The Bank
Privacy Policy and Cookies Settings
Privacy Policy
PRIVACY POLICY OF STOPANSKA BANKA AD – SKOPJE
Protection of privacy and confidentiality of client data is of significant importance to Stopanska Banka AD – Skopje (hereinafter: “Bank/SB”), taking into consideration the nature of banking operations, as well as the data which banks collect in the course of their regular activity.
The Privacy Policy of SB has a purpose to explain the process of collecting, using, processing, disclosing, protecting and destroying (“the life cycle“) of processed personal data.
Each activity related to personal data is performed by SB in accordance with the provisions of the Law on Personal Data Protection and the by-laws passed in relation to this Law, as well as the legal framework that is implemented by the European Union legislation regarding data protection (Eng.: “General Data Protection Regulation-GDPR”).
For the purposes of personal data protection, the Bank has appointed a Personal Data Protection Officer (contact data below), whom subjects may contact about issues related to the processing of their personal data and about the realization of their legal rights. The Bank also has a complete team of legal experts and experts in the IT domain, dedicated to the work on personal data protection of subjects. Additionally, the protection of privacy and confidentiality of client data in the Bank is part of the Code of Ethics of SB, the provisions of which are mandatory to all employees of SB.
This Policy is consisted of the following chapters:
The role of Stopanska Banka AD – Skopje as per the Law on Personal Data Protection
Protection against phishing fraud
Direct marketing
Contact data of the Bank and the Personal Data Protection Officer
ANNEX number 2: Privacy Policy for the employees of Stopanska Banka AD – Skopje
ANNEX number 3: Policy for privacy of the candidates for employment with Stopanska Banka AD – Skopje
1. THE ROLE OF STOPANSKA BANKA AD – SKOPJE AS PER THE LAW ON PERSONAL DATA PROTECTION
In accordance with the provisions of the Law on Personal Data Protection, SB acts as a Controller, i.e. a legal entity that determines the purposes and means of processing the personal data of data subjects.
2. GENERAL PRINCIPLES
As a controller, SB provides protection and processing of personal data in accordance with the enforceable legal framework that it monitors on regular basis, and for that purpose it makes sure that personal data of subjects are processed in accordance with the following principles:
- Lawfulness, fairness and transparency – personal data are processed in accordance with the law, in sufficient manner and transparently in relation to the personal data subject;
- Purpose limitation – personal data are collected for specific, clear and legitimate legally determined purposes and they shall not be processed in a manner that is not in accordance with those purposes;
- Data minimization – personal data that are processed are accurate, relevant and limited to what is necessary in relation to the purposes for which the data are processed. This principle is also relevant in relation to the access to processed personal data;
- Accuracy – personal data are accurate and, where applicable, updated, and all appropriate measures are taken for prompt deleting or correction of the data which are inaccurate or incomplete;
- Storage limitation – personal data are kept in a form that enables identification of personal data subjects, for periods not longer than the necessary ones for the purposes for which they are processed. Personal data may be kept longer than the determined period for keeping only if processed for archiving purposes of public interest, for scientific or historical research or for statistical purposes in accordance with the law, by applying appropriate technical and organizational measures for protection of the rights and liberties of personal data subjects;
- Integrity and confidentiality – personal data are processed in a manner that provides an appropriate level of security of the personal data, including protection from unauthorized or illegal processing, or accidental destruction or damaging, by applying appropriate technical or organizational measures; and
- Accountability – the Bank is responsible for the reconciliation of the above-mentioned principles and can demonstrate the reconciliation at any time, especially upon request/ during control of the Internal auditors, upon request of the Personal Data Protection Officer or the Agency for Personal Data Protection.
The above-mentioned principles of processing are applied cumulatively, all together throughout the whole cycle of personal data processing.
