3. WHY AND ON WHICH LEGAL BASIS DO WE USE YOUR PERSONAL DATA?
In this section we explain why we process your personal data and the legal basis for doing so.
3.1. Your personal data are processed to comply with our various regulatory obligations
Your personal data are processed where necessary to enable us to comply with the regulations to which we are subject, including banking and
financial regulations.
3.1.1. We use your personal data to:
• monitor operations and transactions to identify those which deviate from the normal routine/patterns;
• manage and report risks (financial, credit, legal, compliance or reputational risks etc.) that the BNP Paribas Group could incur in the
context of its activities;
• record, in compliance with the regulations relating to distance selling when apply, communications in any form relating to products
or services purchased;
• assist the fight against tax fraud and fulfil tax control and notification obligations;
• when mandatory, record transactions for accounting purposes;
• prevent, detect and report risks related to Corporate Social Responsibility and sustainable development;
• detect and prevent bribery;
• when applicable, comply with the provisions applicable to trust service providers issuing electronic signature certificates;
• exchange and report different operations, transactions or orders or reply to an official request from a duly authorized local or foreign
financial, tax, administrative, criminal or judicial authorities, arbitrators or mediators, law enforcement, state agencies or public
bodies;
• respond to requests relating to the exercise of your rights, addressed to FLOA in accordance with article 2.
3.1.2. We also process your personal data for anti-money laundering and countering of the financing of terrorism purposes
As part of a banking Group, we must have a robust system of anti-money laundering and countering of terrorism financing (AML/TF) in each
of our entities managed centrally, as well as a system for applying local, European and international sanctions.
In this context, we are joint controllers with BNP Paribas SA, the parent company of the BNP Paribas Group (the term "We" in this section also
includes BNP Paribas SA).
The processing activities performed to meet these legal obligations are detailed in Appendix 1.
3.2. Your personal data are processed to perform a contract to which you are a party or pre-contractual measures taken at your request
Your personal data are processed when it is necessary to enter into or perform a contract to:
• define your credit risk score and your reimbursement capacity;
• evaluate (e.g., on the basis of your credit risk score) if we can offer you a product or service and under which conditions;
• provide you with the products and services subscribed to under the applicable contract;
• keep proof of operations or transactions, including in electronic format;
• manage existing debts (identification of customers in arrears) including payment incidents, overdue payments and amicable or
judicial recovery of any credit granted.
• respond to your requests and assist you;
• ensure the settlement of your succession;
• take into account your registration for the competitions organised by or in partnership with FLOA, manage your participation, enter
You in the prize draws and send You your winnings, where applicable.
3.3. Your personal data are processed to fulfil our legitimate interest or that of a third party
Where we base a processing activity on legitimate interest, we balance that interest against your interests or fundamental rights and freedoms
to ensure that there is a fair balance between them. If you would like more information about the legitimate interest pursued by a processing
activity, please contact us at the following address: Service consommateur – FLOA – 36 rue de Messines – 59 686 Lille Cedex 9.
3.3.1. In the course of our business as a bank, we use your personal data to:
• manage the risks to which we are exposed:
o when mandatory, we monitor your transactions to manage, prevent and detect fraud;
o we handle legal claims and defences in the event of litigation;
o we develop individual statistical models in order to help define your creditworthiness.
• enhance cyber security, manage our platforms and websites, and ensure business continuity.
• use video surveillance to prevent personal injury and damage to people and property.
• enhance the automation and efficiency of our operational processes and customer services (e.g., automatic filling of forms,
tracking of your requests and improvement of your satisfaction based on personal data collected during our interactions with
you such as phone recordings, e-mails or chats).
• to assist you in managing your budget by automatic categorization of your transaction data]
• If necessary, carry out financial operations such as debt portfolio sales, securitizations, financing or refinancing of the BNP
Paribas Group.
• conduct statistical studies and develop predictive and descriptive models for:
o commercial purpose: to identify the products and services that could best meet your needs, to create new offers or
identify new trends among our customers, to develop our commercial policy taking into account our customers'
preferences
o safety purpose: to prevent potential incidents and enhance safety management;
o compliance purpose (e.g., anti-money laundering and countering the financing of terrorism) and risk management;
o anti-fraud purposes.
• organize promotional operations, conduct opinion and customer satisfaction surveys.
3.3.2. We use your personal data to send you commercial offers by electronic means, post and phone
As part of the BNP Paribas Group, we want to be able to offer you access to the full range of products and services that best meet your needs.
Once you are a customer and unless you object, we may send you these offers electronically for our products and services and those of the
Group if they are similar to those you have already subscribed to.
We will ensure that these commercial offers relate to products or services that are relevant to your needs and complementary to those you
already have to ensure that our respective interests are balanced.
We may also send you, by phone and post, unless you object, offers concerning our products and services as well as those of the Group and
our trusted partners.
3.3.3. We analyse your personal data to perform standard profiling to personalize our products and offers
To enhance your experience and satisfaction, we need to determine to which customer group you belong. For this purpose, we build a
standard profile from relevant data that we select from the following information :
• what you have directly communicated to us during our interactions with you or when you subscribe to a product or service;
• resulting from your use of our products or services such as those related to your accounts including the balance of the accounts,
regular or atypical movements, the use of your card abroad as well as the automatic categorization of your transaction data (e.g., the distribution of your expenses and your receipts by category merchants (e.g. purchases made from a travel retailer));
• from your use of our various channels: websites and applications (e.g., if you are digitally savvy, if you prefer a customer journey to
subscribe to a product, or service with more autonomy (selfcare);
Unless you object, we will perform this customization based on standard profiling. We may go further to better meet your needs, if you
consent, by performing a tailor-made customization as described below.
3.4. Your personal data are processed if you have given your consent
For some processing of personal data, we will give you specific information and ask for your consent. Of course, you can withdraw your
consent at any time.
In particular, we ask for your consent for:
• tailor-made customization of our offers and products or services;
• any electronic offer for products and services not similar to those you have subscribed to or for products and services from our
trusted partners;
• personalization of our offers, products and services based on your account data at other banks;
• use of your navigation data (cookies) for commercial purposes or to enhance the knowledge of your profile in accordance with our
Cookie Management Policy.
You may be asked for further consent to process your personal data where necessary.