DATA PROTECTION POLICY

in terms of Regulation (EU) 2016/679

(General Data Protection Regulation)

Cordina CSP Ltd. (registration no. C 103235), (henceforth referred to as “Cordina CSP”) is authorized as a Company Service Provider by the Malta Financial Services Authority, having registered office at Citybel, Level 1, St Marta Street, Victoria VCT 2551, Malta.

This privacy policy applies to personal information held by Cordina CSP and explains how personal information is collected, used and disclosed by Cordina CSP (collectively, ‘we’, ‘our’ or ‘ us’). The Service Provider is committed to respecting the privacy of your personal information. This policy describes theinformation we process when you:

  1. Approach us for the provision of our services

  1. Receive the services upon engagement

  1. Contact us through our social media pages being linkedin.com/company/cordinacsp (the “Social Media Pages”).

We process your data in an appropriate and lawful manner, in accordance with the Data Protection Act (Chapter 586 of the Laws of Malta) (the “Act”), as may be amended or replaced from time to time, and the General Data Protection Regulation (Regulation (EU) 2016/679) (the “Regulation” or the “GDPR”).

The Social Media Pages are not intended for minors, and we do not knowingly collect data relating to minors except and unless where it is necessary in order to provide you with the Services that you may request from us (most commonly, where the requested Services concern your family, including your children). We will treat any information relating to minors which is disclosed to us in connection with the Services in a sensitive manner and with the utmost confidentiality.

It is important that you read this Notice together with any other privacy or fair processing notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This Notice supplements the other notices and is not intended to override them.

In terms of use of the Social Media Pages, please note that we are only Controller with respect to any information you may send to us via direct messages where we request further information. There are separate Controllers who are responsible for the relevant Social Media Pages and they have their own separate privacy policies – reproduced below, which we recommend you to read as well:

https://www.linkedin.com/legal/privacy-policy

We are otherwise the Controller with respect to personal data provided to us when you:

  1. approach us for the provision of our services.
  2. receive the services upon engagement.
  3. Provide information via direct messages on our Social Media Pages

and the below applies in respect to such personal data provided. If you have any questions, please do not hesitate to contact us – our details are included at Section IX below.


I.          Definitions

“Consent Form” refers to separate documents which we might from time to time provide you where we ask for your explicit consent for any processing which is not for purposes set out in this Notice.

“Data subjects” means living individuals (i.e. natural persons) about whom we collect and process personal data.

“Data controller” or “controller” means any entity or individual who determines the purposes for which, and the manner in which, any personal data is processed.

“Data processor” or “processor” means any entity or individual that processes data on our behalf and on our instructions (we being the data controller).

“Personal data” means data relating to a living individual (i.e. natural person) who can be identified from the data (information) we hold or possess. This includes, but is not limited to, your name and surname (including maiden name where applicable), address, date of birth, nationality, gender, civil status, tax status, identity card number & passport number, contact details (including mobile and home phone number and personal email address), photographic image, bank account details, emergency contact information as well as online identifiers. The term “personal information”, where and when used in this Notice, shall be taken have the same meaning as personal data. It does not include data where the identity has been removed and cannot be re-obtained (anonymous data).

“Processing” means any activity that involves use of personal data. It includes obtaining, recording or holding the data, or carrying out any operation or set of operations on the data including, organising, amending, retrieving, using, disclosing, erasing or destroying it. Processing also includes transferring personal data to third parties.

“Sensitive personal data”, “sensitive data” or “special categories of personal data” includes information about a person’s racial or ethnic origin, political opinions, religious or similar beliefs, trade union membership, physical or mental health or condition or sexual life, or about the commission of, or proceedings for, any offence committed or alleged to have been committed by that person, the disposal of such proceedings or the sentence of any court in such proceedings. This type of sensitive data can only be processed under strict conditions.

Note that personal data does not include information relating to a legal person (for example, a company or other legal entity). In that regard, information such as a company name, its company number, registered address and VAT number does not amount to personal data in terms of both the Act and the GDPR. Therefore, the collection and use of information strictly pertaining to a legal person does not give rise to data controller obligations at law. We will still naturally treat any and all such information in a confidential manner, in accordance with our standard practices and professional secrecy obligations.


