Privacy notice - before 19 July 2023
Our privacy promise
Your privacy is important to ClearBank ("ClearBank", "we", "us" and "our"). We are committed to protecting your personal data and being transparent about the personal data we hold and use and, wherever possible, giving you control over how we use your personal data.
Privacy and data protection are an integral part of our systems and services. ClearBank is ISO 27001 certified and maintains a number of security measures to protect your personal data. These include data access controls with respect to ClearBank personnel and ClearBank customers including two factor authentication, encryption of confidential and personal data, monitoring, data loss prevention controls and IT security policies. Your personal data is backed up in different locations and audit logs record user and system activities, exceptions, and information security events. Our personnel undergo regular data protection training and are required to adhere to data protection, confidentiality, and IT security policies and our third party service providers are bound by contractual obligations with regards to data protection, confidentiality, and IT security.
This notice applies to any individual associated with a customer or prospective customer of ClearBank which includes partners, directors, shareholders, beneficial owners, company secretaries, trustees, members and employees and to anyone whose personal data we process in connection with the provision, or possible provision, of services by us to our customers ("you" and "your") including as a result of communications and interactions with us, through the use of our services directly or indirectly (including processing payments) and as necessary in order to enable us to comply with our legal and regulatory obligations (for example by carrying out verification, anti-money laundering, and sanctions checks).
Please read this notice carefully. Among other things, it explains:
- What personal data we may collect about you in connection with: (i) our delivery of, and your use of our website, software, systems and the provision of our transactional and agency products and services (including use of the Clear.Bank Portal and Clear.Bank API) together the "Clear.Bank Services"; and (ii) any related interaction between you and us;
- How and why we process your personal data and the lawful basis or bases by which we process your personal data and other important information, such as how long we retain your personal data and who we share your personal data with; and
- Your rights in relation to the personal data we hold about you.
We may collect, use, disclose and store information about you when:
- you interact or use the ClearBank website at www.clear.bank ("ClearBank Website"), the ClearBank Portal and/or the ClearBank API;
- you correspond with us;
- you register for or use any of the ClearBank Services including indirectly through a customer of ours and as a result of making or receiving a payment that is processed by us;
- your employer or a business that you are associated with or with whom you are contracted to, registers for or uses any of the ClearBank Services (a "Related Entity");
- we carry out ongoing diligence, monitoring and screening, or respond to an external inquiry, in respect of anti-money laundering, politically important persons, source of wealth, fraud, sanctions and other crimes;
- you report an error in or request technical support for the ClearBank Portal or ClearBank API or generally request any customer care support;
- you make a complaint; and/or
- you provide data for other legal and regulatory purposes.
This notice is intended to be communicated to you in a concise, transparent, intelligible, and easily accessible manner, but we appreciate that you may have queries or want to seek clarification as to its terms. If so, please contact us (using the details set out at paragraph 2 below) and we will endeavour to respond to you as soon as possible.
We may make changes to this notice from time to time, including as may be necessary or prudent to reflect any changes in the ways in which we process personal data or any changes in data protection laws. Any changes and updates to this notice will be posted on the ClearBank Website (www.clear.bank). Please check this notice regularly so that you are aware of any changes.
Who we are and our contact details
For the purposes of data protection laws, ClearBank Limited, a company registered in England and Wales with company number 09736376 whose registered office is at 4th Floor, Prologue Works, 25 Marsh St, Bristol, BS1 4AX and which is authorised by the Prudential Regulation Authority and regulated by the Prudential Regulation Authority and the Financial Conduct Authority under registration number 754568 usually operates as the data controller. For some processing activities required in the provision of the ClearBank Services (including the processing of transactions), we will be a joint controller with our customer which might be a Related Entity. In other activities, we may be a processor, acting on the specific instructions of a customer or third party which might be a Related Entity.
For further information regarding when we process your personal data as a joint controller and with whom, or as a processor, please contact us. For information regarding how a Related Entity processes your personal data, please contact that relevant Related Entity.
If you have any queries regarding this notice or the way in which we process your personal data, please contact us at:
Email: [email protected]
Telephone: 020 3111 2328
Data Protection Officer
4th Floor, Prologue Works
25 Marsh St
Changes to your personal data
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes or if you become aware that any personal data that we hold is not accurate.
What personal data we collect
The type of personal data we process may include (as applicable) the following:
- Identity Data: Name, address, date of birth, age, marital status, title, maiden name, gender, nationality, country of residence, driving licence, birth certificate, marriage certificate, national ID card, passport and other identification documents (including utility bills, national insurance number, social security number, tax number, residence permit, payslips or other), job title, role, directorship, shareholding, employer, company/organisation name and details on a business card or in an email signature, Curriculum Vitae, education details, socio-demographic details, details regarding sanctions and whether you are a politically exposed person or a family member of a politically exposed person.
