Privacy Notice – Al Masraf

Privacy Notice

Privacy Notice

Arab Bank for Investment & Foreign Trade (AL MASRAF) Privacy Policy

Introduction

Al Masraf has developed this Privacy Notice to explain how we may collect, retain, process, share and transfer your personal data when you visit our websites, use our services, or visit us in person. This Privacy Statement is designed to help you obtain information about our privacy practices and to help you understand your privacy choices when you use our websites, products, and services.

Scope

This Notice applies to all information we collect about you, directly and/or automatically though our website, our mobile application(s), and through third parties.

Personal, Anonymous, and Aggregate Information

Personal Data, also referred to as PII or personally identifiable information, is Information that identifies or reasonably can be used to identify you. Examples include your: (i) Name, (ii) Mailing address, (iii) Email address, (iv) Phone number, (v) Date of birth or age, (vi) Credit/debit card number, (vii) Emirates ID details, (viii) Mobile device information, (ix) How you use our sites and mobile applications, (x) Geo-location and (xi) Social media information. Anonymous Information is information that does not identify you and cannot reasonably be used to identify you specifically. Finally, Aggregate Information is information taken from many people’s data and combined into anonymous groups or categories.

The Personal Data We Use

Subject to limitations explained in this Notice, Al Masraf may collect and use the following personal data:

  • Your name and other personally identifying information
  • Communication preferences and details
  • Login and authentication information
  • Online profile information
  • Online activity
  • Payment methods and history
  • Information about the device(s) you use
  • Information about the service usage
  • Support information
  • Cookies
  • Social media information
  • Date of birth
  • Copy of identification document
  • Payment information
  • Subscription preferences
  • Financial and credit history
  • Location information and GPS data
  • CCTV images (e.g., in our stores)
  • Voice recordings of customers
  • Biometric Data

How We Use Personal Data

We may process your Personal Data as an individual client or a representative of a corporate client for the following purposes:

  • To enter into a contract with you or to take steps pursuant to your request prior to entering into a contract;
  • To perform activities such as data analysis, audits, usage trends to determine the effectiveness of our campaigns and as input into improving products and services and enhancing our Digital Platform;
  • To respond to your inquiries and address your requests;
  • To deliver marketing communications that we believe may be of interest to you;
  • To inform you about important information regarding our Digital Platforms, changes to terms, conditions, and policies and/or other administrative information;
  • To offer you our products or services, which you may have applied for or shown, interest in;
  • To allow you to apply for our products or services (e.g., to prequalify for a loan, apply for a credit card, or to open an account, investment account, insurance or other financial product);
  • To evaluate your eligibility for our products or services;
  • To provide you with products or services you have requested, e.g. fulfilling a payment request or any other transaction;
  • To perform our obligations under KYC norms (e.g. sharing your information with third parties to verify details you have provided to us like your identity, to authenticate you and verify your information;
  • To allow you to participate in surveys and other forms of market research, contests and similar promotions and to administer these activities. Some of these activities have additional rules, which may contain additional information about how Personal Data is used and shared;
  • To improve risk control for fraud detection and prevention, to comply with laws and regulations, and to comply with other legal processes and law enforcement requirements;
  • To allow you to utilize Digital Platform features by granting us access to information from your device such as contact lists, or geo-location when you request certain services;
  • To use it in other ways as required or permitted by law or with your consent;
  • To protect our legal rights and comply with our legal obligations.

Opting Out of Data Usage

If we intend to use your Personal Data for a purpose that is different from the purposes listed in this Notice or if we intend to disclose it to a third party acting as a controller not previously identified, we will offer you the opportunity to opt-out of such uses and/or disclosures where it involves non-sensitive information or opt-in where sensitive information is involved.

Third-Party Processing

We may share the information we collect with our business partners and other third parties for (1) Non-Marketing Purposes, (2) joint marketing purposes, and (3) our business partners’ or our own marketing purposes. Sensitive Information will only be shared for Non-Marketing Purposes. When we provide Sensitive Information or other Personal Data to our business partners and other third parties, we require them to exercise reasonable care to protect such information and restrict the use of such information to the purposes for which it was provided to them. “Non-Marketing Purposes” includes, but is not limited to, (1) validating your identity; (2) conducting statistical or demographic analysis; (3) processing, fulfilling, and tracking purchases or other transactions; (4) complying with legal and regulatory requirements; (5) customizing your experience on our websites and in person; (6) protecting and defending against legal actions or claims; (8) preventing fraud; (9) collecting debt; (10) satisfying contractual obligations; (11) evaluating employment applications; and (12) cooperating with law enforcement or other government agencies for purposes of national security, public safety, or matters of public importance when we believe that disclosure of information is necessary or appropriate to protect the public interest.

Retention of Personal Data

We retain your personal data for as long as we need to fulfill our business purposes that are in line with legal, regulatory or statutory obligations. Factors that influence the length of time that we retain your data include: the information needed to provide products, services, and experiences to you; the data needed to manage your account, ensure secure payment, and contact you; and, finally, the data needed to serve any advertising based on personal interests and preferences.

As per the UAE Consumer Protection Standards, all Personal Data, documents, records and files will be securely retained for a minimum of 5 years. A copy of your expressed consent will be retained for 5 years after the relationship has terminated.

Outsourcing of business process/service

Al Masraf shall ensure that necessary outsourcing controls for data security are in place to protect against any data breaches. The level of security controls shall be determined based on the materiality of the process or service to be outsourced.

Adequate Protection

Al Masraf have taken reasonable measures to protect security and confidentiality of your personal data and will ensure that transfers of personal data are in accordance with applicable law and is carefully managed to protect your privacy rights and interests. Furthermore, transfers will be limited to countries which are recognized as providing an adequate level of legal protection or where we can be satisfied that alternative arrangement are in place to protect your privacy rights.

