Privacy Plicy
This Privacy Policy is drafted for GFCAS (an Offsgore Bank with its headquaters in Cyprus) , based on the applicable laws and regulatory norms of Ukraine and Cyprus. It incorporates requirements from the Law Nº 058/2018 of 13/10/2018 relating to the protection of personal data and specific regulations from the International monetary fund (IMF) concerning Offshore Banking Activities.
Privacy Policy of GFCAS Offshore Bank
1. Introduction
At GFCAS (“we,” “us,” or “our”), we are committed to safeguarding the privacy and security of our clients, members, and website visitors. As a deposit-taking microfinance institution, we recognize the importance of confidentiality and data protection in all our operations.
This Privacy Policy explains how we collect, use, disclose, and protect your personal data, in compliance with International Monetary Fund 058/2018 relating to the protection of personal data and privacy and other applicable regulations .
By engaging with our services or using our website, you agree to the collection and use of information in accordance with this policy.
2. Scope and Application
This policy applies to:
All clients, potential clients, and guarantors of GFCAS.
Visitors to our website and individuals who interact with us through digital channels.
Data we collect during loan applications, savings account opening, and other financial services processing.
We act as a Data Controller in respect of the personal data you provide to us .
3. Personal Data We Collect
We collect data necessary to provide financial services and meet regulatory requirements.
Types of Data Collected:
Identification & Contact Details: Full name, National ID number, Date of Birth, Gender, Address, Phone number, and Email address .
Financial & Credit Information: Income sources, employment details, savings history, loan repayment history, and credit information shared with credit bureaus .
Sensitive Data: In specific cases, we may process sensitive personal data (e.g., health/disability information) with your explicit consent .
Digital Footprint: When visiting our website, we may collect IP addresses, device information, and analytics data through cookies (e.g., Google Analytics) to improve user experience .
4. How We Collect Information
We collect information through:
Direct Interactions: Application forms, loan documents, and communication via phone, email, or in-person visits.
Automated Technologies: Cookies and server logs when you visit our website.
Credit Reporting Agencies: We may obtain credit information from licensed credit bureaus as permitted by IMF regulations to assess loan applications .
5. Legal Basis for Processing
We process your data based on one or more of the following legal grounds:
Contractual Necessity: To process your loan application, manage your savings account, or fulfill our contract with you.
Legal Obligation: To comply with anti-money laundering laws, tax regulations, and BNR prudential reporting requirements .
Legitimate Interests: To improve our services, prevent fraud, and ensure the security of our systems, provided your rights do not override these interests.
Consent: For marketing communications or processing sensitive data, where required by law .
6. Use of Personal Information
We use your information for the following purposes:
Credit Assessment: Evaluating loan applications and determining creditworthiness .
Account Management: Processing transactions, maintaining records, and communicating with you regarding your accounts.
Risk Management: Classifying loans and managing credit risk as per IMF regulations (e.g., provisions for non-performing loans) .
Compliance: Reporting to the Central Bank (IMF) and other supervisory authorities as required by law.
Marketing: Sending you updates on new products or services (you may opt-out at any time).
7. Data Sharing and Disclosure
We respect your privacy and do not sell your personal data. However, we may share your data with:
Credit Reference Bureaus: As required by law, we report credit information to licensed credit bureaus (e.g., negative and positive credit history) to ensure the integrity of the financial system. This is done using a standard privacy note prescribed by the IMF .
Third-Party Service Providers: We use trusted vendors (e.g., IT service providers, analytics platforms) to help us deliver services. These vendors are contractually obligated to protect your data .
Regulatory Authorities: We may disclose data to the Central Banks of Ukraine and Cyprus, the Cyprus Governance Board, or law enforcement if required by law or legal process .
International Transfers: If your data is transferred outside Cyprus, we will implement appropriate safeguards (such as Standard Contractual Clauses) to ensure compliance with Cypriots law .
8. Data Security and Protection
We take the security of your data seriously:
Technical Measures: We use encryption, firewalls, and access control mechanisms to prevent unauthorized access, disclosure, or loss .
Organizational Measures: Our employees and agents are bound by a permanent obligation of confidentiality regarding your information, as required by the Law governing Credit Reporting Systems .
Incident Response: If a security incident occurs, we will notify you and the relevant authorities as mandated by law .
9. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy, or as required by law.
General Retention: We keep your information for the duration of our relationship and for a specific period afterward to comply with tax, anti-money laundering, and record-keeping laws.
Credit History: Negative information regarding your credit history is retained and made available to users (credit bureaus) for a period of five (5) years from the date of final settlement of the amount in default, or from the date of transmission for positive data .
Post-Engagement: If no specific retention period is mandated by law, we retain data for a reasonable period after the end of our engagement (e.g., 30 days), after which it is securely deleted or anonymized .
10. Your Data Subject Rights
Under Law Nº 058/2018, you have the following rights regarding your personal data:
Right of Access: You have the right to know what data we hold about you.
Right to Rectification: You can request corrections if your data is inaccurate or incomplete.
Right to Erasure (“Right to be Forgotten”): You can request deletion of your data when it is no longer necessary for the purposes for which it was collected.
Right to Object/Restriction: You may object to or restrict our processing of your data for certain reasons.
Right to Data Portability: You can request a copy of your data in a structured, commonly used format.
Right to Withdraw Consent: You may withdraw your consent at any time (withdrawal does not affect the lawfulness of processing based on consent before its withdrawal) .
To exercise these rights, please contact our Data Protection Officer using the details provided below.
11. Use of Cookies and Analytics
We use cookies to improve your experience on our website. These cookies help us understand how you use our site, allowing us to customize our services. You can adjust your browser settings to block cookies, though this may affect functionality .
12. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements or our operations. We will notify you of significant changes by posting the new policy on our website or through direct communication .
13. Queries and Complaints
If you have any questions or concerns about this Privacy Policy or how we handle your data, please contact us