- Contact Data: Email address, address, telephone number, mobile number, other information in an email signature.
- Financial Data: Bank account details, account number, sort code, your financial position, assets, income, salary details, source of wealth information.
- Transactional Data: Payment transaction details, account number, sort code, payment amount and any information contained in a payment reference.
- Correspondence Data: Information which you provide in, or we learn about you from, any correspondence or communications with us, including details of any enquiries or requests for technical support and any complaints.
- Usage Data: Device IP address, the pages of the ClearBank website that you visit, usage information for the ClearBank website and the ClearBank Portal.
- Security Data: Username, password, security word and hint, memorable word.
- Technical Data: Type of device, unique device identifier (e.g. an IMEI number, IP, or Mac address), network information, the type of operating system and browser you use, time zone settings and other device related information.
- Publicly Available Data: Details obtained from online searches or that is otherwise available in public records including identity data, socio-demographic data, financial and economic data, data obtained from the electoral register and Companies House.
- Marketing and Communications Data: Your marketing preferences and communication preferences.
Information about why we process, and the lawful basis upon which we rely to process, the above personal data is set out in the table at paragraph 5 below.
4.2 We may process special categories of personal data (also known as sensitive personal data) including details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data. This data may be transferred to us without our knowledge including in a payment reference or obtained by us for the purposes of our money laundering and verification checks (for example, within data that reveals political opinions). We may also process information about criminal convictions and offences including terrorist offences and fraudulent activity. Such information is recorded by us and may be shared with financial crime prevention agencies, law enforcement agencies, regulators, and other financial institutions.
4.3 We may collect personal data from you directly and we may also obtain personal data from third parties or public sources including the following:
4.3.1 A Related Entity or a customer of ours;
4.3.2 Third parties engaged by a Related Entity or a customer of ours;
4.3.3 Financial Institutions, payment service providers, payment system operators and other financial services companies (to (amongst other things) provide the ClearBank Services, process a payment and prevent, detect and prosecute fraudulent and criminal activity);
4.3.4 LexisNexis (a third party company engaged by us to carry out identification and money laundering checks);
4.3.5 Credit reference agencies;
4.3.6 Law enforcement and fraud prevention agencies;
4.3.7 Regulatory and government bodies such as the Prudential Regulation Authority, Financial Conduct Authority, HM Revenue and Customs, the Bank of England, National Crime Agency;
4.3.8 Companies House;
4.3.9 Public registers;
4.3.10 Third party websites; or
4.3.11 External legal counsel and other professional advisors.
The purposes for which we process your personal data
5.1 We use your personal data for a number of purposes but only where we are allowed to by the law.
5.2 We may process your personal data in any circumstances where such processing is necessary:
5.2.1 in order to perform any agreement we have entered into with a Related Entity or a customer or otherwise as necessary in the provision of the ClearBank Services, including to process a transaction;
5.2.2 to comply with any applicable law or regulation; and/or
5.2.3 for the purposes of the legitimate interests pursued by us or a third party. These legitimate interests include the purposes identified in the table below at paragraph 5.7 but also include other commercial interests and our internal administrative purposes. Where we rely on legitimate interests as the lawful basis for processing your personal data, we will put in place appropriate safeguards to protect your data and to ensure that your interests or fundamental rights and freedoms are not overridden by those legitimate interests.
5.3 We may also process your personal data where we have your consent which may be obtained for us by a Related Entity. Where we rely on consent as the lawful basis for processing your personal data, you have the right to withdraw your consent at any time and if you wish to do so, you should contact our Data Protection Officer using the contact details set out in paragraph 2 above. Where we obtain your consent to send you marketing communications, you can unsubscribe by following the unsubscribe link within the communication. The withdrawal of consent does not affect the lawfulness of processing based on consent before withdrawal or the lawfulness of processing based on other lawful grounds.
5.4 We may process special categories of personal data and data relating to criminal convictions and offences where:
5.4.1 we have your explicit consent;
5.4.2 the processing is necessary for reasons of substantial public interest because of the law; and/or
5.4.3 the processing is necessary for the establishment, exercise, or defence of legal claims.
5.5 We may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data.
5.6 We may process your personal data ourselves or in conjunction with our third-party service providers in accordance with paragraph 7.
