Joint Data Controllers
Joint Data Controllers
Pursuant to Articles 13–14 of EU Regulation 679/2016—the General Data Protection Regulation (“GDPR”)—Alfatrust Certification S.A. (“Alfatrust”) and Banca Transilvania S.A. (“BT” or “the Bank”), whose identification and contact details are set forth in the Terms and Conditions for the provision of certification services for qualified digital certificates, hereby inform you regarding the processing of the User’s (“data subject”) personal data that they carry out as joint controllers for the purpose specified in section b of this notice.
The purpose and legal basis for the processing of personal data
The purpose and legal basis for the processing of personal data
The purpose for which the associated operators process the User’s data is to issue and manage the Qualified Digital Certificate (“the Certificate”).
BT is the operator that identifies the User, collects the personal data necessary for issuing the Qualified Digital Certificate, and transmits this data to Alfatrust so that Alfatrust can issue the certificate.
The data that BT collects from Users is the data processed by the Bank in its own records, in the context of the business relationship that is being established or is currently in progress between the User and the Bank at the time the data is transmitted to Alfatrust.
During the certificate’s validity period, personal data is processed by associated operators, as applicable, as well as in cases where Users request the suspension or revocation of the certificate in accordance with the procedures detailed in the Terms and Conditions of Service.
The legal bases for processing personal data for the specified purpose are a legal obligation (Art. 6(1)(c) of the GDPR), the conclusion or performance of a contract (Art. 6(1)(b) of the GDPR), and the legitimate interests of the associated controllers (Art. 6(1)(f) of the GDPR).
With regard to legal obligations, both BT—as the credit institution with which the User initiates or maintains a business relationship—and Alfatrust—as the accredited certification service provider from which the User wishes to obtain a certificate— are subject to the applicable legal provisions in the field of anti-money laundering and counter-terrorist financing, pursuant to which they must collect a series of personal data from customers. This data is also necessary for the conclusion/performance of the Agreement under which the User is permitted to use the certificate to sign documentation in relation to the Bank.
To assist users who wish to submit a request to suspend or revoke their certificate, the affiliated operators have a legitimate interest in offering these users (who are also customers of the Bank) the option to submit such requests not only directly to Alfatrust, but also through the BT Call Center. Processing these requests involves the exchange of Users’ personal data between the two affiliated operators.
Contact information—including phone number and home address—will be processed by any of the associated operators whenever it is necessary to contact the end user to ensure the proper conduct of the contractual relationship pertaining to the qualified digital certificate.
Categories of personal data and individuals whose personal data is processed
Categories of personal data and individuals whose personal data is processed
The personal data processed for the purpose of fulfilling the aforementioned objective are those required by law to be collected by a credit institution or a certification service provider for the prevention of money laundering and the combating of terrorism, namely: first name, last name, personal identification number (CNP), home address/residence, expiration date of the identification document, telephone number, and a copy of the identification document. All such data, as recorded in the Bank’s records, will be made available to Alfatrust for the issuance and management of the Qualified Digital Certificate.
The processing of this personal data is necessary for the generation of the Qualified Digital Certificate. The User's refusal to have this data processed will make it impossible to issue the Qualified Digital Certificate.
The individuals affected by this processing are solely Users, as defined in the Terms and Conditions of Use.
Recipients of Personal Data
Recipients of Personal Data
With the exception of the associated controllers between whom personal data processed for the purpose of the processing will be exchanged, the data are disclosed, where appropriate, to the employees of the associated controllers who need to know them, to IT service providers, auditors, authorities and institutions entitled to know them.
Period of processing personal data
Period of processing personal data
Information regarding a Qualified Digital Certificate (including personal data) is processed by Alfatrust for a period of 10 years from the date of its expiration, in accordance with the legally established time limits.
At Banca Transilvania, the remote electronic signature, applied based on the Qualified Digital Certificate issued by Alfatrust on documentation signed in connection with BT, is retained for the entire duration of the business relationship between the User and BT, plus the periods established in applicable banking legislation, namely at least 5 years from the termination of the business relationship with the credit institution.
The rights of data subjects regarding the processing of their personal data for the stated purpose
The rights of data subjects regarding the processing of their personal data for the stated purpose
Any User, in their capacity as a data subject, is guaranteed the right to exercise the following rights regarding the processing of their personal data with respect to any of the associated controllers: the right of access, the right to rectification, the right to restriction of processing, the right to erasure, the right to object to processing, and the right to data portability.
Users may exercise these rights or contact the data protection officers with any questions or requests regarding the processing of your personal data as follows:
- to Banca Transilvania S.A. – by email to dpo@btrl.ro or by submitting a request to the BT headquarters, marked “For the attention of the Data Protection Officer (DPO)”
- to Alfatrust Certification S.A.—by email to dataprotection@alfasign.roor by submitting a request to Alfatrust’s headquarters, marked “For the attention of the Data Protection Officer (DPO).”
Users also have the right to file a complaint with the supervisory authority—the National Supervisory Authority for Personal Data Processing (ANSPDCP), located inBucharest, Sector 1, 28–30 General Gh. Magheru Boulevard.

