FirstRand Limited privacy statement
In accordance with data protection law, the following information provides an overview of how FirstRand Bank Limited (London Branch) collects, uses and discloses personal data that we receive when you visit and use this website (the “Site”), provide services or supply goods on our behalf, communicate with us, or otherwise interact with us, whether online or offline.
It is important that you read this Privacy Notice so that you are fully aware of how and why we are using your data.
If you are an employee, representative, director, shareholder, ultimate beneficial owner, guarantor or beneficiary of one of our customers or prospective customers, our Customer Fair Processing Notice will also apply to the extent we separately process your personal data in connection with our services.
1. About us
The Site is owned and operated by FirstRand Bank Limited (London Branch) (“we”, “us” and “our”), the UK branch of FirstRand Bank Limited, acting through its Rand Merchant Bank division (“RMB”), which is incorporated under the laws of South Africa. Our UK registered address is at Austin Friars House, 2-6 Austin Friars, London, EC2N 2HD.
We are registered as a data controller with the UK Information Commissioner’s Office (registration number Z1384125).
2. Who can you contact about personal data?
If you have any queries concerning this notice or our data processing practices, our Data Protection Officer can be contacted by email at firstname.lastname@example.org. You can also write to us using our registered UK address, as set out above.
3. What personal data might we hold about you and where do we get it from?
Information you give us
You may provide us with personal data, including when you:
- use the Site;
- request additional information about our services; or
- otherwise communicate with us (whether through the Site, by email or phone).
If you work for one of our suppliers, you may also provide us with personal data when providing the relevant goods or services on our behalf.
The categories of personal data you provide include:
- Contact details, such as name, email address and phone number;
- Employment details, such as your employer and job title; and
- Communications data, such as any other personal data you provide in your communications with us.
Information we process automatically
We also collect, store and use information about your use of the Site, and about your computer, tablet, mobile or other device through which you access the Site. This includes the following information:
- Technical Data: including the Internet protocol (IP) address, browser type, internet service provider, device identifier, your login information, time zone setting, browser plug-in types and versions, preferred language, activities, operating system and platform, and geographical location; and
- Usage Data: including the full Uniform Resource Locators (URL), clickstream to, through and from the Site, pages you viewed and searched for, page response times, length of visits to certain pages, referral source/exit pages, page interaction information (such as scrolling, clicks and mouse-overs), date and time pages are accessed, website navigation and search terms used, and whether you have opened our marketing newsletters.
Information we collect from third parties
We may obtain personal data about you from the following third parties:
- other FirstRand Group entities, other companies and financial institutions;
- analytics providers; and
- publicly available sources (e.g. the press, registers of companies, publicly accessible websites, including social media platforms); and
- your employer.
We may also collect, use and share “Aggregated Data” such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is anonymised and is not considered personal data as it will not directly or indirectly reveal your identity.
The Site is not intended for or directed at children under the age of 18 years and we do not knowingly collect information relating to children under this age.
4. What will we use your data for and does the law allow this?
Under applicable data protection law, we are only permitted to use your personal data where we have a lawful basis for doing so. The purposes for which we process your personal data are summarised below, together with the lawful basis under data protection law which allow us to do this:
- For compliance with a legal obligation or acting in the public interest
As a bank, we are subject to a number of statutory and regulatory obligations that may require us to collect, store or disclose personal data, such as for anti-money laundering purposes or to respond to investigations or disclosure orders from the police, regulators of FirstRand Group entities, and tax or other public authorities (including outside the UK).
- For the purposes of legitimate interests
Where necessary, we process your personal data to serve our legitimate interests or those of a third party, so long as such interests are not outweighed by a greater need to protect your privacy. Cases where we rely on our legitimate interests to process your personal data include (but are not limited to):
- To respond to your queries and provide you with information and materials that you request from us. Legitimate interest: to develop and grow our business and maintain good customer relations.
- To send you promotional materials and other materials that may be of interest to you. Legitimate interest: to market our services.
- To invite you to events or other functions we believe may be of interest to you. Legitimate interest: to market our services.
