1. These rules regulate the process of processing data on individuals by the ARDSHINBANK ՕSC (hereinafter referred to as the Bank).
2. The Bank shall process and protect individual’s personal data in accordance with the Law on Protection of Personal Data (hereinafter referred to as the Law).
The definitions used in these rules shall have the meaning determined by the Law on Protection of Personal Data.
3. Personal data of individuals shall be processed in the presence of any of the following grounds:
1) with the consent of the individual or his representative (if such power is specially stipulated by the power of attorney),
2) for fulfilling the obligations within those assumed as part of the contractual relations,
3) for protecting vital interests of individuals,
4) for performing a task proceeding from public interest or for performing official duties provided to the authorized body,
5) for protection of legal interests pursued by the Bank.
4. By using the Website (Bank’s official website: ardshinbank.am, Bank’s mobile app and social networks) or through the use of other technical and software means, an individual shall accept these rules published on the Website and give his consent to the use of individual’s personal data in the manner described in these rules,
5. Individuals’ personal data shall be used by the Bank for the following purposes:
1) identification of individuals,
2) authentication of personal data submitted by individuals (verification, clarification, updating),
3) responding to inquiries of individuals, providing updates and sending important information regarding the service,
4) improving services provided by the Bank and offering new services based on the preferences and conduct of individuals,
5) ensuring service quality meeting the requirements of individuals, including improving the Bank’s Website for the purpose of increasing the quality of service,
6) fulfilling the obligations stipulated by the agreement signed between the Bank and the individuals,
7) revealing possible problems and fraud and managing further processes originating from that,
8) notifying about change (changes) in the information contained in the terms of banking services,
9) protecting Bank’s legal interests, including ensuring information, including cyber security requirements,
10) for the purpose of ensuring the requirements of the Republic of Armenia legislation.
6. For the purpose of improving the Website’s operation, collecting general statistical information on the use of the Website, as well as providing more client-centered services, some information about the individual can be automatically collected and stored, including, but not limited to information on the device used by the individual (for example, the type/model of the device, the type of browser, including its next version (Google Chrome, Safari, etc.)), the operational system, including its next version (iOS, Android and others), the Website’s pages visited by the individual, the period that the individual spends on the Website, geographical data (the Website’s visits according to countries), the Website’s visits from various electronic platforms (other websites, apps, etc.), the individual’s activity on the Website for understanding and remembering his preferences.
The information indicated in this clause shall be received on all individuals in a consolidated form. This information is quantitative, it does not contain any personal information about any specific individual and can in no case be sufficient or enable to identify the individual.
7. To ensure security of personal data collected, the Bank shall undertake appropriate technical and software and administrative and organizational protective actions in accordance with the regulations of the Republic of Armenia legislation, including the Central Bank of Armenia, as well as internal legal acts regarding information security.
8. The individual’s personal data shall be stored until the goals stipulated by clause 5 of these rules are fulfilled.
9. The Bank may transfer personal data of an individual to third persons with the individual’s consent or in cases provided for by law.
10. In the case provided for by the Republic of Armenia legislation, a written application on correction, destruction and (or) termination of collection or use of individual’s personal data provided to the Bank shall be studied and processed in the manner established by the Republic of Armenia legislation and (or) the Bank’s internal legal acts, if the Bank’s rights for achieving legal purposes required for processing personal data are not restricted by that. The response to the application shall be provided within ten business days following its receipt. The written application may also be sent to the electronic address non-compliance@ardshinbank.am.
11. Any amendment to these rules shall come into effect from the moment of its placement on the Bank’s official website.