Privacy Notice Regarding the Use of the "pushTAN My Portal" App
This Privacy Policy provides information about how we process your personal data when you use the "pushTAN Mein Portal" app on mobile devices to access our services.
1. General Information
We, Bethmann HAL, a brand of ABN AMRO Bank N.V. Frankfurt Branch (hereinafter "Bethmann HAL" or "we"), are the data controller within the meaning of the General Data Protection Regulation (GDPR) for the processing of your personal data when you use the app for mobile devices running Android and iOS operating systems. Further information about the app can also be found in the License and Terms of Use as well as in our Privacy Policy, which are available in the app’s menu.
The app contains applications and provides access to these applications. This allows you to use various applications via the app in accordance with your bank’s contractual terms and conditions and usage guidelines (Services).
This information is provided in accordance with Articles 12–14 of the GDPR. Depending on the specific design of individual communication functions, requirements of the Telecommunications and Telemedia Data Protection Act (TTDSG) may also apply.
2. Processing of Your Personal Data
a) Installation and Provision of the App
When you download the app, you provide personal data to the provider of the respective app store (Google Play Store or Apple App Store), but not to us. We are not responsible for the processing of personal data by the app store provider.
We have access to statistical reports on app downloads. This data is anonymous and includes information such as the operating systems and versions used. We do not combine this anonymous data with your personal data.
If you post a review and/or comment about the app in the respective app store, we process personal data (such as your username) by viewing your published review. We do this to make the app available through app stores, to monitor quality based on aggregated download statistics, and, if necessary, to respond to store feedback. The legal bases for this are Article 6(1)(b) of the GDPR (to the extent necessary for provision and processing) and Article 6(1)(f) of the GDPR (legitimate interest in quality control and feedback management).
b) Setting Up the App
To use the app, you must first set it up and agree to the license and terms of use before using it for the first time. Creating a user account is not required when setting up the app.
During setup, the following data may be processed in particular: the app version and operating system information (e.g., the OS version), the setup timestamp, and technical identifiers or tokens (e.g., for push notifications). This processing is necessary for the initial activation of the app, to ensure its usability, and, where implemented, to perform security and integrity checks. The legal basis is Article 6(1)(b) of the GDPR (performance of the user relationship / provision of services) and, where applicable, Article 6(1)(c) of the GDPR (compliance with legal / regulatory requirements, such as security requirements).
c) Use of the App (Operation, Communication, Logging)
When using the app, an internet connection is generally required to enable app functionality, provide content, or perform security checks. In doing so, the app processes your device’s IP address as well as other transaction-related data, such as information about the app version.
The transaction-related data is stored in log files in a pseudonymized or technically separated manner for a period of seven days for security purposes and to enable any necessary security checks; this information is not processed beyond this period. The processing is carried out to provide app functions, for IT security (for example, to defend against or analyze attacks and for error analysis), and – where implemented – to prevent misuse and fraud. The categories of data processed include, in particular, IP address, timestamps, app version, technical device and operating system parameters, as well as event or error codes and log data regarding the use of app features. The legal bases are Article 6(1)(b) of the GDPR (provision of app services) and Article 6(1)(f) of the GDPR (IT security, error analysis, and prevention of misuse).
d) pushTAN Function (Transaction Approval / Authentication)
The app can be used to authorize or approve transactions or operations via pushTAN. In this process, an approval request is displayed in the app and confirmed by you, for example, using an app PIN and/or a device lock or biometric authentication at the operating system level.
In this context, we process data to carry out the authentication/authorization procedure (pushTAN), to ensure the integrity and security of the transaction approval, and to ensure traceability and security logging to the extent required. Typically, this involves processing transaction or operation references (e.g., reference IDs), timestamps of the request and approval, status information (requested, approved, canceled), device- or app-related identifiers for device binding (e.g., token/instance ID or app installation ID), as well as – where applicable – security or integrity information (e.g., indications of root/jailbreak or debug status). The legal basis is Article 6(1)(b) of the GDPR (performance of the contract/services) and, where necessary, Article 6(1)(c) of the GDPR (compliance with legal and regulatory requirements regarding strong customer authentication and IT security). Log and security data related to pushTAN authorization are stored only for as long as necessary for security, error analysis, and compliance with statutory retention requirements.
e) Transfer of Personal Data for the Purpose of Providing Services (Recipients)
As a technical service provider, we transfer personal data to recipients or categories of recipients when the app is used so that they can provide services and app features. These include, in particular, Google Firebase (app development platform; specifically Firebase Cloud Messaging and Firebase Crashlytics for Android) and the Apple Push Notification Service (APNs) for iOS.
Firebase Cloud Messaging (FCM) is used to send push notifications (within the app) to your device. In this process, your device is assigned a pseudonymized push reference (Instance ID), which serves as the destination for push notifications. Firebase Crashlytics is used to report app crashes on Android devices and facilitate troubleshooting; crashes are grouped, and the circumstances leading to the crash are analyzed. APNs is used to send push notifications to iOS devices; here, too, the device is assigned a pseudonymized push reference (Instance ID).
