Personal data controller
Personal data controller
Banca Transilvania S.A., with its registered office in Cluj-Napoca, at 30-36 Calea Dorobanților, registered with the Trade Registry under No. J1993004155124, CUI RO5022670 (“the bank,” “BT”), hereby informs you how it will process, in its capacity as a data controller, personal data (“personal data,”“data”) in connection with the provision of the BT Pay Web Internet banking service (“BT Pay Web”). The situations in which BT is not the controller of the processed data are specifically outlined in this notice. BT Pay Web is offered to BT customers (“customers,” “BT customers”), in accordance with the Terms and Conditions for the Use of and Conducting Banking Transactions via the BT Pay Web Internet Banking Service (“BT Pay Web Terms and Conditions”).
Persons concerned
Persons concerned
This privacy notice pertains to the processing of personal data belonging to BT Pay users, as defined in the BT Pay Web Terms and Conditions. If you are a BT Pay Web user (whether you are the account holder or a user authorized by the account holder), you are a data subject under this processing. BT will periodically update this notice without imposing less favorable conditions regarding data processing and protection. Changes will be communicated via BT Pay Web, and the updated version will be available for review at any time on BT Pay Web and on the BT website, in the Privacy Hub section. The current version of this notice always applies to BT Pay Web users. If you have any questions or concerns regarding how BT processes personal data, you can contact us at dpo@btrl.ro.
Personal Data Processed in BT Pay Web, Purposes and Legal Bases for Processing
Personal Data Processed in BT Pay Web, Purposes and Legal Bases for Processing
1. To ensure security on BT Pay Web and prevent fraud
To ensure data security in BT Pay Web and to prevent fraud, we process the following data based on legal obligations and legitimate interests:
- Device information: ID, model, operating system type/version, RAM, total bandwidth, connection type used, history of devices used, information regarding recent use of the device for calls (without access to the content of those calls or the identities of the people you are talking to).
- IP Address and IP-Based Location
- The presence of potentially dangerous applications (e.g., malware, remote control applications)
This data is essential for the security of the application. If you object to its use, you will not be able to use BT Pay Web. Also, to ensure the security of BT Pay Web and prevent fraud, we process data necessary for: logging into BT Pay Web and authorizing transactions.
Depending on the risk of fraud, based on the processing of this data, the bank may: block BT Pay Web until unsafe third-party applications are removed, block suspicious transactions, or contact the user. Optionally, you can also upload a profile picture to BT Pay Web. If you upload one, we will process the image to provide additional protection for your data in BT Pay Web.
2. To log in to BT Pay Web
If you are designated as a BT Pay Web user under the contract the customer has entered into with the bank for this service, we must identify you and verify that you are the user designated in the contract in order for you to access BT Pay Web. We perform these verifications through a strict authentication process, in accordance with payment services legislation. To this end, we process the following information: the user ID assigned by the bank, your password, and the phone number you provided to the bank (for sending one-time login codes for BT Pay Web and, where applicable, for authorizing certain transactions, for which you will receive SMS messages).
3. To use BT Pay Web
To fulfill the BT Pay Web contract entered into with the customer, to comply with the bank’s legal obligations, and based on our legitimate interest, we process personal data as follows:
3.1 Account, Card, and Transaction Data
To view, use, and manage checking accounts, credit accounts, credit cards, savings accounts, and deposits in BT Pay Web, BT processes the following categories of personal data related to these accounts, as applicable: IBANs, balances, currencies, cards linked to the accounts, and Star points associated with certain credit cards; transaction data (amount, description, date, exchange rate, payee details—last name, first name, account number, transaction history); recurring payments, predefined beneficiaries (including the names under which they are saved), data regarding the opening and management of deposits and savings accounts (amounts, start/end dates, transfer frequency), information regarding interest and related taxes, and, in the case of credit products, including details of the checking account from which the monthly installment is deducted, contract number, credit account balance, loan amount, loan start and end dates, monthly installment amount, any outstanding balances, repayment schedule, loan-related insurance, and their status.
3.2. Other data processed for various BT Pay Web features
The Beneficiary Name Display Service (SANB) for the Purpose of Preventing Fraud
We have a legal obligation and a legitimate interest in preventing bank fraud. To protect you in the case of interbank transactions (payments to accounts at other banks), BT, together with other associated operators, processes your personal data in accordance with the details set forth in the Information Notice regarding the processing of personal data within the Beneficiary Name Display Service (SANB). For intra-bank payments (payments to BT accounts), BT alone processes the same categories of personal data used within the SANB. The legal basis for processing your data is BT’s legitimate interest in preventing fraud in intra-bank payments (BT-to-BT). Your full first name(s) (one or more, as applicable) and the initial of your last name, as registered with BT, will be displayed to other BT customers who initiate a payment to your BT account from a banking app, regardless of whether the payment is completed or not.
