FİBABANKA ANONİM ŞİRKETİ PRIVACY NOTICE FOR CUSTOMERS
We, as Fibabanka Anonim Şirketi (the “Company” or “Fibabanka”), acting in the capacity of data controller, conduct sensitivity at maximum level, for processing and protection of the personal data of you, as our customers, in compliance with the Law on Personal Data Protection no. 6698 (“LPPD”) and the secondary legislation thereof (jointly, the “PDP Law”).
By this Privacy Notice, we would like to inform you regarding the personal data processing activities performed by our Company with regards to you, as our customers.
1.Your Personal Data That Shall Be Processed, Collecting Methods, Processing Purposes and Reasons of Legality
Your personal data specified below (“your personal data”) shall be collected by automatic and non-automatic means, and shall be processed accordingly, by our Company, within the scope of implementation of the agreements and in line with the requirements of the services that shall be provided to you; electronically, verbally or in writing in physical or electronic environments, being connected, limited and commensurate to the purposes defined below and in accordance with the principles defined in the LPPD and in compliance with the PDP Law.
This Privacy Notice is prepared, in a manner covering the legal reasons defined in the law with regards to your personal data that shall be processed within the scope of all products and/or services offered to you by our bank.
Your personal data that shall be processed within the framework of the products and/or services offered by our Bank, are as follows:
Your Personal Data That Shall Be Processed:
Reasons of Legality:
Managing the customer accounts with regards to prescription (time-barring) in deposit accounts; fulfilling the obligations within the scope of FATCA; process of identification of tax residence of individual customers by financial institutions; communication, approval and reporting processes; executing blockage transactions on accounts; meeting information requests by official authorities and institutions; sending warning letter to the debtors; making inquiry regarding customers in the Land Registry and Cadastre Information System (“TAKBIS”); making KKB inquiry for follow-up of the risks which shall occur in relation to the faith of the customers; conducting Promissory Note-Cheque Concentration Observation to follow the risks that shall occur in relation to the faith of the credits; conducting observation of other bank cheques to follow the risks that shall occur in relation to the faith of the credits; conducting EUS observation to follow the risks that shall occur in relation to the faith of the credits; conducting observation of the overdue credits (NPL) to follow the risks that shall occur in relation to the faith of the credits; conducting observation for bankruptcycomposition with creditors (concordat) to follow the risks that shall occur in relation to the faith of the credits; conducting limit-risk observation to follow the risks that shall occur in relation to the faith of the credits; conducting observation of cash credits to follow the risks that shall occur in relation to the faith of the credits; conducting observation of the bank cheques inquired via clearing process to follow the risks that shall occur in relation to the faith of the credits; conducting observation of collaterals to follow the risks that shall occur in relation to the faith of the credits; conducting observation on legal follow-up to follow the risks that shall occur in relation to the faith of the credits; conducting cheque index inquiry to follow the risks that shall occur in relation to the faith of the credits; conducting TAKBIS inquiry to follow the risks that shall occur in relation to the faith of the credits; examining the KKB records for managing the processes intended for following credit payments; examining the TAKBIS records for managing the processes intended for following credit payments; managing the processes intended for following credit payments - Expertise report; conducting Application Observation Screen KKB Inquiries to evaluate credit applications by current customers; conducting inquiry of the information relating to credits used in the last 24 hours to evaluate credit applications by current customers; conducting Cheque-Promissory Note Inquiries to evaluate credit applications by current customers; Conducting Application Observations to evaluate credit applications by current customers - Intelligence; examining Individual Loan Request Form to evaluate credit requests received from branches; conducting Individual KKB Inquiries to evaluate credit requests received from branches; taking Identity Certificate to evaluate credit requests received from branches; examining Income Certificate to evaluate credit requests received from branches; examining Individual Loan Request Form to evaluate credit requests received from branches; examining Individual Loan Request Form to evaluate credit requests received within the scope of store internal rating system (“SIRS”); conducting Individual KKB Inquiries to evaluate credit requests received via SIRS; taking Identity Certificate to evaluate credit requests received via SIRS channel; updating credit card limits; ensuring information security in the FTP usage processes; reporting, to the senior management, the information obtained in process of following the cheques; following customer account activities; intelligence / Memzuç (Central Bank Over-all Credit Risk Records) inquiry; evaluating credit applications - risk centre; evaluating credit applications- Central Decision Support System (“CDSS”); conducting GIB (Revenue Administration of Turkey) inquiries to identify the customers for whom credit can be allocated; conducting KKB inquiries to identify the customers for whom credit can be allocated; presenting account statements to the customers; taking requests for credit card / bank card; in the process of SIM card blockage removal process, identity chip scanning by Near Field Communication “NFC”; in the phone number updating process, identity chip scanning by NFC; following buy/sell transactions at the bank; account inquiries relating to tax audits; taking action in relation to attachment (seizure) letters; branch internal audit reports; reporting daily transactions to the Central Bank of the Republic of Turkey (“CBRT”); transfer process of foreign currency funds equal to USD 50,000 and above; receiving store credit applications by SMS; receiving applications by SMS, via the Bank’s outsourcing business partners, institutions from which it receives support services mainly Tarfin A.