3. For what purposes do we process personal data, what data is it, for how long do we keep it, and to whom can we disclose it?
A. Personal data processed for identity verification and identification
The legislation on preventing money laundering requires us to verify the identity of individuals requesting to open a current account (to establish a business relationship with the bank) and to contract products/services. We also have a legitimate interest in preventing identity theft fraud attempts and conducting checks to allow the process to proceed only for those who meet the applicable conditions.
For these purposes, we use a remote identification process via video means, in accordance with the applicable legislation in this field. We use your personal data from the identification document – “identity document” (identity card, electronic identity card, or, depending on your specific situation, Romanian passport), contact details, and facial biometric data.
We will use biometric data only with your explicit consent. If you wish to give your consent, please check the box next to the text “I agree with the processing of biometric data” from the dedicated BT Pay screen. If you do not agree with this processing, you can request the opening of a current account at a BT branch, where such data will not be processed.
Before freely deciding whether you want to give your explicit consent for processing biometric data, here is how we will perform remote identification in BT Pay:
- Photograph your identity document – (requires camera access) – we extract your identity data from it using optical character recognition (a process that automatically extracts letters and numbers from the photographed ID card) and compare it with the data from the identity card issued by the General Directorate for Personal Records D.G.E.P. (seehere details about the processing of data provided by D.G.E.P.). We also verify your date of birth and the type of identity document you photographed, to ensure you meet the conditions for completing the process in BT Pay.
- Move in front of the camera (camera access required) – we use your live image to verify that you are a real person. Additionally, we automatically compare facial features from your selfie with those from the photo ID you provided and with your face data obtained from D.G.E.P. The comparison is carried out biometrically based on criteria such as the color, size, and tilt of the eyes; the position and distance between key facial features like the eyes, eyebrows, lips, and nose. Following the comparison, the software will provide a result (accepted or rejected, as applicable), indicating the likelihood that the faces in the two images belong to the same person. The data used for and resulting from the comparison arebiometric data , which uniquely identifies you. If the score given by the facial recognition tool is unsatisfactory, you will be able to restart the application process at a BT branch.
- If the result of the facial biometric comparison is satisfactory, we will use the data from your identity document to complete the application for opening a business relationship with the bank and contracting transactional products.
- We will also ask for contact details—phone number and email address—which we will verify to ensure they are correct and belong to you.
If you successfully complete opening the current account, this contact information will also be used:
- to send you messages of particular or general interest related to your status as a bank client (including as necessary for your use of certain transactional products contracted), messages evaluating BT’s service quality, or responses to various requests/complaints you send us.
- to send you advertising messages (direct marketing), only if you agree to the processing of your data for advertising purposes
The remote identification process via video means described above can only be carried out with your consent, which is required by Romanian legislation regarding remote identification through video means. By checking the box next to the text “I agree with remote identification via video meansyou give your express consent to undergo the remote identification process for the purpose of applying customer due diligence measures to establish a business relationship with Banca Transilvania, as well as your consent regarding the taking of photographs and/or image captures of you and your identity document.
The personal data indicated at points 1-4, used for identification, are also processed to allow you to initially set the security code (PIN) in the application.
For remote identification in BT Pay, we use the services of the service provider Onfido and some of its subcontracted partners. They process the data from your photographed identity document, your image (from selfies/videos taken in BT Pay), and your facial biometric data only on behalf of and under the instructions of the bank. Onfido and its partners may be located in third countries, such as the UK (with adequate data protection recognized by the European Commission), or in other countries without such a decision. In the latter cases, we have ensured that data transfers are carried out based on appropriate guarantees provided by the GDPR, consisting of standard contractual clauses approved by the European Commission, which you can find here:https://eur-lex.europa.eu/legal-content/RO/TXT/PDF/?uri=CELEX:32021D0914
If you do not complete the current account opening request initiated in BT Pay by applying the qualified electronic signature, the collected personal data will be kept for 30 days.
Instead, if you signed the current account opening request via BT Pay and then gave up on opening the account or your account opening was declined, as well as if you became a BT account holder client through this process, the data retention periods indicated in section I (i) apply BT Privacy Policy.
