in terms of Regulation (EU) 2016/679
(General Data Protection Regulation)
Cordina CSP Ltd. (registration no. C 103235), (henceforth referred to as “Cordina CSP”) is authorized as a Company Service Provider by the Malta Financial Services Authority, having registered office at Citybel, Level 1, St Marta Street, Victoria VCT 2551, Malta.
This privacy policy applies to personal information held by Cordina CSP and explains how personal information is collected, used and disclosed by Cordina CSP (collectively, ‘we’, ‘our’ or ‘ us’). The Service Provider is committed to respecting the privacy of your personal information. This policy describes theinformation we process when you:
We process your data in an appropriate and lawful manner, in accordance with the Data Protection Act (Chapter 586 of the Laws of Malta) (the “Act”), as may be amended or replaced from time to time, and the General Data Protection Regulation (Regulation (EU) 2016/679) (the “Regulation” or the “GDPR”).
The Social Media Pages are not intended for minors, and we do not knowingly collect data relating to minors except and unless where it is necessary in order to provide you with the Services that you may request from us (most commonly, where the requested Services concern your family, including your children). We will treat any information relating to minors which is disclosed to us in connection with the Services in a sensitive manner and with the utmost confidentiality.
It is important that you read this Notice together with any other privacy or fair processing notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This Notice supplements the other notices and is not intended to override them.
In terms of use of the Social Media Pages, please note that we are only Controller with respect to any information you may send to us via direct messages where we request further information. There are separate Controllers who are responsible for the relevant Social Media Pages and they have their own separate privacy policies – reproduced below, which we recommend you to read as well:
https://www.linkedin.com/legal/privacy-policy
We are otherwise the Controller with respect to personal data provided to us when you:
and the below applies in respect to such personal data provided. If you have any questions, please do not hesitate to contact us – our details are included at Section IX below.
“Consent Form” refers to separate documents which we might from time to time provide you where we ask for your explicit consent for any processing which is not for purposes set out in this Notice.
“Data subjects” means living individuals (i.e. natural persons) about whom we collect and process personal data.
“Data controller” or “controller” means any entity or individual who determines the purposes for which, and the manner in which, any personal data is processed.
“Data processor” or “processor” means any entity or individual that processes data on our behalf and on our instructions (we being the data controller).
“Personal data” means data relating to a living individual (i.e. natural person) who can be identified from the data (information) we hold or possess. This includes, but is not limited to, your name and surname (including maiden name where applicable), address, date of birth, nationality, gender, civil status, tax status, identity card number & passport number, contact details (including mobile and home phone number and personal email address), photographic image, bank account details, emergency contact information as well as online identifiers. The term “personal information”, where and when used in this Notice, shall be taken have the same meaning as personal data. It does not include data where the identity has been removed and cannot be re-obtained (anonymous data).
“Processing” means any activity that involves use of personal data. It includes obtaining, recording or holding the data, or carrying out any operation or set of operations on the data including, organising, amending, retrieving, using, disclosing, erasing or destroying it. Processing also includes transferring personal data to third parties.
“Sensitive personal data”, “sensitive data” or “special categories of personal data” includes information about a person’s racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership, physical or mental health or condition or sexual life, or about the commission of, or proceedings for, any offence committed or alleged to have been committed by that person, the disposal of such proceedings or the sentence of any court in such proceedings. This type of sensitive data can only be processed under strict conditions.
Note that personal data does not include information relating to a legal person (for example, a company or other legal entity). In that regard, information such as a company name, its company number, registered address and VAT number does not amount to personal data in terms of both the Act and the GDPR. Therefore, the collection and use of information strictly pertaining to a legal person does not give rise to data controller obligations at law. We will still naturally treat any and all such information in a confidential manner, in accordance with our standard practices and professional secrecy obligations.
The personal information we collect depends on the services you are interested in. Such information may include current and historical information about youincluding:
Other regulatory requirements e.g. country of taxation or foreign tax payer reference;
The collection of your personal information can occur during our customer due diligence process, at account opening stage or in response to additional information requests on a particular service in line with relevant laws and regulations. If you do not provide us with the personal information required, wemay not be able to process or assess your application to provide you with our services.
Personal information is in most instances collected directly from you. You are responsible for making sure the information you give us is accurate and up todate and inform us of any changes as soon as possible.
We may also collect information about you from publicly available sources such as, but not limited to information from credit rating agencies, the Central Credit Register maintained by the Central Bank of Malta and other databases provided by third party providers. We may use this information to keep yourdata up to date and to verify information we collect. Moreover, this information may be used to comply with our legal obligation including amongst others the prevention and detection of financial crime.
Cordina CSP will only process the personal information collected from you or from external sources when we have a lawful basis to process your personal information, in line with GDPR. We will process your personal information for the following purposes and lawful reasons:
We use various measures to keep your information safe and secure and require our staff to protect information and apply appropriate safeguards for the useand transfer of information.
We will retain your personal information for as long as required for the purposes for which your data was collected and processed or required by laws and regulations. This means that we will keep your data in line with our retention policies which take into account our business, administrative, legal and otherregulatory retention requirements.
Generally our retention of your personal data shall not exceed the period of six (6) years from the termination of the professional (service) relationship with Us. This retention period enables us to make use of your personal data for AML reporting obligations to the FIAU (a legal obligation) and/or for the assertion, filing or defence of possible legal claims by or against you or your respective entity (taking into account applicable statutes of limitation). In certain cases, we may need to retain your personal data for a period of up to eleven (11) years in order to comply with applicable accounting and tax laws (this will primarily consist of your financial and transaction data). There may also be instances where the need to retain personal data for longer periods, as dictated by the nature of the services provided.Disclosing your personal information
We may share your personal information with others where lawful to do so in the following instances:
When sharing your personal information, we will always ensure that we respect relevant secrecy obligations.
For the purpose of providing you with our services, to fulfil our legal obligations, to protect the public interest or for our legitimate interest we may be required to transfer your personal information to so called third countries i.e. countries outside the EEA Such transfers can be made if any of thefollowing conditions apply:
You as a data subject have rights in respect of personal data we hold on you. These rights include:
All of the above requests may be forwarded, if applicable to third party processors involved in the processing of your personal data as previously listed.You can exercise the above rights through a written communication as per details provided in Section IX ‘Contacting us or the Data ProtectionCommissioner. You may also file a claim with the Information and Data Protection Commissioner’s Office (https://idpc.org.mt) or to the respective data protection regulator in your country particularly when you consider that the exercise of your rights has not been achieved satisfactorily. We would, however, appreciate the opportunity to deal with your concerns before you approach the supervisory authority.
This Data Protection Policy may be updated from time to time. This version was last updated on the 19th of December, 2022.
If you have any questions or concerns regarding our privacy policy you can contact our Data Protection Officer by sending an email to [email protected] or a letter to the Data Protection Officer, Citybel, Level 1, St Marta Street, Victoria (Gozo) VCT 2551, Malta.
You can also lodge a complaint or contact the competent supervisory authority on data protection matters, such as in particular the supervisory authority in the place of your habitual residence or your place of work. In the case of Malta, this is the Office of the Information and Data Protection Commissioner (the “IDPC”) (https://idpc.org.mt/en/Pages/Home.aspx). We would, however, appreciate the opportunity to deal with your concerns before you approach the supervisory authority, so please contact us in the first instance.