Ş. (“Tarfin”), AlışGidiş Elektronik Ticaret A.Ş. (“AlışGidiş”); upon receiving credit application, conducting check at GIB (Revenue Administration of Turkey); conducting KKB (Credit Bureau of Turkey) corporate inquiry to evaluate the customers’ credit applications; conducting KKB individual inquiry to evaluate the customers’ credit applications; making identity verification of customers, for whom product shall be defined; conducting KKB individual inquiry to evaluate customer credit limit; conducting KKB corporate inquiry to evaluate customer credit limit; conducting GIB inquiry to evaluate customer credit limit; conducting cheque index inquiry to evaluate customer credit limit; following deteriorations in the credit performances of current customers via the Main Banking Early Warning Observation Screen; conducting MKDS (Central Decision Support Systems) inquiry to follow deteriorations in the credit performances of current customers; conducting KKB inquiry to follow deteriorations in the credit performances of current customers; observing Memzuç (Central Bank Over-all Credit Risk Records) records to follow deteriorations in the credit performances of current customers; conducting KKB individual inquiry to follow deteriorations in the credit performances of current customers; conducting POS inquiry for customer credit limit evaluation; conducting KKB corporate inquiries to make evaluations on suitability for commercial credit; conducting KKB corporate inquiries for evaluation of the cheques that shall be accepted as collateral; conducting KKB individual inquiries for evaluation of the cheques that shall be accepted as collateral; examining the cheque reports for evaluation of the cheques that shall be accepted as collateral; in case any delay or problem is encountered in credit payments, making inquiry regarding the customers’ immovable properties via TAKBIS; examining Firm Presentation Reports (“FPR”) received from the branches; taking consent from owner of immovable property for Land registry and Cadastre Sharing System (“TAKPAS”); establishing right of pledge in the Registry of Pledge on Movable Assets for Commercial Enterprises (“TARES”); keeping log records for incorrect tapping; following by which user SMS and OTP’s are triggered; conducting KKB inquiries for current customers to analyse their financial data for the purpose of credit assessment / credibility; conducting TAKBIS inquiries for current customers to analyse their financial data for the purpose of credit assessment / credibility; examining financial analysis reports of current customers to analyse their financial data for the purpose of credit assessment / credibility; evaluating the customer complaints; verifying a customers in the conversations that shall be made; conducting KKB check for the purpose of evaluating customers, to whom credit shall be marketed, with regards to risk.
Transactions concerning cheques/promissory notes taken for collateral or collection purposes: giving promotion for customers’ pensions (retirement salaries); managing the processes relating to remittance transactions; managing the processes relating to EFT/Instant and Continuous Transfer of Funds (Fast and Secure Transfers “FAST”) transactions; banking transactions of foreigners; checking necessary documents for defining Fiba Key; managing customers’ personal information; conducting/managing agreement processes; meeting information requests by branches of the bank; meeting requests relating to reference letters; making collection from the customers who are transferred to legal follow-up process; assigning receivable subject to execution proceeding file and process management; giving information to the units relating to information requests by official authorities and institutions; intermediating for invoice payments of customers; making necessary definitions to enable use of FTP; conducting batch EFT/SWIFT transactions of customers in FTP; providing customers with access to FTP; making necessary definitions to enable use of Web Service Protocol; providing customers with access to Web Service Protocol; making necessary definitions to enable use of Account Statement Web Service Application; providing customers with the means to follow account activities; intermediating for invoice payments by dealers to provide cash flow of parent firm; providing financing to customers in consideration for post-dated receivables of customer suppliers; signing protocol relating to electronic account statement process; creation of records, based on account activities, automatically in the customers’ accounting system; sending Printed Swift Card; informing the customers relating to campaign results; offering virtual POS service to the customers; informing the customers relating to changes in interest rates; having access to customer data within the scope of conversations made in relation to a transaction; recording conversations made in relation to a transaction; giving approval relating to deposit products; calling the customers on daily basis within the scope of customer transactions; giving approval for expenses incurred for customers; making evaluations to define limit for customers; making analyses for pricing process; taking action relating to customer complaints; account opening; making equity (stock) transactions; making foreign exchange and metal trading (buy-sell) transactions; taking customer information for cherry account application; making crypto currency transfers; taking applications for time deposit account; taking applications for demand deposit account; presenting vehicle insurance offers; presenting BES (Private Pension System) offers; presenting offers for other elementary insurances (DASK, home, fire, etc.); evaluating applications for life insurance; taking applications relating to products via official web site; updating the communication information; taking the information required for customer system check; entering password for self-service updating; entering the passwords in the SIM card blockage removal screen; identity chip scanning by NFC in the SIM card blockage removal process; identity chip scanning by NFC in the phone number updating process; issuing statutory earthquake insurance policy; issuing health insurance policy; entering into BES (Private Pension System) agreement; issuing casco (casualty and collusion - full coverage vehicle insurance) policies; presenting vehicle insurance offers; issuing casco policies; presenting BES offers; evaluating life insurance applications; issuing special workplace package