Javascript is requiredPrivacy Policy

Privacy Policy

What information can you find here?

We, Bethmann Bank, a brand of ABN AMRO Bank N.V. Frankfurt Branch (hereinafter referred to as "Bethmann HAL" or "we"), inform you about how we collect personal data in the publicly accessible areas of the Bethmann HAL websites (in particular www.bethmann-hal.de, https://tenor.bethmannbank.de and www.abnamro.de (hereinafter referred to as the "Website" or "Websites")) and what data protection claims and rights you are entitled to in this regard. Which of your personal data we process in detail depends not least on which functions of the website you use. If the processing of personal data differs from the information set out in this data protection notice for some functions (for example, in protected areas of the website after your log-in), we will inform you separately.

The Online Banking Privacy Policy can be found here (German).

The push TAN privacy policy can be found here (German).

Table of Contents

What information can you find here?

  • Who is responsible for your data?
  • To whom does this privacy policy apply?
  • What is personal data and which of your personal data do we use?
  • What categories of personal data do we process?
  • Where do we get personal data from?
  • Special categories of personal data ("sensitive data")
  • Data of minors
  • What (purpose of processing) do we process your data for?
  • Purely informational use of our website
  • Use of advanced features of our website
  • Use of digital means of communication
  • Use of your data for direct marketing
  • Online events
  • Other purposes (in particular security and abuse prevention)
  • Cookies
  • Use of Google Maps on our website
  • What is our legal basis for using your personal data?
  • Who gets your data?
  • Is personal data transferred to a third country or to an international organisation?
  • To what extent is my personal data used for profiling (scoring)?
  • To what extent is there automated decision-making in individual cases?
  • How long will we keep your personal data?
  • Use of artificial intelligence (AI)
  • Protection of your data
  • Transparency
  • What data protection rights do you have?
  • Information about your right to object according to Art. 21 GDPR
  • Do you have a complaint or is something still unclear?
  • Why are there changes to the privacy policy?

Who is responsible for your data?

The controller of your personal data and provider of this website is the

ABN AMRO Bank N.V. Frankfurt Branch

Mainzer Landstraße 1

60329 Frankfurt am Main

Further information about the bank can also be found in our imprint.

For any data protection enquiries, you can also contact us at:

ABN AMRO Bank N.V. Frankfurt Branch

Privacy Officer

Mainzer Landstraße 1

60329 Frankfurt am Main

Phone: +49 69 2177-0

E-mail: datenschutz@de.abnamro.com

In our group of companies, there is a Group Data Protection Officer, whom you can reach at the following contact details:

ABN AMRO Bank N.V.

Chief Privacy Officer

Gustav Mahlerlaan 10

1082 PP Amsterdam, Netherlands

E-Mail: privacy.office@nl.abnamro.com

To whom does this Privacy Notice apply?

This data protection notice applies to visitors to the publicly accessible areas of our websites. In addition, depending on the function used, they may also be relevant for persons who are not themselves customers of Bethmann HAL but are related to an interaction or transaction with our bank (e.g. payment recipients, authorised representatives, legal representatives, beneficial owners or citizens). Supplementaryor deviating data protection information may apply to individual products / services (e.g. online banking, push TAN, digital events); we will inform you separately about this or provide corresponding information / links.

What is personal data and which of your personal data do we use?

This data protection notice deals with the processing of personal data (Art. 4 No. 2 of the European General Data Protection Regulation (hereinafter referred to as "GDPR")) on our websites. Personal data is information that either relates directly to you as a natural person or can be associated with you, i.e. can be related to you. Personal data includes, for example, your personal details (first name, surname, address, birthday, etc.), all types of contact details (e.g. telephone, e-mail address), gender, marital status, other information that you would find in an application and CV (e.g. about your education, professional experience) and any other information that we can assign to you as a natural person (e.g. data about your use of the telemedia we offer,  e.g. time of access to our website, apps or newsletters, pages clicked on by us or entries).

What categories of personal data do we process?

Depending on the use of our website, we process in particular:

  • Usage / device data (e.g. IP address, time of access, pages accessed, browser / deviceinformation),
  • Communication data (e.g. email address, content of your request),
  • Contract/transaction reference (if you are a customer or concerns a transaction/interaction: e.g. assignment / reference data),
  • Event/participation data (e.g. name, e-mail, technical metadata for online formats),
  • Cookies/consent data (e.g. consent status, cookie categories).
  • If we use audio/video communication (e.g. video consultation) or transcription functions in online meetings, we will provide separate information in advance about the purpose, legal basis, recipientand storage period.