3. CATEGORIES OF PERSONAL DATA THAT ARE PROCESSED ON PART OF THE BANK
SB collects, keeps and processes personal data, which are communicated or have already been communicated to the Bank by potential and/ or current clients and generally, by persons that perform business activities with the Bank at any capacity and in all phases of the business cooperation, in the context of products/ services provided by the Bank or via the Bank, as well as data that arise from Statements of bank accounts and/ or from previous loan products of the above-mentioned category of persons, from the banking system.
Primary source of personal data of the Bank are data that subjects provide to the Bank themselves, in the course of completing (fulfilling) the Application for client registration at the first business contact with the Bank (in case of clients).
We would like to point out that the Bank is processing personal data only within the volume that is necessary for the purposes of processing.
Specifically, SB may process the following personal data:
i. Personal data submitted by subjects, like for example: identification data (name and surname, date and place of birth, ID card data or passport data, personal ID number etc.), demographic data (gender, nationality, marital status), contact data (postal address, phone number, e-mail address), financial data (information in relation to the salary and property, taxes etc.), data about access to electronic applications (for ex. logging into e-bank/ m-bank), data of electronic identity identification (for ex. digital signature), data about geolocation of devices (for ex. at remote payment via mobile phones, tablets, PCs etc.) and the like.
Personal data subjects are obliged to immediately notify the Bank about any type of change in relation to the abovementioned data.
ii. Personal data the Bank collects, like for example:
v Personal data in relation to the implementation of analysis measures, disclosure of certain persons or subjects against which restrictive financial measures were pronounced, as well as for prevention of money laundering and financing of terrorism;
v Personal data for monitoring and assessment of the creditworthiness, managing risks of the Bank and in general – for the needs of contractual or business relations of clients with SB;
v In accordance with the enforceable legal framework for submitting data to competent authorities;
v In the context of the correspondence and general communication of clients with the Bank;
v Data of economic nature, which provide assessment of the investment, the financial status and the behavior of clients;
v “cookies” and auxiliary technologies that enable access to and use of specific sites and/ or websites;
v Information provided by supervisory, judicial and other public and independent bodies, related to criminal verdicts, violations, implementation of public interest protective measures, confiscations and pledges;
v Data involving clients that are publicly accessible via the Internet or in another manner;
v Data on employees of SB, persons on training or volunteering with SB, in accordance with the enforceable legal framework in this domain (Law on egistrations in the labor domain, Law on Labor Relations etc.), explained in more detail in Annex 2 of this Policy;
v Data about employment candidates of SB, explained in more detail in Annex 3 of this Policy;
v Personal data collected throughout the use of the website and the digital services of the Bank, explained in more detail in Annex 1 of this Policy.
Personal data processed by SB are kept in paper form and/ or in electronic form.
PERSONAL DATA OF MINORS (UNDERAGE PERSONS)
The Bank is undertaking appropriate measures for protection of personal data of minors, in accordance with regulations. Data of minors are kept by SB only in case they were provided by the persons - guardians of the minors, and only for the needs of the business relations with the Bank in favor of the minors, except if not prescribed otherwise in accordance with the law (like for ex. in exceptional cases, if a minor aged 16 is with a married status, in which case he/ she acquires a status of ‘capable to work’).
We would like to mention that the products and services provided by SB are in no case intended for use by minors. Furthermore, SB is not providing IT services to children in the context of Article 12 of the Law on Personal Data Protection.
4. PURPOSES OF PERSONAL DATA PROCESSING
SB is processing personal data of subjects that are collected in the course of establishing/ extending the business relations with the Bank, for the following purposes:
In the context of realization of the agreement or prior to its signing, especially:
1. To confirm the identity of the client;
2. To realize communication with clients in the pre-agreement activity process or about issues related to the business relations with SB, as well as to undertake actions for collection of overdue claims of SB;
3. To prepare, conclude and manage the Agreement with SB and to take actions for fulfillment of obligations towards clients, as well as for the purposes of realization, management, monitoring and processing of client transactions i.e. to efficiently provide the required product/ service by SB;
4. To provide realization of transactions that are processed via the electronic banking system (transactions realized via the digital services);
5. To assess the accuracy of the offered product/ service and especially to assess the accuracy at providing investment and auxiliary services, as well as to provide accurate information, to supervise the management and monitoring of investment products and to include the client, if possible, in the competent client market for the specific type of product.
