Privacy Policy
Sagicor Bank (Barbados) Limited (“Sagicor Bank”) significantly values your trust in us. We truly understand our duty to protect and responsibly use the information that you share with us, and we pledge our commitment to fulfilling that responsibility. The purpose of this Privacy Agreement, a policy applied by Sagicor Bank is to inform you on how we treat your Personal Information.
This Privacy Agreement, as amended from time to time, replaces all previous privacy agreements, either written or oral, between you and us regarding the collection, use and disclosure of your Personal Information.
This Privacy Agreement is divided into the following sections:
- Who we are
- Collecting, Using and Disclosing your Information
- Cookies and similar technologies
- Marketing
- Your rights
- Keeping your personal information secure
- Accessing your information
- Use and disclosure of information for certain products or services
- Maintaining the accuracy of personal information
- Refusal or withdrawal of consent
- Changes to this privacy statement
Who we are
We ask that you read this Privacy Agreement carefully as it contains important information on who we are, how and why we collect, store, use, process and share Personal Information, your rights in relation to your Personal Information (also referred to as “Data”) and on how to contact us and the relevant data protection regulator in the event that you have a complaint.
In this Privacy Agreement: “we”, “our”, “us” and “Sagicor Bank”, means Sagicor Bank (Barbados) Limited, or any of its branches, agencies, subsidiaries and affiliates. Sagicor Bank includes companies engaged in the following services to the public: digital wallet, online banking, deposits, loans and other personal financial services; credit, charge, debit and payment card services; full service and discount brokerage services; mortgage loans; insurance services; and services related to the above such as loyalty programs. “Sagicor Group” means the Sagicor group of companies affiliated to or parent or controllers of Sagicor Bank.
This Privacy Agreement is applicable to each individual that has applied for, signed an application, enrolled in, or uses any personal or business banking, insurance, or financial product or service offered by us (“Service(s)”) including any co-applicant(s), guarantor(s), personal representatives, or an individual who participates in a Sagicor Bank contest, survey, event or has otherwise provided Personal Information to us (“you” and “your”).
“Personal Information” or “Data” means information, such as contact information, financial and account information, age and gender, identification numbers, income and employment information related to an identifiable individual. This may include information provided by the individual or collected by Sagicor Bank from the use of its products and services, third parties or public sources, and includes information in any format, including digital formats.
“Process” or “processing” means any use of the same data including obtaining, recording, storing, organizing, adapting, altering, retrieving, consulting on the Personal Information collected from you.
Collecting, Using and Disclosing your Information
Sagicor Bank is a multinational organization with business processes, management structures, vendor arrangements and technical systems that cross borders. We collect, use and are responsible for certain Personal Information about you. When we do so we are regulated by Data protection legislation and we are responsible as ‘controller’ of your Personal Information for the purposes of Data protection legislation.
What We Collect from You
We collect Personal Information about you when you access our digital platforms, app, website, social media platforms, register with us, complete an online application form, request an online meeting with a customer service representative, make a payment towards a policy, make a claim, log into your account, apply for any of our Services, request a quote or contact customer service via our website or through a mobile app or complete a survey.
We collect this Personal Information from you either directly, online or indirectly, such as by keeping details of your browsing activity while on our website (see ‘Cookies and similar technologies’ below).
The Personal Information we collect about you depends on the particular activity being carried out through our website. This information may include along with documents to verify the same:
- your name
- your address
- your contact details including email address and contact numbers
- valid government-issued photo-bearing identification
- government-issued identification numbers
- date of birth
- marital status
- employment information
- banking and financial account information
- information on income and financial position
- personal health information and family medical history
- any criminal history
- information regarding citizenship and residency
- details of any feedback you give us by phone, e-mail, post or via social media
- Information about beneficial owners, connected persons, intermediaries and other third parties where this information is required by law
- information about the Services we provide to you
- your account details, such as username, login details
- For legal entities such as corporations, partnerships, trusts, estates, organizations, joint ventures or other organizations, we may collect the information referred to above for authorized persons, including, without limitation signatories, shareholders, directors, officers, partners, trustees, executors, as appropriate.