Where do we get personal data from?

We receive personal data in particular:

  • from you when you use our website, fill in forms or contact us, and
  • from other sources, to the extent permitted by law, such as publiclyavailablesources/registers, or
  • service providers or third parties involved in the provision of digital functions or in the processing of transactions.

Special categories of personal data ("sensitive data")

We only process special categories of personal data within the meaning of Art. 9 GDPR (e.g. biometric data for unique identification, health data)if this is legally permitted/required or if you have given your expressconsent. In caseswhere identification or security procedures are used, we will inform you separately about this inadvance.

Data of minors

If we process personal data of minors (e.g. when legal representatives act in the context of an interaction/request), this will only be done within the framework of the legal requirements. If consent is required, it must be given by the parent or legal guardian.

What (purpose of processing) do we process your data for?

Anyone who receives personal data from you and processes it must be entitled to do so. The law calls this "a basis for processing" your personal data. We process your personal data in accordance with the statutory provisions, in particular the Telecommunications-Telemedia Data Protection Act (TTDSG), the GDPR and the Federal Data Protection Act (hereinafter referred to as the "BDSG") for the following purposes:

Purely informational use of our website

If you use our website purely for informational purposes (if you do not provide us with information via the contact option or make use of other functions of the website), we process the data transmitted by your browser in order to enable you to visit the website by means of cookies for statistical purposes and to improve our internet offer. For the purely informational use of our website, there is no obligation to actively provide personal data.

For more information, please see the "Cookies" section below.

Use of advanced features of our website

In addition to the purely informational use of our website, we offer various services and functions that you can use if you are interested, such as password-protected areas for online banking, a contact form and social media or other third-party functions (e.g. maps from Google). If you use extended functions of our website, we need the information marked as mandatory fields in order to process your request or to provide the function. Without this information, the respective function may not be used.

The collection and processing of personal data in connection with the password-protected areas is only carried out by prior agreement between you and us – please feel free to contact us.

When you contact us by e-mail or via the contact forms, at least your e-mail address and, if applicable, other personal data will be collected, processed and used by us to answer your enquiry, depending on the nature of your enquiry. Information required by us is marked accordingly with an asterisk (*). Voluntary information is often possible, but not marked separately. Information that you send us via the contact form is encrypted and is therefore not visible to third parties.

We provide separate information about the social media or other third-party functions below.

Use of digital means of communication

In addition, we process your personal data in particular in the context of the following events:

  • to stay in personal contact with you even in the context of digital events,
  • to offer you video banking,
  • to find out your opinion about our products and services through event-related surveys,
  • to ensure targeted business communication. This enables us, for example, to offer you specific services, to respond to your specific inquiries and, where applicable, to comply with existing legal obligations. In addition, this procedure serves to protect the data contained in the communication in order to prevent its access and use by unauthorized persons. It is not intended to pass on contact details or other personal information about contact persons to third parties, unless this is necessary for the specific business relationship, such as the execution of a customer order, or for the fulfilment of legal obligations.

Such applications typically use the following data in particular:

  • Participant information, such as first and last name or email address
  • Metadata, such as IP address or duration of the online session
  • for chat, audio or video use: text data for display and, if necessary, logging as well as recording data from the microphone

In detail, we will inform you separately in advance of the applications we use and all associated information, such as the purpose of the processing, legal basis, deletion periods, recipients of the data or your right of revocation.

Use of your data for direct marketing

We would like to offer you relevant products and services that we consider suitable. To make this possible, we process your personal data that we have received from you (e.g. in the case of a specific request via the contact form), as well as data from other sources.

To the extent permitted by law, we may also use personal data in aggregated or anonymised form for statistical analyses, internal evaluations, as well as for the further development of our services and the fulfilment of the Bank's social tasks. A conclusion about individual persons is excluded here.

In order to be able to offer relevant products and services, we make use of our internal bank systems. Any relevant information we hold about you will be collected herein, including for direct marketing purposes. In order to be able to provide you with relevant offers, we apply customer selection processes.

To the extent that the use of your personal data for direct marketing purposes is not in the legitimate interests of the Bank, we will obtain your consent to do so. In any case, you have a right of objection or revocation, which we will point out to you separately. You also have the right to object to the creation of a personalized customer profile for direct marketing purposes.