insurance policy; issuing home insurance policy for credit; issuing life insurance policy for credit; issuing life insurance (unintended unemployment coverage) policy for credit; matching the information contained in a policy with the information in the database; making a list relating to policies to be renewed; managing card requests; conducting the processes relating to card delivery; managing POS requests by customers; managing cash register POS requests; following the processes concerning investment funds held by the customers; following the processes concerning bonds held by the customers; providing functions relating to messages required for derivative transactions; following monitoring screens relating to customers; making the transactions relating to foreign trade products; SWIFT message processes; remittance transactions sent via the Document Management System (“DMS”); credit payment process regarding customers; meeting information requests received from branches; taking store credit applications by SMS; conducting customer inquiry in the credit application process; receiving credit applications by SMS, via the Bank’s outsourcing business partners, institutions from which it receives support services mainly Tarfin, AlışGidiş, and verifying customer information within the scope of credit disbursement; taking credit application; following applications made via channels out of branches; following credit processes of customers who use agricultural card; obtaining the information relating to applicants to agricultural card life insurance; taking customer instruction relating to delivery of agricultural card account statement; composing the credit offers; fulfilling the obligation of providing information before agreement; entering into overdraft account agreement; taking instruction relating to defining overdraft account; taking overdraft account instruction regarding repayment of credit instalment; taking information updating instruction regarding overdraft account; taking instruction regarding agricultural card credit; signing the undertaking form relating to insurance request; allocating individual loan; entering into housing finance loan agreement; entering into consumer loan agreement; entering into vehicle pledge agreement; entering into treasury bill/government bond pledge agreement; entering into derivative products bonds denominated in foreign currency (Eurobond) pledge agreement; entering into gold pledge agreement; entering into transfer/assignment of receivable agreement; entering into agreement relating to transfer/assignment of POS receivable; entering into derivative transactions framework agreement; entering into bank bond pledge agreement; entering into movable assets and deposits pledge agreement; signing protocol on change in interest/repayment period; composing repayment schedule according to credit agreements; managing the requests relating to letter of guarantee; signing general guarantee undertaking form for prepayment; managing the process relating to delivery of intra-branch documents; entering into company credit card membership agreement; making available (extending) credit with variable interest; defining the collaterals in the system; issuing Authorisation Certificate within the scope of the Direct Debit System (“DDS”); sending the cheques to the Credit Allocation Unit for allocation of limit; in cases where customer is unable to pay his/her debt, taking necessary information for restructuring of the debt; conducting receivable follow-up process and making calls; communicating with the customers for the purpose of debt collection, Process of transactions with bank/credit cards of the Bank at ATMs and pos devices of other banks.
Managing the customer information relating to prescription (time-barring) in deposit accounts; fulfilment of the obligations within the scope of FATCA; process of identification of individual customers’ tax residence by financial institutions; conducting the processes concerning donation payments; fulfilling safe deposit box declaration obligation; communication, approval and reporting processes; making blockage transactions relating to accounts; responding to an inquiry by correspondents in the customers’ foreign currency transactions; maintaining SWIFT operations; communicating with the customers available on IB chat in Bloomberg; conducting the process of offering pricing to customer and branch via Reuters Messenger; PowerBI reporting processes; meeting information requests by official authorities and institutions; making inquiry relating to execution proceeding files of tax offices; preparing independent audit report; following the lawsuit processes; reporting the lawsuit processes to the accounting; giving information regarding customer complaints made via competent authorities; conducting checks on money transfers between the personnel and the customers and other personnel; money transfers from customer accounts where the receiver’s name is the bank’s personnel; evaluating cases where the same phone number is defined both in the name of personnel and a customer; ensuring control of betting transactions; conducting checks on suspicious transactions concerning persons who acted as proxy for more than one customers; checking the transactions made in the accounts of elderly; checking the customers with the same mobile phone number; checking the term deposit accounts opened with past value date; checking the transactions giving rise to liability, made in joint accounts; checking the commission repayments; checking the transactions giving rise to liability, made at branch for customers who reside abroad; checking the transactions giving rise to liability, made by customers who turn into active from dormant (inactive); derivative transactions standard risk coefficient rates pot value check; check on credit customers for whom group definition is not made; transactions made at more than one branches for the same customer on the same day; check regarding individual loans transferred to follow-up process without making any collection; checking the customers, credit limit revision date of whom is past; checking overdraft account limit excess incidents; check regarding customers, credit interest rate applicable to whom is changed; check regarding customers for whom point(s) is/are loaded onto credit card; check on POS commission rate; checks on CIF opened repeatedly; check on legal limit relating to EFT-remittance commissions; tapping inappropriate calls; checking the accounts of real person customers, in the accounts of there are many credit entries; various