- To send you information regarding changes to our policies, other terms and other administrative information such as reminders, technical notices, updates and security alerts. Legitimate interest: to ensure that any changes to our policies, terms and other such technical updates are communicated to you.
- To administer the Site, including resolving technical issues, troubleshooting, data analysis, testing, research, statistical and survey purposes. Legitimate interest: to continually monitor and improve the Site and to ensure network security.
- To share data with other members of our corporate group to ensure that we can allocate resources accordingly. Legitimate interest: to operate our business efficiently.
- If you work for one of our suppliers, to communicate and interact with you to the extent necessary for us to receive the benefit of the relevant goods or services being provided and as otherwise required to maintain our business relationship. Legitimate interest: to ensure we are able to receive the benefit of the relevant goods or services being provided and to maintain our business relationship.
- On the basis of your consent
To the extent the cookies used on the Site result in us processing your personal data (e.g. in relation to certain advertising cookies), we rely on consent for such processing.
If we wish to process your personal data in any other way not covered by the legal justifications above, we may request your consent. Where you give consent, you are entitled to withdraw it at any time
5. Who might we share your data with?
Where necessary to fulfil your instructions to us and for the other purposes outlined above, we may share information about you with a range of recipients including (but not limited to) the following:
- international FirstRand Group entities, including in South Africa;
- regulators, courts, public authorities (including tax authorities), to the extent we are required to do so under applicable law or if necessary to establish, exercise or defend legal claims;
- third party suppliers who provide services on our behalf, including third parties providing website hosting, advertising and analytics services;
- professional advisors, auditors, insurers; and
- potential purchasers of elements of our business.
6. Will we transfer your data to other countries?
FirstRand Bank and its clients are active internationally and thus information relating to you may, in line with the purposes described above, be transferred to countries outside the UK and EEA to so-called “third countries”. Some of these countries may not provide the same standard of data protection laws as those which apply in the UK or the EEA.
Where personal data is transferred to and stored in a country not determined by the UK or European Commission as providing adequate levels of protection for personal data, we take steps to provide appropriate safeguards to protect your personal data, including entering into standard contractual clauses approved by the UK or the European Commission, obliging recipients to protect your personal data.
If you would like further information on the specific mechanism used by us when transferring your personal data outside of the UK or the EEA, please contact us using the contact details set out in section 2 above.
7. How long will we keep your data for?
In general terms, we retain your personal data as long as necessary for the purposes for which we obtained it. In making decisions about how long to retain data we take account of the following:
- The termination date of the relevant contract or business relationship;
- Any retention period required by law, regulation or internal policy;
- Any need to preserve records beyond the above periods in order to be able to deal with actual or potential audits, tax matters or legal claims.
8. Will we use your data for marketing?
We may use your personal data to give you information about products and services offered by us or our FirstRand Group affiliates that we think you or the firm with which you are associated may be interested in receiving. Where we consider it appropriate, we may contact you in this regard by email or telephone.
9. What data protection rights do you have?
You have the following rights (subject to certain statutory exemptions):
- to have your personal data corrected if it’s inaccurate and to have incomplete personal data completed;
- to object to processing of your personal data where we are processing it on the lawful basis of legitimate interests or for direct marketing purposes;
- to withdraw your consent to processing your personal data;
- to restrict processing of your personal data;
- to have your personal data erased;
- to request access to your personal data and information about how we process it; and
- to move, copy or transfer your personal data (“data portability”).
To exercise any of these rights, please write to your usual contact at FirstRand London or the Data Protection Officer via the contact details given in section 2 above.
You also have a right to complain to the Information Commissioner's Office (https://ico.org.uk), which regulates the processing of personal data. We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.
10. Are you under an obligation to provide us with your personal data?
We will indicate to you where the provision of certain personal information is required in order for us to provide you certain services. If you choose not to provide such personal information, we may not be able to provide the services you have requested.
11. Cookies and other tracking technologies
The Site may, from time to time, contain links to and from the websites of our business partners, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.
13. Changes to this privacy notice
We may update this privacy notice from time to time and you can always access the current version at the following RMB website address: www.rmb.co.uk/page/firstrand-limited-privacy-statement