Issuing/Reissuing a Card
From BT Pay Web, you can request the issuance or reissuance of a card for yourself if you are the account holder. In this case, we process, as applicable: the details of the issued or reissued card, the IBAN of the account to which it will be linked, and the card’s shipping address.
Setting transaction limits on accounts and/or blocking cards
From BT Pay Web, you can set transaction limits on your BT accounts, block these cards—either temporarily or permanently—and request that temporarily blocked cards be unblocked. We processinformation regarding the limits you’ve set, account status and details, as well as the phone number registered with BT (these operations are permitted only with an OTP code sent via SMS).
Cash Withdrawals from BT ATMs Using a Code
From BT Pay Web, you can generate a temporary code for an ATM cash withdrawal (valid only for cards issued to individuals). We process the phone number (selected from your contacts or entered by you) to send the code, as well as the card and account information and the transaction details.
Signing Up for Open Banking
To use the Open Banking feature (available for non-BT accounts added to BT Pay Web), BT processes the following information, which may constitute personal data: the IBAN, the balance of the non-BT account, and the transaction history/details from the non-BT accounts (date, amount, transaction details, and the counterparty to the transaction carried out in the non-BT account).
Recharge Phone Card
When you use this option, we process:the phone number being topped up, and the details of the account from which you are making the top-up, including its balance.
Purchase of a vignette
When you purchase or renew your Romanian vignette through BT Pay Web, BT will process: vehicle information, the account from which you make the payment, and your available balance
Viewing/selecting/changing data processing options for advertising purposes
In BT Pay Web, you can indicate your preferences regarding the processing of your data for advertising purposes (consent or refusal, as applicable), including viewing the marketing preferences you have previously indicated to BT regarding the processing of your data for this purpose. Details about this processing can be found in Section C, point 12 of the BT Privacy Policy.
Investments
The products in this section of BT Pay Web are offered by subsidiaries of the bank (member entities of the BT Financial Group). In this case, Banca Transilvania processes your data as a data processor, and the subsidiary is the data controller. Your data held in the bank’s records that is necessary for the conclusion or performance of the contract you enter into with the subsidiary is sent to that subsidiary, which will process it in accordance with the provisions of its own Privacy Policy.
See below for more details:
- To purchase and manage fund units in the funds managed by the bank’s subsidiary—BT Asset Management SAI (BTAM) —through BT Pay, you can become an investor in the funds managed by BTAM by signing a brokerage agreement with BT, and then buy, sell, and manage fund units (UF) in the fund of your choice. BTAM will process your personal data, such as: last name, first name, personal identification number (CNP), BTAM client ID, investment account number, transaction history, balance held in investment funds managed by BTAM, information regarding gains/losses, and withholding tax. You will become a BTAM client. Details regarding the processing of personal data by BTAM can be found in the BTAM Privacy Policy, available on the websitewww.btassetmanagement.ro
4. For communicating with BT Pay Web users
4.1. Communications to Contact Information
To fulfill the contract with the bank, based on our legitimate interest and, where applicable, on your consent (e.g., promotional messages), we process your personal data for communication purposes, as follows:
- When you use BT Pay Web, we will use your phone number to send you messages about the transactions you initiate, including codes that you will use to approve the transactions (if applicable).
- We use the phone number or email address you have on file with the bank to notify you or request additional details regarding transactions initiated through BTPay Web, as well as to prevent fraud attempts (e.g., phishing). If you submit requests (such as requesting a card) or sign up for BT services available on BTPay Web (e.g., SMS Alert, opening deposits, etc.), we will use your phone number to send you notifications regarding the activation of these services or, as applicable, to let you know when the card you requested has arrived at the BT branch you selected for pickup.
- When you send documents from BT Pay Web (e.g., payment receipts, statements, or road toll stickers), we will process the email address you enterin the designated field. This address may belong to other people, but we recommend that you use only your own address. If you choose to send documents to third-party email addresses, you assume the responsibility of informing them in advance that the message they will receive from the email address contact@btrl.ro is from you. You also understand that BT is not liable if the address you entered does not exist, is incorrect, or belongs to someone other than the person to whom you intended to send the documents (which may result in the disclosure of banking information to unauthorized persons). BT is also not liable for situations in which third parties to whom you choose to send the documents express dissatisfaction with receiving the message.
