Privacy Policy
What information can you find here?
We, Bethmann Bank, a brand of ABN AMRO Bank N.V. Frankfurt Branch (hereinafter referred to as "Bethmann HAL" or "we"), inform you about how we collect personal data in the publicly accessible areas of the Bethmann HAL websites (in particular www.bethmann-hal.de, https://tenor.bethmannbank.de and www.abnamro.de (hereinafter referred to as the "Website" or "Websites")) and what data protection claims and rights you are entitled to in this regard. Which of your personal data we process in detail depends not least on which functions of the website you use. If the processing of personal data differs from the information set out in this data protection notice for some functions (for example, in protected areas of the website after your log-in), we will inform you separately.
The Online Banking Privacy Policy can be found here (German).
The push TAN privacy policy can be found here (German).
Table of Contents
What information can you find here?
- Who is responsible for your data?
- To whom does this privacy policy apply?
- What is personal data and which of your personal data do we use?
- What categories of personal data do we process?
- Where do we get personal data from?
- Special categories of personal data ("sensitive data")
- Data of minors
- What (purpose of processing) do we process your data for?
- Purely informational use of our website
- Use of advanced features of our website
- Use of digital means of communication
- Use of your data for direct marketing
- Online events
- Other purposes (in particular security and abuse prevention)
- Cookies
- Use of Google Maps on our website
- What is our legal basis for using your personal data?
- Who gets your data?
- Is personal data transferred to a third country or to an international organisation?
- To what extent is my personal data used for profiling (scoring)?
- To what extent is there automated decision-making in individual cases?
- How long will we keep your personal data?
- Use of artificial intelligence (AI)
- Protection of your data
- Transparency
- What data protection rights do you have?
- Information about your right to object according to Art. 21 GDPR
- Do you have a complaint or is something still unclear?
- Why are there changes to the privacy policy?
Who is responsible for your data?
The controller of your personal data and provider of this website is the
ABN AMRO Bank N.V. Frankfurt Branch
Mainzer Landstraße 1
60329 Frankfurt am Main
Further information about the bank can also be found in our imprint.
For any data protection enquiries, you can also contact us at:
ABN AMRO Bank N.V. Frankfurt Branch
Privacy Officer
Mainzer Landstraße 1
60329 Frankfurt am Main
Phone: +49 69 2177-0
E-mail: datenschutz@de.abnamro.com
In our group of companies, there is a Group Data Protection Officer, whom you can reach at the following contact details:
ABN AMRO Bank N.V.
Chief Privacy Officer
Gustav Mahlerlaan 10
1082 PP Amsterdam, Netherlands
E-Mail: privacy.office@nl.abnamro.com
To whom does this Privacy Notice apply?
This data protection notice applies to visitors to the publicly accessible areas of our websites. In addition, depending on the function used, they may also be relevant for persons who are not themselves customers of Bethmann HAL but are related to an interaction or transaction with our bank (e.g. payment recipients, authorised representatives, legal representatives, beneficial owners or citizens). Supplementaryor deviating data protection information may apply to individual products / services (e.g. online banking, push TAN, digital events); we will inform you separately about this or provide corresponding information / links.
What is personal data and which of your personal data do we use?
This data protection notice deals with the processing of personal data (Art. 4 No. 2 of the European General Data Protection Regulation (hereinafter referred to as "GDPR")) on our websites. Personal data is information that either relates directly to you as a natural person or can be associated with you, i.e. can be related to you. Personal data includes, for example, your personal details (first name, surname, address, birthday, etc.), all types of contact details (e.g. telephone, e-mail address), gender, marital status, other information that you would find in an application and CV (e.g. about your education, professional experience) and any other information that we can assign to you as a natural person (e.g. data about your use of the telemedia we offer, e.g. time of access to our website, apps or newsletters, pages clicked on by us or entries).
What categories of personal data do we process?
Depending on the use of our website, we process in particular:
- Usage / device data (e.g. IP address, time of access, pages accessed, browser / deviceinformation),
- Communication data (e.g. email address, content of your request),
- Contract/transaction reference (if you are a customer or concerns a transaction/interaction: e.g. assignment / reference data),
- Event/participation data (e.g. name, e-mail, technical metadata for online formats),
- Cookies/consent data (e.g. consent status, cookie categories).
- If we use audio/video communication (e.g. video consultation) or transcription functions in online meetings, we will provide separate information in advance about the purpose, legal basis, recipientand storage period.