Conflicts between Law and this Notice

In the event of a conflict between this Notice and any applicable law/regulations, applicable law/regulations will prevail. Al Masraf shall determine the existence of a conflict.

Impact of Automated Decisions

You will not be subject to any decision, Notice, or assessment that will have a significant impact on you based solely on automated decision-making, unless we have a lawful basis for doing so and we have notified you.

Information Sharing with Authorities

Al Masraf will comply with any request by legal and regulatory authorities of the countries in which Al Masraf operates. In such a case, Al Masraf will disclose personal data in response to lawful requests by public authorities, including meeting national security or law enforcement requirements, as well as data breach notification requirements.

Getting in Touch With Us

We use the information you send us to provide you quality customer service, to evaluate the effectiveness of our website, to alert consumers of new services and important news, and to process transactions initiated by you and communicate with you regarding their status.

If you send us sensitive personal data, we will only use that information for the purposes that you sent it. If there is an unanticipated use for the collected information not previously disclosed in this Notice, we will post the Notice changes on this website to keep you notified. You will then have the option to opt out of these new uses.

Please check this website periodically for updates.

Complaints

You have a right to lodge a complaint with your local supervisory authority if you have concerns about how we are processing your personal data. We ask that you please attempt to resolve any issues with us first, although you have a right to contact your supervisory authority at any time. If you have any questions, concerns or complaints regarding our compliance with this notice and the data protection laws, or if you wish to exercise your rights, we encourage you to first contact us at: https://almasraf.ae/contact-us/. You may also contact us through our channels mentioned at: https://almasraf.ae/complaints/

Specification of Use and Need

Prior to collecting, using, or sharing Personal Data, we define and document the specific, legitimate business purposes for which it is needed.

We determine and document how long Personal Data is needed for those defined business purposes and applicable legal requirements.

We do not collect, use or share more Personal Data than is needed or retain it in identifiable form for longer than is needed for those defined business purposes and applicable legal requirements.

Cookies

A cookie is a small piece of data that is stored on your computer, tablet, or phone. Al Masraf uses cookies and similar technologies to improve our services. Many browsers’ settings can be set to decline cookies or alert you when a website is attempting to place a cookie on your computer. If cookies are disabled on your computer, tablet or mobile your experience on the website may be limited. For example, you may not be able to browse freely or use specific functions or features. When your browser or device allows it, we use both session cookies and persistent cookies to better understand how you interact with our services, to monitor aggregate usage patterns, and to personalize and otherwise operate our services such as by providing account security, personalizing the content we show you. Session Cookies are used for technical purposes such as to enable better navigation through our site. These cookies let our server know that you are continuing a visit to our site. Persistent cookies involve any use of multi-session web measurement and customization technologies when personal data is collected.

Do Not Track (DNT) Functionality

While your browser settings may allow you to automatically transmit a “do not track” signal to websites and online services you visit, like many companies, we may not alter our practices when we receive these signals.

Pixels

Pixels and similar technologies are tiny or transparent images that allow us to establish a communication between you and a web server, which collects certain information about your computer or device. This information may include your IP address, browser type, operating system type, and identifiers that have been stored in cookies. We may use beacons on our sites to count the number of visitors to our sites and to recognize users by accessing unique identifiers stored in cookies that we have set on their computers or devices. Being able to access these identifiers enables us to provide a personalized experience on our sites. We may also include beacons in advertisements or in email messages to determine how these are acted on.

Complying with this Notice

Al Masraf ensures compliance with this Notice through a comprehensive audit and enforcement plan. This audit and enforcement plan ensures that the policies set forth in here are consistently and accurately implemented. Additionally, we undertake periodic review of this Notice to determine whether provisions should be updated.

Account Management

You may update, correct or delete information about you at any time by logging into your online account. If you wish to delete your account, you may do so by visiting to the nearest branch or getting in touch one of channels mentioned at: https://almasraf.ae/complaints/, but note that we may retain certain information as required by law or for legitimate business purposes. We may also retain cached or archived copies of information about you for a certain period of time.

Restriction on Minor’s Information

We do not knowingly collect personal data from minors without the consent of their legal parent or guardian. Legal parent or guardian would be required for opening:

  • Savings account for minors under the age 18; and
  • Current account for minors under the age 21

Your Right to Your Data

You can contact us and ask to know what information we have about you. You can also ask us to update incorrect information, delete it, object to our use of it, or get a copy of it. Consent approval shall be taken from you before processing any personal data.Legal Basis for Processing

We will only collect, use and share your personal data where we are satisfied that we have an appropriate legal right to do so. We may have the legal right to do so because: you have consented to us using the personal data; our use of your personal data is in our legitimate interest as a commercial organization; our use of your personal data is necessary to perform a contract or take steps to enter into a contract with you; and/or our use of your personal data is necessary to comply with a relevant legal or regulatory obligation that we have for example fulfilment of a court order. In these cases, we will look after your information at all times in a way that is proportionate and respects your privacy rights.Your Right to Correct or Amend Personal Data

You have a right to request that we rectify inaccurate personal data. We may seek to verify the accuracy of the personal data before rectifying it. We will then determine whether, based on our policies, we will rectify the information.

UAE Consumer Protection Rights: Consent Revocation

Under Consumer Protection Regulation of UAE, you have the right to withdraw expressed consent for the following at any time:

  • The processing of Personal Data by Al Masraf except where Personal Data is required for business operations related to the Consumer’s Products and Services; and
  • Personal Data sharing with Authorized Agents and other third parties for purposes such as but not limited to sales and marketing.

IMPORTANT: By accessing this web site and any of its pages you are agreeing to the terms as mentioned above.

↓