B. As part of the reconciliation of SB with the obligations determined by the enforceable legal and regulatory framework, especially:
1. To prevent and suppress money laundering and terrorist financing and to prevent fraud against the Bank and/ or its clients, as well as for any other illegal action i.e. for identification, verification and monitoring of the business activities of clients.
2. To assess the creditworthiness of clients, where necessary, for disruptive flow of the business relations with clients of the Bank.
3. To assess the compatibility and for every other assessment or categorization of the client in relation to products and services.
4. To register and realize client orders for transactions with financial instruments, including the obligation to register orders provided by phone.
5. To register and keep records of the Bank’s communications by phone (or of third parties the Bank communicates with for collection of mature claims), for the purpose of informing its debtors about their remaining debts.
6. To document requests of clients (for ex. Request for debt restructuring due to inability of the client to repay the debt) and the assessment made therein on part of the Bank.
7. To comply with its obligations arising from the enforceable legal framework and from the decisions of supervisory and court authorities.
8. To detect and transfer information to competent public authorities as well as legal entities with public authorizations, when necessary, in accordance with enforceable legislation.
C. In the context of the legislative and regular activity of the Bank and for protection of its rights and legal interests, especially:
1. To develop and/ or improve products and services offered by the Bank in relation to preferences of clients and the regular realization of transactions.
2. To respond to Requests/ Complains of clients.
3. To assess and manage risks to the activity of the Bank.
4. To prevent criminal acts (for ex. frauds) and to identify and collect data of illegal activities, for physical security of persons and property (including the video surveillance system);
5. To transfer, to provide (directly or as a collateral) and/ or to provide securities for any or all collateral rights, claims, guarantees, securities in accordance with the agreement of the client with SB, to any third party (s);
6. To realize its legal claims with court institutions or other authorities for out-of-court/ alternative dispute resolution,
7. To assess and optimize security procedures, IT systems etc.
D. Based on a provided consent:
1. To send information about new products and/ or services offered by SB corresponding to the interests and preferences of clients. In this case, clients have the right to withdraw the consent at any time, without compensation, via several channels: directly in the Branch by updating the Application for client registration, or by withdrawing the consent at the e-banking/ m-banking digital services, without any influence on the enforceability of any processing that may have taken place based on the consent before it was withdrawn.
2. To better understand the manner of use of SB website and the interaction with its contents, by use of “cookies”.
3. To improve the services it provides via the website, for improved user experience.
4. To improve the effectiveness and the influence of promotional activities of the Bank displayed on other websites and platforms.
In relation to the above-mentioned we would like to point out that no consent is required in the following cases:
• For realization of an agreement concluded with SB or for undertaking required activities in relation to the Request which the client submitted prior to concluding the agreement;
• For fulfillment of the legal obligation of SB as controller;
• For protection of the essential interests of clients and other parties;
• For realization of activities of public interest; and
• When processing is required for the legitimate interests of SB or a third party, except when those interests do not prevail over the interest or basic rights and liberties of the subjects for which personal data protection is required, especially when the subject is a child.
Remark in relation to the automated decision-making, including profiling:
In specific cases, when required for the purposes of concluding or fulfilling the agreements between clients and the Bank, for the purposes of determining the creditworthiness or to prevent a fraud in payments, based on personal data received directly from clients or from another database/ institution, or in accordance with expressed approval by the client, personal data processing may be performed also via automated procedures that result into decisions established on statistical analysis of individual parameters that enable objective assessment of requests of clients. Furthermore, the Bank may conduct profiling of clients (segmentation according to certain characteristics) for accurate direct marketing, and to provide information to clients in accordance with their interests.
