INFORMATION NOTICE REGARDING THE PROTECTION OF CLIENTS & INVESTORS PERSONAL DATA
The protection of your personal data is at the heart of Uptevia concerns.
The purpose of this Notice is to inform you about the personal data we collect about you, why we use and share them, how long we keep them, what your rights are (in terms of control and management of your data) and how you can exercise them.
Our personal data processing activities are subject to the General Data Protection Regulation of the European Union (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016) and/or any other applicable data protection legislation.
As part of its activities, which include capital markets and securities services, we assist all of our Corporate clients and their investors in their issuer record-keeping and general meeting activities.
As such, UPTEVIA is required to process your personal data either as Data Controller (within the meaning of Article 4 of the GDPR) as described in paragraph 4 below “Why and on what legal basis do we use your personal data?”), or as a Processor on behalf of its customers.
- ARE YOU AFFECTED BY THIS NOTICE?
You are affected by this notice, if you are (“You”):
- An employee, consultant, provider, legal representative or beneficial owner of:
- an Issuer client;
- a potential client;
- a client or counterparty of our clients; or
- A shareholder or investor of our clients, in particular Securities Issuers.
- FROM WHOM DO WE COLLECT PERSONAL DATA?
- We may collect personal data directly from you
- And/or indirectly from our Issuer clients or the service provider for whom you work or represent under a service or partnership agreement we have concluded with the latter.
Indeed, in certain circumstances, we collect information about you even if we do not have a direct relationship with you. This may be the case, for example, for shareholders or investors in our relationships with our clients or counterparties. When you provide us with personal data relating to other people, do not forget to inform them of the communication of their data and invite them to read this Notice, which provides them useful information about their rights.
We also collect personal data from:
- other entities of the BNP Paribas SA Group, CACEIS SA;
- from our business partners or our clients’ business partners;
- service providers (e.g. payment initiation service providers and account information service providers such as account aggregators).
- WHAT TYPES OF PERSONAL DATA DO WE COLLECT?
We collect and use your personal data, i.e. any information that identifies you or, in conjunction with other information, which identifies you, necessary for the performance of Uptevia’s missions.
Depending in particular on the person concerned by the processing, we collect different types of personal data about you, including:
- For our Clients / Potential Clients:
Identification data (e.g. surname, first name, email address, telephone number, date and place of birth, gender, professional photography);
Business contact data (e.g. postal address, business telephone number, business email);
Data on education and employment (e.g. function performed);
Data collected as part of our exchanges with you (e.g. meeting minutes).
- For shareholders or investors of our clients, in particular Securities Issuers:
Identification data (e.g. name, surname, personal or business email address, personal or business telephone number, tax address, postal address, nationality, date and place of birth, gender);
Contractual data (e.g. reference / identifier);
Information on working life (e.g. employee reference, reporting HR, compensation data);
Information on family life (e.g. closely related persons);
Economic and financial information (e.g. bank account details, subscription financing data (if arbitration financing/employee savings release));
Login data (e.g. login credentials used to connect to Uptevia applications, IP address);
Data related to transfers and successions (e.g. ownership breakdown, date of death, rights holders, share of rights holders, etc.)
As part of our regulatory obligations, we may collect the following special categories of personal data (or “sensitive data”), only when required by law:
- Concept of politically exposed person (PEP)
- Social security number (as part of the company employee savings plan)
- Information on important religious roles
- Persons under surveillance (insider, terrorist activity)
Please note that you are not required to provide the requested personal data. However, if you do not, we may not be able to provide you with our services.
- WHY AND ON WHAT LEGAL BASIS DO WE USE YOUR PERSONAL DATA?
The purpose of this section is to explain why we process your personal data and on what legal basis we rely to justify it.
4.1 Your personal data is processed to comply with our various legal obligations
Your personal data is processed, when necessary, to enable us to comply with the regulations to which we are subject, including banking and financial regulations.
We use your personal data to:
- Monitor operations and transactions to manage, prevent and detect fraud;
- Monitor and report on risks (financial, credit, legal, compliance, reputational, operational, etc.) that we may face;
- Record, in accordance with the regulations concerning financial instrument markets (MiFID II Directive) and the regulation on market abuse, communications of any form (including telephone conversations, e-mails, instant messaging discussions), related at least to the provision of services regarding stock orders, in particular their reception, transmission, execution and recording;
- Disclose, in accordance with the Shareholder Rights Directive (SRD 2), your personal data to issuers, including information allowing your identification as a shareholder, your proxy votes and your register number;
- Contribute to the fight against tax evasion and comply with our reporting and tax control obligations, including under the U.S. Foreign Account Tax Compliance Act (FATCA) and automatic exchange of information;
- Fulfill our reporting and registration obligations for transactions with the competent authorities (tax, judicial, criminal, etc.);
- Record transactions for accounting purposes;
- Detect and prevent corruption;
- Exchange and report various operations, transactions or requests or respond to an official request from a duly authorized local or foreign judicial, criminal, administrative, tax or financial authority, an arbitrator or mediator, law enforcement authorities, government bodies or public bodies.