B. Personal data processed for client due diligence to prevent money laundering and terrorist financing, as well as for the conclusion and administration of current account agreements and transactional products
For the prevention of money laundering and terrorist financing, the bank applies customer due diligence measures for all individuals who wish to open a current account. For the implementation of these measures, the bank has a legal obligation to collect, update, and store at least the following categories of personal data about the person requesting the opening of the current account: first name, last name, alias, date and place of birth, personal numeric code or another similar unique identification element, citizenship, domicile, residence, address where they live and its legal status, phone number, fax, email address, occupation, employer's name or nature of own activity, purpose and nature of the business relationship with the bank, source of the funds to be used in the business relationship, estimated level of daily transactions, classification as or exclusion from politically exposed persons (PEP), source of wealth and important public function held (only in the case of PEP), as well as the details and a copy of the identity document. Data from your identity document may also be verified and updated (if applicable, once you become a client) based on information provided to the bank by the General Directorate for Persons Record (D.G.E.P). Also, based on information from D.G.E.P., the address where you live/correspondence address registered with the bank will be updated if you declare to the bank that your residence address is the same as your domicile.
The provided data, together with all records obtained through the customer due diligence measures required by law—such as monitoring and verifications performed by the bank, supporting documents, and transaction records, including the results of any analysis conducted regarding you as a client—determine your risk profile and will be retained for a period of 5 years after the termination of the business relationship with the bank. This legally mandated retention period may be extended under the same legislation. Upon expiration of the retention period stipulated by this legislation, the bank will delete or anonymize these data, except in cases where other legal provisions require their continued retention. In accordance with the legal obligation imposed on the bank by the Fiscal Procedure Code, some of the aforementioned data are also processed to fulfill the reporting that BT must submit daily to ANAF regarding account holders, their representatives, signatories on accounts, and beneficial owners. The legal retention period for these data is 10 years from the termination of the business relationship.
At the same time, the bank will assign you identifiers, such as, but not limited to: client code (BT CIF), IBAN codes related to accounts opened at the Bank, numbers related to bank cards, based on which you can be identified in the bank's systems.
In situations where it is mandatory or necessary, your personal data, as a client, will be disclosed/transferred to various categories of recipients (e.g. to ANAF - in accordance with tax legislation, to other banks and their clients to whom/from whom BT clients transfer/receive amounts from/in BT accounts, to service providers used by the bank), including entities that are part of the BT Financial Group, for legitimate purposes and under conditions that ensure their security.
For all details related to the processing of BT customers' data, please read in full Note of information general regarding processing and protection data with character personal belonging Clients BT, to which this specific information note is attached.
C. For collecting options regarding the processing of personal data for advertising purposes, for phone contact to provide support, and for sending push notifications in BT Pay
Collecting marketing options
The bank has a legitimate interest in collecting your choices regarding the processing of personal data for advertising purposes ("marketing preferences"). You are not obliged to express your preferences, but if you choose to do so, you can opt to have your data processed for advertising (to give your marketing consent) or to refuse.We will only send you advertising messages if you give your consent.
Before you freely decide whether you want to receive such messages, please consider the following:
What personal data do we use from you – if you choose to receive advertising messages, we process: your first name, last name, phone number, declared e-mail and correspondence address to the bank. At the same time, to ensure the advertising messages are relevant, we will also use other information we obtain when you use our services/products (e.g. transaction data, age, location, income range, etc.). We will analyze this data automatically (profiling) to form an opinion about the products/services/events that may suit you. It is important to know that, in advertising messages sent by e-mail, we use tracking pixels and/or other similar technologies to better understand how you interact with the messages. Through these technologies, we collect information such as: when/if you opened the e-mail, links or certain areas accessed within the e-mail. This way, we can improve our marketing strategies and send you more relevant advertising messages. You can avoid e-mail tracking through these technologies by adjusting your e-mail inbox settings (according to the options provided by your e-mail service provider).
How long is the agreement valid - if you choose to receive marketing messages, the consent given is valid until you withdraw/modify it or, otherwise, until the end of your status as a BT client - account holder or non-account holder (e.g. authorised person, client representative).
To whom do we disclose your data – if you choose to be contacted for advertising purposes, depending on your option, BT will share your data with:
(1) BT subsidiaries – entities within the Banca Transilvania Financial Group (BT Microfinanțare IFN SA, BT Asset Management S.A.I. S.A., BT Leasing Transilvania I.F.N. S.A., BT Direct I.F.N. S.A., BT Capital Partners S.S.I.F. S.A., BT Pensii Societate de Administrare a Fondurilor de Pensii Facultative S.A., BT Pensia Noastră Societate de Administrare a unui Fond de Pensii Administrat Privat S.A., Inno Investments S.A.I. S.A., BT Broker S.R.L., Fundația Clubul Întreprinzătorului Român, Fundația Clujul are Suflet, and other entities that may join this group in the future), except where you have set communication preferences directly with subsidiaries;
(2) current or future partners of BT and/or BT subsidiaries, whose products/services/events are related to BT services/products – the list of current partners is available at this link or, upon request, at any BT or BT subsidiary branch.