5.7 Information about the purposes for which we use your personal data, the types of personal data we process to achieve these purposes, and the lawful basis by which we process it, is set out in the table below:
5.8 We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose.
5.9 If we need to use your personal data for an unrelated purpose, we will notify you (which may be by way of update to this notice) and we will explain the legal basis which allows us to do so.
5.10 Please note that we may process your personal data without your knowledge or consent where this is required or permitted by law.
What if you refuse to provide us with any personal data?
6.1 Where we need to collect personal data by law, or under the terms of an agreement we have with you or a Related Entity, and you fail to provide that data when requested (or fail to consent to the processing of that data, if necessary), we may not be able to perform the agreement or arrangement we have or are trying to enter into with a Related Entity.
International transfers of personal data
8.1 From time to time it may be necessary for us to transfer your information internationally including to fulfil your request, process a transaction, or otherwise as required in the provision of the ClearBank Services. In particular, your information may be transferred to and/or stored on the servers of third parties identified in paragraph 7 which are based outside of the UK and the EEA.
8.2 However, we will not transfer your personal data outside of the UK and the EEA unless:
8.2.1 such transfer is to a country or jurisdiction which the EU Commission has approved as having an adequate level of protection;
8.2.2 appropriate safeguards are in place in accordance with data protection laws. These safeguards can include the use of standard contractual clauses or binding corporate rules;
8.2.3 any data importer provides us with relevant sources and information relating to the destination country or territory and the laws applicable to the transfer in that destination country in order to substantiate the matters set out in 8.2.1; or
8.2.4 the transfer is otherwise allowed under data protection laws (including where we have consent, the transfer is necessary for important reasons of public interest, is necessary for the establishment, exercise or defence of legal claims or is necessary for the performance of a contract with the data subject).
8.3 We will ensure that where your personal data is transferred outside of the UK and the EEA, the data importer will be contractually obliged to:
(a) ensure your personal data it is afforded the same protection as would be afforded to it within the EEA; and
(b) keep us informed of any development affecting or likely to affect the level of protection your personal data receives in the importer’s country.
Your rights as a data subject
9.1 Subject to any conditions and requirements set out in data protection laws, you may have some, or all, of the following rights in relation to the personal data we hold about you:
9.1.1 the right to request a copy of your personal data held by us;
9.1.2 the right to correct any inaccurate or incomplete personal data held by us;
9.1.3 the right to request that we erase personal data we hold about you;
9.1.4 the right to request that we restrict the processing of your data;
9.1.5 the right to have your personal data transferred to another organisation;
9.1.6 the right to object to certain types of processing of your personal data by us; and
9.1.7 the right to complain (please see paragraph 13 of this notice).
9.2 PLEASE NOTE that these rights are not absolute in all situations and may be subject to conditions and provisions set out in data protection laws. We cannot, therefore, guarantee that we will be able to honour any request from you in connection with the rights set out above. (For example, even if you request that we delete your personal data, we may be required by law to retain some personal data for accounting and record keeping purposes or in order that we comply with our legal and regulatory obligations.)
9.3 For further information, or to exercise any particular right, please contact us at [email protected].
Storage and retention of your personal data
10.1 As a minimum, we need to store your personal data for as long as is necessary to enable us to fulfil the purpose for which it is processed, including to fulfil our legal and regulatory obligations (e.g. relating to record keeping) and to exercise or defend any legal claims.
10.2 We maintain and implement a data retention policy and will delete personal data in accordance with this.
1.1 For as long as we do store your data, we follow generally accepted industry standards and maintain reasonable safeguards to attempt to ensure the security, integrity, and privacy of the information you have provided. All information you provide to us is stored on our secure servers. We are ISO 27001 certified and have implemented a risk assessment framework that is based on the principle of ISO31000 and the NIST Framework.
10.3 It is important that you keep secure and confidential any login credentials that you have for the ClearBank Website and/or ClearBank Portal. You are responsible for maintaining the security and confidentiality of such login credentials. You should notify us promptly if you become aware that the security or confidentiality of your login credentials is compromised.
10.4 We will notify you without undue delay in accordance with the requirements of data protection laws, if we have reason to believe that there has been a personal data breach by us which could adversely affect your rights and freedoms and we are required by law to notify you.
Questions and complaints
13.1 We take our data protection obligations seriously. If you have any questions or complaints about this notice or the way that we handle your personal data, we would appreciate the chance to deal with your concerns in the first instance before you approach the relevant data protection authority. Please contact us using the details provided in paragraph 2 above.
13.2 You have the right to make a complaint at any time to any relevant supervisory authority for data protection issues, including, in the UK, the Information Commissioner's Office (ICO) (www.ico.org.uk)