24/7 Support Service
Information note on the rights of data subjects
Note on personal data
1. IDENTITY OF THE DATA CONTROLLER AND CONTACT DETAILS OF THE PERSON RESPONSIBLE FOR THE PROTECTION OF PERSONAL DATA
1.1. BC “Moldindconbank” S.A., hereinafter referred to as the “Bank,” IDNO – 1002600028096, holder of NBM License Series A MMII No.004507 of 07.03.2018, with its registered address at 38 Armeneasca Street, Chisinau, MD-2012, acting as the controller of personal data, has determined the purposes and means of processing personal data as set out in this Information Note
1.2. Data subjects may contact the person responsible for data protection regarding matters related to the processing of their data and the exercise of their rights under Law No. 133/2011 at the following email address: protectiadatelor@micb.md.
2. LEGAL FRAMEWORK AND BASIS FOR THE PROCESSING OF PERSONAL DATA
2.1. In processing personal data, the Bank acts in compliance with the applicable legal framework:
a) Law No. 202/2017 on the activity of banks
(https://www.legis.md/cautare/getResults?doc_id=121176&lang=ro#);
b) Law No. 133/2011 on the protection of personal data
(https://www.legis.md/cautare/getResults?doc_id=110544&lang=ro);
c) Law No. 308/2017 on preventing and combating money laundering and terrorist financing
(https://www.legis.md/cautare/getResults?doc_id=110418&lang=ro);
d) Other applicable legislative acts.
2.2. Legal basis for processing:
a) performance of the contract concluded between the Bank and the customer — the personal data subject;
b) consent of the personal data subject;
c) pursuit by the Bank of a legitimate interest;
d) legal obligation.
2.3. The storage of personal data is carried out on servers owned by the Bank and located in the Republic of Moldova.
2.4. The processing of personal data also includes the cross-border transfer of personal data to contractual partners that provide the Bank with services necessary for the proper conduct of its banking activities and/or their subcontractors located in the European Economic Area and the United Kingdom, exclusively for the purpose of providing electronic identification services, with the application of appropriate data protection measures.
3. PERSONAL DATA SUBJECTS
The Bank processes data of personal data subjects (individuals) as follows:
3.1. Individuals — customers of the Bank, who benefit from the services /products provided by the Bank;
3.2. Individuals — potential customers of the Bank, who intend or are about to establish contractual relations with the Bank, and former customers who have terminated their business relationship with the Bank;
3.3. Representatives (legal or authorized) and beneficial owners of customers (existing, p potential, or former);
3.4. Visitors to the Bank’s branch premises where video surveillance cameras are installed, as well as visitors to the Bank’s web pages;
3.5. The Bank’s shareholders;
3.6. Third parties outside a direct relationship with the Bank (for example, participants in various events organized by the Bank; persons whose data have been made available to the Bank by any other person with whom the Bank interacts; persons mentioned in conflict-of-interest declarations; persons whose data are indicated in payment orders processed by the Bank, etc.);
3.7. Individuals connected to an applicant for a loan from the Bank;
3.8. Users of technical solutions (electronic identification means) related to the digital onboarding offered by the Bank;
3.9. Contractual partners.
*This Notice does not apply to:
a) the Bank’s employees and prospective employees who have applied for employment;
b) persons undertaking internships, including volunteers and trainees.
These persons are informed about the processing of their data carried out by the Bank in its capacity as employer through a separate document.
4. CATEGORIES OF PERSONAL DATA PROCESSED
4.1. The Bank processes the following categories of personal data:
a) first name and surname;
b) date and place of birth;
c) identity document number and series;
d) IDNP (personal identification number);
e) domicile/residence;
f) electronic and handwritten signature;
g) banking data and financial situation;
h) categories of data necessary for due diligence measures;
i) credit history;
j) landline/mobile phone number and email address;
k) photo/video image;
l) voice (in the case of telephone conversations via the call center or card support);
m) IP address, IP-based location;
n) biometric data;
o) confirmation codes related to the requested services;
p) card number, expiry date, CVV/CVC code, and the name on the card;
q) transaction data (amount, date, location, beneficiary, IBAN, etc.);
r) other data necessary for business purposes.
4.2. The refusal of the personal data subject to provide the categories of data set out in section 4.1 (according to the standard forms), or the provision of false or incorrect information, results in the impossibility of providing the requested services or resolving the submitted requests.
4.3. The period during which the Bank processes the personal data specified in section 4.1 does not exceed the period necessary to fulfill the purposes for which the data are processed.
5. RECORD-KEEPING SYSTEMS AND METHOD OF PROCESSING
5.1. The Bank processes data provided by personal data subjects, data generated after their provision, and data made public by the subjects:
a) within record-keeping systems:
1. obtained through the completion by personal data subjects of standard forms in electronic format (online submission of a loan application);
2. obtained through the manual completion by personal data subjects of the contract or questionnaire regarding the request for a service (initiation of a business relationship), through written correspondence.
b) within video surveillance record-keeping systems and the access control record-keeping system;
c) within the Bank’s manual record-keeping systems for temporary visitors;
d) through the MICB Mobile Banking mobile application / obtained by electronic identification means within the digital onboarding process.