Online events

You can find our privacy policy for online events here.

Other purposes (in particular security and abuse prevention)

Where necessary, we also process personal data to ensure IT security, to prevent fraud / abuse and to comply with legal and regulatory obligations. This may also affect individuals who do not have a direct contractual relationship with us if this is necessary to process transactions or to comply with legal requirements.

Cookies

Cookies are small packets of data that are stored on your hard drive using the browser. Cookies cannot run programs or transmit viruses to your computer.

We use cookies and similar technologies that are necessary for the website to function and for the safe and intended use of the website ("functional cookies"). With your consent, we also use "marketing and analytical cookies". These are used to analyse the use of our website and to personalise content and advertisements to adapt them to your needs and interests. By clicking on "accept" or "reject" in the cookie notice on the website, you determine the extent to which Bethmann HAL may use marketing or analytical cookies.

Please note: If you delete cookies or set your browser to refuse cookies, this may affect the functionality of the website. However, the mere setting that cookies are rejected does not mean that cookies accepted by you or your browser in the past will no longer work – in case of doubt, you must actively delete cookies.

Instructions on how to deactivate or delete cookies in whole or in part in the browser you are using, as well as further information on their use and functionality, can be found in the online help or operating instructions of your browser or device.

Cookie overview bethmann-hal.de:

Functional Cookies

NameTypeDescriptionStorage period
__Host-DeviceTypeMendixRecords the type of device used for the session.One Session
__Host-ProfileMendixCaptures the time zone offset for the session.One Session
__Host-SessionTimeZoneOffsetMendixCaptures the time zone offset for the session.One Session
__Host-XAS_FBPBDEMendixCaptures the ID for the user's session to avoid duplicate forms.One Session
__Host-XASIDMendixCaptures the ID for the user's session to avoid duplicate forms.One Session
ak_bmscAkamaiNecessary for the optimal functioning of the website.One Session
ApplicationGatewayAffinityMicrosoft AzureRequired to route online traffic through the correct servers.One Session
ApplicationGatewayAffinityCORSMicrosoft AzureRequired to route online traffic through the correct servers.One Session
bm_svAkamaiRequired to protect the website against bots.One Session
ccm_consent Used to store the cookie consent agreement, which specifies which cookies can be set.12 months
CONSENTMGRTealiumStores the consent decision of the website visitor.12 months
HomepageTealiumSaves the homepage so that it appears when you visit it again.12 months
JSESSIONIDABN AMROMaintains user status across page requests.13 months
MboxAdobe TargetCookie to identify the browser and the current session cookie issued when you visit the website and to measure the performance of the page content using A/B testing. A/B testing is a method of comparing two versions of a website or app to determine which performs better. The two variants are called A and B and are shown to users randomly.One Session
mboxEdgeClusterAdobe TargetOptimizes the operation of the website.One Session
originURIMendixTells the client where to redirect when a user needs to log in.One Session
PD_STATEFUL_7da1da32-5734-11ec-b960-005056a100f7IBMSession state cookies used by the SAML service to maintain state during multi-stage handshakes.One Session
PD_STATEFUL_82a615c8-7794-11eb-b90f-005056a100f7IBMSession state cookies used by the SAML service to maintain state during multi-stage handshakes.One Session
PHPSESSIDABN AMROPreserves the user's states across all page requests.One Session
tealium_cookie_checkTealiumStores the consent decision of the website visitor.One Session
TS01e66d0fF5To provide load balancing capabilities.13 months
utag_mainTealiumThis cookie is linked to the Tealium data platform and is used to calculate the number of visitors to a website in an anonymous form.12 months
WSESSIONIDABN AMROSecurityOne Session
xasidMendixUsed for multi-instance failover.One Session
at_checkAdobe TargetThis cookie is set based on whether the visitor supports cookies or not.One Session
JSESSIONIDABN AMROMaintains user status across page requests.One Session
_abckAkamaiChecks whether the visitor is a real person and not a bot.12 Months
bm_szAkamaiNecessary to protect the website from bots.One Session
QSI_historyQualtricsUsed for feedback functionality on our website. This special cookie is used instead of the “Site History” cookie for the same purpose (recording the number of page views and how long the visitor stays on the website).One Session
QSI_HistorySessionQualtricsUsed for feedback functionality on our website. This special cookie is used instead of the “Site History” cookie for the same purpose (recording the number of page views and how long the visitor stays on the website).One Session
homepageCookieNewSessionABN AMROUsed to ensure someone is seeing the correct version of the website.One Session
tealium_cookie_checkTealiumWith this cookie we ensure that we know the user's consent status to ensure that no cookies are placed without the correct consent.One Session
tealium_envTealiumThis cookie provides a reference to the Tealium environment used on the respective website.One Session
tealium_used_is_logged_inTealiumThis cookie allows us to ensure that event data is not collected when a customer is logged in.One Session
tealium_ga_enabledTealiumThis cookie checks whether someone is using an ad blocker or not.One Session
test_cookieDoubleClickThis cookie checks whether the user's browser supports cookies.One Session
PD-S-SESSION-IDIBMThis is a session index cookie. If you log out, cookies will ensure that your session ends properlyOne Session