- In addition, when you apply for, enroll in or use a Service, or participate in any contest, survey or event via a digital channel (such as wallet, app, online or mobile banking), we may collect information about your computer or device, operating system, internet connection or telephone account, settings, IP address, device locational data, and transaction data, as well as Personal Information as described above.
- We may collect, use, disclose and retain this information for the purposes described below, as well as to determine which settings are appropriate for your computer system, so we can provide or enhance digital functionality and banking options, for security purposes, internal analysis and reporting. You may withhold consent to the collection, use and disclosure of this information, although in some cases this may prevent you from using the digital channel to apply for or use a Service or to communicate with us, or may reduce the functionality of that channel.
How we Use and Disclose Your Personal Information
We may use and disclose your Personal Information to any person or organization, including any member of Sagicor Group, for the following purposes:
- to create and manage your account with us
- to verify your identity
- to determine the suitability of our Services for you
- to determine your eligibility for our Services
- to set up, manage and provide Services to you
- to provide you with various options for applying and accessing our Services
- to understand your needs
- to arrange for a Sagicor Group representative to contact you when requested
- to process an application, claim or payment
- to notify you of any changes to our website or to our Services that may affect you
- to resolve complaints and handle requests for access to or rectification of data
- to improve our Services
- to meet legal, regulatory or audit requirements, including the requirements of any self-regulatory organization to which we belong
- To help us collect a debt or enforce an obligation owed to us by you
- To respond to a local or foreign court order, search warrant or other lawful demand or request that we believe to be valid, or to comply with the rules of production of a local or foreign court
- To manage and assess our risks
- To prevent or detect fraud or criminal activity or to manage and settle any actual or potential loss in connection with fraud or criminal activity.
When we collect your health information for the purpose of providing an insurance service through one of our affiliates, we will use and disclose such information strictly for that purpose. (See below on Data Recipients).
Verification of Your Identity
You agree that we may collect, use and disclose your national, tax or other government-issued identification number or information, where permitted by law, for income tax reporting purposes and to fulfill other regulatory requirements, as required by law. In addition, we may also collect, use and disclose this information to verify and report credit information to credit bureaus and credit reporting agencies as well as to confirm your identity, where permitted by law. You may refuse to consent to its use or disclosure for purposes other than as required by law. However, this may result in a denial of a Service or product. In addition, information may also be disclosed to foreign taxation authorities such as the U.S. Internal Revenue Service or to any local taxation authority as required under the U.S. Foreign Account Tax Compliance Act (“FATCA”), or similar legislation from other countries or under local law.
Who do we share your Personal Information with?
Data Recipients:
Third-Party Service Providers
We do not directly provide all Services related to your relationship with us and may contract third-party service providers to process or handle Personal Information on our behalf and to assist us with services such as printing, postal and electronic mail distribution, data processing and analytics, marketing (by telephone and electronic means), and providing customer support and you acknowledge and agree that we can release your Personal Information to them.
We may also share your Personal Information with our third-party services providers operating outside of your home jurisdiction for any of the purposes set out above. This will mean that your Personal Information may be disclosed to regulatory authorities under the laws of these jurisdictions. You understand and agree that your Personal Information may be transferred to and collected, used, disclosed or stored in jurisdictions outside of the jurisdiction in which you reside.
Sagicor Bank will ensure that third-party service providers who receive the Personal Information of our customers are bound by a data processing agreement with us requiring that they agree to keep such Personal Information confidential and to use it only to perform their obligations set out under such agreement.
Affiliated companies: We may share your Personal Information with our affiliates within the Sagicor Group in furtherance of our interests in enhancing business efficacy through intra-group operational efficiencies and in promoting business continuity.
Non- affiliated service providers: We may share your Personal Information with non-affiliated third-party service providers of technical, or administrative services who act on our behalf and in accordance with our instructions, including in the contexts of customer support, software and application development, quality assurance, payment processing, mail processing and market research.
Reinsurers: If necessary, a copy of your application and any supporting information may be provided to a reinsurer who has agreed to share the risk associated with providing benefits under your insurance contract.
