1. Who is the data controller and what is the purpose of the processing?
1. Who is the data controller and what is the purpose of the processing?
BT must ensure that online payments are secure. That is why, in BT Pay, we apply identification rules according to the legislation in the field of payment services, through which we verify who you are, what you own and what you know, to ensure your identity. We verify your identity in the app for this purpose in several phases: when you register/re-register in BT Pay, when you set/reset/unlock the PIN (security code) in the app, when you access the app or authorize transactions from it.
2. What are the data we use and what happens if you refuse their processing?
2. What are the data we use and what happens if you refuse their processing?
For registration in BT Pay
- For registration in BT Pay, re-registration if you have not set a PIN or if you have a PIN but have forgotten it
We use the following types of personal data that concern you:
- the data from the identity document - it will be necessary to photograph it (requires access to the camera). We will compare this information with the existing records in the bank's files.
- the image moving faces, from the selfie video that you will need to make (requires access to the camera)
- biometric facial data, obtained by comparing the biometric data of the selfie image with that from the photographed identity document and with your image in the bank’s records. The biometric comparison is based on criteria such as the color, size, and tilt of the eyes, the position and distance between the eyes, eyebrows, lips, and nose. Biometric data uniquely identifies you. They are special/sensitive data. We use biometric data only on the basis of explicit consent.
- If you are adult user, you express this consent for yourself and/or, as the case may be, for a minor over 14 years old whom you legally represent (e.g. you are a parent/guardian), by checking the box/pressing the specific button to express this agreement, which will be displayed in the application. If you do not wish to give your consent for the processing of this type of data, we can identify you and, where appropriate, the minor, at any BT unit, where we will not use biometric data.
- If you are a minor over 14 years old, we will be able to process your biometric data in BT Pay only if your parent gives us consent explicit (as specified in the previous paragraph) . Even if a parent agrees to us processing your biometric data for identification in BT Pay, if you do not feel comfortable with us using such data, do not start the registration process in BT Pay and ask your parent to go to a BT unit, where you can be identified without us processing your biometric data.
- For re-registration in BT Pay after setting a PIN in the application, for setting, resetting, and unlocking the PIN
We use for your identification, as appropriate, all or part of the following personal data: phone number declared to the bank, PIN-ul setat pentru aplicație (dacă ești utilizator major), the image from the selfie you will need to take (requires access to the camera) and the one in the identity document from the bank records that we will compare biometrically, thus using the biometric data of the face your (only if you express your consent for the processing of this type of data, through an explicit action that will be requested on a dedicated screen)
- To access the application and authorize transactions in BT Pay (collectively called “authentication in BT Pay”)
For your identification for authentication in BT Pay, regardless of whether the identification for registration in BT Pay was done directly in the Application or at a BT unit, we process the following categories of personal data, depending on the method you used for authentication:
- if you don't have a PIN set in BT Pay, we processmethod of unlocking the phone your (whatever it may be: fingerprint, face ID, PIN or phone unlock pattern). In this case, the Bank does not know the unlock method used, but implicitly finds out that it was entered correctly if the transaction authorization is successfully completed.
- if you have a PIN set in the app, we use for your identification The PIN.
Additionally, if you choose to activate the use ofbiometric data from the devicefor authentication in BT Pay (fingerprint, face ID – biometric characteristics of the face) we also use this data, without however having access to it. BT only uses the result of the comparison between the fingerprint/face characteristics applied/scanned and the fingerprint/face characteristics stored on the device you are using, to allow you to authenticate in the application. If biometric authentication fails, you will need to use the PIN set in BT Pay to authenticate.
For the carrying out/authorization of certain transactions, we will also usethe biometric data of the face your (only if you express your consent for the processing of this type of data, through an explicit action that will be requested on a dedicated screen). If you do not want us to use this type of data, you can request the processing of the transaction at a BT unit.
3. Data recipients and data transfer to third countries
3. Data recipients and data transfer to third countries
For identification in BT Pay involving photographing the identity document and/or the face (selfie/video selfie), BT uses the services of the provider Onfido and some of its subcontractors, who process, only on behalf of and under the instructions of the bank, the data from the identity document, the image (including the one from the video selfie taken in BT Pay) and respectively the biometric data of the face, used for identification in BT Pay. The data processing will also be carried out in some cases in third countries. The transfer of personal data to these countries is based either on adequacy decisions issued by the European Commission (e.g., in the United Kingdom), or other appropriate safeguards, in accordance with the GDPR mechanisms consisting of Standard Contractual Clauses approved by the European Commission which you can find here: https://eurlex.europa.eu/legal-content/RO/TXT/PDF/?uri=CELEX:32021D0915&from=EN.
4. Special information addressed to US users of the Application, regarding the processing of personal data necessary for identification
4. Special information addressed to US users of the Application, regarding the processing of personal data necessary for identification
U.S. users of BT Pay, as defined in the Terms and Conditions of Use of the Application, should be aware that, in accordance with applicable U.S. legislation for the processing of biometric data, including the Illinois Biometric Information Privacy Act (BIPA), their personal data of this type is processed by Onfido, as detailed in the Onfido policy regarding facial scanning and voice recording, found at the following link:https://onfido.com/facial-scan-policy-and-release/
If you are a BT Pay USA user, by continuing the identification process in the Application as described above, you confirm that you have read, understood, and accept the Onfido Policy regarding facial scanning and voice recording, as well as Onfido Privacy Policy and Onfido Terms and Conditions.
The provisions of this specific information note are supplemented by those of Information note regarding the processing of personal data within the BT Pay mobile application , respectively with those of Information note regarding the processing in BT PAY of personal data of minor users over 14 years old who have a BT account – (in the case of users under 14 years old who use the functionality for minors who have a BT account), as well as with those of General information notes regarding the processing and protection of personal data belonging to BT Customers. The general information note is an integral part of BT Privacy Policies, which you can find on website of Transilvania Bank in the Privacy Hub section or in BT units. In this note you will find details about the rights you benefit from regarding the processing of your data, the ways you can exercise them, the contact details of the BT DPO, and the data retention period.
For the english version of this privacy notice tap here.