4.2. Communications via Secure Messaging
BT Pay Web We will use the secure messaging inbox to send you various informational messages regarding BT and/or the bank’s products and services (e.g., messages about changes to the General Terms and Conditions, the BT Pay Web Privacy Policy, branch hours, or any system outages at the bank, non-banking business days, etc.).
4.3. Displaying Advertising Messages in BT Pay Web
If you have given your consent to have your data processed for advertising purposes, we may also send you such messages through the BT Pay Web service.
5. Use of Cookies by BT Pay Web
At BT Pay Web, we use cookies as detailed in our dedicated Cookie Policy, available at the following page : Cookie-Policy.pdf. Cookies that are strictly necessary for the operation of BT Pay Web may be placed on users’ devices without requiring their consent. Other types of cookies will be placed only if and after the user gives their consent.
Retention period for personal data processed in BT Pay Web
Retention period for personal data processed in BT Pay Web
Your data, as a BT customer, as well as data regarding transactions conducted through BT Pay Web, will be retained for a period of 5 years following the termination of your business relationship with the bank, in accordance with applicable legal provisions, with the exception of data that must be retained for a period of 10 years, in accordance with legal provisions in the areas of finance, accounting, and taxation.
Recipients of personal data processed in BT Pay Web
Recipients of personal data processed in BT Pay Web
Data provided directly by BT Pay Web users or data that the Bank may become aware of in connection with access to and use of this service may be disclosed by Banca Transilvania to certain categories of recipients, as follows:
- other BT customers who have the right and need to know this information (all BT Pay Web users are BT customers)
a. users to whom you have granted access to your accounts and to BT Pay Web
If you are the account holder and have authorized representatives with rights in BT Pay, they will have access within this internet banking service to your personal data mentioned in section 3.1 of this information notice, in accordance with the rights granted, with the exception of information regarding the cards linked to the accounts. Authorized users can view this information, make transfers and currency exchanges, access statements and transaction history, share the IBAN, set up recurring payments, and manage savings and deposits.
b. BT customers who have granted you access to their accounts opened with BT, including BT Pay Web
If you are a user to whom other BT customers—individuals and account holders—have granted access rights to their BT accounts, including within BT Pay Web, they have access to your data, such as: your first and last name, your status as an authorized representative for their accounts, and your status as their designated user in BT Pay Web. When you conduct transactions on these customers’ accounts, we will disclose to them information regarding the transactions you carry out (including details about the individuals to whom you make payments from these accounts).
c. BT customers on whose account you have an additional card issued in your name
If you have an additional card issued on another BT customer’s account, the account holder will also be able to view details of the transactions you’ve made with that card (amount, merchant, date, etc.) in BT Pay Web.
d. BT customers, whether individuals or legal entities, to whom you make payments via BT Pay Web
When you make transactions via BT Pay Web to the accounts of other BT customers from your own accounts, the details of these transactions (typically, your first and last name, the amount, the currency, the account number, and the payment description) will be visible to the recipients to whom you made the payment.
- people to whom you choose to send documents/information from BT Pay Web
If you choose to send proof of payment, statements, or account numbers to email addresses entered in the designated field on BT Pay Web that do not belong to you, the information in those documents will be disclosed to the individuals who have access to those email addresses. BT does not know the identities of those individuals.
- the bank's contractual partners
Service providers who assist us in providing BT Pay Web and in related activities (e.g., providers of SMS and email services).
In some cases, data processing will also take place in third countries. The transfer of personal data to these countries is based either on adequacy decisions issued by the European Commission or on other appropriate safeguards, in accordance with the mechanisms provided for by the GDPR, consisting of Standard Contractual Clauses approved by the European Commission (which you can find here: https://eur-lex.europa.eu/legal. The list of recipients above is supplemented by the list provided in the General Information Notice on the Processing and Protection of Personal Data Belonging to BT Customers, Section VIII.
Rights Regarding the Processing of Personal Data in BT Pay Web
Rights Regarding the Processing of Personal Data in BT Pay Web
The processing of your personal data within BT Pay Web is subject, in addition to this notice, to the provisions of the General Information Notice on the Processing and Protection of Personal Data Belonging to BT Customers, which is an integral part of the BT Privacy Policy and can be found on the website www.bancatransilvania.ro, in the Privacy Hub section or upon request at any branch of the bank. The aforementioned General Information Note also outlines the rights you may exercise regarding the processing of your personal data, the methods by which you may exercise those rights, as well as the contact information for the Data Protection Officer (DPO) and how you may contact them.

