1. Introduction
- Your privacy is very important to us. We are committed to protecting and respecting your personal data. This Privacy Policy is addressed to clients and prospective clients and describes what types of personal data we may collect prior and during the use of our services. It explains how we use, share, and protect your personal data, as well as your rights regarding its processing and how you can exercise them. Please take a moment to read and understand this policy.
We may make changes to this Policy from time to time and it is important that you check this Notice for any updates. Any personal information we hold will be governed by our most current privacy notice. If we make changes, we consider to be important, we will communicate them to you.
Any reference to ‘us’, ‘our’, ‘we’ or ‘BankPro’ in this privacy notice is a reference to BankPro Limited, part of FxPro group, unless otherwise stated.
Similarly, any reference to ‘you’, ‘your’, ‘yours’ or ‘yourself’ in this Policy is a reference to any of our customers and potential customers as the context requires unless otherwise stated. 2. Who we are
- This privacy notice applies to the processing activities of the following data controller entities within the FxPro group of companies, which are:
- FxPro Global Markets Ltd, a company duly incorporated in The Commonwealth of The Bahamas, with registered address at Lyford Manor, Western Road, Lyford Cay, New Providence, N7776, The Bahamas, authorised and regulated by the Securities Commission of The Bahamas (license number SIA-F184) and subject to the supervision of the Bahamas Data Protection Commissioner; (“BankPro”)
- BankPro Limited, a company duly incorporated in The Commonwealth of The Bahamas, with registered address at Lyford Manor, Western Road, Lyford Cay, Nassau, N7776, authorised and regulated by the Central Bank of The Bahamas (master code LIC1139) and subject to the supervision of the Bahamas Data Protection Commissioner. (“BankPro”)
It is important to note that FxPro Financial Services Limited, part of FxPro group, performs significant processing on behalf of the other entities of the FxPro group, and therefore if you are a customer of the non - European entities of the group, we process your personal data in accordance with this notice and you are also entitled to the same protection and rights.3. What kind of personal information do we collect and store?
- As part of our business, we collect personal data from customers and potential customers, including the following:
- name, surname and contact details
- Identification documents number and Tax ID number
- date of birth and gender
- information about your income and wealth including details about your assets and liabilities, account balances, trading statements, tax and financial statements
- profession and employment details
- location data
- knowledge and experience in trading, risk tolerance and risk profile
- IP address, device specifications and other information relating to your trading experience
- Financial Data necessary for processing your transactions and providing our services
- details of your visits to our Website or our Apps including, but not limited to, traffic data, location data, weblogs and other communication data.
- records of your transactions and trading behaviour such us products you trade with us, preference for certain types of products and services, historical data of your activity, financial instructions and transactions.
We use cookies to store and collect information about your use of our Website. Cookies are small text files stored by the browser on your equipment’s hard drive. They send information stored on them back to our web server when you access our Website. These cookies enable us to put in place personal settings and load your personal preferences to improve your experience as well as for targeted marketing. You can find out more about our cookies and how to manage them on our “Cookies Policy” available on our Website.
We are required by law to verify your identity when you are opening a new account or adding a new signatory to an existing account. Anti-Money Laundering (AML) laws require us to sight and record details of certain documents (i.e. photographic and non-photographic documents) to meet the legal standards. Identification documentation, as required under AML legislation or other legislation relevant to the services we provide to you, includes:
(a) Passport;
(b) Driver’s Licence;
(c) National Identity Card (if applicable);
(d) Utility bills;
(e) Trust deed (if applicable);
(f) A credit check on the individual; or
(g) Other information we consider necessary to our functions and activities.
If you are a corporate client, we are required to collect additional information such as corporate documents of address, shareholders, directors, officers, including additional personal information on the Shareholders and Directors. We reserve the right to request any additional information we deem necessary in order to comply with our legal and regulatory requirements.
