SICO BSC (c) and/ or its subsidiaries ("we", "us", and "ours" or “SICO”) is committed to maintaining the confidentiality, integrity and security of information collected from customers, in accordance to applicable privacy laws. For the purposes of applicable privacy law in Bahrain, we are the “Data Manager” in respect of any personal information which we obtain from you.
This Privacy policy defines who we are, how we collect, share and process your personal information through all means including our corporate offices, subsidiaries, affiliates and website. This notice also covers any additional personal information that SICO may collect from you and process during other interactions either directly with SICO or through its data processors.
In addition, this notice provides information on how you can exercise your privacy rights under applicable privacy law.
This notice should be read in conjunction with other privacy policys and product/ service terms and conditions we may provide on specific occasions when we are collecting or processing your Personal Data.
If you have any questions or concerns about our use of your personal information, then please contact us using the contact details provided at the end of this privacy policy.
Data or Personal Data
Any information of any form related to an identifiable individual/legal entity, or an individual/legal entity who can be identified, directly or indirectly, particularly through his/her personal ID number, or one or more of his/her physical, physiological, intellectual, cultural or economic characteristics or social identity.
To determine whether an individual/legal entity can be identified, all the means used by, or that may be available to, the Data Manager or any other person, shall be taken in consideration.
Personal data that we collect may include name, ID and passport numbers, date of birth, email and address. Personal data and supporting documentation required is available in our application forms.
Personal data that we collect may also include legal entity information such as name, business address, details of incorporation, proof of existence, FATCA & CRS status, structure of legal entity and information regarding key persons and/or stakeholders.
Sensitive Personal Data
Any personal information that reveals, directly or indirectly, the individual/legal entity's race, ethnicity, political or philosophical views, religious beliefs, union affiliation, criminal record or any data related to his/her health or sexual life.
Sensitive personal data we collect may include CCTV footage at our premises, audio and video call recordings and chats.
Data Manager
The person who decides, solely or in association with others, the purposes and means of processing of certain personal data. In the events where such purposes and means are prescribed by Law, the Data Manager shall be the person who is responsible for the processing.
Data Processor
The person who processes the data for and on behalf of the Data Manager, not including whoever works for the Data Manager or Data Processor.
Processing
Any operation or set of operations carried out on personal data by automated or non-automated means, such as collecting, recording, organising, classifying in groups, storing, modifying, amending, retrieving, using or revealing such data by broadcasting, publishing, transmitting, making them available to others, integrating, blocking, deleting or destroying them.
Direct Marketing
Any communication, by any means, through which a marketing or advertising material is directed to a specific person.
SICO is a leading regional asset manager, broker, market maker and investment bank. SICO operates under a wholesale banking license from the Central Bank of Bahrain and also oversees three wholly owned subsidiaries: an Abu Dhabi-based brokerage firm, SICO Invest and a specialised regional custody house, SICO Fund Services Company (SFS), and a Saudi-based asset management provider, SICO Financial Saudi Company.
Headquartered in the Kingdom of Bahrain with a growing regional and international presence, SICO as a trusted regional bank, offering a comprehensive suite of financial solutions including asset management, brokerage, investment banking, and market making backed by a robust and experienced research team that provides regional insight and analysis of more than 90 percent of the GCC’s major equities.
For more information about SICO, please visit our website https://www.sicobank.com/
As a part of our legitimate business use, we collect and process the following categories of personal information about our past, existing and prospective customers for the purpose of providing our services:
|
Data class |
Data elements |
|
Identifiers |
Name, email id, CPR/ID/CR no., passport no. |
|
Contact information |
Address, phone, fax and mobile numbers |
|
Financial information |
Account/IBAN number, Bank statement, Salary Certificate/Slip, Wealth, Source of Income, Shareholder details |
|
KYC Documentation |
Board member details, Signatory authority details, CPR/ CR copy, passport copy, Domicile, MOA/AOA |
|
Usage information |
Frequency and type of access, Service/s subscription |
|
Cookies, log files and web beacons |
IP address, location, device type, device id, browser type |
|
Physical and biometric information (identifiers) |
Photograph |
|
CCTV (in SICO’s Premises) |
Video recording |
|
Live calls and chat records |
Call recording, Video recording, chat logs |
|
Other Sensitive information |
PEP |
We collect personal information (under few of data classes mentioned above) of authorized signatories, point of contact and/ or nominee for our customers.