Where do we get personal data from?
We receive personal data in particular:
- from you when you use our website, fill in forms or contact us, and
- from other sources, to the extent permitted by law, such as publiclyavailablesources/registers, or
- service providers or third parties involved in the provision of digital functions or in the processing of transactions.
Special categories of personal data ("sensitive data")
We only process special categories of personal data within the meaning of Art. 9 GDPR (e.g. biometric data for unique identification, health data)if this is legally permitted/required or if you have given your expressconsent. In caseswhere identification or security procedures are used, we will inform you separately about this inadvance.
Data of minors
If we process personal data of minors (e.g. when legal representatives act in the context of an interaction/request), this will only be done within the framework of the legal requirements. If consent is required, it must be given by the parent or legal guardian.
What (purpose of processing) do we process your data for?
Anyone who receives personal data from you and processes it must be entitled to do so. The law calls this "a basis for processing" your personal data. We process your personal data in accordance with the statutory provisions, in particular the Telecommunications-Telemedia Data Protection Act (TTDSG), the GDPR and the Federal Data Protection Act (hereinafter referred to as the "BDSG") for the following purposes:
Purely informational use of our website
If you use our website purely for informational purposes (if you do not provide us with information via the contact option or make use of other functions of the website), we process the data transmitted by your browser in order to enable you to visit the website by means of cookies for statistical purposes and to improve our internet offer. For the purely informational use of our website, there is no obligation to actively provide personal data.
For more information, please see the "Cookies" section below.
Use of advanced features of our website
In addition to the purely informational use of our website, we offer various services and functions that you can use if you are interested, such as password-protected areas for online banking, a contact form and social media or other third-party functions (e.g. maps from Google). If you use extended functions of our website, we need the information marked as mandatory fields in order to process your request or to provide the function. Without this information, the respective function may not be used.
The collection and processing of personal data in connection with the password-protected areas is only carried out by prior agreement between you and us – please feel free to contact us.
When you contact us by e-mail or via the contact forms, at least your e-mail address and, if applicable, other personal data will be collected, processed and used by us to answer your enquiry, depending on the nature of your enquiry. Information required by us is marked accordingly with an asterisk (*). Voluntary information is often possible, but not marked separately. Information that you send us via the contact form is encrypted and is therefore not visible to third parties.
We provide separate information about the social media or other third-party functions below.
Use of digital means of communication
In addition, we process your personal data in particular in the context of the following events:
- to stay in personal contact with you even in the context of digital events,
- to offer you video banking,
- to find out your opinion about our products and services through event-related surveys,
- to ensure targeted business communication. This enables us, for example, to offer you specific services, to respond to your specific inquiries and, where applicable, to comply with existing legal obligations. In addition, this procedure serves to protect the data contained in the communication in order to prevent its access and use by unauthorized persons. It is not intended to pass on contact details or other personal information about contact persons to third parties, unless this is necessary for the specific business relationship, such as the execution of a customer order, or for the fulfilment of legal obligations.
Such applications typically use the following data in particular:
- Participant information, such as first and last name or email address
- Metadata, such as IP address or duration of the online session
- for chat, audio or video use: text data for display and, if necessary, logging as well as recording data from the microphone
In detail, we will inform you separately in advance of the applications we use and all associated information, such as the purpose of the processing, legal basis, deletion periods, recipients of the data or your right of revocation.
Use of your data for direct marketing
We would like to offer you relevant products and services that we consider suitable. To make this possible, we process your personal data that we have received from you (e.g. in the case of a specific request via the contact form), as well as data from other sources.
To the extent permitted by law, we may also use personal data in aggregated or anonymised form for statistical analyses, internal evaluations, as well as for the further development of our services and the fulfilment of the Bank's social tasks. A conclusion about individual persons is excluded here.
In order to be able to offer relevant products and services, we make use of our internal bank systems. Any relevant information we hold about you will be collected herein, including for direct marketing purposes. In order to be able to provide you with relevant offers, we apply customer selection processes.
To the extent that the use of your personal data for direct marketing purposes is not in the legitimate interests of the Bank, we will obtain your consent to do so. In any case, you have a right of objection or revocation, which we will point out to you separately. You also have the right to object to the creation of a personalized customer profile for direct marketing purposes.
Online events
You can find our privacy policy for online events here.
Other purposes (in particular security and abuse prevention)
Where necessary, we also process personal data to ensure IT security, to prevent fraud / abuse and to comply with legal and regulatory obligations. This may also affect individuals who do not have a direct contractual relationship with us if this is necessary to process transactions or to comply with legal requirements.
