Heritable Bank Plc Data Protection

Statement of Principles

We believe that the protection of your personal information is very important. We also recognise that the manner in which we collect, and share, information about you is equally important.

This Statement outlines:

  • how we use and protect information about you; and
  • states the principles reflecting our commitment to safeguarding that information

Our principles are:

  1. To comply with our obligations under the Data Protection Act 1998 and any other relevant legislation;
  2. To ensure that any personal information we hold about you and your business with us is kept in strict confidence;
  3. To obtain personal information about you in a fair and lawful manner;
  4. To maintain appropriate procedures to ensure that personal information we hold about you is accurate and, where necessary, kept up to date;
  5. To maintain appropriate technical and organisational safeguards to protect personal information against loss, theft, unauthorised access, disclosure, copying, use or modification;
  6. If we choose to use third parties to process data, we do so in accordance with applicable law and take all reasonable precautions regarding the practices of the provider to protect personal information;
  7. Not to sell your personal information.

Use of Personal Information

Any information collected about you will be treated as confidential and will be used only as follows:

  • For considering this and any subsequent applications you may make to us and for the administration of your account(s) opened as a result;
  • For statistical analysis;
  • For marketing purposes (see below);
  • For fraud and money laundering prevention;

Marketing and market research

If you open an account with us, we may share your information with our associated companies or third parties with whom we have a business relationship. We or they may contact you by post, telephone, fax, e-mail or other means to tell you about services that may be of interest to you. You may indicate on our application forms that you do not wish to benefit from this service and we will respect your decision. Alternatively, you may write to us at any time and state that you do not wish to be contacted for this purpose and we will delete your name from our mailing lists. If you would like to be added to our mailing list please contact us.

Heritable Bank uses pixels, or transparent GIF files, to help us manage our online advertising. These GIF files are provided by our advertising management partner, DoubleClick. These files enable DoubleClick to recognize a unique cookie on your Web browser, which in turn enables us to learn which advertisements bring users to our website. The cookie was placed by us, or by another advertiser who works with DoubleClick. With both cookies and Spotlight technology, the information that we collect and share is anonymous and not personally identifiable. It does not contain your name, address, telephone number, or email address. If you require any more information about DoubleClick, including information about how to opt out of these technologies, please visit http://www.doubleclick.net/us/corporate/privacy .

Information provided by you through this website will only be used by Heritable Bank for direct marketing purposes strictly in accordance with the requirements of the Telecommunications (Data Protection & Privacy) Regulations 1999 and the Privacy & Electronic Communications (EC Directive) Regulations 2003.

We will not send unsolicited e-mail advertisements to anyone who has previously visited our web site unless they have subsequently opened an account with us and have agreed that we may do so.

Disclosure of Information

We will treat your account details as private and confidential and will not disclose information about them to any third parties, unless:

  • We have your consent to do so or you request that we do so;
  • We are required by law;
  • We have a public duty to disclose that information;
  • Our interests require disclosure. We will not give your details out for marketing purposes, even to other companies in our Group, if you instruct us not to. Other than to those individuals and entities referred to, or in the circumstances described, in this statement information about you will not be revealed by us to any external body or person

Your information may be disclosed to or as follows:

  • Other applicants or guarantor(s) to this account;
  • Other companies within our Group;
  • Credit Reference Agencies;
  • Where you borrow or may borrow from us, we may give details of your account and how you manage it to Credit Reference Agencies;
  • If you borrow and do not repay in full and on time, we may tell Credit Reference Agencies who may record the outstanding debt;
  • The financial intermediary introducing your account ( except if you instruct us not to do so) or any business that provides insurance services relating to your Agreement, as may be necessary for the purposes of the administration of any policy or insurance relating to your Agreement and dealing with any claims arising under such policy. In dealing with insurance applications and claims, it may be necessary for us, or the insurance company providing the insurance, to obtain information about any criminal record you may have;
  • Any agent acting on our behalf;
  • Our regulators;
  • Our lawyers, auditors and external advisors;
  • Third party service providers;
  • Anyone to whom we may transfer our rights and duties under your Agreement with us.

Your Rights

Under the Data Protection Act 1998 you have a legal right to:

  • Access your personal records held by credit and fraud agencies. We will supply their names and addresses upon request.
  • Receive a copy of the information we hold about you if you apply for this in writing. A fee will be payable for providing this information.
  • Have rectified any information that is inaccurate.

Please note that for our mutual protection and to improve service standards we may monitor and/or record telephone calls.

Please be aware that internet communications are not secure unless the data being sent is encrypted. Therefore we can accept no responsibility for the unauthorised access by a third party and/or the corruption of any data being sent to us.