We obtain this information in a number of ways, including directly from you via your use of our services and websites, the account opening applications, our demo sign up forms, webinar sign up forms, or automatically via website cookies, and similar tracking technology built into our Websites and Apps, subscribing to news updates and from information provided in the course of our ongoing relationship. We may also collect information from third parties either through bought-in third party marketing lists, publicly available sources, social media platforms, introducing brokers and affiliates, bankers and credit card processors, subscription-based intelligence databases and other third-party associates. We may also request additional personal information voluntarily for purposes such as market research, surveys, or special promotions. If you choose not to provide required information, we may be unable to offer certain products or services.
We may record any communications, including electronic, by telephone, in person or otherwise, in relation to the services we provide to you and our relationship with you. These recordings will be our sole property and may constitute evidence of the communications between us. Such telephone conversations may be recorded without the use of a warning tone or any other further notice.
Further, if you visit any of our offices or premises, we may have CCTV surveillance which will record your image for security and monitoring purposes. 4. Who may we disclose personal information to?
- As part of using your personal information for the purposes set out above, we may disclose your information to:
- affiliated entities within the FxPro group that provide financial and other services;
- third party apps providers when you use our apps, communication systems and trading platforms which are provided to us by third parties;
- service providers and specialist advisers who have been contracted to provide us with services such as administrative, IT, analytics and online marketing optimization, financial, regulatory, compliance, insurance, research or other services;
- introducing brokers and affiliates with whom we have a mutual relationship;
- payment service providers and banks processing your transactions;
- auditors or contractors or other advisers auditing, assisting with or advising on any of our business purposes;
- courts, tribunals and applicable regulatory authorities as agreed or authorised by law or our agreement with you;
- government bodies and law enforcement agencies where required by law and in response to other legal and regulatory requests;
- any third-party where such disclosure is required in order to enforce or apply our Terms and Conditions of Service or other relevant agreements;
- anyone authorised by you.
We endeavour to disclose only the minimum personal data that is required for these parties to perform their contractual obligations to us. Our third-party service providers are not permitted to share or use personal data we make available to them for any other purpose than to provide services to us.
Our websites or apps may have links to external third-party websites. Please note that third party websites are not covered by this privacy notice and those sites are not subject to our privacy standards and procedures. We encourage you to review the privacy policies of any third-party sites you visit. 5. When and how do we obtain your consent?
- We may process your personal data for one or more lawful basis of processing (“Lawful Basis”) depending on the specific purpose for which we are using your data.
The Lawful basis are the following:- To perform our contractual obligations towards you
- To comply with the legal and regulatory requirements
- To pursue our legitimate interests
If our use of your personal information does not fall under one of these Lawful basis, we will require your consent. Such consent shall be freely given by you and you have the right to withdraw your consent at any time by contacting us using the contact details set out in this privacy policy or by unsubscribing from email lists.
We may use personal data provided by you through our website or otherwise and personal data provided during our business relationship to communicate with you for marketing promotional purposes as well as to provide you with market news and analytical reports. The channels used for such communications may include phone calls, emails, notifications through your online account portal and SMS notifications, including push notifications.
You have the right to opt out of these communications by using your online account portal or by sending an email to our DPO, at dpo@bankpro.com using the registered email address you disclosed to us, in case you do not have access to your online portal account, or one has not been provided to you for any reason. 6. Management of personal information
- We are committed to safeguarding and protecting personal data. We implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to protect your personal data from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed. To ensure that the processes we follow for the management of personal information comply with this policy and applicable legislation, we have appointed a Data Protection Officer (DPO).
We require third-party organizations who handle or obtain personal information to acknowledge the confidentiality of this information, undertake to respect any individual’s right to privacy and comply with all relevant data protection laws and this privacy notice.
Our data protection measures in place include the following:- Training employees who handle personal information to respect the confidentiality of customer information and the privacy of individuals;
- Requiring our employees to use passwords and two-factor authentication when accessing our systems;
- Implementation of Chinese walls to ensure employees only have access to the personal data required for the purposes of the tasks they handle;
- Using data encrypting technologies during data transmission during internet transactions and client access codes transmitted across networks;
- Employing firewalls, intrusion detection systems and virus scanning tools to protect against unauthorised persons and viruses entering our systems;
- Using dedicated secure networks or encryption when we transmit electronic data;
- Practising a clean desk policy in all premises occupied by us and our related bodies corporate and providing secure storage for physical records; and
- Employing physical and electronic means such as access cards, cameras and guards to protect against unauthorized access.
