{"id":3814,"date":"2025-03-13T16:10:43","date_gmt":"2025-03-13T16:10:43","guid":{"rendered":"https:\/\/www.selfpay.ro\/legal\/selfpay-now\/legal-selfpay-now-politica-de-confidentialitate-open-banking\/"},"modified":"2025-08-07T17:07:42","modified_gmt":"2025-08-07T17:07:42","slug":"privacy-policy-open-banking","status":"publish","type":"page","link":"https:\/\/www.selfpay.ro\/en\/legal\/selfpay-now\/privacy-policy-open-banking\/","title":{"rendered":"Legal &#8211; SelfPay Now &#8211; Privacy Policy Open Banking"},"content":{"rendered":"<p><strong>PERSONAL DATA PRIVACY NOTICE<\/strong><\/p>\n<p><strong>I. INTRODUCTION<\/strong><\/p>\n<p><strong>\u00a0<\/strong><strong>IRIS Solutions OOD<\/strong>, UIC 204997709 (hereinafter referred to as &#8220;<strong>Iris<\/strong>&#8220;, &#8220;<strong>the Company<\/strong>&#8221; or &#8220;<strong>we<\/strong>&#8220;) is a legal entity, registered in the Bulgarian Commercial Register, with UIC\u00a0 204997709, with registered office and management address in the city of Sofia, 111B Tsarigradsko Shose Blvd., Sofia Tech Park, Incubator Building, 1st floor, licensed to provide account information services in accordance with Article 4, item 7 and item 8 of the Bulgarian PSPSA, registered in the Register of Licensed Payment Institutions in the Republic of Bulgaria, administered by the Bulgarian National B; The Company is personal data controller within the meaning of the Personal Data Protection Act (PDPA) and collects, processes and stores your personal data under the terms of this Privacy Notice.<\/p>\n<p>You can contact us at the following contact data:<\/p>\n<p>Address: Sofia, 111B Tsarigradsko shose Blvd., Sofia Tech Park, Incubator Building<\/p>\n<p>e-mail: bdo@irisbgsf.com<\/p>\n<p>This Personal Data Privacy Notice (hereinafter referred to as the <strong>&#8220;Privacy Notice&#8221;<\/strong>) has been prepared and is based on the current Bulgarian and European legislation regarding personal data protection.<\/p>\n<p>This Privacy Notice regulates the processing by Iris of personal data of Account Holders, who have entered into an agreement with SELFPAY SA in terms of processing of their Account Information and have given a valid Service authorization for initiating a request for facilitating and transfer of Account information from the primary Account Information controller to SELFPAY SA.<\/p>\n<p><strong>II. GENERAL PROVISIONS AND DEFINITIONS<\/strong><\/p>\n<p>The terms below have the following meaning for the purposes of this Privacy Notice:<\/p>\n<p>\u201c<strong>Account Information<\/strong>\u201d means Account related unaggregated data, such as Account Holder`s name, Account number, balances, transaction history, etc., except for \u201csensitive payment data\u201d as per art. 4, para. 12 of PSD2, generated and administered by an \u201caccount servicing payment service provider\u201d as per art. 4, para. 17 of PSD2 as a primary data controller;<\/p>\n<p><strong>&#8220;Service<\/strong>&#8221; means facilitating of the transfer of Account Information from the primary Account Information controller to SELFPAY SA;<\/p>\n<p>SELFPAY SA, with registered headquarters in Romania, Bucharest, 2<sup>nd<\/sup> District, no. 153-155 Dacia Blv, 7<sup>th<\/sup> floor, postal code 020057, incorporated under no. J2009009919407 with Trade Register, UIC 26067497, Fiscal attribute RO, registered, hereby represented by Adrian Daniel Badea hereby recipient of the Service for further administration and use of the Account Information as per its arrangements with the Account Holder.<\/p>\n<p><strong>&#8220;GDPR&#8221; <\/strong>means Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\/46\/EC (General Data Protection Regulation).<\/p>\n<p><strong>&#8220;Personal Data&#8221; <\/strong>means the information under section III, p. 1 to 3 herein below, as defined in Article 4, para. 1 of the GDPR (Regulation (EU) 2016\/679).<\/p>\n<p><strong>III. COLLECTION OF PERSONAL DATA<\/strong><\/p>\n<p>We collect the following Personal Data about you with regard to the Service:<\/p>\n<ol>\n<li>Name, surname, family name;<\/li>\n<li>Payment account numbers (IBAN, BIC, );<\/li>\n<li>Account balance and payment operations description (history);<\/li>\n<li>E-mail.