receivable (VR) transactions settled by making available credit; checking the credit card payments made from the account of a person different from the card holder; checking the cash deposit withdrawal transactions with one day difference; checking the credit payments made by funds transferred from a different customer; correctness of credit allocation fee charged to financial consumers; customers who have proxy/curator and to whom individual loan is made via a channel out of branch; customers who gain profit from foreign exchange transactions concurrently; buying foreign currency by funds made available within the scope of credit; buying crypto currency by funds made available within the scope of credit; reporting made to the Banking Regulation and Supervision Agency (“BRSA”); keeping the log records relating to credits regarding which refusal decision is taken; ensuring information security in the FTP usage processes; reporting the information obtained in the follow-up process of the cheques, to the senior management; following customer account activities; conducting the process for creating record for trial balance; taking necessary action for correcting records with reverse direction; sending the bank’s legal books to the Revenue Administration; AssetsLiabilities Committee (“ALCO”) reporting; Oracle Business Intelligence (“OBI”) reports; making tax payments of customers; reporting annual transaction activities made within the scope of customer relations; reporting annual transaction activities; credit reporting; reporting restructured credits; answering the questions regarding legislation, received from business units; conducting work activities intended to avoid damages which may be suffered by 1st and 2 nd degree customers due to fraud; conducting processes for identification of credit applications made by issuing inaccurate document; identifying banned persons by making categorisations of persons; making reporting to the Audit Committee, conducting the processes for evaluating denunciation forms; evaluations AML declarations; reporting daily provisional commercial credit repayments; reporting daily provisional commercial credit information; reporting derivative financial instruments; conducting the processes of automating ALCO reports; conducting the processes of automating derivative financial instruments reporting; in order to protect customers against damages they may suffer within the scope of external fraud, monitoring customer transactions and preventing incidents; in order to protect customers against damages they may suffer within the scope of external fraud, monitoring customer transactions and observing card information for the purpose of preventing incidents; weekly reporting relating to customers who suffer a fraud and any damages sustained by customers; conducting fraud detection checks in order to prevent damages which may be sustained by customers; communicating with the customer for customer verification; conducting the process of acquiring customers who comply with the criteria defined for the know your customer process; making necessary examinations in order to respond to requests received from official authorities/processes of reporting to official authorities; communicating with correspondent banks relating to customer transactions; conducting the process of approval of acquiring customers who comply with the criteria defined for the know your customer process; making necessary examinations in order to respond to requests received from official authorities/processes of reporting to official authorities; making expense entries; conducting Corporate Credits-Cash CreditsCredit Monitoring for monitoring and following credit projects; conducting Limit-Risk-Customer and Group Based Risk Monitoring for monitoring and following credit projects; examining Memzuç (Central Bank Over-all Credit Risk Records) report screens for monitoring and following credit projects; examining Project Assessment Presentations for monitoring and following credit projects; examining collateral observation screens for monitoring and following credit projects; conducting the interest risk and liquidity risk processes; BRSA (Banking Regulation and Supervision Agency) reporting; customer scoring, classification and rating process; ALCO reporting; International Financial Reporting Standards (“IFRS”) reporting; BRSA reporting; resolving complaints relating to automatic teller machines (“ATM”); resolving complaints relating to common ATM’s; branch internal audit reports; taking action in relation to attachment letters; meeting information requests by official authorities; account inquiries relating to tax examinations; giving information to competent institutions regarding opened investment accounts; giving information to competent institutions relating to gold transfers; monitoring buy/sell transactions at the bank; processes of issuing voucher/receipt manually; conducting the process relating to customs declarations; meeting information requests by official authorities; reporting daily transactions to the CBRT (Central Bank of the Republic of Turkey); transfer process of funds in foreign currency equal to USD 50,000 and above; conducting identity verification of customers for whom product shall be defined; obtaining information regarding tax residence in a foreign country; obtaining customer information for delivery of security key; making physical settlements within the scope of audits made at the branches; conducting process audits within the scope of banking processes; conducting examinations and investigations within the scope of banking processes; in case of complaints raised by the customers, examining the customer accounts; reporting the findings; BRSA reporting; Financial Crimes Investigation Board (“MASAK”) reporting; notifying failures encountered in application opened for access by customers; conducting KKB (Credit Bureau of Turkey) Inquiries for credit performance reporting to the Credit Guarantee Fund (CGR Reporting); conducting credit performance reporting to the Credit Guarantee Fund (CGR Reporting); fulfilling the pre-agreement information obligation; independent audit reporting; evaluating customer complaints; making analyses relating to quality level of voice records and reporting them to the BRSA; verifying customers in the conversations made; recordings phone conversations made by the call centre with the customers; sending incorrect voice record to the customers; customer verification on the phone; customer scoring, classification and rating process.
Complaint and reputation management.