Analytical Cookies

NameTypeDescriptionStorage period
_GAGoogleRequired to distinguish users13 months
_gaGoogleUsed to distinguish individual users.24 months
_gidGoogleServes to distinguish individual users, but only has a runtime of 24 hours.24 hours
_gac_gb_* GoogleThis cookie is only set if Google Analytics 4 is linked to Google Ads. It contains information about Google Ads campaigns90 days
_ga_* GoogleUsed to store session state2 years
lms_analytics LinkedIn Used to identify LinkedIn members in a specific country for analytics purposes.30 days
AnalyticsSyncHistoryLinkedInUsed to store information about when synchronization with the lms_analytics cookie occurred for users in certain countries.30 days
queryStringLinkedInUsed to continue marketing tracking preferences.30 days
SIDLinkedInUsed to determine what visitors do before they convert on LinkedIn microsites.One session
VIDLinkedInID associated with a LinkedIn microsite visitor that is used to measure conversions for lead generation.12 months
s_pltLinkedInTracks the time it took to load the previous page.One session
TDCPMTradeDeskThis cookie contains information about how end users use this website and what advertising end users may have seen before visiting this website.12 months
TDIDTradeDeskThis cookie contains information about how end users use this website and what advertising end users may have seen before visiting this website12 months
UserMatchHistoryLinkedInThis is used for LinkedIn Advertising ID sync.30 days
li_oatmlLinkedInUsed to identify LinkedIn members outside of LinkedIn for advertising and analytics outside of certain countries and to serve ads in certain countries for a limited time.30 days
lms_adsLinkedInFor advertising purposes that identify LinkedIn members outside of LinkedIn in certain countries.30 days
li_fat_idLinkedInIndirect member ID of the member used for conversion, routing and analysis.30 days
li_sugrLinkedInFor probabilistic mapping of user identities outside a specific country.3 months
_guidLinkedInUsed to identify LinkedIn members who advertise through Google Ads.3 months
brwsrLinkedInThis is a partner marketing cookie for LinkedIn.2 years
ABSELBLinkedInThis cookie is a load balancer cookie for partner marketing.2 years
lidcLinkedInUsed by the social networking service LinkedIn to track usage of its integrated services.1 day
UserMatchHistoryLinkedInThese cookies are set by LinkedIn for advertising purposes, e.g. For example, to track visitors to display more relevant advertising, to allow users to use the “Apply on LinkedIn” or “Join LinkedIn” features, to collect information about how visitors use the website, etc.One session
langLinkedInThis cookie is used to set default locale/language preferences.One session
li_gcLinkedInThis cookie is used to store the customer's consent to the use of non-essential cookies.24 months
li_rmLinkedInUsed as part of LinkedIn's Sign in feature and set when a user clicks Save Sign in on a device to help them sign in on that device.1 year
AnalyticsSyncHistoryLinkedInUsed to store information about when synchronization with the lms_analytics cookie occurred for users in certain countries.30 days
fcookieLinkedInThis cookie determines whether the user is human or robot.7 days
li_sugrLinkedInUsed by LinkedIn Insight tags as a browser identifier.90 days
rtcLinkedInThis cookie is used to prevent misuse on LinkedIn.120 seconds
goog_pem_modLinkedInUsed to send data about a visitor's device and behavior to Google Analytics. Tracks visitors across all devices and marketing channels.permanent