Intermediaries: To facilitate service delivery under the insurance contract you applied for and keep customer records up to date, your Personal Information may be shared with any licensed intermediary (sales agent or broker) acting on your behalf.
Other Disclosures: We may disclose your Personal Information to third parties if we reasonably believe that disclosure of such information is helpful or reasonably necessary to comply with any applicable law or regulation, to comply with or respond to a legal process or law enforcement or governmental request, to enforce our terms and conditions or other rights (including investigations of potential violations of our rights), to detect, prevent, or address fraud or security issues, or to protect against harm to the rights, property, or safety of Sagicor Bank.
Our legal basis for processing your Personal Information
When we use your Personal Information, we are required to have a legal basis for so doing. There are various legal bases on which we may rely, depending on what Personal Information we process and why.
The legal bases we may rely on include:
Consent: where you have clearly consented to the processing of your Personal Information for a specific purpose.
To process sensitive Personal Information including information on your financial position or on your criminal history we need your consent. If you do not consent or later elect to withdraw your consent to the processing of your financial information, we will not be able to provide you with insurance services. You should only give your consent to the processing of your sensitive Personal Information if you are doing so voluntarily.
Any consent that you give must be given from an informed position and specific to the purpose for which it is requested.
Contract: where our use of your Personal Information is necessary because you have asked us to take specific steps before entering into a contract or for performance of a contract that we have concluded with you such as insurance policies.
We collect and use your Personal Information in taking steps to conclude an insurance contract with you and to perform under that contract, if concluded. Your Personal Information is required to evaluate our ability to provide you with benefits and/or coverage as per your application and where your application is accepted, to administer our contract with you.
Legal obligation: where our use of your Personal Information is necessary to comply with law (not including contractual obligations).
Legitimate interest: where our use of your Personal Information is necessary to advance our legitimate interests or those of a third party (unless your right to privacy overrides our legitimate interest).
How long do we retain your personal information for?
You agree that we may retain and use your Personal Information for as long as it is needed for the purposes described in this Privacy Agreement, even if you cease to be a customer, subject to applicable law.
Cookies and other tracking technologies
A cookie is a small text file which is placed onto your device (e.g. computer, smartphone or other electronic device) when you use our website. These cookies help us recognize you and your device(s) and store some information about your preferences or past actions.
There are a number of different types of cookies, however, our website uses the following types:
- Functionality – these are necessary cookies that enable us to recognise you on our website and remember your previously selected preferences; these may include what location you are in
- Performance Optimization: these cookies enable us to provide you provide you with a responsive service and to make your experience of our website better.
- Advertising - these cookies are used to collect information about your visit to our website, the content you viewed, any links you followed and information about your browser, device and IP address.
Sagicor Bank or its third party service providers may also use various web tools including Web Beacons and Tagging on our websites and advertisements to evaluate and improve our websites and other electronic offerings, tailor our Services, enhance our customer experience and communicate with you regarding products and Services that may be of interest.
- Tagging is a customized code on our websites that provide the ability to monitor user activity on Sagicor Bank websites. This software can be used to capture user activity to be used by us or a third party for analysis so that we can understand and enhance our user experience and provide further security controls.
- Web Beacons are small images embedded in our websites that, when combined with Cookies, help provide us with information about the use and effectiveness of our website.
Sagicor Bank may use video surveillance in and around our branches, bank machines and other locations for the purpose of safeguarding our clients and employees and protecting against theft, fraud and vandalism. Any video images recorded are destroyed when they are no longer required for business or other purposes, and any Personal Information is safeguarded in accordance with this Privacy Agreement.
If you do not want cookies used in connection with your visit to our Website, or if you wish to limit their use, you can choose not to accept non-essential cookies and can generally also adjust the browser settings on your device. Most Internet browsers allow you to set your own preferences for use of cookies. Please be aware however that this may affect some functionality as you navigate the website which could impact your browsing experience.