Instance IDs represent a unique identifier for each instance of the app and are stored until you request that Google or Apple delete the respective ID. The data is then removed from live and backup systems within the timeframe specified by the provider. Data processing when using Firebase services and APNs is based on Article 6(1)(f) of the GDPR (e.g., stability/error analysis and secure delivery of technical push notifications) and/or Article 6(1)(b) of the GDPR (provided that push notification delivery is an essential part of service provision).
To the extent that personal data is transferred to third countries (such as the United States), this is done only in compliance with the requirements of Articles 44 et seq. of the GDPR. Recipients may include, in particular, IT service providers or hosting providers, providers of push notification services, and providers of crash/error analysis services. App store providers may act as independent data controllers and process data in accordance with their own privacy policies.
3. Special Categories of Personal Data
We generally process special categories of personal data as defined in Article 9 of the GDPR (such as health data) only if it is permitted or required by law, or if you have given your explicit consent.
Note on biometrics: If you enable Face ID/Touch ID or comparable biometric unlocking features on your device, biometric processing typically takes place exclusively at the operating system or device level. In such cases, we generally do not receive any raw biometric data, but only the result (e.g., "successful/failed") of the local device authentication.
4. Provision of App Services by Data Processors
For the processing of personal data in connection with the use of the app, external service providers (processors) may be engaged to process personal data on our behalf. Appropriate contracts have been entered into with these service providers. If individual providers act as independent data controllers (for example, app stores or parts of the push notification infrastructure), they process this data in accordance with their own privacy policies.
5. How Long We Retain Your Personal Data
Unless otherwise specified in this Privacy Policy, we generally store the personal data collected in connection with the use of the app for the duration of the respective contractual relationship. In addition, we store your personal data only to the extent required by mandatory statutory retention obligations. If we no longer need your personal data for the aforementioned purposes, it will be blocked for the duration of the statutory retention periods and will not be further processed; once the retention periods have expired, the information will be deleted.
For example: Security or system logs are generally stored for seven days (as described in Section 2c), although in individual cases, a different retention period may be necessary for IT security. Crash and error reports (for example, via Crashlytics) are generally processed until the error is resolved or in accordance with the provider’s parameters and are subsequently deleted or anonymized. We store PushTAN authorization logs only to the extent necessary for verification, security, and legal obligations. Tokens and instance IDs are stored until uninstallation or a deletion request is made, or in accordance with the respective provider’s policy (see Section 2e).
6. Your Rights
You have the right to request information from us at any time regarding whether we are processing your personal data. Provided that the legal requirements are met, you also have the right to request that we correct and/or complete, delete, or restrict the processing of the relevant personal data, as well as the right to data portability and the right to object to our processing of your personal data. If you have given consent to the use of personal data, you may revoke this consent at any time with future effect.
To exercise your rights, you may contact us informally:
ABN AMRO Bank N.V. Frankfurt Branch
Privacy Officer
Postfach 10 06 32
60006 Frankfurt am Main
Email: datenschutz@de.abnamro.com
You also have the right to file a complaint with the competent data protection authority. The Hessian Data Protection Commissioner, located at Wilhelmstraße 7, 65185 Wiesbaden, is responsible for the Bank. For more information, please visit https://www.datenschutz.hessen.de.
To the extent that processing is based on your consent (for example, optional push notifications or optional features), you may revoke your consent at any time. You may also be able to grant or revoke consent through the system settings on your device (for example, push notifications).
7. Pflicht zur Bereitstellung von Daten / Folgen der Nichtbereitstellung
Providing certain data is technically necessary for using the app and, in particular, for pushTAN authorization. This includes, in particular, an internet connection, token/instance IDs for push delivery, and security-related log data. If you do not provide this data or deny the required permissions, you may not be able to use the app or the pushTAN feature, either in whole or in part.
8. Automatisierte Entscheidungen / Profiling
There is no automated decision-making within the meaning of Article 22 of the GDPR.
9. Herkunft der Daten
We process data that you provide in the app or that is generated through your use of the app (usage/log data), as well as technical data provided by your device or operating system and the push/crash services used (for example, tokens, instance IDs, or crash information).
10. Kontaktdaten Datenschutzbeauftragter
Für Fragen zum Thema Datenschutz (einschließlich der Geltendmachung Ihrer Rechte) können Sie sich auch direkt an unseren Datenschutzbeauftragten wenden. Die Kontaktdaten sind:
ABN AMRO Bank N.V. Frankfurt Branch
Privacy Officer
Postfach 10 06 32
60006 Frankfurt am Main
Telefon: +49 69 2177-0
E‑Mail: datenschutz@de.abnamro.com
7. Obligation to Provide Data / Consequences of Failure to Provide Data
8. Automated Decisions / Profiling
There is no automated decision-making within the meaning of Article 22 of the GDPR.
9. Source of the Data
We process data that you provide in the app or that is generated through your use of the app (usage/log data), as well as technical data provided by your device or operating system and the push/crash services used (for example, tokens, instance IDs, or crash information).
10. Contact Information for the Data Protection Officer
If you have any questions regarding data protection (including how to exercise your rights), you can also contact our Data Protection Officer directly. The contact information is as follows:
ABN AMRO Bank N.V. Frankfurt Branch
Privacy Officer
Postfach 10 06 32
60006 Frankfurt am Main
Phone: +49 69 2177-0
Email: datenschutz@de.abnamro.com
As of June 2026