Also, for the purpose of sending advertising messages, your data will be disclosed to service providers who will process it as authorized representatives of BT, BT subsidiaries, or their partners.
Which communications are not affected by marketing preferences — the choices made regarding the processing of personal data for advertising purposes, whatever they may be: (a) do not relate to messages of general or specific interest for customers, which BT sends based on its legitimate interests to properly manage the business relationship or based on its legal obligations; (b) do not affect the subscription/unsubscription of the e-mail address entered in the forms available on BT websites to receive information from various fields of interest. Subscription to the newsletters available on the site is done through those online forms, and unsubscription is managed by following the unsubscribe link in the newsletters received after subscription.
Based on the above information, during the process of opening a current account via BT Pay you will be presented with both the option to decline receiving advertising messages and the option to consent to receiving such messages. The consent option will be divided into several categories from which you can choose: BT and/or BT subsidiaries’ products and services, events organized by BT and/or BT subsidiaries, partners’ products/services related to BT or BT subsidiaries’ products/services, and events organized by BT partners.
If you are already a BT non-account holder client who has previously given consent for data processing for advertising purposes and now select options that change or withdraw the previously given consent, we will record your new choices in our records and respect them. However, it may take up to 5 business days for us to ensure the removal of your data from campaigns currently underway. During this time, you may still receive advertising messages in line with your former choices.
Also, if you previously expressed your refusal to have your data processed for advertising purposes and you give your consent during the BT Pay current account opening process, the newly expressed option will take precedence.
Regarding the processing of your personal data for advertising purposes, you are guaranteed the rights provided by the General Data Protection Regulation (GDPR).
If you choose to consent to receiving advertising messages, you can withdraw/modify it at any time and/or object to profiling for advertising purposes as follows:
- by accessing the „Options for processing personal data for advertising purposesfrom the bank's website- www.bancatransilvania.ro;
- by accessing the dedicated section on the BT Pay Web internet/mobile banking platform;
- at BT branches, where you can request our employees to update your preferences regarding the processing of your personal data for advertising purposes;
- by sending a request to this effect to the BT headquarters, marked “Attention DPO”;
Collecting consent and phone contact for support purposes
If at any point you pause the online application process, we want to provide the necessary support to help you resume it. If you decline phone contact for support, you can register your objection by unchecking the corresponding box on the dedicated BT Pay screen.
Collecting the preference for and sending push notifications in BT Pay
Also at the beginning of the process, you will be asked if you allow receiving push notifications in BT Pay. If you accept such notifications and do not complete the application process within the deadline set after you have set your PIN, we will send you notifications to remind you to resume the process. In this case, you will resume the process from where you left off. If you do not set a PIN or if you do not complete the process within the set deadline, you will need to start the process over if you wish to open your current account through BT Pay.
D. For concluding the contracts related to the transactional products from the subscription you will choose
Depending on the type of current account subscription you choose, we process your personal data regarding the chosen subscription type, including the transactional products included (e.g., cards, internet banking), as well as for setting the applicable fees for the products included in the subscription.
Please note that for insurance products included in certain subscription types, the operator of your personal data necessary for concluding and executing the insurance contract/policy is the insurer providing those services. BT processes insurance data as an operator only for the purpose of collecting the insurance premium payment (included in the subscription).
E. For the issuance and management of the Qualified Digital Certificate issued by Alfatrust Certification S.A. for signing documentation related to BT
To complete the process of opening a BT current account through BT Pay, you will need to sign electronically with a qualified electronic signature the application for opening the contractual/business relationship and for contracting the transactional products included in the subscription and, if applicable, the form with options regarding the processing of your data for advertising purposes.
Issuing and using the digital certificate for signing involves no cost to you, but it is necessary for BT and Alfatrust to jointly process, as joint controllers, your personal data for issuing this electronic signature, as explained below:
a. Operators of personal data
Based on Art. 13-14 of EU Regulation 679/2016 - General Data Protection Regulation (“GDPR”), Alfatrust Certification S.A. (“Alfatrust”) and Banca Transilvania S.A. (“BT” or “Bank”), having the identification and contact data indicated within the Terms and Conditions for providing certification services for qualified digital certificates,informs you about the processing of your personal data as a User (“data subject”), carried out as associated controllers for the purpose mentioned under point b below.
b. The purpose and legal basis for processing personal data
The purpose for which the associated operators process the User's data is the issuance and management of the Qualified Digital Certificate ("the Certificate").