bcookieLinkedInBrowser ID cookies are used to uniquely identify the device accessing LinkedIn in order to detect abuse on the platform.2 years
bscookieLinkedInThis cookie allows users to share posts on their own website. Additionally, these cookies show how many people clicked on LinkedIn and the ad results.1 year
trkCodeLinkedInLinkedIn uses this cookie to support the functionality of the “Follow us” invitation box.1 year
trkInfoLinkedInLinkedIn uses this cookie to support the functionality of the “Follow us” invitation box.1 year
li_oatmlLinkedInCollects information about how visitors use our website.30 days
liapLinkedInCookies used to connect to LinkedIn and/or activate the LinkedIn Follow function.90 days
lisscLinkedInUsed by the social networking service LinkedIn to track usage of its integrated services.1 year
spectroscopyIdLinkedInThese cookies are set by LinkedIn for advertising purposes, e.g. For example, to track visitors to display more relevant advertising, to allow users to use the Apply on LinkedIn or Join LinkedIn features, to collect information about how visitors use the website, etc.1 session
_fbpMetaMeta cookies used for website analytics, ad targeting and measurement3 months
ActMetaMeta cookies used for website analytics, ad targeting and measurement1 year
c_userMetaMeta cookies used for website analytics, ad targeting and measurement1 year
DatrMetaMeta cookies used for website analytics, ad targeting and measurement1 year
FrMetaMeta cookies used for website analytics, ad targeting and measurement1 year
m_pixel_rationMetaMeta cookies used for website analytics, ad targeting and measurement1 year
PlMetaMeta cookies used for website analytics, ad targeting and measurement1 year
presenceMetaMeta cookies used for website analytics, ad targeting and measurement1 year
SbMetaMeta cookies used for website analytics, ad targeting and measurement1 year
SpinMetaMeta cookies used for website analytics, ad targeting and measurement1 year
WdMetaMeta cookies used for website analytics, ad targeting and measurement1 year
XsMetaMeta cookies used for website analytics, ad targeting and measurement1 year
AA003MetaMeta cookies used for website analytics, ad targeting and measurement3 months
ATNMetaMeta cookies used for website analytics, ad targeting and measurement2 years
"_GA"GoogleUsed to differentiate users.13 months
"_GA_<container-id>"GoogleUsed to maintain the user's session state.13 months
ar-debugGoogleThis cookie is used by Google Add Services to debug ads. This cookie is included with GA4, but is NOT used by Bethmann. However, it cannot be disabled and therefore appears sometimes.12 months
__cf_bmLinkedInThe __cf_bm cookie is a cookie required to support Cloudflare Bot Management and is currently in private beta. As part of our bot management service, this cookie helps manage inbound traffic that matches the criteria associated with bots.30 minutes
_uetvidLinkedInThis cookie is used by Microsoft Ads (Bing) to determine which advertisements to display that may be relevant to the end user browsing the website.3 years
li_mcLinkedInThis cookie is used as a temporary cache to avoid database queries for a member's consent to the use of non-essential cookies. It is also used to have consent information available on the customer site in order to enforce consent on the customer site.6 months
fptctx2LinkedInThis cookie is used to prevent misuse of LinkedIn payment processes.One session
dfpfptLinkedInThis cookie serves as a unique user identifier to prevent misuse of LinkedIn payment processes.2 years