Cookies
Cookies are small packets of data that are stored on your hard drive using the browser. Cookies cannot run programs or transmit viruses to your computer.
We use cookies and similar technologies that are necessary for the website to function and for the safe and intended use of the website ("functional cookies"). With your consent, we also use "marketing and analytical cookies". These are used to analyse the use of our website and to personalise content and advertisements to adapt them to your needs and interests. By clicking on "accept" or "reject" in the cookie notice on the website, you determine the extent to which Bethmann HAL may use marketing or analytical cookies.
Please note: If you delete cookies or set your browser to refuse cookies, this may affect the functionality of the website. However, the mere setting that cookies are rejected does not mean that cookies accepted by you or your browser in the past will no longer work – in case of doubt, you must actively delete cookies.
Instructions on how to deactivate or delete cookies in whole or in part in the browser you are using, as well as further information on their use and functionality, can be found in the online help or operating instructions of your browser or device.
Cookie overview bethmann-hal.de:
Functional Cookies
| Name | Type | Description | Storage period |
| __Host-DeviceType | Mendix | Records the type of device used for the session. | One Session |
| __Host-Profile | Mendix | Captures the time zone offset for the session. | One Session |
| __Host-SessionTimeZoneOffset | Mendix | Captures the time zone offset for the session. | One Session |
| __Host-XAS_FBPBDE | Mendix | Captures the ID for the user's session to avoid duplicate forms. | One Session |
| __Host-XASID | Mendix | Captures the ID for the user's session to avoid duplicate forms. | One Session |
| ak_bmsc | Akamai | Necessary for the optimal functioning of the website. | One Session |
| ApplicationGatewayAffinity | Microsoft Azure | Required to route online traffic through the correct servers. | One Session |
| ApplicationGatewayAffinityCORS | Microsoft Azure | Required to route online traffic through the correct servers. | One Session |
| bm_sv | Akamai | Required to protect the website against bots. | One Session |
| ccm_consent | Used to store the cookie consent agreement, which specifies which cookies can be set. | 12 months | |
| CONSENTMGR | Tealium | Stores the consent decision of the website visitor. | 12 months |
| Homepage | Tealium | Saves the homepage so that it appears when you visit it again. | 12 months |
| JSESSIONID | ABN AMRO | Maintains user status across page requests. | 13 months |
| Mbox | Adobe Target | Cookie to identify the browser and the current session cookie issued when you visit the website and to measure the performance of the page content using A/B testing. A/B testing is a method of comparing two versions of a website or app to determine which performs better. The two variants are called A and B and are shown to users randomly. | One Session |
| mboxEdgeCluster | Adobe Target | Optimizes the operation of the website. | One Session |
| originURI | Mendix | Tells the client where to redirect when a user needs to log in. | One Session |
| PD_STATEFUL_7da1da32-5734-11ec-b960-005056a100f7 | IBM | Session state cookies used by the SAML service to maintain state during multi-stage handshakes. | One Session |
| PD_STATEFUL_82a615c8-7794-11eb-b90f-005056a100f7 | IBM | Session state cookies used by the SAML service to maintain state during multi-stage handshakes. | One Session |
| PHPSESSID | ABN AMRO | Preserves the user's states across all page requests. | One Session |
| tealium_cookie_check | Tealium | Stores the consent decision of the website visitor. | One Session |
| TS01e66d0f | F5 | To provide load balancing capabilities. | 13 months |
| utag_main | Tealium | This cookie is linked to the Tealium data platform and is used to calculate the number of visitors to a website in an anonymous form. | 12 months |
| WSESSIONID | ABN AMRO | Security | One Session |
| xasid | Mendix | Used for multi-instance failover. | One Session |
| at_check | Adobe Target | This cookie is set based on whether the visitor supports cookies or not. | One Session |
| JSESSIONID | ABN AMRO | Maintains user status across page requests. | One Session |
| _abck | Akamai | Checks whether the visitor is a real person and not a bot. | 12 Months |
| bm_sz | Akamai | Necessary to protect the website from bots. | One Session |
| QSI_history | Qualtrics | Used for feedback functionality on our website. This special cookie is used instead of the “Site History” cookie for the same purpose (recording the number of page views and how long the visitor stays on the website). | One Session |
| QSI_HistorySession | Qualtrics | Used for feedback functionality on our website. This special cookie is used instead of the “Site History” cookie for the same purpose (recording the number of page views and how long the visitor stays on the website). | One Session |
