Information on the processing of personal data in the context of the provision of the BT POS App payment solution
Version applicable from 16.11.2023
1. General provisions
Banca Transilvania, S.A. with registered office in Cluj-Napoca, 30-36 Calea Dorobanților Street, Cluj County, registered at the Trade Register under number J12/4155/1993, unique code RO 5022670, contact telephone: 02648028 (hereinafter referred to as "BT") offers its customers the payment solution - BT POS App (hereinafter referred to as "BT POS App").
We hereby inform you what personal data we are going to use for the identification/authentication of users (identity verification), for the security of this payment solution for fraud prevention purposes, as well as in the context of the use of the BT POS App functionalities, for what and on what basis we use this data, to whom we disclose it, for how long we keep it, how we protect it and what rights data subjects have.
This information shall be supplemented by the provisions the General Information Notice on the processing and protection of personal data of BT customers which is an integral part of the BT Privacy Policy which can be found on the website www.bancatransilvania.ro or by accessing the following link https://www.bancatransilvania.ro/politica-prelucrare-si-protectie-date-personale/.
This information may be revised by BT from time to time. Users will be notified if such changes occur via the website www.btepos.ro.
2. What data we collect to authenticate BT POS App users
In order to use the BT POS App solution that you have contracted from BT you need to log in as an authorised user. This authentication is based on merchant ID, terminal ID and a password. The credentials are sent by BT via SMS to the phone number of the legal representative stated in the contract.
3. What data we collect to ensure the security of the BT POS App
In order to protect your BT POS App transactions and information within this platform, we will collect and use the Advertising ID of the phone on which you have the BT POS App installed, other phone security identifiers (e.g. Instance ID/ Device Identifier) and tokens generated, model, phone manufacturer and operating system type, app version, to verify that each time you log in you are still using the same phone you registered with to use the BT POS App. We also process the IP address(es) of the phone and, where applicable, the tablet or PAD with which you log in to the BT POS App.
4. What data we process when you use the BT POS App
In order to fulfil our legal obligations, to provide you with the BT POS App solution you have contracted for your company and, where applicable, because we have a legitimate interest in preventing fraud and communicating with BT POS App users to support them and to ask them to evaluate the quality of the BT POS App solution we use:
Card and transaction data
When you use the BT POS App, we will by default have access to information about: transactions made by your customers with the card, the PAN of these cards, the transaction ID (RRN), the amounts charged to the company's accounts, including information mentioned in the payment explanations. Although this solution is exclusively dedicated to legal entity customers of Banca Transilvania, and information about legal entities is not usually considered as personal data, if you have an entity such as a P.F.A., I.I., individual form of exercising liberal professions (e.g. individual law firms, notaries, bailiffs' offices, etc.) you should be aware that information about them is subject to the personal data regime and the bank will treat it in accordance with the applicable legal provisions in this field. We also process your and/or your clients' personal data, such as beneficiaries of collections, individuals or P.F.A., I.I., individual forms of self-employment.
Date of contact
Based on the BT POS App solution purchase agreement, we will use the phone number of the legal representative to send the SMS validating the phone number and login data, and the e-mail address to send you various reports on the transactions carried out through the solution.
Because we have a legitimate interest in supporting you in using the BT POS App (support) and because we want to know your opinion about this solution (service quality assessment) we will use the contact details you have provided to the bank as a customer to contact you for this purpose. You have the right to object to such contact. For details, please read the section on your rights in relation to the processing of your personal data.
Data collected for error identification and correction purposes
When you use the application and technical errors occur, we will capture the following data to identify and fix them: device, operating system, operating system version, error type and description.
Permissions required in the context of using the application
When you install the app, you will be asked for permissions to access your device's camera to upload a profile picture. You are not obliged to upload such a picture and can:
- Allow/ Deny access
- Allow/ Deny/ While using the app
- Allow/ Refuse/ Just this once
If you refuse to grant access to the camera, you can still use the BT POS App. If you have granted permission, you can withdraw it at any time afterwards.
Other permissions required for the use and operation of the app, as set by the operating system vendor of the device you are using and for which explicit user consent is not required, are detailed in the "Permissions" section of the Play Store/ Apple Store for the BT POS App (e.g. permissions to notify you when you do not have an Internet connection).
5. To whom we may disclose data as a result of using the BT POS App solution
When transactions are carried out via the BT POS App, the related data (usually PAN, amount, explanation of the payment), will also be accessible to the payer who made the payment and, implicitly, to the credit/payment institutions where they have opened the respective accounts.
Your data processed in the BT POS App may be accessed on a need-to-know basis and only on the basis of personal data protection safeguards by the bank's contractual partners who support us in providing the BT POS App solution.
The list of addressees shall be supplemented by the list provided for in General Information Notice on the processing and protection of personal data of BT Customerssection VIII.
6. How long we keep the data processed in the context of providing the BT POS App solution
Your data, as a BT customer, as well as the data related to the transactions carried out through the BT POS App are subject to the retention regime provided for by the applicable regulations in the field of prevention of money laundering and terrorist financing, in the field of payment services or in the accounting and financial - tax field.
7. How we ensure the protection of personal data in the BT POS App solution
Banca Transilvania takes all necessary technical and organisational measures to protect personal data within the BT POS App solution.
Despite these precautions, the Bank cannot guarantee that unauthorised persons will not gain access to your personal data via the terminals you use to access the BT POS App if they are unprotected or inadequately protected.
You are solely responsible for maintaining the confidentiality and security of the terminal used to access the BT POS App (phone, tablet, PAD) and in particular the login ID and/or login passwords (password, fingerprint or other security method provided by the phone/tablet/ PAD).
8. What rights do users of the BT POS App have?
In accordance with the provisions of the General Data Protection Regulation ("GDPR"), as a data subject of the processing of personal data in the context of the use of the BT POS App, you are guaranteed the following rights: The right to be informed (we fulfil our obligation to inform you herewith), the right of access, the right to rectification, the right to erasure of data, the right to restriction of processing, the right to data portability, the right to object, the right to withdraw consent (for processing based on this legal basis), the right to address the National Authority for the Supervision of Personal Data Processing (ANSPDCP) and justice. You will find these rights detailed including in the provisions the General Information Notice on the processing and protection of personal data of BT customers.
You can exercise these rights with BT at BT or contact the BT Data Protection Officer (DPO) by sending a request by post to the aforementioned BT headquarters - with the indication - "to the attention of the DPO" - or by electronic means to the e-mail address dpo@btrl.ro.
You also have the right to contact the National Authority for the Supervision of Personal Data Processing (ANSPDCP)(plangere@dataprotection.ro).