Marketing Cookies

NameTypeDescriptionStorage period
_GA_<container-id>GoogleUsed to get session status.13 months
at_checkAdobe TargetTemporary cookie to check if the cookie read/write capability is enabled on the browser.One session
NIDGoogleThis cookie stores information about user preferences and information about Google Maps.6 months

Use of social media on our website

Social network buttons are implemented on our website, which link to social networks such as XING, LinkedIn, Facebook, Instagram and Twitter. By clicking on one of the buttons, you will first be taken to a login page of the respective social network, if you are not yet logged in there at the time of the mouse click, or to our respective company page in the respective social network.

In the event that you are already logged in to the respective social network at the time of clicking on one of our social network buttons, the social network already has the opportunity to collect data about you when you click on the button and, in particular, can recognize which website you come from.

If you do not want a social network to collect data about you in the manner described above, you must in any case log out of the respective social network before clicking on one of our social network buttons; depending on the social network, however, the simple use of the recommend function may be limited or even excluded.

For further details on data protection for the social networks linked on our pages, we recommend that you regularly consult the current data protection declarations of the operators of the respective social networks:

30, 20354 Hamburg, Germany.

XING's privacy policy is available at:

https://www.xing.com/privacy

LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA.

The LinkedIn Privacy Notice is available at:

https://www.linkedin.com/legal/privacy-policy

Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

The Data Policy is available at:

https://de-de.facebook.com/about/privacy/

Google, Amphitheatre Parkway, Mountain View, CA 94043, USA.

Google's privacy policy is available at:

http://www.google.com/intl/de/policies/privacy/index.html

Twitter Inc. (X), 1355 Market Street, Suite 900, San Francisco, CA 94103, USA.

The X Privacy Policy is available at:

https://x.com/de/privacy

YouTube

The YouTube Privacy Policy is available at:

https://policies.google.com/privacy?hl=de

Use of Google Maps on our website

The Google Maps interface is integrated into our website to visually display geographical information about our group companies. When using Google Maps, Google also collects, processes and uses data about the use of the Maps functions by visitors to the website. You can find more information about data processing by Google in Google's privacy policy under https://www.google.com/intl/de/policies/privacy/index.html. Third-party information: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001 https://www.google.com/intl/de_US/help/terms_maps.html.

What is our legal basis for using your personal data?

We process your data that reaches us via the website either on the basis of legitimate interest within the meaning of Art. 6 (1) (f) GDPR or, if you have given explicit consent, on the basis of this consent and Art. 6 (1) (a) GDPR. If your contact is aimed at concluding a contract with us, the additional legal basis for the processing is Art. 6 (1) (b) GDPR.

Who gets your data?

Within the Bank, access to your data is granted to those entities that need it to communicate with you (e.g. to process your contact requests), for the purpose of initiating a contract with you or to protect our interests in optimising our website, e.g. with regard to user-friendliness and the customer-oriented design of content. Processors used by us (Art. 28 GDPR) may also receive personal data for these purposes. These can be companies in the categories of banking services, IT services, logistics, printing services, telecommunications, consulting and consulting, as well as sales and marketing. We carefully select these companies. In a contract with them, we make clear agreements about how they handle your data. We remain responsible ourselves if we involve another company that acts on our behalf.

Within the ABN AMRO Group, personal data may be transferred within the Group – if necessary – for internal administrative purposes, to ensure uniform security, risk and compliance standards, and to fulfil legal obligations. In doing so, we ensure an appropriate level of protection through Group-wide data protection requirements (Binding Corporate Rules).

In order to ensure an adequate level of security, the ABN AMRO Group has adopted Binding Corporate Rules (BCRs) within the meaning of the EU General Data Protection Regulation, which ensure that personal data exchanged within the Group is protected. For more information on the ABN AMRO Group's Binding Corporate Rules, please visit the  ABN AMRO website.

If you are a customer of our company, we may also have to pass on your personal data to other recipients outside our company in some situations. With regard to the transfer of data to recipients outside the bank, it should first be noted that according to the general terms and conditions agreed between you and us, we are obliged to maintain secrecy about all customer-related facts and evaluations of which we become aware (banking secrecy). We may only pass on information about you if required by law, if you have consented or if we are authorized to provide a bank report. Under these conditions, recipients of personal data can be, for example:

  • Public bodies and institutions (e.g. Deutsche Bundesbank, Federal Financial Supervisory Authority, European Banking Authority, European Central Bank, tax authorities) in the event of a legal or regulatory obligation.
  • Other credit and financial services institutions or similar entities to which we transfer personal data in order to carry out the business relationship with you (depending on the contract: e.g. correspondent banks, custodian banks, stock exchanges, credit agencies). For example, if you transfer money to another bank, your data will of course also be sent to this bank. Otherwise, payment transactions would not be possible.

Other data recipients may be those entities for which you have given us your consent to the transfer of data or for which you have exempted us from banking secrecy in accordance with the agreement or consent.

Is personal data transferred to a third country or to an international organisation?

We use services (e.g. Google Analytics 4) whose providers are partly located in third countries whose level of data protection may not correspond to that of the EU. To the extent that this is the case and the European Commission has not issued an adequacy decision for these countries, we take appropriate precautions to ensure an adequate level of data protection for any data transfers. These include, for example, standard contractual clauses of the EU. Where this is not possible, we base the data transfer on exceptions to Art. 49 GDPR, in particular on your explicit consent or the necessity of the transfer for the performance of the contract.

If a transfer from a third country is provided for and there is no adequacy decision or no suitable safeguards, it is possible that authorities in the respective third country can gain access to the transferred data and that the enforceability of your rights as a data subject cannot be guaranteed.