| homepageCookieNewSession | ABN AMRO | Used to ensure someone is seeing the correct version of the website. | One Session |
| tealium_cookie_check | Tealium | With this cookie we ensure that we know the user's consent status to ensure that no cookies are placed without the correct consent. | One Session |
| tealium_env | Tealium | This cookie provides a reference to the Tealium environment used on the respective website. | One Session |
| tealium_used_is_logged_in | Tealium | This cookie allows us to ensure that event data is not collected when a customer is logged in. | One Session |
| tealium_ga_enabled | Tealium | This cookie checks whether someone is using an ad blocker or not. | One Session |
| test_cookie | DoubleClick | This cookie checks whether the user's browser supports cookies. | One Session |
| PD-S-SESSION-ID | IBM | This is a session index cookie. If you log out, cookies will ensure that your session ends properly | One Session |
Analytical Cookies
| Name | Type | Description | Storage period |
| _GA | Required to distinguish users | 13 months | |
| _ga | Used to distinguish individual users. | 24 months | |
| _gid | Serves to distinguish individual users, but only has a runtime of 24 hours. | 24 hours | |
| _gac_gb_* | This cookie is only set if Google Analytics 4 is linked to Google Ads. It contains information about Google Ads campaigns | 90 days | |
| _ga_* | Used to store session state | 2 years | |
| lms_analytics | Used to identify LinkedIn members in a specific country for analytics purposes. | 30 days | |
| AnalyticsSyncHistory | Used to store information about when synchronization with the lms_analytics cookie occurred for users in certain countries. | 30 days | |
| queryString | Used to continue marketing tracking preferences. | 30 days | |
| SID | Used to determine what visitors do before they convert on LinkedIn microsites. | One session | |
| VID | ID associated with a LinkedIn microsite visitor that is used to measure conversions for lead generation. | 12 months | |
| s_plt | Tracks the time it took to load the previous page. | One session | |
| TDCPM | TradeDesk | This cookie contains information about how end users use this website and what advertising end users may have seen before visiting this website. | 12 months |
| TDID | TradeDesk | This cookie contains information about how end users use this website and what advertising end users may have seen before visiting this website | 12 months |
| UserMatchHistory | This is used for LinkedIn Advertising ID sync. | 30 days | |
| li_oatml | Used to identify LinkedIn members outside of LinkedIn for advertising and analytics outside of certain countries and to serve ads in certain countries for a limited time. | 30 days | |
| lms_ads | For advertising purposes that identify LinkedIn members outside of LinkedIn in certain countries. | 30 days | |
| li_fat_id | Indirect member ID of the member used for conversion, routing and analysis. | 30 days | |
| li_sugr | For probabilistic mapping of user identities outside a specific country. | 3 months | |
| _guid | Used to identify LinkedIn members who advertise through Google Ads. | 3 months | |
| brwsr | This is a partner marketing cookie for LinkedIn. | 2 years | |
| ABSELB | This cookie is a load balancer cookie for partner marketing. | 2 years | |
| lidc | Used by the social networking service LinkedIn to track usage of its integrated services. | 1 day | |
| UserMatchHistory | These cookies are set by LinkedIn for advertising purposes, e.g. For example, to track visitors to display more relevant advertising, to allow users to use the “Apply on LinkedIn” or “Join LinkedIn” features, to collect information about how visitors use the website, etc. | One session | |
| lang | This cookie is used to set default locale/language preferences. | One session | |
| li_gc | This cookie is used to store the customer's consent to the use of non-essential cookies. | 24 months | |
| li_rm | Used as part of LinkedIn's Sign in feature and set when a user clicks Save Sign in on a device to help them sign in on that device. | 1 year | |
| AnalyticsSyncHistory | Used to store information about when synchronization with the lms_analytics cookie occurred for users in certain countries. | 30 days | |
| fcookie | This cookie determines whether the user is human or robot. | 7 days | |
| li_sugr | Used by LinkedIn Insight tags as a browser identifier. | 90 days | |
| rtc | This cookie is used to prevent misuse on LinkedIn. | 120 seconds | |
| goog_pem_mod | Used to send data about a visitor's device and behavior to Google Analytics. Tracks visitors across all devices and marketing channels. | permanent | |
| bcookie | Browser ID cookies are used to uniquely identify the device accessing LinkedIn in order to detect abuse on the platform. | 2 years | |
| bscookie | This cookie allows users to share posts on their own website. Additionally, these cookies show how many people clicked on LinkedIn and the ad results. | 1 year | |