4.2 We also process your personal data to combat money laundering and terrorist financing
We must have a robust anti-money laundering and combating the financing of terrorism (AML/CFT) system.
This may require processing your personal data primarily within the framework of our Know Your Customer (KYC) procedure, to identify you, verify your identity, and check the information about you against sanctions lists, before and during the provision of our services.
The processing operations implemented to meet these legal obligations are detailed in Appendix A.
4.3 Your personal data is processed to execute a contract to which you are a party or pre-contractual measures taken at your request or for the purposes of setting up the services
Your personal data is used when it is necessary for the conclusion or performance of a contract to provide our customers with the products and services subscribed to in accordance with the applicable contract.
4.4 Your personal data is processed to meet our legitimate interest or that of a third party
Where we base processing on legitimate interest, we balance that interest with your interests or fundamental rights and freedoms to ensure that there is a fair balance between them.
- As part of our business, we use your personal data for the following legitimate purposes:
Manage your access to and use of our web communication channels and applications as part of our contractual and pre-contractual relationships with our clients and shareholders.
- Communicate with you in the context of services provided to our clients and/or counterparties; Manage the risks to which we are exposed:
– we keep evidence and sometimes record operations, transactions, and communications when you interact with our employees (for example, in our discussion forums, by email, or during videoconferences);
– we monitor transactions to manage, prevent, and detect fraud, and, if required by law, we create a list of frauds (which will include the fraudsters);
– we manage legal actions and defend our position in case of litigation.
- Improve cybersecurity and data loss prevention measures, manage our platforms and websites, and ensure business continuity.
- Monitor access to property and prevent bodily injury and harm to persons and property via video surveillance.
- Monitor compliance with our internal policies and procedures. This may include monitoring voice, email and instant messaging (chat) communications when you interact with our employees.
- Comply with the applicable provisions for trust service providers issuing electronic signature certificates.
- Perform our asset management services whenever you are an indirect beneficiary of these services, including for the following purposes:
- the creation and maintenance of your shareholders or investors register;
- the receipt, entry, and processing of voting instructions from your shareholders;
- the provision of tax services performed on your behalf (withholding tax reduction, tax recovery);
- the safekeeping of your physical securities;
- the management of your access to and use of our online communication channels and applications;
- Conduct statistical studies and develop predictive and descriptive models for purposes of:
- security: to prevent potential incidents and improve security management;
- compliance and risk management (such as combating money laundering and terrorist financing);
– fraud prevention.
- COOKIES AND BROWSING DATA
As part of our use of our digital services, we may use your browsing data in accordance with our Cookie Policy.
Cookies are small text, image or software files that may be placed and/or read from your device when you access our Website and/or the Application. The term “device” specifically refers to computers, smartphones, tablets, and any other device used to access the Internet.
As part of our business, we only use cookies called strictly necessary cookies. These cookies are essential to allow the Site/Application to function properly. They may include, for example, cookies that collect session IDs and identification data, cookies that allow to customize the interface of a Site and/or an Application (for example, for the choice of the language or presentation of a service) or certain audience measurement cookies. This category also includes cookies that enable us to comply with our legal obligations, including ensuring a safe online environment (for example, detecting repeated login failures to prevent unauthorized persons from accessing your account).
- WITH WHOM DO WE SHARE YOUR PERSONAL DATA AND WHY?
6.1. With our Issuer Clients
As an agent of our Issuer Clients, we share your personal data with the Issuer Clients of which you are shareholders or investors.
6.2. With BNP Paribas and CACEIS Groups entities
As a company belonging to the BNP Paribas and CACEIS Groups, we work closely with these entities. Your personal data may thus be shared within the BNP Paribas and CACEIS Groups, when necessary, to:
- comply with our various legal and regulatory obligations described above, in particular in terms of reporting;
- fulfil our contractual obligations or serve our legitimate interests described above;
- conduct statistical studies and develop predictive and descriptive models for security, compliance, risk management and anti-fraud purposes;
Data sharing with Group companies may extend to intra-group subcontractors who perform services on our behalf.