Marketing Purposes
In order to better understand your use of our Services and to identify other products, services or offers from Sagicor Bank or select third parties that may be of interest to you, we may analyze and use your information as well as share your information within Sagicor Bank for these purposes. Unless you indicate otherwise, we may also use and share your contact information within Sagicor Group so that we and our affiliates may contact you directly to tell you about products, services, offers, promotions, events and other valuable information from Sagicor Group and select third parties, including via mail, telephone, SMS, text messaging, email or other electronic channels. This consent will also apply to any companies that form a part of Sagicor Group or Sagicor Bank in the future. We will never share your information with third parties outside of Sagicor Group for marketing purposes without your express consent. If you have a Service with us, you agree that we may use, disclose to and collect from credit bureaus, credit reporting agencies or financial service industry databases (where applicable), credit and other information about you in order to offer you preapproved credit products or margin facilities. We may also do this after the Service has ended. We have a legitimate interest in providing our prospective customers and clients with services that are well suited to their needs. To this end, provided that our processing of your Data will not impose on your interests, rights and freedoms to an extent that overrides our legitimate interest, we will use your personal information to grow our business intelligence through data analysis and the compilation of statistics so as to provide you with relevant information; identify services that may be of interest to you; develop and improve our financial services in response to customer needs; and make customized business conservation offers.
For direct marketing that requires your consent, when you apply for any of the Services we provide, we will ask whether you would like us to send you marketing communications.
If you have previously agreed to receive our marketing communications, you can unsubscribe at any time or withdraw your consent to the use and disclosure of your Personal Information for the above marketing purposes at any time by contacting us at dataprotection@sagicor.bank or by selecting the unsubscribe option we include in every marketing communication. For more information on your rights, see ‘Your rights’ below.
Your rights
You have a number of important rights as it relates to your Data, including rights to:
- fair processing of information and transparency in our use of your personal information
- be informed whether your Personal Information is being processed by us or on our behalf by a third party service provider
- access to your Personal Information
- require us to correct any mistakes in your information which we hold
- require the erasure of Personal Information concerning you in certain situations
- receive the Personal Information concerning you which you have provided to us, in a structured, commonly used and machine-readable format and to transmit this data to a third party in certain situations
- object at any time to processing of your Personal Information for direct marketing
- object to any decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you
- object in certain other situations to our continued processing of your personal information
- the right to lodge a complaint with the Data Protection Commissioner or equivalent in your jurisdiction, where applicable
- restrict our processing of your Personal Information in certain circumstances
- claim compensation for damages caused by our breach of the Data Protection Act
You have the right to withdraw consent to the processing of your Personal Information at any time. Withdrawing consent will not affect the lawfulness of any processing done prior to withdrawal.
If you would like to exercise any of these rights, please write to:
- The Data Privacy Officer, Worthing Corporate Centre, Worthing, Christ Church, BB15008 or at email dataprotection@sagicor.bank.
Please provide:
- enough information to identify you (e.g. account number, name and address),
- proof of your identity and address (a copy of your driving licence or passport and a recent utility bill or bank statement, and
- the information to which your request relates including any account or reference number(s) known to you.
Keeping your personal information secure
We have appropriate security measures in place to prevent personal information from being accidentally lost or used or accessed in an unauthorized way. We limit access to your personal information to those who have a genuine business need to know. Those processing your information will do so only in an authorized manner and are subject to a duty of confidentiality. We have procedures in place to deal with any suspected data security breach. We will notify you and the relevant data protection regulator of any data security breach where we are legally required to do so.
Accessing Your Information
You are able to access your Personal Information which we hold on file subject to legal, regulatory and contractual requirements. Some of this information is already accessible by you, through your account statement updates; by visiting the branch or office where you regularly do business; by accessing your account online; or through the Customer Contact Centre. In order to process your request, we may request specific details from you, such as branch and account number, and clarification on the specific information or time period you are requesting access to. Except where prohibited by law, once your identity has been verified and the scope of your request confirmed, within a reasonable period or such period as required by law, we will provide you with access to your information. If necessary, we will notify you that we require an extension.