| trkCode | LinkedIn uses this cookie to support the functionality of the “Follow us” invitation box. | 1 year | |
| trkInfo | LinkedIn uses this cookie to support the functionality of the “Follow us” invitation box. | 1 year | |
| li_oatml | Collects information about how visitors use our website. | 30 days | |
| liap | Cookies used to connect to LinkedIn and/or activate the LinkedIn Follow function. | 90 days | |
| lissc | Used by the social networking service LinkedIn to track usage of its integrated services. | 1 year | |
| spectroscopyId | These cookies are set by LinkedIn for advertising purposes, e.g. For example, to track visitors to display more relevant advertising, to allow users to use the Apply on LinkedIn or Join LinkedIn features, to collect information about how visitors use the website, etc. | 1 session | |
| _fbp | Meta | Meta cookies used for website analytics, ad targeting and measurement | 3 months |
| Act | Meta | Meta cookies used for website analytics, ad targeting and measurement | 1 year |
| c_user | Meta | Meta cookies used for website analytics, ad targeting and measurement | 1 year |
| Datr | Meta | Meta cookies used for website analytics, ad targeting and measurement | 1 year |
| Fr | Meta | Meta cookies used for website analytics, ad targeting and measurement | 1 year |
| m_pixel_ration | Meta | Meta cookies used for website analytics, ad targeting and measurement | 1 year |
| Pl | Meta | Meta cookies used for website analytics, ad targeting and measurement | 1 year |
| presence | Meta | Meta cookies used for website analytics, ad targeting and measurement | 1 year |
| Sb | Meta | Meta cookies used for website analytics, ad targeting and measurement | 1 year |
| Spin | Meta | Meta cookies used for website analytics, ad targeting and measurement | 1 year |
| Wd | Meta | Meta cookies used for website analytics, ad targeting and measurement | 1 year |
| Xs | Meta | Meta cookies used for website analytics, ad targeting and measurement | 1 year |
| AA003 | Meta | Meta cookies used for website analytics, ad targeting and measurement | 3 months |
| ATN | Meta | Meta cookies used for website analytics, ad targeting and measurement | 2 years |
| "_GA" | Used to differentiate users. | 13 months | |
| "_GA_<container-id>" | Used to maintain the user's session state. | 13 months | |
| ar-debug | This cookie is used by Google Add Services to debug ads. This cookie is included with GA4, but is NOT used by Bethmann. However, it cannot be disabled and therefore appears sometimes. | 12 months | |
| __cf_bm | The __cf_bm cookie is a cookie required to support Cloudflare Bot Management and is currently in private beta. As part of our bot management service, this cookie helps manage inbound traffic that matches the criteria associated with bots. | 30 minutes | |
| _uetvid | This cookie is used by Microsoft Ads (Bing) to determine which advertisements to display that may be relevant to the end user browsing the website. | 3 years | |
| li_mc | This cookie is used as a temporary cache to avoid database queries for a member's consent to the use of non-essential cookies. It is also used to have consent information available on the customer site in order to enforce consent on the customer site. | 6 months | |
| fptctx2 | This cookie is used to prevent misuse of LinkedIn payment processes. | One session | |
| dfpfpt | This cookie serves as a unique user identifier to prevent misuse of LinkedIn payment processes. | 2 years |
Marketing Cookies
| Name | Type | Description | Storage period |
| _GA_<container-id> | Used to get session status. | 13 months | |
| at_check | Adobe Target | Temporary cookie to check if the cookie read/write capability is enabled on the browser. | One session |
| NID | This cookie stores information about user preferences and information about Google Maps. | 6 months |
Use of social media on our website
Social network buttons are implemented on our website, which link to social networks such as XING, LinkedIn, Facebook, Instagram and Twitter. By clicking on one of the buttons, you will first be taken to a login page of the respective social network, if you are not yet logged in there at the time of the mouse click, or to our respective company page in the respective social network.
In the event that you are already logged in to the respective social network at the time of clicking on one of our social network buttons, the social network already has the opportunity to collect data about you when you click on the button and, in particular, can recognize which website you come from.
If you do not want a social network to collect data about you in the manner described above, you must in any case log out of the respective social network before clicking on one of our social network buttons; depending on the social network, however, the simple use of the recommend function may be limited or even excluded.