<\/li>\n<\/ol>\n<p><strong><u>By giving a valid Service authorization hereunder, you express your informed and explicit consent to provide your Personal Data in order to be collected and processed by us. Comprehensive information about the use of Personal Data by us can be found in this Privacy Notice. <\/u><\/strong><\/p>\n<p><strong>IV. PURPOSE OF PROCESSING<\/strong><\/p>\n<p>We use your Personal Data for the following purposes:<\/p>\n<ul>\n<li>provide the Service;<\/li>\n<li>any inquiries or questions you have about our Service;<\/li>\n<li>compliance with other applicable regulatory requirements;<\/li>\n<li>inform you about changes in our General terms.<\/li>\n<\/ul>\n<p>In the event that Iris plans to use your Personal Data for other purposes, we will notify you in advance and ask for your explicit consent.<\/p>\n<p><strong>V. GROUNDS FOR PROCESSING PERSONAL DATA:<\/strong><\/p>\n<ul>\n<li>Providing the Service, we will transfer your Account Information to \u201cSELFPAY SA\u201d (\u201c<strong>data subject to the Service<\/strong>\u201d), whereas we shall ensure that such processing will always be in compliance with this Privacy Notice and any applicable laws.<\/li>\n<\/ul>\n<p>We store your Account information only within the individual Account Holder\u2019s session which is necessary to accomplish the particular Service and we do not have further access to this data. We shall provide your Account Information to SELFPAY SA \u00a0when you initiate the Service through SELFPAY SA\u2019s client Application or through the website of SELFPAY SA.<\/p>\n<ul>\n<li>We may process the information contained in any inquiries and complaints you send to us about our services (<strong>&#8220;data for inquiries\u201d). <\/strong><\/li>\n<li>We may process all personal data specified in this Notice when necessary to establish, exercise or defend \/ against lawsuits \/ claims, whether in court proceedings or in administrative or out-of-court proceedings. The legal basis for this processing is our legitimate interests, namely the protection and enforcement of our legal rights, your legal rights and the legal rights of third parties.<\/li>\n<li>In addition to the specific purposes for which we may process your personal data set out in this Privacy Notice, we may also process your personal data when such processing is necessary to comply with a legal obligation.<\/li>\n<\/ul>\n<p><strong>VI. SECURITY<\/strong><\/p>\n<p>Iris uses reasonable electronic, human and technical measures to protect Personal Data from loss, theft, alteration or misuse. However, keep in mind that even the best security measures cannot completely eliminate all risks.<\/p>\n<p><strong>VII. YOUR RIGHTS<\/strong><\/p>\n<ul>\n<li><strong>The right to be informed<\/strong><\/li>\n<\/ul>\n<p>Iris will provide you with information about the processing when we collect personal data from you, as well as through privacy notices such as this.<\/p>\n<ul>\n<li><strong>Right of access<\/strong><\/li>\n<\/ul>\n<p>You have the right to access your personal data and details of how we process them. You can request details about the personal data that the Company holds about you by contacting us at e- mail: <a href=\"mailto:bdo@irisbgsf.com\">bdo@irisbgsf.com.<\/a><\/p>\n<ul>\n<li><strong>Right to rectification<\/strong><\/li>\n<\/ul>\n<p>You have the right to rectify or request rectification of your personal data if it is inaccurate or incomplete.<\/p>\n<p>Iris makes its best effort to keep the personal data processed accurate and up-to-date. However, we rely on our customers to make sure that some of the information which is related to them, is accurate and up to date. We encourage customers to notify Iris in case of any changes to their information (for example, by updating your account information).<\/p>\n<ul>\n<li><strong>Right to object<\/strong><\/li>\n<\/ul>\n<p>You have the right to object to certain uses of personal data, such as direct marketing.<\/p>\n<ul>\n<li><strong>Right to be forgotten<\/strong><\/li>\n<\/ul>\n<p>You have the right to request that we delete or remove personal data from our records when there is no good reason to continue processing them. Where personal data are still needed for lawful purposes, it will not be possible to delete this data, so some requests may be rejected.