In these cases, clients have the right not to be subject to decision established only by automatic processing, including the profiling that results in legal consequences or in a similar manner significantly affects the client, except in case the decision:
а) is required for concluding or fulfilling the agreement between the personal data subject and the Bank.
b) is allowed in accordance with the enforceable legal framework, which also stipulates appropriate measures for protection of the rights and liberties and the legitimate interests of the subject; or
c) is established based on expressed consent by the subject.
The Bank is applying appropriate measures for protection of the rights and liberties and the legitimate interests of personal data subjects, and at least the right of providing a human intervention on part of SB, the right to express the personal attitude and the right to dispute those decisions. This type of Decisions is not established on separate categories of personal data, except in the cases as permitted in accordance with the Law on Personal Data Protection.
5. OTHER PARTIES TO WHICH THE BANK MAY DISCLOSE PERSONAL DATA OF SUBJECTS
The Bank is disclosing personal data to public authorities in accordance with their legal authorization, within the frame of NBG Group, for the purposes of the legitimate interests of SB and the Group, and to third parties with which the Bank cooperates within the scope of its regular operations.
More specifically, the Bank may disclose personal data of subjects only in case it is obliged in accordance with the law, a decision of a competent authority, or to third parties, i.e. to the following category of personal data users: government authorities or legal entities established in the country to perform public authorizations, an agency or other bodies and to third parties (individuals or legal entities) that act upon order or in the name of the Bank, such as:
(а) the companies of NBG Group, as well as all parties (individuals and legal entities) that cooperate with NBG in any form, acting in the name and for account of the Bank. For the purposes of the legitimate interests of SB and NBG Group (primarily for more efficient and safer personal data processing, obligations for reporting on group level or passing of strategic decisions within the frame of the Group), the Bank may disclose personal data of its clients within the frame of NBG Group;
(b) third parties (individuals and legal entities) that cooperate with SB in any form, acting in the name and for account of the Bank, to achieve the purpose for processing the agreement, including the following categories:
1. Companies that inform debtors and/or guarantors about their debts prior to or after the finalization of preparation activities required for out-of-court and in-court procedures for collection of their remaining debts by the Bank;
2. Companies – suppliers of IT equipment and services;
3. Security Agencies of property and people;
4. Companies for consulting services;
5. Companies – data providers;
6. Companies for transport of documentation, and for its keeping, archiving, printing and destroying;
7. Real estate agencies;
8. Companies preparing payment cards;
9. Companies that provide data keeping.
(c) Insurance companies and insurance representatives in the context of providing insurance products;
(d) Social Insurance bodies, public institutions and institutions such as the Central Register, the Cadaster, the Macedonian Credit Bureau etc.
(e) Institutions for realization of interbank and other payment operations – MIPS and KIBS, financial institutions, institutions for processing transactions with payment cards, payment institutions, electronic money issuers, stock-exchange markets, depositors, custodians, settlement companies.
(f) Supervisory, court, independent and other bodies of national and European level, for fulfillment of legal obligations of the Bank and the Group, in competence in accordance with enforceable regulations or by court decision, such as the National Bank, the Securities Commission, the Public Revenue Office, the Financial Investigations Office and other supervisory agencies and regulators, the Ministry of Internal Affairs, courts, prosecutors, enforcers, notaries, lawyers and law offices.
(g) Audit and consulting companies.
(h) Companies for acquisition of claims.
(i) Companies that provide electronic identification services and are registered in the Register of confidential services providers, in the part of verification of clients related to the use of digital services.
(j) Companies that provide cloud services.
The Bank may disclose personal data to subjects of appropriate supervisory agencies, police authorities, public courts or other public regulatory bodies and agencies, wherever required in accordance with the stipulated legal regulations, on regular or temporary basis, as result of previously received requests or without a received request or another notification.