Sending warning letter to the debtors; assigning a receivable subject to execution proceeding file and process management; following and conducting execution proceedings; managing the lawsuit/execution proceeding processes; assigning a receivable to asset fund firm; following the execution proceedings; commencing execution proceeding against debtor persons via “icratek”; managing the lawsuit processes; taking letter of guarantee from other banks in the processes of stay of execution; following and conducting intermediation affairs; making KKB (Credit Bureau of Turkey) Individual Inquiries for monitoring the customers whose liabilities are past due; making KKB (Credit Bureau of Turkey) Corporate Inquiries for monitoring the customers whose liabilities are past due; following the customers whose liabilities are past due; for customers subject to follow-up proceedings, assigning the monitoring and collection process to related business unit or lawyer; in the lawsuit, the process regarding is completed by the legal unit, making the cost payments; presenting, to related business units, the list relating to immovable properties subject to right of repurchase (redemption); entering into right of repurchase (redemption) agreements for conducting pre-sale and sale transactions of immovable properties acquired by the bank, for set off against the bank’s receivable; sending the expertise report to intermediary institutions for conducting presale and sale transactions of immovable properties acquired by the bank, for set off against the bank’s receivable; ordering preparation of expertise reports for immovable properties which shall be accepted as collateral, and checking them; reporting, to related business unit, the immovable properties which shall be sold; making a list of debtors who shall be called.
Making periodic reporting on the basis of profit; reporting, to related business units, the customers whose payments are delayed; sharing necessary information with related business units for conducting the execution proceeding processes; reporting processes made to the senior management in order to ensure accuracy of related information in the reports that shall be prepared for the BRSA; reporting regarding routine checks made in order to check whether there is any mistake in the data or accounting; preparing the Board of Directors report; checking, issuing, profitability evaluation of derivative transactions; option-settlement (swap) end-of-day reports; monitoring customer profitability; monitoring yields of deposits; conducting the process of automating the board of directors reports; requesting customer data via PowerBI for organising campaign; reporting customer transaction details; ; monitoring customer profitability; conducting monitoring of employees’ performance; making reporting to the senior management; transactions made via digital channels and statistical analysis thereof; improving customer experience on digital channels; improving customer experience on the bank’s channels; monitoring the calls; monthly reporting to the board of directors; preparing executive summary relating to FTR’s and presenting a report to the Assistant General Manager; defining the collaterals in the system; making customer segmentation for composing a marketing strategy; monitoring customer complaints; conducting monitoring of customer representatives’ performance evaluation; designating the target customer group who shall be communicated for marketing purposes; confirming the information on segmentation.
Communicating with the customers for the purpose of making product promotion; sending commercial electronic message relating to insurance products; sharing guest information with the team who organise an open air movie event at a hotel and making reservation; statistical analysis; sending gifts to customers on special days; complaint and reputation management; face recognition system within the scope of SIM card blockage removal process; face recognition system within the scope of phone number updating process; collecting customer feedbacks; management of NPS questionnaires; sending commercial electronic message relating to insurance products; keeping central sales lists; regardless of the customer segment in which related customer is included, sending SMS/e-mail and making calls to the customers within the scope of marketing activities, including also individual and/or commercial credit marketing purposes; calling the customers for the purposes of providing information/marketing; meeting information requests by the bank’s branches; evaluating life insurance applications; issuing health insurance policy; meeting information requests by a counterparty bank; obtaining the information relating to persons who apply for agricultural card life insurance; processes of sending money to abroad / receiving money from abroad; providing customers who want to buy goods and/or services from the Bank’s outsourcing business partners, with the opportunity to use consumer loan with more advantageous interest, cost and/or commission rates, and directing the customers who want to benefit from these opportunities, to AlışGidiş via the branches of Fibabanka or electronic banking channels, and making their membership transactions, and providing customers with the opportunity to benefit from the products, services and loyalty programs offered by AlışGidiş, Customizing the offered products and services according to acclaim, usage habits, necessity.
2. Sharing Your Personal Data with Third Persons
2.1 Disclosure / Transfer in Turkey
Your personal data described above, shall be disclosed/transferred to the receiver groups specified below, in accordance with the purposes and reasons of legality set forth below.
