General privacy statement
What personal data do we collect
As FBC we collect personal data which includes but is not limited to the below:
- Your name and contact details.
- Communication details.
- Authentication data.
- Online profile data.
- Online activity/profile usage.
- Purchasing information.
- Payment history.
- Information about the devise(s) you use.
- Information about the service usage.
- Social media plug-in information.
- Date of birth.
- Copy of identification document.
- Your credit/debit card information.
- Subscription preferences.
- Financial and credit history.
- Location information and GPS data.
- CCTV on our premises including banking halls.
- Any other information you upload or provide us with.
How we use Personal Data
FBC uses the information collected to provide a safe, efficient and customised experience. We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent. Here are some of the details on how we do that:
To manage the service: We use the information we collect to provide our services and features to you, to measure and improve those services and features.
To contact you: We may contact you with service-related announcements from time to time. You may opt out of all communication except for essential updates.
Who else may process personal data
FBC may share the information collected with any member of the FBC Holdings group and also business partners/Third Parties in order to provide a safe, efficient and customised experience. Here are some details on how we do that:
To provide services: FBC may share your personal data with agents, contractors or partners of FBC in connection with services that these individuals or entities perform for or with FBC. These contractors are restricted from using this data in any way other than to provide services for FBC or for the collaboration in which they and FBC are engaged.
To make a payment: When you enter into transactions with others or make payments on FBC`s website, we will share transaction information with those third parties necessary to complete the transaction. We will require those third parties to respect your privacy and adequately protect your information.
To respond to legal requests and prevent harm: FBC reserves the right to share your information to respond to duly authorised information requests of governmental authorities or where required by law.
We never sell your personal data to third parties such as marketers without your consent.
How long do we use personal data
FBC deletes your personal information after the useful period. Following legal requirements:
To manage the services: We shall retain the personal data as indicated for this purpose, for no more than 10 years and as a compliance requirement.
We encourage anyone interested to raise any concerns using the contact information in our “Contact Us” page and we will investigate and attempt to resolve any complaints and disputes regarding the use and disclosure of personal data.
If you have questions or comments about this notice, you may email us at firstname.lastname@example.org or by post to:
FBC Holdings Limited
Group Marketing division
45 Nelson Mandela Avenue, Harare
How do we keep your information safe?
FBC implements commercially reasonable technical and organizational security controls to protect your personal data against theft, loss or misuse. Your data will be stored in a secure operating environment that is not accessible without authorization. FBC applies mitigation measures following periodic risk assessments to ensure an adequate level of protection of your personal data.
Do we collect information from minors?
In Short: We do not knowingly collect data from or market to children under 18 years of age without the consent of their legal guardian.
Where the data subject is a child under the age of 18, his or her rights may be exercised by his or her parents or legal guardian. We do not knowingly solicit data from or market to children under 18 years of age. By using the services, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent’s use of the services. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please contact us at email@example.com
Your right to access Personal Data
In addition to the information that is available on the FBC website, you have the right to access the personal data that FBC holds about you, all subject to the exemptions as contained in applicable laws and regulations. If you request for the information, FBC will assist you. Your identity will need to be confirmed before you are provided with access to personal data. Generally FBC does not charge for providing information, but if the request requires significant staff time, FBC reserves the right to charge for such requests.
Your right to correct or amend Personal Data
If you believe there is a mistake in your personal data, you have a right to ask for the information to be corrected. Based on the applicable laws of Zimbabwe, you may have the right to request access to the personal information we collect from you, change that information, or delete it. To request to review, update, or delete your personal information, please send an email to firstname.lastname@example.org
In Short: You may review, change, or terminate your account at any time.
If you are located in Zimbabwe and you believe we are unlawfully processing your personal information, you also have the right to complain to the Postal & Telecommunications Regulatory Authority of Zimbabwe, which is the designated Data Protection Authority.
Withdrawing your consent: If we are relying on your consent to process your personal information (Non sensitive, Sensitive, Genetic, Biometric and Health information), which may be expressed and/or implied consent depending on the applicable law, you have the right to withdraw your consent at any time. You can withdraw your consent at any time by contacting us by using the contact details provided in the section ‘HOW CAN YOU CONTACT US ABOUT THIS NOTICE?‘ below.
However, please note that this will not affect the lawfulness of the processing before its withdrawal, nor when applicable laws allow, will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.
Opting out of marketing and promotional communications: You can unsubscribe from our marketing and promotional communications at any time by clicking on the unsubscribe link in the emails that we send, replying ‘STOP’ or ‘UNSUBSCRIBE’ to the SMS messages that we send, or by contacting us using the details provided in the section ‘HOW CAN YOU CONTACT US ABOUT THIS NOTICE?‘ below. You will then be removed from the marketing lists. However, we may still communicate with you — for example, to send you service-related messages that are necessary for the administration and use of your account, to respond to service requests, or for other non-marketing purposes.
Cookies and similar technologies: Most Web browsers are set to accept cookies by default. If you prefer, you can usually choose to set your browser to remove cookies and to reject cookies. If you choose to remove cookies or reject cookies, this could affect certain features or services of our Services.
If you have questions or comments about your privacy rights, you may email us at email@example.com
Validity and Approval
This document is valid as of the date of approval Board Group Risk and Compliance Committee.
The owner of this document is the Information Security Function, who must check and, if necessary, update the document at least once a year.
When evaluating the effectiveness and adequacy of this document, the following criteria need to be considered:
Number of reported personal data breaches.