Use and Disclosure of Information for Certain Products and Services:
Credit Cards, Mortgages, Loans, other Credit Products
When you apply for, accept, guarantee a loan or credit facility, or otherwise become indebted to us, and from time to time during the course of the loan or credit facility, you agree that we may obtain, use, verify, share and exchange credit and other information (except health information) about you with others including: credit bureaus, mortgage insurers, creditor insurers, registries, our branches and affiliates, and other persons with whom you may have financial dealings, as well as any other person as may be permitted or required by law. You agree that, we may do this throughout the relationship we have with you and you also authorize any person whom we contact in this regard to provide such information to us and we can continue to disclose your Personal Information to credit bureaus even after the loan or credit facility has been retired and, subject to applicable law, you may not withdraw your consent to our doing so.
If you have a Service with us such as a Sagicor Bank credit card or line of credit product, you agree that we may give information (except health information) about you to electronic payment service providers, credit or charge card associations, loyalty program partners and their employees and agents for the purposes of processing, authorizing and authenticating your transactions (as the case may be), providing you with customer assistance services, and for other purposes related to your Services. We may also give this information in respect of your participation in contests and promotions administered by the electronic payment service providers, credit or charge card associations and loyalty program partners on our behalf.
Insurance Products (where applicable to you)
Kindly note, subject to applicable legal requirements, once you apply for, enroll in or sign an application in respect of or accept an insurance service via Sagicor Bank, you automatically agree that we may use, give to, obtain, verify, share and exchange information about you with third parties including references you have provided, hospitals and health practitioners, government health insurance plans, other insurers, medical information and insurance service bureaus, law enforcement representatives, private investigators, and other groups or companies where collection is necessary to underwrite or otherwise administer the service requested, including the assessment of claims. You also authorize any person whom we contact in this regard to provide such information to us. If you accept an insurance service via Sagicor Bank, you may only withdraw your consent, as indicated below, so long as the consent does not relate to the underwriting or claims where Sagicor Bank or its affiliates are required to collect and report information to insurance service bureaus after the application has been underwritten or the claim has been adjudicated. This is required to maintain the integrity of the underwriting and claims systems.
Maintaining the Accuracy of Personal Information
You acknowledge that all the information provided by you will, at any time, be true and complete. You are required to advise us if any of your Personal Information changes or becomes inaccurate or out of date, so we can update our records.
Refusal or Withdrawal of Consent
Subject to legal, regulatory and contractual requirements, you can refuse to consent to our collection, use or disclosure of information about you, or you may withdraw your consent to our further collection, use or disclosure of your Personal Information at any time in the future by giving us reasonable notice. However, depending on the circumstances, withdrawal of your consent may prevent us from providing you, or continuing to provide you, with some Services, means of access to Services, or information that may be of value to you. We will act on your instructions as quickly as possible but there may be certain uses of your Personal Information that we may not be able to stop immediately. You cannot refuse our collection, use and disclosure of Personal Information required by third party service providers essential for the provision of the Services or required by our regulators, including self-regulatory organizations. You may inform us at any time to stop using Personal Information about you to promote our Services or the products and services of third parties we select. If you wish to refuse consent or to withdraw consent as outlined in this Privacy Agreement, you may do so at any time by contacting the branch or office with which you are dealing with.
Changes to this Privacy Agreement
You agree that we can amend, modify, change or replace this Privacy Agreement at any time to take into consideration changes in laws and regulations, our practices or to address other issues. We will post the amended Privacy Agreement on our public website. We may also notify you of any changes to this Privacy Agreement in accordance with applicable law, which may be in any of the following ways:
- A notice on our public website or your Sagicor Bank online portal, digital app or wallet;
- A notice in our branches;
- A notice in your statement; or
- A notice prominently displayed at our ATMs or on our ATM screens.
We consider you to have received the written notice:
a) On the same day that it was sent if sent by fax or by Electronic Communication;
b) Printed in your statement; or
c) When it is posted in our branches, posted on our app, website, displayed at our ATMs or on our ATM screens.
Your continued use of your Account (including maintenance of funds in), or any Service following notice of such change means that you agree to and accept the new terms and conditions of the Privacy Agreement as amended. Should you not agree with any of the changes made, you must immediately (1) stop using your Account or Services, (2) notify us that you are terminating your respective agreement with us; and (3) close the Account(s) or other Services (where permitted).