II.               Information we collect

The personal information we collect depends on the services you are interested in. Such information may include current and historical information about youincluding:

  • Core personal data e.g. name, contact information, gender, date and place of birth, identification documents (photo ID, passport, national ID card);
  • Data about your education, profession or work;
  • Details of your family members and other relationships;
  • Financial information e.g. your credit rating or history and information provided for investment purposes;

Other regulatory requirements e.g. country of taxation or foreign tax payer reference;

  • Market research g. information obtained from surveys and focus groups;
  • Compliance Data (AML and KYC) includes the following due diligence information and documentation relating to our clients, or their respective UBO, shareholders, founders, beneficiaries, directors, representatives and/or administrators (as applicable) where the client is a legal person: (i) copy of identity document, (ii) copy of a recently issued utility bill, (iii) professional references, (iv) ‘KYC’ (database) checks and (iv) any other documentation which may be mandated from time to time by the Prevention of Money Laundering Act (Chapter 373 of the Laws of Malta) (“PMLA”), the Prevention of Money Laundering and Funding of Terrorism Regulations (“PMLFTR”), the Financial Intelligence Analysis Unit (“FIAU”) and/or any other competent authority or related legislation.
  •  

The collection of your personal information can occur during our customer due diligence process, at account opening stage or in response to additional information requests on a particular service in line with relevant laws and regulations. If you do not provide us with the personal information required, wemay not be able to process or assess your application to provide you with our services.

Personal information is in most instances collected directly from you. You are responsible for making sure the information you give us is accurate and up todate and inform us of any changes as soon as possible.

We may also collect information about you from publicly available sources such as, but not limited to information from credit rating agencies, the Central Credit Register maintained by the Central Bank of Malta and other databases provided by third party providers. We may use this information to keep yourdata up to date and to verify information we collect. Moreover, this information may be used to comply with our legal obligation including amongst others the prevention and detection of financial crime.


III.              The purpose of handling your personal information

Cordina CSP will only process the personal information collected from you or from external sources when we have a lawful basis to process your personal information, in line with GDPR. We will process your personal information for the following purposes and lawful reasons:

  • when we need to process your personal information to provide you with the appropriate services, process your transactions and instructions andcommunicate our policies and terms;
  • when we need to process your personal information to comply with our legal obligations to verify your identity and carry out customer due diligence and screening in line with our legal obligations including the prevention or detection of financial crime and for audit purposes;
  • when processing of your personal information is necessary for the performance of a task carried out in the public interest such as theprevention and detection of financial
  • when we have your consent to process your personal information for a specific purpose.
  • in the defence and protection of our legal rights and interests;
  • when we need to pursue our legitimate interest:
    • to manage our relationship with you to undertake risk management;
    • for customer profiling and data analytical

We use various measures to keep your information safe and secure and require our staff to protect information and apply appropriate safeguards for the useand transfer of information.

  1. Retaining your personal data

 

We will retain your personal information for as long as required for the purposes for which your data was collected and processed or required by laws and regulations. This means that we will keep your data in line with our retention policies which take into account our business, administrative, legal and otherregulatory retention requirements.

Generally our retention of your personal data shall not exceed the period of six (6) years from the termination of the professional (service) relationship with Us. This retention period enables us to make use of your personal data for AML reporting obligations to the FIAU (a legal obligation) and/or for the assertion, filing or defence of possible legal claims by or against you or your respective entity (taking into account applicable statutes of limitation). In certain cases, we may need to retain your personal data for a period of up to eleven (11) years in order to comply with applicable accounting and tax laws (this will primarily consist of your financial and transaction data). There may also be instances where the need to retain personal data for longer periods, as dictated by the nature of the services provided.Disclosing your personal information

 

We may share your personal information with others where lawful to do so in the following instances:

  • With our affiliates who may assist us in the provision of services to you;
  • To correspond with lawyers, architects, surveyors and other third parties as required;
  • With regulators, auditors, law courts, Central Bank of Malta, credit rating and fraud prevention agencies and other authorities as required for us to complywith our legal obligations and for reporting, compliance, auditing purposes;
  • Other parties in connection with litigation or asserting or defending legal rights and interests;
  • With IT service providers who are contracted by us to carry out technical, support and maintenance on the data stored on our

When sharing your personal information, we will always ensure that we respect relevant secrecy obligations.


