This Privacy Policy (“Policy”) aims to describe how Bison Bank, S.A. and Bison Digital Assets, S.A. (each an “Entity” and jointly the “Group” or “Entities”) processes personal data, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation or “GDPR”), Law 58/2019 of 8 August 2019, which ensures the execution of the GDPR, and all the other legislation on personal data protection.
Personal data subject to processing refers to the personal data of the Group’s clients (including representatives and beneficial owners, if applicable) and of the users of the websites or mobile applications of the Group (“Clients”).
The data controller are the entities that provides service or product, both with registered office at Rua Barata Salgueiro, 33, Piso 0, 1250-042 Lisboa, Portugal.
Personal data includes all the information relating to a natural person who is identified or identifiable, directly, or indirectly, such as, among others, name, civil or tax identification number, location data, or other specific elements of this person’s physical, physiological, genetic, psychological, economic, cultural or social identity.
In its provision of services and offer of products, the Group processes or may process various categories of personal data, including, but not limited to:
The Group collects the personal data of its Clients through the following means:
In the context of commercial and contractual relationships, the Group has the obligation to collect the personal data of Clients, potential Clients and other holders (e.g., representatives, beneficial owners) necessary to comply with pre-contractual and contractual, or even regulatory, obligations and steps.
Data processing is defined as an operation or set of operations performed on personal data, performed by manual or automated means, including collection, storage, use, copying and transfer.
The personal data of the Group’s Customers is used in a lawful and transparent manner and for specific purposes, with reference to the respective legal bases:
Execution of a contract or pre-contractual due deligence
Compliance with legal obligations
Legitimate interest
Consent of the data subject
i) What are cookies?
Cookies are small text files with relevant information that are downloaded onto the user’s access device (computer, mobile phone/smartphone, or tablet) through the browser when a website is visited by the user.
The use of cookies not only enables the website to recognize the user’s device the next time he/she visits it, but also improves the operation and experience of this website.
The cookies used by the Entities on their websites do not collect personal information that could identify the user. They only process and keep general information, namely the form or place of origin of the users’ access and the way that they use Group’s websites, among other aspects.
The cookies only keep demographic data and information related to the users’ preferences.
The users may, at any time, through their browser, decide to be notified of the reception of cookies, and may block their entry into their system. However, it should be highlighted that rejection of the use of cookies on the Group’s websites could result in precluding access to some of their areas and not permitting the entire browsing experience on Group’s websites.
ii) What are cookies used for?
Cookies are used to help determine the usefulness, interest and number of uses of websites, enabling faster and more efficient browsing, and eliminating the need to repeatedly enter the same information.
iii) What type of cookies do we use?
Each cookie used has a function and an expiry date. Regarding function, the cookies used may be:
Essential cookies – Some cookies are essential to access specific areas of the Entities’ websites. These enable browsing website and using their applications, such as access to secure areas of Group’s websites through login. Without these cookies, the services requiring them cannot be made available.
Functional cookies – These cookies enable remembering the user’s preferences relative to browsing on Group’s website. Accordingly, the users do not need to reset and personalize it each time they visit it.
Name | Type | Purpose | Duration |
_icl_visitor_lang_js | Functional cookies | Record the last language used for the next time the user returns to the Entities websites. | 1 Month |
Analytical cookies – These cookies are used to analyze the way that the Entities websites are used, enabling the highlighting of articles or services that could be of interest to the users, the monitoring of the websites performance, and knowledge of which are the most popular pages, what is the most effective method of links between pages or to determine the reason why some pages are receiving error messages. These cookies are used for purposes of creation and statistical analysis only, and never collect information of personal nature. This means that the Group can provide a high-quality experience by personalizing its offer and rapidly identify and correct any problems that may arise.
Name | Type | Purpose | Duration |
_ga | Analytical cookies | Record a single ID that is used as statistical data of the Client’s visit. | 2 Years |
_gid | Analytical cookies | Record a single ID that is used as statistical data of the Client’s visit. | Session |
Regarding expiry date, the cookies used may be:
Permanent cookies – These are stored on the user’s access devices (computer, mobile phone/smartphone, or tablet), at browser level, and are used whenever the user returns to the Entities websites. They are used to direct the browsing according to the user’s interests, enabling the Group to provide a more personalized service.