For the purposes of conducting KKB (Credit Bureau of Turkey) individual inquiry in order to evaluate credit applications by customers; conducting KKB corporate inquiry in order to evaluate credit applications by customers; scanning identity chip by NFC in the SIM card blockage removal process; scanning identity chip by NFC in the phone number updating process; managing / conducting the business processes intended to follow buy/sell transactions at the bank; conducting the processes relating to taking consent form; conducting the processes relating to establishing right of pledge; identification process of tax residence of individual customers by financial institutions; fulfilling the obligations within the scope of FATCA; making blockage transactions relating to the accounts; meeting information requests by official authorities and institutions; communication, approval and reporting processes; ensuring information security in the FTP usage processes; providing customers with the means to have access to Web Service Protocol; responding to requests receive from official authorities; for the purpose of sending warning letters to the debtors; to the Competent Public Authorities and Institutions (Identity Sharing System, Address Sharing System,
Revenue Administration, MERSIS, Artisans and Craftsmen Information System (“ESBIS”), KKB (Credit Bureau of Turkey), NRIS (execution proceeding information), UYAP (National Judicial Network Project), e-Attachment, Central Depository of Securities (“MKK”), Takasbank, Borsa İstanbul, General Directorate of Land Registry and Cadastre, BRSA (Banking Regulation and Supervision Agency), Ministry of Treasury and Finance, Savings Deposit Insurance Fund (“SDIF”), MASAK (Financial Crimes Investigation Board), Banks
Association of Turkey (“TBB”), Ministries, PDP (Personal Data Protection) Board, Security Forces, Offices of Public Prosecutor, Courts, CBRT (Central Bank of the Republic of Turkey), Chairmanship of the Tax Audit Board, Execution Offices, Tax Offices, Customs Directorates, Municipalities, Notaries Association of Turkey, Postal and Telegraph Administration (“PTT”)),
For the purposes of conducting Application Monitoring Screen KKB Inquiries in order to evaluate credit applications by current customers; conducting Application Observations in order to evaluate credit applications by current customers - intelligence; conducting Cheque-Promissory Note Inquiries in order to evaluate credit applications by current customers; conducting inquiry relating to credit used in the last 24 hours in order to evaluate credit applications by current customers; updating credit card limits; taking requests for bank card; presenting account statements to the customers; taking requests for credit card, evaluating customer complaints; verifying customers in the conversations made; examining the financial analysis reports of current customers in order to analyse their financial data for credit evaluation / credibility purposes; conducting KKB inquiries of current customers in order to analyse their financial data for credit evaluation / credibility purposes; conducting TAKBIS inquiries of current customers in order to analyse their financial data for credit evaluation / credibility purposes; managing / conducting the business processes relating to monitoring buy/sell transactions at the bank; to the suppliers; for the purpose of carrying out transactions with credit/debit cards in ATMs and POS devices of other Banks.
For the purposes of conducting the processes relating to donation payments; meeting requests relating to reference letters; managing requests relating to letter of guarantee; providing customers with the means to follow account activities; conducting/managing DDS (Direct Debit System) processes, making collection from the customers transferred to legal follow-up process; to other Receiver Groups (institution to which donation is made, addressee institutions/persons, firms with which it is intended to share account information, firms with which a business relation is maintained, attorney/law office from which services are received),
For the purposes of transactions relating to cheques/promissory notes taken for collateral or collection purposes; managing the processes relating to EFT/FAST transactions; making collection from the customers transferred to legal follow-up process; assigning a receivable subject to execution proceeding and process management; to the Private Law Legal Entities (banks, Kredi Garanti Fonu A.Ş., Türkiye Varlık Fonu Yönetimi A.Ş.),
For the purposes of giving promotion for customers’ retirement (pension) salaries; managing the processes relating to remittance transactions; managing the processes relating to EFT/FAST transactions; taking credit applications; taking store credit applications by SMS; receiving credit applications by SMS, via the Bank’s outsourcing business partners, institutions from which it receives support services mainly Tarfin, AlışGidiş, and verifying customer information within the scope of credit disbursement; scanning identity chip by NFC in the SIM card blockage removal process; scanning identity chip by NFC in the phone number updating process; managing/conducting the business processes intended for following customers’ promissory note processes; managing/conducting the business processes intended for following processes relating to investment funds held by the customers; to Competent Public Authorities and Institutions (SSI (Social Security Institution), CBRT (Central Bank of the Republic of Turkey), Identity Sharing System, Address Sharing System, Revenue Administration, MERSIS (Central Registration System), ESBIS ( Artisans and Craftsmen Information System), KKB (Credit Bureau of Turkey), MKK (Central Depository of Securities), Takasbank, Borsa İstanbul),
For the purposes of presenting BES (Private Pension System) offers; evaluating applications for life insurance; matching the information in the process of issuing policy; issuing insurance policies; obtaining the information relating to applicants to agricultural card life insurance; managing insurance requests; to the Group Companies,
For the purposes of making updating transactions relating to individual customers; sending Printed Swift Card; offering Virtual POS service to the customers; evaluating applications for life insurance, managing the card requests; conducting processes relating to delivery of cards; managing customer complaints; managing/conducting the business processes intended for following customers’ promissory note processes; managing/conducting the business processes intended for providing the functions relating to messages required for derivative transactions; managing/conducting the business processes intended for following processes relating to investment funds held by the customers; managing/conducting the business processes intended for execution of transactions relating to foreign trade products; managing/ conducting the business processes intended for SWIFT message processes; to the Suppliers,
For the purposes of account opening; presenting vehicle insurance offers; presenting offers for other elementary insurances (DASK, home, fire, etc.); issuing insurance policies; matching the information in the process of issuing policy; conducting customer inquiry in the credit application process; verifying customer information; managing insurance requests; to the Business Partners.