V.    Transferring your personal information outside the European Economic Area (‘EEA’)

For the purpose of providing you with our services, to fulfil our legal obligations, to protect the public interest or for our legitimate interest we may be required to transfer your personal information to so called third countries i.e. countries outside the EEA Such transfers can be made if any of thefollowing conditions apply:

  • the EU Commission has determined that there is an adequate level of protection in the country in question; or
  • other appropriate safeguards have been taken such as the use of standard contractual clauses approved by the EU Commission or the dataprocessor has valid binding corporate rules in place, or
  • in exceptional circumstances such as to fulfil a contract with you or subject to your consent to a specific matter


VI.   Your privacy rights

You as a data subject have rights in respect of personal data we hold on you. These rights include:

  • accessing the personal information Cordina CSP holds about you and the information related to its processing;
  • requesting the rectification of data if it is incomplete or inaccurate;
  • requesting the erasure of data unless we are required to retain such data;
  • requesting the withdrawal of your consent for a specific processing activity;
  • receiving in a structured, widely-used format, the personal information related to you which you have provided to Cordina CSP and transfer them toanother controller where technically possible (data portability);
  • Objecting or restricting the processing of personal;

All of the above requests may be forwarded, if applicable to third party processors involved in the processing of your personal data as previously listed.You can exercise the above rights through a written communication as per details provided in Section IX ‘Contacting us or the Data ProtectionCommissioner.  You may also file a claim with the Information and Data Protection Commissioner’s Office (https://idpc.org.mt) or to the respective data protection regulator in your country particularly when you consider that the exercise of your rights has not been achieved satisfactorily. We would, however, appreciate the opportunity to deal with your concerns before you approach the supervisory authority.


VII.    Marketing

We strive to provide you with choices regarding certain personal data uses, particularly around advertising and marketing. Through some of the Personal Data collected, we are able to form a view on what we think you or your respective entity may want or need in terms of shipping and corporate administrative services. This is how we decide which of our Services may be of most relevance or interest for you and/or your respective entity.

You may receive marketing communications from us (which may consist of newsletters, industry and legislative updates, mailshots, publications and/or information about our events, seminars and webinars) where:

·       you have entered into a relationship with us (be it as a client, the owner or representative of the corporate client or as a business partner), regardless of whether a formal service agreement has been signed or otherwise; and
·       provided you have not opted out of receiving marketing from us (see Your right to object below).

Where the above does not apply to you, we will only send you our marketing communications where you have expressly consented to receive them from us.

Third-party marketing
 
We will get your express opt-in consent before we share your personal data with any third parties (including our associated corporate entities) for marketing purposes.
 
Opting out
 
You can ask us to stop sending you marketing communications (unsubscribe) at any time by following the opt-out (unsubscribe) links on any marketing communication sent to you


VIII.  Changes to the Data Protection Policy

This Data Protection Policy may be updated from time to time. This version was last updated on the 19th of December, 2022.


IX.  Contacting us or the Data Protection Authority

If you have any questions or concerns regarding our privacy policy you can contact our Data Protection Officer by sending an email to [email protected] or a letter to the Data Protection Officer, Citybel, Level 1, St Marta Street, Victoria (Gozo) VCT 2551, Malta.

You can also lodge a complaint or contact the competent supervisory authority on data protection matters, such as in particular the supervisory authority in the place of your habitual residence or your place of work. In the case of Malta, this is the Office of the Information and Data Protection Commissioner (the “IDPC”) (https://idpc.org.mt/en/Pages/Home.aspx). We would, however, appreciate the opportunity to deal with your concerns before you approach the supervisory authority, so please contact us in the first instance.