a. To comply with our legal and regulatory obligations
We use your personal data to comply with various legal and regulatory obligations, including:
- Real estate regulations
- banking and financial regulations in compliance with which we:
- set up security measures in order to prevent abuse and fraud;
- detect transactions which deviate from the normal patterns;
- monitor and report risks that institution could incur; and
- record, when necessary, phone calls, chats, email, etc.
- reply to an official request from a duly authorised public or judicial authority;
- prevention of money-laundering and financing of terrorism;
- compliance with legislation relating to sanctions and embargoes;
- fight against tax fraud and fulfilment of tax control and notification obligations.
b. To perform a contract with you or to take steps at your request before entering into a contract
We use your personal data to enter into and perform our contracts, including to:
- provide you with information regarding our products and services;
- assist you and answer your requests;
- evaluate if we can offer you a product or service and under which conditions; and
- provide products or services to our corporate clients of whom you are an employee or a client.
c. To fulfil our legitimate interest
We use your personal data in order to deploy and develop our products or services, to improve our risk management and to defend our legal rights, including:
- proof of transactions;
- fraud prevention;
- IT management, including infrastructure management (e.g. : shared platforms) & business continuity and IT security;
- establishing individual statistical models, based on the analysis of transactions, for instance in order to help define your credit risk score;
- establishing aggregated statistics, tests and models, for research and development, in order to improve the risk management of our group of companies or in order to improve existing products and services or create new ones;
- training of our personnel by recording phone calls to our call centres;
- personalising our offering to you and that of other BNP Paribas entities through:
- improving the quality of our products or services;
- advertising products or services that match with your situation and profile which we achieve.
This can be achieved by:
- segmenting our prospects and clients;
- analysing your habits and preferences in the various channels (emails or messages, visits to our website, etc.);
- sharing your data with another BNP Paribas entity, notably if you are – or are to become – a client of that other entity;
- matching the products or services that you already hold or use with other data we hold about you; and
- monitoring transactions to identify those which deviate from the normal routine.
Your data may be aggregated into anonymised statistics that may be offered to professional clients to assist them in developing their business. In this case your personal data will never be disclosed and those receiving these anonymised statistics will be unable to ascertain your identity.
d. To respect your choice if we requested your consent for a specific processing
In some cases, we must require your consent to process your data, for example:
- where the above purposes lead to automated decision-making, which produces legal effects or which significantly affects you. At that point, we will inform you separately about the logic involved, as well as the significance and the envisaged consequences of such processing;
- if we need to carry out further processing for purposes other than those above in section 3, we will inform you and, where necessary, obtain your consent.