For further details on data protection for the social networks linked on our pages, we recommend that you regularly consult the current data protection declarations of the operators of the respective social networks:
30, 20354 Hamburg, Germany.
XING's privacy policy is available at:
LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA.
The LinkedIn Privacy Notice is available at:
https://www.linkedin.com/legal/privacy-policy
Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
The Data Policy is available at:
https://de-de.facebook.com/about/privacy/
Google, Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google's privacy policy is available at:
http://www.google.com/intl/de/policies/privacy/index.html
Twitter Inc. (X), 1355 Market Street, Suite 900, San Francisco, CA 94103, USA.
The X Privacy Policy is available at:
YouTube
The YouTube Privacy Policy is available at:
https://policies.google.com/privacy?hl=de
Use of Google Maps on our website
The Google Maps interface is integrated into our website to visually display geographical information about our group companies. When using Google Maps, Google also collects, processes and uses data about the use of the Maps functions by visitors to the website. You can find more information about data processing by Google in Google's privacy policy under https://www.google.com/intl/de/policies/privacy/index.html. Third-party information: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001 https://www.google.com/intl/de_US/help/terms_maps.html.
What is our legal basis for using your personal data?
We process your data that reaches us via the website either on the basis of legitimate interest within the meaning of Art. 6 (1) (f) GDPR or, if you have given explicit consent, on the basis of this consent and Art. 6 (1) (a) GDPR. If your contact is aimed at concluding a contract with us, the additional legal basis for the processing is Art. 6 (1) (b) GDPR.
Who gets your data?
Within the Bank, access to your data is granted to those entities that need it to communicate with you (e.g. to process your contact requests), for the purpose of initiating a contract with you or to protect our interests in optimising our website, e.g. with regard to user-friendliness and the customer-oriented design of content. Processors used by us (Art. 28 GDPR) may also receive personal data for these purposes. These can be companies in the categories of banking services, IT services, logistics, printing services, telecommunications, consulting and consulting, as well as sales and marketing. We carefully select these companies. In a contract with them, we make clear agreements about how they handle your data. We remain responsible ourselves if we involve another company that acts on our behalf.
Within the ABN AMRO Group, personal data may be transferred within the Group – if necessary – for internal administrative purposes, to ensure uniform security, risk and compliance standards, and to fulfil legal obligations. In doing so, we ensure an appropriate level of protection through Group-wide data protection requirements (Binding Corporate Rules).
In order to ensure an adequate level of security, the ABN AMRO Group has adopted Binding Corporate Rules (BCRs) within the meaning of the EU General Data Protection Regulation, which ensure that personal data exchanged within the Group is protected. For more information on the ABN AMRO Group's Binding Corporate Rules, please visit the ABN AMRO website.
If you are a customer of our company, we may also have to pass on your personal data to other recipients outside our company in some situations. With regard to the transfer of data to recipients outside the bank, it should first be noted that according to the general terms and conditions agreed between you and us, we are obliged to maintain secrecy about all customer-related facts and evaluations of which we become aware (banking secrecy). We may only pass on information about you if required by law, if you have consented or if we are authorized to provide a bank report. Under these conditions, recipients of personal data can be, for example:
- Public bodies and institutions (e.g. Deutsche Bundesbank, Federal Financial Supervisory Authority, European Banking Authority, European Central Bank, tax authorities) in the event of a legal or regulatory obligation.
- Other credit and financial services institutions or similar entities to which we transfer personal data in order to carry out the business relationship with you (depending on the contract: e.g. correspondent banks, custodian banks, stock exchanges, credit agencies). For example, if you transfer money to another bank, your data will of course also be sent to this bank. Otherwise, payment transactions would not be possible.
Other data recipients may be those entities for which you have given us your consent to the transfer of data or for which you have exempted us from banking secrecy in accordance with the agreement or consent.
Is personal data transferred to a third country or to an international organisation?
We use services (e.g. Google Analytics 4) whose providers are partly located in third countries whose level of data protection may not correspond to that of the EU. To the extent that this is the case and the European Commission has not issued an adequacy decision for these countries, we take appropriate precautions to ensure an adequate level of data protection for any data transfers. These include, for example, standard contractual clauses of the EU. Where this is not possible, we base the data transfer on exceptions to Art. 49 GDPR, in particular on your explicit consent or the necessity of the transfer for the performance of the contract.
