First Investment Bank AD („We", „the Bank") hereby provides you with information regarding the processing of your personal data when using our payment services and payment instruments (including bank cards).
What kind of personal data do we process?
The personal data processed are as follows:
Name, EGN, PN, PNF or NRA assigned number, gender, date of birth, country of birth, place of birth, citizenship, ID document details, residence address, correspondence address, IP address, home phone, office phone, mobile phone, e-mail, jurisdiction of residence for tax purposes, tax number, politically exposed person, employer, occupation, origin of funds, IBAN, account statements.
On what grounds do we process your personal data?
Processing of your data is necessary for the conclusion and execution of a contract for opening and maintenance of a bank account and provision payment services, for the issuance of bank cards, for the use of e-banking services, as well as for contracts for related services of the Bank.
The Bank also collects and processes your data in compliance with its legal obligations under the Law on Measures against Money Laundering, the Law on Measures Against the Financing of Terrorism, the Tax and Social Insurance Procedure Code, the Law on Credit Institutions, the Payment Services and Payment Systems Act, the Distance Financial Services Act.
Pursuing its legitimate interests, the Bank may also process your personal data in connection with sharing information that would be of interest to you, as well as for direct marketing, provided that you have not objected to the use of your personal data for these purposes.
For what purposes do we use your personal data?
Your personal data is used for the purposes of provision of payment services and use of payment instruments requested/ordered by you, such as opening of payment accounts, execution of credit transfers and direct debits, utility and periodic payments, purchase and sale of currency, depositing and withdrawing cash, payment transactions with bank cards or other similar instruments, one-time transactions, use of the Bank's electronic banking services.
The Bank processes your personal data for the purpose of preventing, investigating and detecting fraud related to payment services.
The Bank also processes your personal data for the purposes of preventing money laundering and terrorist financing (including risk categorization of customers), automatic exchange of financial information for the purposes of the Register of Bank Accounts and Safe Deposit Boxes, and for other purposes expressly provided for by law.
Can we use your personal data to share information that would be of interest to you?
We may use your personal data for the purpose of research, event invitations, greetings, postcards, marketing newsletters, offers, promotions or campaigns for participation in raffles or games organized by the Bank or its partners.
With whom can we share your personal data?
The Bank respects and protects the privacy of your personal data. Subject to legal requirements, we may disclose your personal data to institutions or persons under current legislation, including the Bulgarian National Bank, the NRA, the court, prosecution, investigation authorities, the Ministry of Interior, the SANS, or others specified by law.
For the purposes of performing the services requested by you, the Bank may provide your personal data to other persons such as correspondent banks, payment and card system operators, other payment service providers.
For what period do we store your personal data?
The Bank stores your personal data for no longer than is absolutely necessary. In order to fulfill our contractual obligations, we retain such data throughout the duration of the client relationship.
Normally, the Bank retains your data for a period of 5 years, such period starting from the beginning of the calendar year following the year of termination of the relationship.
The Bank may also retain your personal data for a longer period of time in view of reporting, tax, accounting purposes, or for the defense of legal claims related to its legitimate interests. Once the legal grounds expire, the Bank shall cease processing your personal data.
What are your rights with respect to your personal data
Subject to Bulgarian legislation, you have the following rights with respect to your personal data processed by us:
- right of access your personal data processed by the Bank and receiving a copy thereof;
- right to rectification of your personal data processed by the Bank in case it is incomplete or inaccurate;
- right to call for erasure of your personal data by us if any of the following applies: the personal data are no longer necessary in relation to the purposes for which they were collected; you have withdrawn your consent and there is no other legal ground for processing; your personal data have been unlawfully processed; and others.
- right to object to the processing of your personal data in the cases provided by law;
- right to portability of your personal data, and of receiving such data in a structured, commonly used and machine-readable format (provided that the Bank has the relevant technical capability);
- right to withdraw your consent for processing of your personal data at any time and free of any charges.
Detailed information on the terms and conditions under which you can exercise your rights can be found in the Procedure for the exercise of rights related to personal data of First Investment Bank AD, published on our website at: www.fibank.bg, as well as in any of our offices in the country.
You also have the right to file a complaint with the Personal Data Protection Commission when the relevant prerequisites exist.
How to contact us?
You may contact us at the following address:
First Investment Bank AD
111P, "Tsarigradsko shose" Blvd.
1404 Sofia
Phone: (02) 817 11 00; (02) 9 100 100
Data Protection Officer of First Investment Bank AD:
Dimitar Hristov
First Investment Bank AD
111P, "Tsarigradsko shose" Blvd.
1404 Sofia
E-mail: dpo@fibank.bg