b) This privacy notice is issued on behalf of all the Valla entities (affiliation leader and participating members), so when we mention “we”, “us” or “our” in this privacy notice, we are referring to the relevant companies in the Valla Group responsible for controlling and or processing your data.
c) We will let you know which entity will be the controller/processor for your personal data if you formally engage us to provide you with a service.
d) We take privacy and security of your information seriously and will only use such personal information as set out in this Privacy Notice and in ways which are reasonably ancillary to what is set out below.
e) The identity of the relevant Valla entity responsible for your personal data in such situations can be provided to you by email email@example.com
f) References to “you” include all individuals whose personal data we collect, hold and process in the course of operating the various business within Valla.
g) Visitors to our website should review our Website Privacy Notice at www.vallalimited.com
3. THE PERSONAL INFORMATION WE PROCESS
a) Pursuant to section 4 and 5 of this privacy notice we may collect various types of personal data about you, including:
i. Your identification information (which may include your name, ID card and passport numbers, nationality, place and date of birth, gender, photograph and/or IP address
ii. Your data relating to claims, court cases and convictions,
iii. Your data that identifies direct or direct Politically Exposed Person (PEP) status,
iv. Your tax status information (which may include your tax residency, tax ID and/or tax status);
v. Your contact information (which may include postal address and e-mail address and your home and mobile telephone numbers);
vi. Your family relationships (which may include your marital status, the identity of your spouse and the number of children that you have);
vii. Your professional and employment information (which may include your level of education and professional qualifications, your employment, employer’s name and details of directorships and other offices which you may hold);
viii. Your financial information, including sources of funds and wealth and details of your assets (which may include details of your assets, shareholdings and your beneficial interest in assets, and your credit history);
b) We may also collect and process personal data regarding people connected to you, either by way of professional (or other) association or by way of family relationship.
c) In addition to the above we will collect other information as may be necessary for Valla to provide its services and to discharge its anti-money laundering and countering the financing of terrorism (AML/CFT) legal and regulatory obligations to Know its Client through the process of Customer Due Diligence (CDD) process.
4. WHERE WE OBTAIN YOUR PERSONAL INFORMATION:
a) Pursuant to section 5 (why we collect your personal information) of this privacy notice we collect your personal information from the following sources:
i. Personal information which you give to us, including but not limited to:
a. Such other forms and documents as we may request that are completed in relation to the provision of any of our services;
b. Information gathered through client due diligence carried out as part of our compliance with regulatory requirements; or
c. Any personal information provided by way of correspondence with us by phone, e-mail or otherwise;
ii. Personal information we receive from third-party sources, such as:
a. Entities in which you or someone connected to you has an interest;
b. Your legal and/or financial advisors;
c. Other financial institutions who hold and process your personal information;
d. Credit reference agencies and financial crime databases for the purposes of complying with our regulatory requirements; and
e. Personal information received in the course of dealing with advisors, regulators, official authorities and service providers by whom you are employed or engaged or for whom you act.
f. Held in a public register, e.g. information that is held in a central register of beneficial ownership in the country of establishment,
g. Persons that are subject to public disclosure rules, e.g. on exchanges or regulated markets (or consolidated subsidiaries of such persons), or subject to licensing by a statutory regulator
h. Information that is published in financial statements prepared under generally accepted accounting principles, or information available as a result of a listing of securities on a stock exchange;
iii. Personal information publicly available,
a. In commercial databases and press reports.
b. From open internet sources via search engines (e.g. Google, Bing, etc.)
5. WHY WE COLLECT YOUR PERSONAL INFORMATION:
A. LAWFUL GROUNDS FOR PROCESSING:
a) We may hold and process your personal information on the following lawful grounds:
i. The processing is necessary for our legitimate interests, provided your interests and fundamental rights do not override those interests;
ii. The processing is necessary to comply with our contractual duties;
iii. The processing is necessary to comply with our legal and regulatory obligations;
iv. Where we have obtained your consent to processing your personal information for a specific purpose; and
v. On rare occasions, where it is needed in the public interest.