Session cookies – These are temporary cookies available until the session is closed. Next time the users access their browser, these cookies will no longer be stored. The information obtained by these cookies enables managing the sessions, identifying problems and providing a better browsing experience.
iv) Blocking the use of cookies
All browsers enable the user to accept, refuse or delete cookies. This can be done by selecting the appropriate definitions in the browser. Users are thus allowed to partially or completely deactivate the cookies used on Entities’ websites at any given time. For further information, see the instructions and manuals of the actual browser.
Nevertheless, the Entities inform that by deactivating the cookies on their websites they might not function properly.
Further information on cookies in www.allaboutcookies.org
7. Storage Period
The personal data collected are processed in strict compliance with the applicable legislation and stored in specific databases.
The Group processes and stores personal data in accordance with the respective purposes and observing the applicable legal time limits.
Whenever there is no specific legal requirement, the data will be stored and kept only for the appropriate time and to the extent necessary to pursue the purposes for which they were collected, unless the rights of objection, erasure or withdrawal of consent are exercised within the legal limits.
When the personal data are necessary for the Entities to prove compliance with contractual obligations or requirements of other nature, they can be kept for as long as the corresponding rights are valid.
To this end, and taking into account the specific rules in force as to certain legal obligations of keeping and reporting information, the different time limits for the storage of personal data according to the categories in which their processing falls are:
Financial activity & ML/CTF
Commercial bookkeeping
Taxation
Marketing
Cookies
Video surveillance
The holder of personal data, under the terms of applicable law, has the following rights:
These rights may be exercised with reasonable frequency and without undue delay or cost.
The data subject may exercise any of the aforesaid rights under the terms of paragraph 12 below.
The data subject also has the right to submit complaints related to the Group’s breach of the provisions regarding personal data protection to the Portuguese Data Protection Authority (“CNPD”) or other competent supervisory authorities.
In order to ensure the protection of personal data, the Group has taken various security, technical and organizational measures aimed at protecting the personal data against their destruction, loss, modification, disclosure, unauthorized access or any other form of unlawful treatment.
If any Entity outsources to other entities the provision of services that involve the assignment of personal data (e.g. providers of services related to IT, archives, support to back-office activity, consulting, private security, etc.), these entities shall be mandatorily required to take the necessary technical and organizational measures to protect the personal data against their destruction, loss, modification, disclosure, unauthorized access or any other form of unlawful treatment.
When necessary or appropriate (i) considering the applicable law; (ii) for compliance with legal obligations/court orders; (iii) to respond to requests of public or governmental authorities; or (iv) when the data subject has given consent, the Group may disclose the Clients’ personal data to the following third-party entities:
If any of the entities are established in third countries that do not assure an adequate level of personal data protection, the Group undertakes to ensure that these entities implement the necessary technical and organizational measures to protect the personal data under the terms stipulated in paragraph 9 above.
The Group shall transfer data to third countries that do not belong to the European Union or to the European Economic Area only in the cases permitted by law. Transfers of data to entities outside the European Union may occur, namely, when this is necessary for (i) the execution of a contract between the Client and the Group; (ii) procedures prior to the formation of the contract decided at the Client’s request; (iii) the conclusion or execution of a contract concluded in the Client’s interest; or (iv) by explicit authorization of the Client.
In the event of any doubt or question related to this Policy or to the exercise of your rights of the data holder, please contact the Entities, through notification of the Data Protection Officer (“DPO”), by email to epd@bisonbank.com or by letter addressed to the Entities for the attention of the DPO and sent to the Group headquarters.
The Group reserves the right to change this Policy at any time.
COVID-19: follow the measures adopted by Bison Bank. Exceptional PPR Redemptions - Amendments and Deadline Extension - until September 30th, 2021. Know More.
The Bank became aware of the existence of an online platform called BANIF – BC that uses a similar company name of the extinct Banif - Banco de Investimento, S.A.. Know More.