Google Analytics 4 is a tool provided by Google LLC, a company based in the United States of America. It serves ABN AMRO Bank N.V. as the operator of the website "bethmannbank.de" and the associated My Portal apps for the analysis of your use. By collecting website and app data, your behavior can be tracked. Information that can be evaluated is, for example, the number of visitors to a website, which content is accessed most often, or the length of time each visitor spends on individual content. Other important information that ABN AMRO Bank N.V. may receive is demographic characteristics such as language and location or the browser used to access it. The aim is to use the collected data to obtain information about the use of the website and the apps in order to drive further development and optimisation of the content and functions. When using Google Analytics 4, various personal data of yours is therefore processed. This is done for the purpose of compiling extensive statistics and providing ABN AMRO Bank N.V. with information about the use of its website and apps. The data may be stored on Google servers in the United States of America. The United States of America is a third country that has a lower level of data protection than EU countries. You have the option of opting out of data collection.

To what extent is my personal data used for profiling (scoring)?

In some cases, we process your personal data automatically with the aim of evaluating certain personal aspects (hereinafter referred to as "profiling"), in particular if a contract is to be concluded or has been concluded with you. For example, we use profiling in the following cases:

Due to legal and regulatory requirements, we are obliged to combat money laundering, terrorist financing and crimes that endanger assets. Data evaluations (e.g. in payment transactions) are also carried out.

In order to be able to provide you with targeted information and advice about products, we use evaluation instruments. These enable needs-based communication and advertising, including market and opinion research.

As part of the assessment of your creditworthiness, we use scoring. This calculates the probability with which a customer will meet his payment obligations in accordance with the contract. For example, income circumstances, expenses, existing liabilities, occupation, employer, length of employment, experience from the previous business relationship, contractual repayment of previous loans and information from credit reference agencies can be included in the calculation. The scoring is based on a mathematical-statistically recognized and proven procedure. The calculated score values support us in making decisions in the context of product deals and are incorporated into ongoing risk management.

To what extent is there automated decision-making in individual cases?

For the establishment and execution of the business relationship, we do not use any automated decision-making in accordance with Art. 22 GDPR that has legal effect on you or similarly significantly affects you. If we use these procedures in individual cases, we will inform you separately if this is required by law.

How long will we keep your personal data?

We process and store your personal data for as long as it is necessary to fulfil the respective purpose. We have described the storage period of cookies above. We have no influence on the storage period of data with third parties, unless there is a contractual relationship with them (e.g. in the area of social media) – here the storage periods result from the respective provisions of the providers.

To the extent necessary and legally permissible, we process and store your personal data for the duration of our business relationship, which also includes, for example, the initiation and execution of a contract. It should be noted that our business relationship is a continuing obligation that is designed for years.

If the data is no longer required for the fulfilment of contractual or legal obligations, it will be deleted on a regular basis, unless its – temporary – further processing or storage is necessary in particular for the following purposes:

  • Fulfilment of retention and documentation obligations, which arise in particular from the German Commercial Code (HGB), the Tax Code (AO), the Banking Act (KWG), the Money Laundering Act (GwG) and the Securities Trading Act (WpHG).
  • Preservation of evidence within the framework of the statutory statute of limitations, in particular according to §§ 195 et seq. of the German Civil Code (BGB).

Use of artificial intelligence (AI)

We use artificial intelligence (AI), including generative AI systems, to make our internal processes and services more efficient and secure. AI-supported applications support our employees, for example, in analyzing information, processing inquiries or improving workflows.

It may be necessary for personal data to be processed in the context of the use of AI systems. This is done exclusively for clearly defined and permissible purposes, such as quality assurance, the optimisation of our services or the guarantee of IT and information security.

We use artificial intelligence responsibly and in a controlled manner. We ensure that the use of AI systems is always in line with the applicable legal requirements (in particular the GDPR) as well as with our internal guidelines and principles for the use of artificial intelligence.

Our AI applications are not used unsupervised. Usage is monitored to avoid misuse or misuse and to ensure that decisions with legal or significant effects on individuals are not exclusively automated.

Insofar as personal data is processed in the context of AI-supported applications, we are responsible for this under data protection law. The processing is carried out in particular on the basis of our legitimate interests, for example:

  • to improve our internal processes and services,
  • to protect our systems, property and data subjects,
  • to comply with legal and regulatory requirements.

