13. Security
We are committed to ensuring that your information is secure with us and with the third parties who act on our behalf. For more information about the steps we are taking to protect your information please contact us at +34 951 81 80 01
Schedule A – Schedule of Purposes of Processing
We will only use and share your information where it is necessary for us to carry out our lawful business activities. Your information may be shared with and processed by other efpg companies. We want to ensure that you fully understand how your information may be used. We have described the purposes for which your information may be used in detail below:
A. Contractual necessity
We may process your information where it is necessary to enter into a contract with you for the provision of our products or services or to perform our obligations under that contract. Please note that if you do not agree to provide us with the requested information, it may not be possible for us to continue to operate your policy and/or provide products and services to you. This may include processing to:
a) assess and process applications for products or services;
b) provide and administer those products and services throughout your relationship with efpg, including opening, setting up or closing your policies or products; collecting and issuing all necessary documentation; executing your instructions; processing transactions, including transferring money between policies; making payments to third parties; resolving any queries or discrepancies and administering any changes. Calls to efpg companies may be recorded and monitored for these purposes;
c) manage and maintain our relationships with you and for ongoing customer service. This may involve sharing your information with other efpg companies to improve the availability of our services.
d) communicate with you about your policy(s) or the products and services you receive from us.
B. Legal obligation
When you apply for a product or service (and throughout your relationship with us), we are required by law to collect and process certain personal information about you. Please note that if you do not agree to provide us with the requested information, it may not be possible for us to continue to operate your policy and/or provide products and services to you. This may include processing to:
a) confirm your identity;
b) perform checks and monitor transactions and location data for the purpose of preventing and detecting crime and comply with laws relating to money laundering, fraud, terrorist financing, bribery and corruption, and international sanctions. This may require us to process information about criminal convictions and offences, investigate and gather intelligence on suspected financial crimes, fraud and threats and share data with law enforcement and regulatory bodies;
c) assess affordability and suitability of initial applications and throughout the duration of the relationship, including analysing customer credit data for regulatory reporting;
d) share data with third parties to help recover funds that have entered your policy as a result of a misdirected payment by such a third party;
e) share data with police, law enforcement, tax authorities or other government and fraud prevention agencies where we have a legal obligation, including reporting suspicious activity and complying with court orders;
f) deliver mandatory communications to customers or communicate updates to product and service terms and conditions;
g) investigate and resolve complaints;
h) conduct investigations into breaches of conduct and corporate policies by our employees;
i) manage contentious regulatory matters, investigations and litigation;
j) perform assessments and analyse customer data for the purposes of managing, improving and fixing data quality;
k) provide assurance that efpg has effective processes to identify, manage, monitor and report the risks it is or might be exposed to;
l) investigate and report on incidents or emergencies on efpg’s properties and premises;
m) coordinate responses to business-disrupting incidents and to ensure facilities, systems and people are available to continue providing services; and
n) monitor dealings to prevent market abuse.
C. Legitimate interests of efpg Companies
We may process your information where it is in our legitimate interests to do so as an organisation and without prejudicing your interests or fundamental rights and freedoms.
a) We may process your information in the day-to-day running of our business, to manage our business and financial affairs and to protect our customers, employees and property. It is in our interests to ensure that our processes and systems operate effectively and that we can continue operating as a business. This may include processing your information to:
I. monitor, maintain and improve internal business processes, information and data, technology and communications solutions and services;
II. ensure business continuity and disaster recovery and respond to information technology and business incidents and emergencies;
III. ensure network and information security, including monitoring authorised users’ access to our information technology for the purpose of preventing cyber-attacks, unauthorised use of our telecommunications systems and websites, prevention or detection of crime and protection of your personal data;
IV. provide assurance on efpg’s material risks and report to internal management and supervisory authorities on whether efpg is managing them effectively;
V. perform general, financial and regulatory accounting and reporting;
VI. protect our legal rights and interests;
VII. manage and monitor our properties for the purpose of crime prevention and prosecution of offenders, for identifying accidents and incidents and emergency situations and for internal training; and
VIII. enable a sale, reorganisation, transfer or other transaction relating to our business.
b) It is in our interest as a business to ensure that we provide you with the most appropriate products and services and that we continually develop and improve as an organisation. This may require processing your information to enable us to:
I. identify new business opportunities and develop enquiries and leads into applications or proposals for new business and to develop our relationship with you;
II. send you relevant marketing information (including details of other products or services provided by us or other EFPG companies which we believe may be of interest to you);
III. understand our customers’ actions, behaviour, preferences, expectations, feedback and financial history in order to improve our products and services, develop new products and services, and improve the relevance of offers of products and services by EFPG companies;
IV. monitor the performance and effectiveness of products and services;
V. assess the quality of our customer services and provide staff training. Calls to EFPG companies may be recorded and monitored for these purposes;
VI. perform analysis on customer complaints for the purposes of preventing errors and process failures and rectifying negative impacts on customers;
VII. compensate customers for loss, inconvenience or distress as a result of services, process or regulatory failures;
VIII. identify our customers’ use of third-party products and services in order to facilitate the uses of customer information detailed above; and
IX. combine your information with third-party data, such as economic data in order to understand customers’ needs better and improve our services.
We may perform data analysis, data matching and profiling to support decision-making with regard to the activities mentioned above. It may also involve sharing information with third parties who provide a service to us.
c) It is in our interest as a business to manage our risk and to determine what products and services we can offer and the terms of those products and services. It is also in our interest to protect our business by preventing financial crime. This may include processing your information to:
I. carry out financial, credit and insurance risk assessments;
II. manage and take decisions about your policies;
III. carry out checks (in addition to statutory requirements) on customers and potential customers, business partners and associated persons, including performing adverse media checks, screening against external databases and sanctions lists and establishing connections to politically exposed persons;
IV. share data with third parties, fraud prevention agencies and law enforcement agencies;
V. trace debtors and recover outstanding debt;
VI. for risk reporting and risk management.
Application decisions may be taken based on solely automated checks of information from third parties and internal EFPG records. For more information on how we access and use information from credit reference and fraud prevention, agencies see Section 11 – Due Diligence and fraud prevention agencies in this document.