5.2. In all cases of personal data collection, such data are processed by the Bank within its security perimeter, with the necessary organizational and technical measures implemented to ensure an adequate level of personal data protection. The mechanism for ensuring the protection of personal data is established in the Bank’s Security Policy on the Processing of Personal Data, including the related regulations and instructions that describe the protection processes and measures.
5.3. The organizational and technical measures implemented by the Bank fall within the applicable legal limits and have been evaluated by the National Center for Personal Data Protection in terms of their compliance.
6. PURPOSE OF THE PROCESSING OF PERSONAL DATA
6.1.The Bank processes personal data for the following purposes:
a) actions necessary for concluding and carrying out contractual relationships with customers, suppliers, partners, etc., for the purpose of providing banking services and procuring goods and services;
b) actions necessary for negotiating, concluding, and carrying out employment contractual relationships with employees and/or service provision relationships with service providers;
c) identification and verification of customers’ identity by electronic means; remote identification of a person by electronic means is a process of identifying and verifying the identity of an individual based on the presented identity documents, facial biometric measurements, image comparison, and information communicated by the individual and/or obtained from external data sources, using digital means (digital onboarding);
d) provision by the Bank of services/products (advertising);
e) carrying out customer due diligence procedures;
f) support communication with customers, users of the MICB Mobile Banking mobile application, and third parties, including within the digital onboarding process;
g) preventing fraud, ensuring information and physical security;
h) use of the MICB Mobile Banking application;
i) sharing data with other licensed banks and other mobile applications within the Open Banking system;
j) assessment of solvency, reduction of lending risk, determination of the debt burden of customers interested in customized offers related to the Bank’s lending products or in contracting such products (credit risk analysis);
k) other purposes related to the Bank’s activity, in compliance with the applicable legal framework.
7. PERIOD OF PROCESSING OF PERSONAL DATA
7.1. The Bank processes personal data for the period necessary to identify personal data subjects, achieve the purposes for which the data were collected, and throughout the entire duration of the contractual relationship and provision of services.
7.2. In accordance with its legal obligations, the Bank retains all documents and information necessary for complying with due diligence measures regarding customers and beneficial owners, including, where available, information obtained through electronic identification means/digital onboarding (which also includes biometric data), for a period of 5 (five) years from the termination of the business relationship or from the date of an occasional transaction.
7.3. For persons who have not completed the remote identification process / have not completed the digital onboarding process, the data are stored on the Bank’s internal servers for a period of 1 (one) year, exclusively for the purpose of providing support and clarifications regarding possible suspicions of fraud, reporting suspicious activities and fraud incidents to the NBM, after which they are permanently deleted under secure conditions.
8. RECIPIENTS OF PERSONAL DATA
8.1. The Bank may disclose, transfer, or grant access to personal data to the following recipients:
a) persons authorized by the Bank;
b) another personal data subject or their representative, based on a legal ground;
c) contractual partners, within the limits of the needs arising from business relations, including contractual partners that provide the Bank with services necessary for the proper conduct of its banking activities and/or their subcontractors located in the European Area and the United Kingdom, exclusively for the purpose of providing electronic identification services, with the application of appropriate data protection measures;
d) law enforcement, tax, supervisory, control authorities, and other entities empowered by law to request from the Bank and process personal data, upon their reasoned request.
9. RIGHTS OF PERSONAL DATA SUBJECTS
9.1. Right to information — this is the right of the personal data subject to be informed about the identity of the controller, the purpose of processing the collected data, the recipients or categories of recipients of the personal data, the existence of the rights of access, intervention, and objection provided by the Law on the protection of personal data, as well as the conditions under which these rights may be exercised.
9.2. Right of access — this is the right of the personal data subject to obtain from the Bank, based on a request, confirmation or denial as to whether personal data relating to them are being processed by the Bank, information regarding the purposes and categories of data processed, the recipients or categories of recipients to whom the data are disclosed, the manner in which automated data processing is carried out, the legal consequences generated by the processing for the data subject, and the manner of exercising the right of intervention in relation to personal data.
9.3. Right of intervention — this is the right to obtain from the Bank, based on a request, the rectification, updating, blocking, or erasure of data whose processing contravenes the Law on the protection of personal data, in particular incomplete or inaccurate data.
9.4. Right to object — this is the right of the personal data subject to object at any time, on justified and legitimate grounds related to their particular situation, to the processing of data relating to them, except where legal provisions provide otherwise.
9.5. Right not to be subject to an individual decision — this consists of the possibility to request and obtain the withdrawal, cancellation, or re-evaluation of any decision producing legal effects with respect to the data subject that was adopted solely on the basis of automated processing intended to assess certain aspects of their personality, such as professional competence, reliability, behavior, or other similar aspects.
9.6. Access to justice — this is the right to bring a claim before the court in the event of a violation of rights and legitimate interests related to the field of personal data, in order to obtain redress for the damage suffered
10. COOKIES
10. Notice regarding cookies. A cookie refers to information collected when accessing the web pages micb.md, www.transfer.md, direct.micb.md, wb.micb.md, pudracard.micb.md, actionari.micb.md, and credit.micb.md, in order to identify the user who accessed certain informational content. This is generated by the Bank’s server and the computer on which the browser of the personal data subject operates. The information contained in the cookie is set by the server and may be used by that server whenever the user visits the website. A cookie may be considered an identity card of the internet user, indicating to a website when the user has returned. Similar technologies also apply to mobile devices (tablet, smartphone) from which information is accessed on that web page.