7. How do we store personal information and for how long?
- We store personal information using a combination of secure computer storage facilities and paper-based files and other records and take steps to protect the personal information we hold from misuse, loss, unauthorised access, modification or disclosure.
When we determine that personal information is no longer needed, we will either remove identifying details or securely destroy the records. However, we may need to retain records for an extended period due to legal and regulatory obligations. For example, we are subject to laws and regulations which require us to retain copies and evidence of the actions taken by us in regard to your identity verification, sources of incomes and wealth, maintain records of your financial transactions and monitor them, maintain records of telephone, chat and email communications, payment instructions, orders and trades history, handling of your complaints and records that can demonstrate that we have acted in line with regulatory code of conduct throughout the business relationship. These records must be maintained for a period of six years after our business relationship with you has ended, or even longer if we are asked by our Regulators or there is another valid reason.
Personal data provided by you as a prospective client during account opening registration in case the registration was never completed or your account opening application was rejected, will be maintained for six months unless there is a regulatory or other valid reason requiring us to keep it for a longer period of time.
If you have opted out of marketing communications, we will retain your details on our suppression list to ensure you do not receive such communications.
The personal data we collect from you may be transferred to and stored in countries outside The Bahamas. It may also be processed by staff located outside The Bahamas who work for us, our suppliers, or affiliated companies of FxPro group. We will take all reasonable steps to ensure that your data is treated securely and in accordance with this Privacy Policy.
Where we transfer your data to third parties in other jurisdictions, we may rely on data protection agreements or other applicable legal mechanisms to safeguard your information. If you would like a copy of these arrangements, please contact us using the details provided below. 8. Your rights
- Please note that these rights may not apply in all circumstances. You are entitled to:
(a) Request access to your personal data (commonly known as a 'data subject access request');
(b) Request correction of the personal data that we hold about you;
(c) Request erasure of your personal data. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request;
(d) Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms;
(e) Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:- If you want us to establish the data's accuracy;
- where our use of the data is unlawful, but you do not want us to erase it;
- where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or
- you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it;
(f) Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information (i.e. not to hard copies) which you initially provided consent for us to use or where we used the information to perform a contract with you; and
(g) Withdraw consent at any time where we are relying on consent to process your personal data.
You also have the right to opt out from receiving marketing communications from us through your online account portal or by sending an email to our DPO, at dpo@bankpro.com using the registered email address you disclosed to us, in case you do not have access to your online portal account, or one has not been provided to you for any reason.
If you wish to exercise your rights, please contact us by email at dpo@bankpro.com using the registered email address you disclosed to us. We may request that you verify your identity prior to processing your request.
We aim to respond to all requests within 1 (one) month. Occasionally, it may take us longer than 1 (one) month if your request is particularly complex or you have made a number of requests. In this case, we will notify you within 1 (one) month of the receipt of your request and keep you updated.
We may charge you a reasonable fee when a request is manifestly unfounded, excessive or repetitive, or we receive a request to provide further copies of the same data. In this case we will send you a fee request which you will have to accept prior to us processing your request. Alternatively, we may refuse to comply with your request in these circumstances. 9. What if you have a query or a complaint?
- If you have a concern about any aspect of our privacy practices, you can contact us to make a query or a complaint by email at dpo@bankpro.com.
We try to respond to all requests within 1 (one) month. Occasionally, it may take us longer than 1 (one) month if your request is particularly complex or you have made a number of requests. In this case, we will notify you within 1 (one) month of the receipt of your request and keep you updated.
If you are not satisfied with our response to your complaint, you have the right to lodge a complaint with our supervisory authority, the Office of the Data Protection Commissioner (DPC) of the Bahamas. Alternatively, if you reside outside the Bahamas, you may also have the right to lodge a complaint with the data protection authority in your country of residence.
You can find details about how to do this on the following website:
http://www.bahamas.gov.bs/dataprotection
Call +1 242 603 2226 or live chat •BankPro HQ: Lyford Manor, Western Road, Lyford Cay, New Providence, The Bahamas