If a transfer from a third country is provided for and there is no adequacy decision or no suitable safeguards, it is possible that authorities in the respective third country can gain access to the transferred data and that the enforceability of your rights as a data subject cannot be guaranteed.
Google Analytics 4 is a tool provided by Google LLC, a company based in the United States of America. It serves ABN AMRO Bank N.V. as the operator of the website "bethmannbank.de" and the associated My Portal apps for the analysis of your use. By collecting website and app data, your behavior can be tracked. Information that can be evaluated is, for example, the number of visitors to a website, which content is accessed most often, or the length of time each visitor spends on individual content. Other important information that ABN AMRO Bank N.V. may receive is demographic characteristics such as language and location or the browser used to access it. The aim is to use the collected data to obtain information about the use of the website and the apps in order to drive further development and optimisation of the content and functions. When using Google Analytics 4, various personal data of yours is therefore processed. This is done for the purpose of compiling extensive statistics and providing ABN AMRO Bank N.V. with information about the use of its website and apps. The data may be stored on Google servers in the United States of America. The United States of America is a third country that has a lower level of data protection than EU countries. You have the option of opting out of data collection.
To what extent is my personal data used for profiling (scoring)?
In some cases, we process your personal data automatically with the aim of evaluating certain personal aspects (hereinafter referred to as "profiling"), in particular if a contract is to be concluded or has been concluded with you. For example, we use profiling in the following cases:
Due to legal and regulatory requirements, we are obliged to combat money laundering, terrorist financing and crimes that endanger assets. Data evaluations (e.g. in payment transactions) are also carried out.
In order to be able to provide you with targeted information and advice about products, we use evaluation instruments. These enable needs-based communication and advertising, including market and opinion research.
As part of the assessment of your creditworthiness, we use scoring. This calculates the probability with which a customer will meet his payment obligations in accordance with the contract. For example, income circumstances, expenses, existing liabilities, occupation, employer, length of employment, experience from the previous business relationship, contractual repayment of previous loans and information from credit reference agencies can be included in the calculation. The scoring is based on a mathematical-statistically recognized and proven procedure. The calculated score values support us in making decisions in the context of product deals and are incorporated into ongoing risk management.
To what extent is there automated decision-making in individual cases?
For the establishment and execution of the business relationship, we do not use any automated decision-making in accordance with Art. 22 GDPR that has legal effect on you or similarly significantly affects you. If we use these procedures in individual cases, we will inform you separately if this is required by law.
How long will we keep your personal data?
We process and store your personal data for as long as it is necessary to fulfil the respective purpose. We have described the storage period of cookies above. We have no influence on the storage period of data with third parties, unless there is a contractual relationship with them (e.g. in the area of social media) – here the storage periods result from the respective provisions of the providers.
To the extent necessary and legally permissible, we process and store your personal data for the duration of our business relationship, which also includes, for example, the initiation and execution of a contract. It should be noted that our business relationship is a continuing obligation that is designed for years.
If the data is no longer required for the fulfilment of contractual or legal obligations, it will be deleted on a regular basis, unless its – temporary – further processing or storage is necessary in particular for the following purposes:
- Fulfilment of retention and documentation obligations, which arise in particular from the German Commercial Code (HGB), the Tax Code (AO), the Banking Act (KWG), the Money Laundering Act (GwG) and the Securities Trading Act (WpHG).
- Preservation of evidence within the framework of the statutory statute of limitations, in particular according to §§ 195 et seq. of the German Civil Code (BGB).
Use of artificial intelligence (AI)
We use artificial intelligence (AI), including generative AI systems, to make our internal processes and services more efficient and secure. AI-supported applications support our employees, for example, in analyzing information, processing inquiries or improving workflows.
It may be necessary for personal data to be processed in the context of the use of AI systems. This is done exclusively for clearly defined and permissible purposes, such as quality assurance, the optimisation of our services or the guarantee of IT and information security.
We use artificial intelligence responsibly and in a controlled manner. We ensure that the use of AI systems is always in line with the applicable legal requirements (in particular the GDPR) as well as with our internal guidelines and principles for the use of artificial intelligence.
Our AI applications are not used unsupervised. Usage is monitored to avoid misuse or misuse and to ensure that decisions with legal or significant effects on individuals are not exclusively automated.
Insofar as personal data is processed in the context of AI-supported applications, we are responsible for this under data protection law. The processing is carried out in particular on the basis of our legitimate interests, for example:
- to improve our internal processes and services,
- to protect our systems, property and data subjects,
- to comply with legal and regulatory requirements.