6.3. With recipients, third parties to Uptevia and its subcontractors:
In order to achieve some of the purposes described in this Notice, we may, when necessary, share your personal data with subcontractors who perform services on our behalf (for example, IT, logistics, printing, telecommunications, collection, consulting, distribution and marketing services).
When we deem it necessary, we may also share your personal data with other data controllers, such as:
- Our service providers and subcontractors who supply products and services on our behalf (for example, IT service providers, cloud service providers, database suppliers);
- Banking and business partners, independent agents, intermediaries or brokers, financial institutions, counterparties, trade repositories with whom we have links if such a transfer is necessary to provide services or products to you or to meet our contractual or legal obligations or process transactions (e.g. banks, correspondent banks, custodians, securities issuers, paying agents, exchange platforms, insurance companies, payment system operators, payment card issuers or intermediaries, mutual guarantee companies or financial security institutions);
- Regulators and/or independent agencies, local or foreign financial, tax, administrative, criminal or judicial authorities, arbitrators or mediator, public authorities or institutions or institutions (such as the Bank of France and other central banks), to whom we are required to disclose data at their request;
- In connection with our defense, action or proceeding;
- To comply with a regulation or recommendation from a competent authority that applies to us;
- Service providers or third party payment service providers (information about your bank accounts), for the purposes of providing a payment initiation service or account information at your request;
- Certain regulated professions such as lawyers, notaries, or auditors, in particular when specific circumstances so require (litigation, audit, etc.) as well as to our insurers or any current or potential buyer of Uptevia’s companies or activities.
- INTERNATIONAL TRANSFERS OF PERSONAL DATA
In certain circumstances (e.g. to provide international services or for operational efficiency), your data may be transferred to another country.
In case of international transfers from:
- the European Economic Area (EEA) to a non-EEA country, the transfer of your personal data may take place on the basis of a decision by the European Commission, where the latter has recognised that the country to which your data will be transferred ensures an adequate level of protection;
- other countries for which international transfers are subject to limitations, we will implement appropriate safeguards to ensure the protection of your personal data.
For other transfers, we will implement an appropriate safeguard to ensure the protection of your personal data, namely:
- Standard Contractual Clauses approved by the European Commission; or
- binding corporate rules.
In the absence of an adequate decision or an appropriate safeguard, we may rely on a derogation applicable to the particular situation (e.g. if the transfer is necessary for the exercise or defence of legal claims).
You can obtain further information about the scope of our international transfers by sending a written request to dpo@uptevia.com
- HOW LONG DO WE KEEP YOUR PERSONAL DATA?
We retain your personal data for the longer of the following periods:
- the necessary period required by applicable law;
- the duration defined with regard to our operational constraints, such as proper bookkeeping, effective customer relationship management, as well as to assert legal claims or respond to requests from authorities and regulators.
Telephone records are kept for 5 years from their collection.
Most of the personal data collected in respect of a customer is retained for the duration of the contractual relationship with that customer and for a specified number of years from the end of the relationship or in accordance with applicable law.
For further information about how long your personal data will be stored or the criteria used to determine this period, you can contact us at the address set out in paragraph 9.1 (How to contact us) above.
- WHAT ARE YOUR RIGHTS AND HOW CAN YOU EXERCISE THEM?
In accordance with applicable data protection legislation, you have rights that allow you to exercise meaningful control over your personal data and how we use it.
9.1. How to contact us?
If you wish to exercise the rights summarised below or if you have any questions about our use of your personal data under this Notice, please contact us at dpo@uptevia.com.
Depending on our role regarding the processing of your personal data (“Data Controller”, “Processor”), we will respond directly to all your requests within the deadlines provided for by the regulations.
9.2. You can request access to your personal data
Upon request, when we act as Data Controller, we will provide you with a copy of your personal data as soon as possible, together with information relating to its use.
Your right of access to your personal data may, in certain cases, be limited by applicable law and/or regulations. For example, anti-money laundering and combating the financing of terrorism regulations prohibit us from giving you direct access to your personal data processed for this purpose. In this case, you must exercise your right of access to the CNIL, which may ask us to provide it with the data concerned.
9.3. You can request the rectification of your personal data
If you consider that your personal data is inaccurate or incomplete, you may request that it be amended or supplemented. In some cases, you may be asked for a supporting document.
9.4. You can request the erasure of your personal data
If you wish, you can request the deletion of your personal data to the extent permitted by law.
9.5. You can object to the processing of your personal data based on legitimate interest
If you do not agree to processing based on legitimate interest, you may object to it, on grounds relating to your particular situation, indicating precisely the processing concerned and the reasons. We will no longer process your personal data unless there are compelling legitimate grounds for processing them or these are necessary for the establishment, exercise or defence of legal claims.