For the purpose of independent audit reporting, to the Other Receiver Group (Audit Firms),
For the purposes of independent audit reporting; managing the information relating to the customers; identification process of tax residence of customers by financial institutions; fulfilment of the obligations within the scope of FATCA; fulfilment of the declaration obligation relating to safe deposit boxes; conducting blockage transactions relating to accounts; meeting information requests by official authorities and institutions; conducting inquiry relating to execution proceeding files of tax offices; giving information relating customer complaints made via competent institutions; reporting made to the BRSA (Banking Regulation and Supervision Agency); communication, approval and reporting processes; weekly reporting regarding customers who suffer a fraud and damages sustained by customers; ensuring information security in the FTP usage processes; providing customers with the means to have access to Web Service Protocol; making necessary examinations in order to provide response to requests receive from official authorities; making necessary examinations in order to provide response to requests receive from official authorities - processes of reporting to official authorities; making tax payments of customers; MASAK (Financial Crimes Investigation Board) reporting; managing/conducting the business processes relating to the customs declarations process; responding to requests received from official authorities; managing/conducting business processes relating to buy/sell transactions at the bank; reporting to the Audit Committee; conducting work activities intended to protect 1st and 2nd degree customers against any damages which they may suffer due to fraud; conducting processes intended to identify credit applications made by issuing inaccurate documents, derivative financial instruments reporting; daily provisional commercial credits repayments reporting; daily provisional commercial credits information reporting; credit reporting; restructured credits reporting; sending the bank’s legal books to the Revenue Administration; to Competent Public Authorities and Institutions (BRSA (Banking Regulation and Supervision Agency), Ministry of Treasury and Finance, SDIF (Savings Deposit Insurance Fund), Revenue Administration, MASAK (Financial Crimes Investigation Board), CIMER (Presidency’s Communication Centre), TBB (Banks Association of Turkey), TBB Risk Centre, Ministries, PDP (Personal Data Protection) Board,
Security Forces, Offices of Public Prosecutor, Courts, Tax Offices, Consumer Arbitration Board (CAB), General Directorate of Customs, CBRT (Central Bank of the Republic of Turkey), MKK (Central Depository of Securities),
Takasbank, Borsa İstanbul, Execution Offices, Customs Directorates, Municipalities, Chairmanship of the Tax Audit Board, KKB (Credit Bureau of Turkey), BKM (Interbank Card Centre)),
Derivative financial instruments reporting; daily provisional commercial credits repayments reporting; daily provisional commercial credits information reporting; credit reporting; restructured credits reporting; sending the bank’s legal books to the Revenue Administration; preparing independent audit report; following the lawsuit processes, ALCO reporting; OBI reports; non-cash credits reporting; conducting the processes for automating ALCO reports; conducting the processes for automating credit reporting; conducting the processes for automating derivative financial instruments reporting; evaluating customer complaints; verifying customers in the conversations made; making analyses relating to quality level of voice records and reporting them to the BRSA; recordings phone conversations made by the call centre with the customers; providing internal communication of the personnel, customer verification on the phone; identifying banned persons by making categorisations of persons; managing complaint processes; managing / conducting the business processes intended to follow buy/sell transactions at the bank; obtaining customer information for providing security key; to the Suppliers,
For the purpose of credit performance reporting to the Credit Guarantee Fund; to Private Law Legal Entities (Kredi Garanti Fonu A.Ş.),
For the purpose of managing complaint processes; to the business partners.
For the purpose of complaint and reputation management, to the Suppliers.
For the purposes of assigning a receivable subject to an execution proceeding file and process management; assigning a receivable to a firm included in the assets fund; to Real Persons and Private Law Legal Entities (Banks, Türkiye Varlık Fonu Yönetimi A.Ş.),
For the purpose of assigning a receivable to a firm included in the assets fund; to Other Receiver Group (firms included in the assets fund),
For the purpose of sending warning letter to the debtors, to Competent Pubic Authorities and Institutions
(Notaries Association of Turkey, PTT (Postal Administration),
For the purposes of managing lawsuit/execution proceeding processes; following and conducting execution proceeding transactions; following and conducting intermediation transactions; commencing execution proceeding against debtor persons on “icratek”; for customer subject to follow-up proceedings, assigning the follow-up and collection process to related business unit or lawyer; to the Suppliers,
For the purpose of sending the expertise report to intermediary institutions in order to make pre-sale and sale transactions of the immovable properties acquired by the bank for set off against receivable; to the Business Partners.
(article 5/2 (f)),
For the purposes of making periodic reporting on profit basis; reporting relating to routine checks made to check whether there is any mistake in data or accounting; conducting the process for automating the board of directors reports; to the Suppliers.
For the purposes of issuing insurance policies; obtaining the information relating to applicants to agricultural card life insurance; to the Group Companies.