Personal data will only be processed to the extent and for the duration necessary for the respective purpose. After the purpose of processing has ceased to exist, the data will be deleted or anonymised, provided that there are no statutory retention obligations.

Protection of your data

To protect your personal data, we use appropriate technical and organisational security measures, in particular:

  • Access restrictions: Access to personal data is only granted to authorized persons with appropriate authorization.
  • Encryption: Data is technically protected during transmission to prevent unauthorized access.
  • Data protection controls: Compliance with data protection regulations is regularly reviewed.

Transparency

Our employees are regularly trained in the responsible use of artificial intelligence. Additional information on the use of certain AI applications, including how they work, can be found in the corresponding usage and data protection notices.

What data protection rights do you have?

Every data subject has the right to information pursuant to Art. 15 GDPR, the right to rectification pursuant to Art. 16 GDPR, the right to erasure pursuant to Art. 17 GDPR, the right to restriction of processing pursuant to Art. 18 GDPR and the right to data portability pursuant to Art. 20 GDPR. The right to information and the right to erasure are subject to the restrictions under §§ 34 and 35 BDSG. In addition, there is a right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR in conjunction with § 19 BDSG). We generally respond to inquiries from data subjects within one month. In justified cases, this period may be extended in accordance with the legal requirements, in which case we will inform you accordingly.

You can revoke your consent to the processing of personal data at any time.

Information about your right to object according to Art. 21 GDPR

Case-by-case right of objection:

You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you that is carried out on the basis of Art. 6 (1) (f) GDPR (data processing on the basis of a balancing of interests); this also applies to profiling based on this provision within the meaning of Art. 4 No. 4 GDPR, which we use for credit assessment or advertising purposes.

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that outweigh your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.

The objection can be made in any form and should be addressed to:

ABN AMRO Bank N.V. Frankfurt Branch

Privacy Officer

P.O. Box 10 06 32

60006 Frankfurt am Main

Phone: +49 69 2177-0

E-mail: datenschutz@de.abnamro.com

Right to object to the processing of data for advertising purposes:

In individual cases, we process your personal data for the purpose of direct marketing. You have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling, insofar as it is related to such direct advertising. If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes.

In addition, you can tell us at any time that you do not wish to receive offers for our products and services.

The objection can be made in any form and should be addressed to:

ABN AMRO Bank N.V. Frankfurt Branch

Privacy Officer

P.O. Box 10 06 32

60006 Frankfurt am Main

Phone: +49 69 2177-0

E-mail: datenschutz@de.abnamro.com

Do you have a complaint or is something still unclear?

Please contact us if you have any questions about this Privacy Notice. We are happy to help you. In addition to the data protection officer, our complaint management department is also available to assist you in this regard. In particular, if you do not agree with how we handle your data, you can file a complaint with the

ABN AMRO Bank N.V. Frankfurt BranchComplaint Management

P.O. Box 10 06 32

60006 Frankfurt am Main

.

You also have the right to lodge a complaint with the relevant data protection authority. For the bank, the Hessian Data Protection Commissioner, Wilhelmstraße 7 1, 65185 Wiesbaden, is the responsible data protection supervisory authority; For more information, see https://www.datenschutz.hessen.de

What can you do to protect your banking information?

What to do if you receive a phishing email:

Do you suspect that you are dealing with a phishing email? Please follow our recommendations:

  • Do not click on any files, links, or attachments in the email or text message
  • Do not reply to the email or text message
  • If you have clicked on an insecure link or an insecure file, notify us of the scam
  • Forward the phishing email to: phishing@de.abnamro.com
  • Instantly delete the fake email or text message

For more information, click here.

The security of our IT systems

We are continuously working to improve our systems and processes and thus make online banking as secure and reliable as possible for you. If you should nevertheless notice a weak point, we would be very grateful if you would point it out to us. Because despite all care, mistakes can happen. If you notice or suspect a vulnerability in our IT systems, we ask you to inform us first and thus support us in finding a solution. With your help, we can constantly improve to prevent fraud or system failures. If you make these vulnerabilities in our IT systems public without first talking to us about them, this can have serious consequences. Criminals could use your information in this way, for example, for Internet fraud.

Reporting weak spots in IT systems - ABN AMRO

Why are there changes to the privacy policy?

This privacy policy is regularly amended in order to adapt it to changes in the law and/or the processing of personal data by Bethmann HAL. You can see this by the revision date of this document listed below. We recommend that you review this Privacy Policy periodically.

As of: June 2026