B. PURPOSES OF PROCESSING
a) Your personal information may be processed for the purposes set out below (“Purposes”).
b) The Purposes based on our legitimate interests are set out in the following paragraphs “b I to b iv” inclusive):
i. facilitating the administration of our business and/or our service providers;
ii. Communicating with you as necessary in connection with our services;
iii. Monitoring and recording telephone and electronic communications and transactions:
a. For quality, business analysis, training and related purposes in order to improve service delivery; and
b. for investigation and fraud prevention purposes, for crime detection, prevention, investigation and prosecution of any unlawful act (or omission to act);
iv. Disclosing your personal information to any Valla or financial institution in providing our services;
C. OTHER REASONS FOR PROCESSING
a) To enforce or defend our legal and contractual rights or those of third party service providers;
b) To comply with legal or regulatory obligations imposed on us including but not limited to discharge its anti-money laundering and countering the financing of terrorism (AML/CFT) legal and regulatory obligations to Know its Client through the process of Customer Due Diligence (CDD) process.
c) Liaising with or reporting to any regulatory authority (including tax authorities) with whom we are either required to cooperate or report to, or with whom we decide or deem it is appropriate to cooperate in relation to tax matters.
6. SHARING PERSONAL INFORMATION
a) To facilitate the running of our business and our services we may share your personal information with our Group companies and third parties, including
i. financial institutions
ii. investment managers,
iv. IT service providers,
v. auditors and
vi. legal professionals
b) Where we share your information with a third party, we require the recipients of that personal information to put in place adequate measures to protect it.
c) Where we transfer your personal information outside the European Economic Area, we will ensure that it is protected and transferred in a manner consistent with legal requirements applicable to the information. This can be done in a number of different ways, for instance:
i. The country to which we send the personal information may be approved by the European Commission as providing adequate protection for personal data;
ii. By utilising a contract based on model contractual clauses which have been approved by the European Commission; or
iii. Where the recipient is located in the US, it may belong to the EU-US Privacy Shield scheme.
d) In other circumstances, the law may permit us to otherwise transfer your personal information outside the EEA.
i. When transferring data between EU AND European Free Trade Association (EFTA). countries the necessary safeguards are deemed to be in place due to GDPR – The EU / EFTA countries are:
a. EU = Austria, Belgium, Bulgaria, Croatia, Republic of Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden and the UK.
b. EFTA = Norway, Liechtenstein and Iceland
ii. Also personal data can flow from the EU to a third country without any further safeguard being necessary where the EU has given equivalent status. The European Commission has so far recognised
c. Canada (commercial organisations),
d. Faroe Islands,
g. Isle of Man,
i. New Zealand,
k. Uruguay and
l. The US (limited to the Privacy Shield framework) as providing adequate protection.
i. If you would like further information about the safeguards we have in place to protect your personal information, please contact firstname.lastname@example.org
7. RETENTION OF PERSONAL INFORMATION
a) Your personal information will be retained for as long as required:
i. For the purposes for which the personal information was collected;
ii. In order to establish or defend legal rights or obligations or to satisfy any reporting or accounting obligations; and/or
iii. As required by data protection laws and any other applicable laws or regulatory requirements.
8. ACCESS TO AND CONTROL OF PERSONAL INFORMATION – YOUR RIGHTS
a) You have the following rights (which may be exercisable depending on the circumstances) in respect of the personal information about you that we process:
i. The right to access and port personal information;
ii. The right to rectify personal information;
iii. The right to restrict the use of personal information;
iv. The right to request that personal information is erased; and
v. The right to object to processing of personal information.
b) You also have the right to lodge a complaint about the processing of your personal information either with us or with the applicable jurisdictional regulator for data protection matters:
i. The Office of the Information Commissioner in Jersey (https://oicjersey.org) in connection with Valla entities.
ii. Where we have relied on consent to process your personal information, you have the right to withdraw consent at any time. You also have the right to object to processing on the basis of legitimate interests (although this right is subject to certain exceptions).
iii. If you wish to exercise any of the rights set out in this paragraph, please contact email@example.com
10. COMMUNICATIONS AND MEDIA
A. PEOPLE WHO EMAIL US
a) Valla force the use of TLS (an encrypted end to end tunnel) for the secure transmission of emails.
If your email service does not support TLS, you should be aware that any emails we send or receive may not be protected in transit. Please contact us for further detail should you require it.
b) We will also monitor any emails sent to us, including file attachments, for viruses or malicious software.
c) Please be aware that you have a responsibility to ensure that any email you send is within the bounds of the law.
B. VISITORS TO OUR WEBSITE
a) We are committed to protecting and respecting your privacy on-line. We are aware of the concern which exists over the use of personal information provided over the internet and therefore, we do not collect personal data through our website.
a) If you have any questions about this data protection Privacy Notice or how we handle your personal information (e.g. our retention procedures or the security measures we have in place), or if you would like to make a complaint, please contact the Data Protection Officer at firstname.lastname@example.org
D. CHANGES TO THIS PRIVACY NOTICE
a) We keep our privacy notice under regular review.
b) This privacy notice was last updated on 29 May 2018.