Personal data will only be processed to the extent and for the duration necessary for the respective purpose. After the purpose of processing has ceased to exist, the data will be deleted or anonymised, provided that there are no statutory retention obligations.
Protection of your data
To protect your personal data, we use appropriate technical and organisational security measures, in particular:
- Access restrictions: Access to personal data is only granted to authorized persons with appropriate authorization.
- Encryption: Data is technically protected during transmission to prevent unauthorized access.
- Data protection controls: Compliance with data protection regulations is regularly reviewed.
Transparency
Our employees are regularly trained in the responsible use of artificial intelligence. Additional information on the use of certain AI applications, including how they work, can be found in the corresponding usage and data protection notices.
What data protection rights do you have?
Every data subject has the right to information pursuant to Art. 15 GDPR, the right to rectification pursuant to Art. 16 GDPR, the right to erasure pursuant to Art. 17 GDPR, the right to restriction of processing pursuant to Art. 18 GDPR and the right to data portability pursuant to Art. 20 GDPR. The right to information and the right to erasure are subject to the restrictions under §§ 34 and 35 BDSG. In addition, there is a right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR in conjunction with § 19 BDSG). We generally respond to inquiries from data subjects within one month. In justified cases, this period may be extended in accordance with the legal requirements, in which case we will inform you accordingly.
You can revoke your consent to the processing of personal data at any time.
Information about your right to object according to Art. 21 GDPR
Case-by-case right of objection:
You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you that is carried out on the basis of Art. 6 (1) (f) GDPR (data processing on the basis of a balancing of interests); this also applies to profiling based on this provision within the meaning of Art. 4 No. 4 GDPR, which we use for credit assessment or advertising purposes.
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
The objection can be made in any form and should be addressed to:
ABN AMRO Bank N.V. Frankfurt Branch
Privacy Officer
P.O. Box 10 06 32
60006 Frankfurt am Main
Phone: +49 69 2177-0
E-mail: datenschutz@de.abnamro.com
Right to object to the processing of data for advertising purposes:
In individual cases, we process your personal data for the purpose of direct marketing. You have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling, insofar as it is related to such direct advertising. If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes.
In addition, you can tell us at any time that you do not wish to receive offers for our products and services.
The objection can be made in any form and should be addressed to:
ABN AMRO Bank N.V. Frankfurt Branch
Privacy Officer
P.O. Box 10 06 32
60006 Frankfurt am Main
Phone: +49 69 2177-0
E-mail: datenschutz@de.abnamro.com
Do you have a complaint or is something still unclear?
Please contact us if you have any questions about this Privacy Notice. We are happy to help you. In addition to the data protection officer, our complaint management department is also available to assist you in this regard. In particular, if you do not agree with how we handle your data, you can file a complaint with the
ABN AMRO Bank N.V. Frankfurt BranchComplaint Management
P.O. Box 10 06 32
60006 Frankfurt am Main
.
You also have the right to lodge a complaint with the relevant data protection authority. For the bank, the Hessian Data Protection Commissioner, Wilhelmstraße 7 1, 65185 Wiesbaden, is the responsible data protection supervisory authority; For more information, see https://www.datenschutz.hessen.de
What can you do to protect your banking information?
What to do if you receive a phishing email:
Do you suspect that you are dealing with a phishing email? Please follow our recommendations:
- Do not click on any files, links, or attachments in the email or text message
- Do not reply to the email or text message
- If you have clicked on an insecure link or an insecure file, notify us of the scam
- Forward the phishing email to: phishing@de.abnamro.com
- Instantly delete the fake email or text message
For more information, click here.
The security of our IT systems
We are continuously working to improve our systems and processes and thus make online banking as secure and reliable as possible for you. If you should nevertheless notice a weak point, we would be very grateful if you would point it out to us. Because despite all care, mistakes can happen. If you notice or suspect a vulnerability in our IT systems, we ask you to inform us first and thus support us in finding a solution. With your help, we can constantly improve to prevent fraud or system failures. If you make these vulnerabilities in our IT systems public without first talking to us about them, this can have serious consequences. Criminals could use your information in this way, for example, for Internet fraud.
Why are there changes to the privacy policy?
This privacy policy is regularly amended in order to adapt it to changes in the law and/or the processing of personal data by Bethmann HAL. You can see this by the revision date of this document listed below. We recommend that you review this Privacy Policy periodically.