For the purpose of sending commercial electronic message; to Other Receiver Group (Message Management System),
For the purpose of evaluating applications for life insurance; to the Group Companies
,
For the purposes of calling the customers for information/marketing purposes; evaluating applications for life insurance; sharing guest information with the team who organise an open air movie event at a hotel and making reservation; complaint and reputation management; collecting feedbacks by customers; to the Suppliers,
For the purposes of providing customers who want to buy goods and/or services from the Bank’s outsourcing business partners, with the opportunity to use consumer loan with more advantageous interest, cost and/ or commission rates, and directing the customers who want to benefit from these opportunities, to AlışGidiş via the branches of Fibabanka or electronic banking channels, and making their membership transactions, and providing customers with the opportunity to benefit from the products, services and loyalty programs offered by AlışGidiş; to Business Partners (AlışGidiş A.Ş.).
Our Company undertakes that, other than purposes defined above, it shall not disclose/transfer your personal data to third persons, without obtaining your explicit consent.
2.2 Disclosure to Abroad
Your personal data described above shall be disclosed to the Banks located abroad if you give explicit consent, within the scope of processing of fulfilment of the obligations within the scope of FATCA; transfer process of foreign currency funds in an amount equal to USD 50,000 and above; making batch EFT/SWIFT transactions of the customers on FTP; SWIFT message processes; making the transactions relating to foreign trade products; communicating with correspondent banks relating to customer transactions; identification process of tax residence of individual customers by financial institutions; providing response to questions of correspondents in the customers’ foreign currency transactions; maintaining SWIFT operations; controlling the transactions giving rise to liability, made at the branches for customers located abroad; obtaining information regarding tax residency in a foreign country; meeting information requests by a counterparty bank; sending money to abroad / receiving money from abroad, carrying out process of transactions with bank/credit cards of the Bank by customers at ATMs and pos devices of banks abroad.
3. Protection, Preservation and Destruction of Your Personal Data
Your personal data shall be processed by our Company during the period required by the purpose of processing personal data, and in any, shall be kept until the end of legally required period. Upon expiry of the keeping period, your personal data shall be erased from electronic and physical environments, shall be destroyed or anonymised according to the PPD (Protection of Personal Data) legislation, in accordance with our Company’s Policy on Protection and Secrecy of Personal Data, Policy on Protection and Secrecy of Private Personal Data and Policy on Keeping/Storage and Destruction of Personal Data.
For the purposes of prevent access to your personal data by unauthorised persons, processing of your personal data incorrectly, disclosure thereof, amendment/erasure thereof for illegal reasons, to ensure protection and security thereof; our Company shall take all technical and administrative measures in accordance with the PPD (Protection of Personal Data) legislation.
In case your personal data is damaged and/or is obtained by third persons/is disclosed as a result of attacks committed against the physical archive and/or servers and/or other systems of our Company; our Company shall inform you and the Personal Data Protection Board immediately.
4. Your right to be informed
Under The Law on Personal Data Protection, Article 11, you can apply to our Company; (a) to be informed whether your personal data is processed, or not; (b) if processed, to request information in relation thereto; (c) to learn purpose of processing and whether it is used according to intended purpose, or not; (d) to know the third persons to whom your personal data is disclosed in Turkey and abroad; (e) if processed incompletely or incorrectly, rectification thereof; (f) to request the erasure or destruction of your personal data under the conditions laid down in Article 7; (g) to request notification of the transactions made according to the paragraphs (e) and (f), to third persons to whom personal data has been disclosed/transferred; (h) to object against any outcome which shall arise due to analysis thereof by means of automatic systems exclusively, and (i) to request compensation for the damage arising from the unlawful processing of your personal data.
5. Your requests
If you have any question or request relating to processing of your personal data within the scope of this Privacy Notice, you can apply to our Company either by the Online Form available at the web address https://www.fibabanka.com.tr/bilgi-toplumu-hizmetleri/kvkk-kapsaminda-basvuru-talepleri or via the Registered E-Mail System.
Our Company shall handle and finalise the application requests, according to the nature of related request and at the latest within 30 (thirty) days, according to article 13 of the LPPD (Law on Personal Data Protection). When required due to nature of related transaction, tariff set by the PDP Board shall be applicable. If your request is refused, reason/s of refusal shall be specified in our response letter.
If you think that your personal data processed by our Company, is outdated, incomplete or incorrect, for your declarations relating to change(s) in your personal data, please contact our Company immediately via the e-mail address fibabanka.kisiselveri@hs03.kep.tr.
This Privacy Notice can be updated in order to adapt to changing conditions and legal regulations. You can follow the updates via the web address https://www.fibabanka.com.tr/.
Data Controller
Fibabanka Anonim Şirketi
MERSİS Number: 0209000780814852
Adress: Esentepe Mahallesi Büyükdere, Caddesi No:129 Şişli İstanbul/Türkiye
E-posta: fibabanka.kisiselveri@hs03.kep.tr