9.6. You can suspend the use of your personal data
If you dispute the accuracy of the data we use or object to your data being processed, we will verify or review your request. During the period of study of your request, you have the possibility to ask us to suspend the use of your data.
9.7. You may withdraw your consent
If you have given your consent to the processing of your personal data you can withdraw this consent at any time.
9.8. You can request the portability of part of your personal data
You may request to retrieve a copy of the personal data you have provided to us in a structured, commonly used and machine-readable format. Where technically feasible, you may request that we pass this copy on to a third party.
9.9. You can file a complaint with the Personal Data Protection Authority
In addition to the rights mentioned above, you can file a complaint with the Commission Nationale de l’Informatique et des Libertés (CNIL) at the following address:
3 Place de Fontenoy
TSA 80715
75334 PARIS CEDEX 07
Tel: +33 (0)153732222
Website: www.cnil.fr
Appendix A
Processing of personal data to combat money laundering and terrorist financing
We belong to the BNP Paribas and CACEIS Banking Groups, which must have a robust system to combat money laundering and terrorist financing (AML/CFT) at entity level, managed centrally, an anti-corruption mechanism, as well as a mechanism to comply with international sanctions (these are all economic or commercial sanctions, including all laws, regulations, restrictive measures, embargoes or asset freezes, decreed, governed, imposed or implemented by the French Republic, the European Union, the US Department of the Treasury’s Office of Foreign Asset Control, and any competent authority in the territory where we are established).
In the context of this processing, we act as Data Controllers.
For AML/CFT purposes and compliance with international sanctions, we implement the following treatments to meet our legal obligations:
- A reasonably designed KYC (Know Your Customer) to identify, update and confirm the identity of our customers, including their beneficial owners and agents where applicable;
- Enhanced identification and verification of high-risk clients, Politically Exposed Persons (PEPs) (PEPs are persons designated by regulation who, by virtue of their functions or positions (political, jurisdictional or administrative), are more exposed to these risks) and high-risk situations;
- Written policies and procedures, as well as controls reasonably designed to ensure that the business does not enter into – or maintain – a relationship with shadow banks;
- A policy, based on its assessment of the risks and economic situation, of not generally performing or engaging in any business activity or relationship, regardless of the currency:
o for, on behalf of, or for the benefit of any person, entity or organisation subject to sanctions by the French Republic, the European Union, the United States, the United Nations, or, in certain cases, other local sanctions in the territories in which the Group operates;
o involving, directly or indirectly, territories under sanctions, including Crimea/Sevastopol, Cuba, Iran, North Korea or Syria; or involving financial institutions or territories that may be linked to, or controlled by, terrorist organisations, recognised as such by the competent authorities in France, within the European Union, the United States or the United Nations.
- Filtering our customer bases and transactions, reasonably designed to ensure compliance with applicable laws;
- Systems and processes to detect suspicious transactions and to report suspicions to the relevant authorities;
- A compliance programme reasonably designed to prevent and detect corruption and influence peddling in accordance with the Sapin II Act, the U.S. FCPA, and the UK Bribery Act.
In this context, we have to appeal:
o services provided by external providers that maintain lists of Politically Exposed Persons (PEP);
o public information available in the press on facts relating to money laundering, the financing of terrorism or corruption;
o knowledge of a risky behaviour or situation (existence of a suspicion report or equivalent) that can be identified at the level of Uptevia.
We carry out these checks when entering into a relationship, but also throughout the relationship we have with you, on yourself, but also on the transactions you carry out. At the end of the relationship and if you have been the subject of an alert, this information will be kept in order to identify you and adapt our control if you re-enter into a relationship with Uptevia, or as part of a transaction to which you are a party.
To meet our legal obligations, we exchange information collected for AML/CFT, anti-corruption or international sanctions purposes between entities of the BNP Paribas SA and CACEIS Groups. When your data is exchanged with countries outside the European Economic Area that do not have an adequate level of protection, transfers are governed by the standard contractual clauses of the European Commission. When additional data is collected and exchanged in order to comply with regulations of non-EU countries, this processing is necessary to enable BNP Paribas and CACEIS Groups and their entities to comply with both their legal obligations and to avoid local sanctions, which is our legitimate interest.
For the purpose of data sharing in the context of the fight against money laundering and terrorist financing, the entities of the BNP Paribas and CACEIS Groups have organised the sharing of personal data of natural persons linked to legal persons who are customers of Uptevia. When exchanging data with another entity, we are jointly responsible for processing with that entity.