processed in BT Go can be accessed, according to the need to know and only based on adequate personal data protection guarantees, by the bank's contractual partners who support us in providing the BT Go service.
➢ financial-banking entities
- when making transactions through BT Go to clients of other banks/payment institutions, the data related to the payments (usually, the name of the professional paying client, the amount, payment explanations) will be sent to the beneficiary bank of the payment for transaction processing
- when you use the open banking functionality from BT Go for the legal entity accounts for which you are a user, we will disclose to the financial institutions to which you grant access, respectively for the accounts for which you grant access, as applicable: the account number, the balance and the transactions carried out through these BT accounts (with all their details – date, amount, currency, account number and name/denomination of the counterparty in the transaction etc)
The list of recipients is completed with the one provided within General information notes regarding the processing and protection of personal data belonging to BT clients, section VIII.
4. How long do we keep the processed data in the context of providing the BT Go service
4. How long do we keep the processed data in the context of providing the BT Go service
Your data, as a BT client, as well as the data regarding the transactions carried out through the accounts (including through BT Go) are subject to the retention regime provided by the applicable normative acts, being at least 5 years from the termination of your business relationship with the bank, unless longer legal terms apply which can be up to 10 years from the end of the business relationship.
5. How do we ensure the protection of personal data in BT Go
5. How do we ensure the protection of personal data in BT Go
Banca Transilvania takes all necessary technical and organizational measures to protect personal data within BT Go.
Despite these precautions, the Bank cannot guarantee that unauthorized persons will not obtain access to your personal data through the terminals you use to access BT Go, in case they are unprotected or inadequately protected.
You are solely responsible for maintaining the confidentiality and keeping safe the terminal used to access BT Go (phone, computer, etc.) and especially the login ID and/or login passwords (password, fingerprint, or any other security method provided by the phone).
6. What are the rights enjoyed by BT Go users
6. What are the rights enjoyed by BT Go users
In accordance with the provisions of the General Data Protection Regulation (“GDPR”), as a data subject of the processing of personal data in the context of using BT Go, you are guaranteed the following rights: the right to be informed (we fulfill our obligation to inform you through this document), the right of access, the right to rectification, the right to data erasure, the right to restriction of processing, the right to data portability, the right to object, the right to address the National Authority for the Supervision of Personal Data Processing (ANSPDCP) and the courts.
Find these rights presented in detail including in General information note regarding the processing and protection of personal data belonging to BT Clients, with which this specific information note is completed, and which you can find on the website bancatransilvania.ro, in the Privacy Hub section.
You can exercise these rights at BT or contact BT's data protection officer (DPO) by sending a request by mail to the previously indicated BT headquarters - with the mention - "attention DPO" - or electronically at the e-mail address dpo@btrl.ro.
You also have the right to address the National Authority for the Supervision of Personal Data Processing (ANSPDCP) - (plangere@dataprotection.ro).
This BT Go privacy policy may be revised by BT at certain intervals. Users will find in the app and on the BT website, in the section Privacy Hub – specific information notes, the up-to-date version of the note.