BT is the operator that identifies the User, respectively collects from them the personal data necessary for issuing the Qualified Digital Certificate, and transmits it to Alfatrust so that this operator can issue the certificate.
The data that BT collects from Users are those processed by the Bank in its own records, in the context of the business relationship that is initiated between the User and the Bank at the time of data transmission to Alfatrust.
During the validity period of the certificate, personal data is processed by associated operators, as applicable, including in cases where Users request the suspension or revocation of the certificate in the ways detailed in the Terms and Conditions of service provision.
The legal obligation (Art. 6 para. 1 letter c GDPR), the conclusion/performance of the Contract (Art. 6 para. 1 letter b GDPR) and the legitimate interest of the associated controllers (Art. 6 para. 1 letter f GDPR) are the grounds for processing personal data for the defined purpose.
Regarding the legal obligation, both BT – as the credit institution with which the User establishes a business relationship, and Alfatrust – as the accredited certification service provider from whom the User wishes to obtain a certificate, are subject to the legal provisions applicable to the prevention of money laundering and terrorist financing, under which they must collect certain personal data. This data is also necessary for the conclusion/performance of the Contract under which the User is permitted to use the certificate to sign documentation related to BT.
To assist Users who wish to submit a request to suspend or withdraw their certificate, the associated operators justify a legitimate interest in offering them the possibility to submit these requests not only directly to Alfatrust but also through BT. Processing these requests involves exchanging Users' personal data between the two associated operators. Contact details – phone number and home address – will be processed by either of the associated operators whenever it is necessary to contact the end user to ensure the proper management of the contractual relationship related to the qualified digital certificate.
c. Categories of personal data and of persons whose personal data are processed.
Personal data processed in order to fulfill the mentioned purpose are those provided by law as mandatory to be collected by a credit institution, respectively by a certification services provider for the prevention of money laundering and the sanctioning of terrorism, namely: name, surname, personal numeric code (CNP), home/residence address, identity document validity date, phone number and copy of the identity document. All these data, as collected by the Bank, will be made available to Alfatrust for the issuance and management of the Qualified Digital Certificate.
Processing of these personal data is necessary for the generation of the Qualified Digital Certificate. The User's refusal to have these data processed leads to the impossibility of issuing the Qualified Digital Certificate.
The individuals targeted by this processing are only the Users, as they are defined in the Terms and Conditions of use.
d. Recipients of personal data.
Except for associated controllers between whom personal data processed for the purpose of processing will be exchanged, the data are disclosed, as applicable, to the employees of associated controllers who need to know them, to IT service providers, auditors, authorities, and institutions entitled to access them.
e. The period of processing of personal data.
The information regarding a Qualified Digital Certificate (including personal data) is processed by Alfatrust for a period of 10 years from the date of its expiration, in accordance with the legally established deadlines.
At the level of Transilvania Bank, the remote electronic signature, applied based on the Qualified Digital Certificate issued by Alfatrust on the documentation signed in relation to BT, is kept for the entire period during which a business relationship is conducted between the Client User and BT, to which are added the terms established in the applicable banking legislation, namely at least 5 years from the termination of the business relationship with the credit institution.
f. Rights of the data subjects regarding the processing of their personal data for the indicated purpose.
Each User, in their capacity as a data subject, is guaranteed the exercise of the following rights regarding the processing of their personal data at any of the associated operators: the right of access, the right to rectification, the right to restrict processing, the right to erasure of data, the right to object to data processing, the right to data portability.
Users can exercise these rights or contact the data protection officers for any questions/requests regarding the processing of personal data, as follows:
at Banca Transilvania S.A. - by message sent to the e-mail address dpo@btrl.ro or by a request sent to the BT headquarters, with the mention "to the attention of the data protection officer (DPO)"
to Alfatrust Certification S.A.- by message sent to the email address dataprotection@alfasign.ro or by a request sent to Alfatrust headquarters, with the mention "to the attention of the data protection officer (DPO)".
Users also have the right to file a complaint with the supervisory authority - the National Supervisory Authority for Personal Data Processing (ANSPDCP), with headquarters îin Bucharest, sector 1, Bd. G-ral Gh. Magheru no. 28-30.