The Bank is cooperating only with third parties that may implement appropriate technical and organizational measures, as per regulations and standards of the Bank, in due course providing appropriate protection of personal data. In these cases, the third parties (personal data processors) are obliged with a specific Agreement that makes sure personal data are processed only in accordance with the instructions provided by the Bank, and by obeying the protection technical and organizational measures that provide security of personal data.
*Remark: In accordance with the Law on obligation relations (Article 426 paragraph 1), SB may transfer and/ or sell the claims on debtors of SB, in the course of which it is inevitable to also transfer personal data of involved parties. In such situations, no consent is required from the debtor, but SB is obligatorily notifying debtors about the assignment of claims.
6. TRANSFER OF PERSONAL DATA OF SUBJECTS TO OTHER COUNTRIES
The Bank may transfer personal data it processes within the frame of NBG in accordance with the provisions of the Law on Personal Data Protection.
If required, for example for the purposes to realize the Agreement for use of services of external entities, when the service provider is an external entity from abroad, the Bank may transfer personal data in other countries – members of EU, NATO or EEA, and it notifies therein the Agency for personal data protection in accordance with the Law on Personal Data Protection. The Bank also has the right to transfer personal data to other countries that are not member - countries of EU, NATO or EEA, upon previous approval for transfer of personal data from the Agency of personal data protection i.e. upon received Decision for accuracy on part of the Agency, in case they estimated that the third country provides an appropriate level of personal data protection, as well as by providing protection mechanisms such as standard contracting clauses within the frame of agreements for transfer of data
7. RETENTION PERIOD OF PERSONAL DATA
Basic principle in relation to keeping the personal data is that the Bank is keeping them in accordance with enforceable legal regulations, but not for longer periods than the required ones for the purposes for which they are processed. The period for keeping is related to the basis for which personal data are processed. For example, if personal data processing is required for fulfillment of legal obligations, most frequently the period of keeping is determined within the specific law (e.g. the client’s file of all bank clients is kept for 10 years from the last transaction in accordance with the Law on AML/TF).
As exception, the Bank may keep the data for longer periods than the stipulated ones, in case it receives requests from competent court authorities or other regulatory bodies, as well as for the needs of conducting active court procedures in which the Bank is involved. In those cases, the period for keeping the data is extended until the moment the court procedure is completed and final decision is passed.
Upon expiry of the period for keeping the data, SB is destroying the data in accordance with relevant Procedure of the Bank, by obeying the provisions of the enforceable regulations. Furthermore, it makes sure that this process is obeyed on part of third parties that provide services in the name and for account of the Bank and the other business associates.
8. RIGHTS OF PERSONAL DATA SUBJECTS
Personal data subjects have a certain set of rights determined in accordance with the Law on personal data protection, explained below.
- Right to be informed (Article 16, 17 and 18 of the Law)
SB is informing personal data subjects about the process of data processing, the purposes of processing, the categories of personal data that are processed, the users/ categories of users in case there are any, the purpose of cross-border transfer (in case transferred, information about appropriate protection measures with a possibility of receiving a copy or information where they are available), the time period for keeping the personal data/ criteria used for determining that period, the legitimate interests of SB in case the processing is made in accordance with this basis for personal data processing, the existence of an automated deciding process, including profiling, as well as information about the rights of personal data subjects. In accordance with the transparency principle, SB is informing personal data subjects about issues related to personal data via several channels: i. brief information within the Application for registration of clients, which is the first formal step at the establishing of business relations, ii. this Privacy policy, which is publicly available on the website of SB and in printed form in all branches, iii. the flyer for personal data protection intended for the clients, which are available in all branches, and via iv. a notification about video surveillance in all the places in which the Bank has installed cameras.
We would like to notify that SB is not obliged to submit this information in the cases as stipulated in accordance with the Law on Personal Data Protection (Article 18 paragraph 5).
- Right to access (Article 19 of the Law)
Personal data subjects have the right to receive confirmation from SB in relation to whether their personal data are processed and in case so, they have to right to receive information in accordance with the right to information.