<\/p>\n<ul>\n<li><strong>Right to restriction of processing<\/strong><\/li>\n<\/ul>\n<p>You have the right to &#8220;block&#8221; the processing of personal data in limited circumstances. This right may be exercised:<\/p>\n<ol>\n<li>If the accuracy of your personal data is disputed and needs to be verified;<\/li>\n<li>If the processing is illegal, but you do not want the personal data to be deleted; or<\/li>\n<li>If personal data is no longer required by Iris, but you want the data to be retained for legal<\/li>\n<\/ol>\n<ul>\n<li><strong>Right to data portability<\/strong><\/li>\n<\/ul>\n<p>This right applies only to personal data that is provided to us in a structured, widely used and machine-readable format and which we process on the basis of your consent or to enter into a contract with you.<\/p>\n<p>The right to data portability allows individuals to reuse their personal data in different services; allowing them to move or copy data from one organization to another if they choose.<\/p>\n<ul>\n<li><strong>Right to withdraw your consent<\/strong><\/li>\n<\/ul>\n<p>When we process personal data on the basis of your consent, the consent should be freely expressed, specific, informed and unambiguous, given through a statement or clearly confirmatory action. \u00a0You have the right to withdraw your consent to the processing of your personal data at any time with a separate request addressed to Iris in the case of processing based on a given consent.<\/p>\n<ul>\n<li><strong>Complaint to the supervisory authority<\/strong><\/li>\n<\/ul>\n<p>You have the right to lodge a complaint directly with the supervisory authority, the competent authority being the Commission for Personal Data Protection:<\/p>\n<p>Commission for Personal Data Protection, Sofia, 1592, 2 Prof. Tsvetan Lazarov Blvd., tel: + 3592 \/ 91-53-518, E-Mail: <a href=\"mailto:kzld@cpdp.bg\">kzld@cpdp.bg<\/a><\/p>\n<p>In the event that you wish to exercise any of these rights, please contact us through the contacts provided in Section II of this Privacy Notice.<\/p>\n<p><strong>VIII. MISCELLANEOUS<\/strong><\/p>\n<p>Iris may update this Notice periodically by publishing a new version and all changes and additions to the Privacy Notice will be applied only after the publication of its current content.<\/p>\n<p>Notwithstanding the above, we reserve the right to notify you at the email address you provide of changes to these policies. That is why you must always keep your contact details up to date.<\/p>\n<p>If you have any questions or comments about this Privacy Notice, please contact us at <a href=\"mailto:bdo@irisbgsf.com\">bdo@irisbgsf.com.<\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>PERSONAL DATA PRIVACY NOTICE I. INTRODUCTION \u00a0IRIS Solutions OOD, UIC 204997709 (hereinafter referred to as &#8220;Iris&#8220;, &#8220;the Company&#8221; or &#8220;we&#8220;) is a legal entity, registered in the Bulgarian Commercial Register, [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":0,"parent":1227,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"templates\/legal-template.php","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-3814","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.selfpay.ro\/en\/wp-json\/wp\/v2\/pages\/3814","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.selfpay.ro\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.selfpay.ro\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.selfpay.ro\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.selfpay.ro\/en\/wp-json\/wp\/v2\/comments?post=3814"}],"version-history":[{"count":4,"href":"https:\/\/www.selfpay.ro\/en\/wp-json\/wp\/v2\/pages\/3814\/revisions"}],"predecessor-version":[{"id":4326,"href":"https:\/\/www.selfpay.ro\/en\/wp-json\/wp\/v2\/pages\/3814\/revisions\/4326"}],"up":[{"embeddable":true,"href":"https:\/\/www.selfpay.ro\/en\/wp-json\/wp\/v2\/pages\/1227"}],"wp:attachment":[{"href":"https:\/\/www.selfpay.ro\/en\/wp-json\/wp\/v2\/media?parent=3814"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}