Personal data collected and processed by us is restricted to the minimum information required by us to provide our services or as required by the regulators. The consequence of not providing mandatory information could result in our inability to provide the service requested by you.
We collect personal data that you provide voluntarily through our website, for example, when completing online forms to contact us, subscribing to a newsletter, using one of our online benchmark tools, subscribing to receive marketing communications from us, participating in surveys or registering for events that we are organising. The information we collect about you may include:
When you visit our website or login into online banking portal, we may collect certain information automatically from your device.
Specifically, the information we collect automatically may include information like:
We may also collect information about how your device has interacted with our website, including the pages accessed and links clicked.
Collecting this information enables us to better understand the visitors who come to our website, where they come from, and what content on our website is of interest to them. We use this information for our internal analytics purposes and to improve the quality and relevance of our website to our visitors.
Some of this information may be collected using cookies and similar tracking technology, as explained further in our Cookies Notice, which is available on our website under “Privacy policy” section.
From time to time, we may receive personal information about you from third party sources (including credit reference agencies, World Checking services, other banks who provide references on you), but only where we have checked that these third parties either have your consent or are otherwise legally permitted or required to disclose your personal information to us.
The types of information we collect from third parties may include:
The purpose of collecting your personal data:
We rely upon the following legitimate bases to process your personal data:
Our legal basis for collecting and processing the personal information described above will depend on the personal information concerned and the specific context in which we collect it. Given the fact that the only personal information collected about you on our website is that which you send to us or which is collected automatically via cookies, and given that you are able to disable cookies if you wish and are deemed to consent to their use if you proceed on our website without disabling them, we regard any information collected as obtained with your consent.
Our Cookie Notice is also on this website and describes what cookies we use and why. When you first go our website https://www.sicobank.com/ there will be a pop-up banner directing you to the Cookie Notice. If you continue to use the website you will be deemed to accept our use of cookies.
We will provide you with choices regarding certain Personal Data uses, particularly around marketing and advertising.
We may use your Identity, contact details, Service usage patterns and Profile data to identify potential services which may be of interest to you.
We will provide you an option to opt-in to our marketing activities (including newsletters, promotions, new service update, etc.) at the time of registering for the services. Existing customers who are already registered in our systems, will continue to receive our marketing communications unless they opt-out.
We will request your express consent before we share your Personal Data with any company outside SICO for marketing purposes.
You can ask us to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you or by contacting us at any time.
You may still receive messages for a short period of time until updated marketing preferences are set.
In general, we will use the personal information we collect from you only for the purposes described in this Privacy policy or for purposes that we explain to you at the time we collect your personal information. However, we may also use your personal information for other purposes that are not incompatible with the purposes we have disclosed to you (such as archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes) if and where this is permitted by applicable data protection laws.
If you have questions about or need further information concerning the specific legal basis on which we collect and use your personal information, please contact us using the contact details provided under “How to contact us” section.
If we need to use your Personal Data for an unrelated purpose, we will notify you to explain the legal basis which allows us to do so or, where required by law, to seek your consent.
We will only disclose your personal data to our group companies and third-parties outside of SICO:
We may disclose your personal information to the following categories of recipients:
A list of our current group companies, current service providers and partners is available in Appendix at the end of this notice;
Your personal information may be transferred to and processed outside Bahrain. These countries may have data protection laws that are different to the laws of your country (and, in some cases, may not be as protective). SICO will only disclose your personal information to group companies and third parties that have agreed in writing to provide privacy protection in line with this privacy policy.
We may need to transfer this data outside Bahrain for providing uninterrupted services to you (e.g., core banking through our group companies and affiliates overseas). We minimise the personal information that is transferred outside Bahrain.
Our group companies and third-party service providers and partners operate in the countries listed in Appendix at the end of this notice. This means that when we collect your personal information, we may process it in any of these countries.
As the Data Manager we have a responsibility to apply technical and organizational measures capable of protecting the data against unintentional or unauthorized destruction, accidental loss, unauthorized alteration, disclosure or access, or any other form of processing.
We have instituted adequate measures for providing an appropriate level of security aligned to the nature of the data being processed, and the risks that may arise from this processing. Our various security measures include encryption, firewalls and access controls. Data is shared within SICO (including employees, vendors, agents, etc.) on a need-to-know basis and under strict confidentiality arrangements.
Notwithstanding this, despite our best efforts, we cannot absolutely guarantee the security of data against all threats. We have implemented suitable measures to identify, monitor and report any breaches to personal data in line with the requirements of the law.
We retain personal information we collect from you where we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, regulatory, tax or accounting requirements).
Retention periods are set in accordance with local regulatory and professional retention requirements to meet our professional and legal requirements, to establish, exercise or defend our legal rights, and for archival purposes.
Incomplete onboarding information such as partially submitted forms or documents that were not finalized by the customer will be retained for a maximum of 90 days. After 90 days, all incomplete records will be securely deleted. Individuals may also request earlier removal of their incomplete data at any time.
When we have no ongoing legitimate business need to process your personal information, we will either dispose, delete or anonymise it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely encrypt and store your personal information and isolate it from any further processing until deletion is possible. The only exception to “Not processing” backup archives may be where it becomes necessary to retrieve that archived information.
Under the provisions of the law, you are provided with the following rights in relation to the processing of your personal data. To exercise your rights under the law, you may be required to authenticate yourself with adequate proof of identity.
To opt-out from receiving direct marketing communications, please contact us through any of the channels mentioned in “How to contact us” section.
You can also have the right to object a decision, which involves you and is taken based only on automated processing of your personal data.
Withdrawal of consent to process certain mandatory personal data related to services provided by SICO, may result in our inability to continue the provision of those services or discontinuation of existing services that was contracted earlier, where such information needs to be shared and having direct implication on the consent withdrawal.
We are required by law to confirm your identity and ensure your right to access your Personal Data (or to exercise any of your other rights) prior to processing any requests from you, to ensure that personal data is not disclosed to any person who has no right to receive it.
We may also contact you to ask you for further information in relation to your request to speed up our response.
It is important that the Personal Data we hold about you is accurate and up-to-date. It is your obligation to keep us informed if your Personal Data changes during your relationship with us. Please contact Customers Relations unit to update your personal data whenever required.
We may update this Privacy policy from time to time in response to changing legal, technical or business developments. When we update our Privacy policy, we will take appropriate measures to inform you, consistent with the significance of the changes we make. We will obtain your consent to any material Privacy policy changes if and where this is required by applicable data protection laws.
You can see when this Privacy policy was last updated by checking the “last updated” date displayed at the footer of this Privacy policy.
If you have any questions or concerns about our use of your personal information or you want to use your data protection rights, please contact us through any of the following channels.
List of the categories of vendors and third parties who may be passed personal data by SICO.
Disclosure outside Bahrain:
|
Vendor/Third Party |
Location |
|
SICO subsidiaries |
UAE or other location, where a new subsidiary will be formed in future |
|
Equity Brokers (Asset Management) |
MENA |
|
Regulators |
Multiple countries |
|
Legal advisors |
Multiple countries |
|
Auditors |
Multiple countries |
|
External counterparties (Stock exchange or brokerage firms) |
Saudi Arabia, Qatar, Muscat and Kuwait |
|
SICO Subsidiary and DFM |
UAE |
|
Correspondent banks |
GCC, Europe & USA |
|
Clearing services provider |
UK |
|
Cloud IT infrastructure provider |
AWS |
|
Customer screening / Identity validation & verification provider |
US and Europe |
Disclosure / Sourcing within Bahrain:
|
Vendor/Third Party |
Central bank - CBB |
Trustee, custodians, share registrars |
Listing agents |
Receiving banks and investors |
Bahrain clear |
Bahrain bourse |
Advisors – Custodian, Due diligence, Allotment, Tax, Legal |
Auditors |
Log data with security operations center |
iGV |
Beyon Connect |