- Right to rectification (Article 20 and 23 of the Law)
Personal data subjects have the right to a correction of their erroneous personal data.
- Right to deletion (Article 21 of the Law)
Personal data subjects have the right to request from SB to delete their personal data in case the conditions are fulfilled in accordance with the Law on Personal Data Protection. Upon request of the personal data subject, SB shall delete them only if the personal data are no longer required for the purposes for which they were collected or, where appropriate, in case the personal data subject withdraw the consent and the personal data were processed based on the provided consent (in case of direct marketing). Of essential importance is to mention that, in accordance with the Law on AML/TF, banks keep client files of all clients for a period of 10 years from the last transaction / attempted transaction.
By deleting the data, SB makes sure they are also deleted by third parties with which the Bank cooperates and processes those data.
- Right to restrict processing (Article 22 of the Law)
Personal data subjects have the right to require from SB to limit their personal data processing in case the conditions are met in accordance with the Law on Personal Data Protection, including under condition the processing is no longer required for the purposes of reconciliation with the legal obligation that requires processing in accordance with the law that is being applied in relation to SB.
- Right to object (Article 25 of the Law)
Personal data subjects have the right to submit an objection to the Bank at any time, based on the specific situation related to them, when their personal data processing is based on the legitimate interest of the Bank or a third party or in public interest, including profiling based therein. In case personal data is processed for the purposes of direct marketing, subjects have the right at any time to submit an objection for their personal data processing and to request from the Bank to stop the processing of personal data for those purposes.
- Right related to automated decision making and profiling (Article 26 of the Law)
Personal data subjects have the right not to be subject to a decision based only upon automatic processing of their personal data, including profiling that results in legal consequences or in a similar manner significantly influences the client, except in the cases as stipulated in accordance with the Law on Personal Data Protection.
- Right to data portability (Article 24 of the Law)
Personal data subjects have the right to receive their personal data, which they have provided to the Bank in a structured, usually used, machine readable form, and they have the right to transfer them to another controller without being disrupted by the Bank, in case conditions are met in accordance with the Law on Personal Data Protection.
Please be notified that the Request for realization of the rights is available in print form in the Branches of the Bank and in electronic form, at the following link: https://www.stb.com.mk/naselenie/zashtita-na-licni-podatoci/ and it may be submitted personally in the Branches, wherein you are required to identify yourself so that we can confirm your identity, prior to proceeding to process your request.
Prior to submitting the Request for realization of the rights, all personal data subjects are encouraged and asked to read the relevant legal provision quoted above, which contains the limitations in relation to when and how the rights are realized, all to avoid unnecessary and unfounded requests to the Bank.
At the same time, we would like to mention that the Bank provides the required information without compensation, except in the case when the Requests are clearly unfounded or excessive, especially if the same requests are repeated. In these cases, the Bank will either refuse to act on the Request or will charge a fee considering the volume, complexity and time required to provide the information or act on the Request, for which you will be notified accordingly.
9. PROTECTION AGAINST PHISHING
Phishing is a type of fraud that takes into account a set of activities of unauthorized users by using false messages via SMS, e-mail or false websites, trying to receive confidential personal data from users, like for example their PRN, username, passwords, PIN numbers etc.
For the purposes to protect clients from phishing, i.e. from attempts for fraud by unauthorized third parties, which are trying, in different manners, to acquire personal data without authorization, the Bank is regularly publishing notifications in public, for the purposes to pay attention to these malevolent attempts, and it provides instructions as to how clients can recognize an attempt of fraud, take measures and protect against risk, accordingly.
The Bank is pointing out that, in accordance with internal procedures, it does not require from its clients, via phone or e-mail, to disclose their personal data (for ex. their PRN, ID client number, transaction account, username, password etc.). In case the client receives such a request, or a similar request, it should be deleted and the Bank should immediately be notified accordingly.
10. VIDEO SURVEILLANCE SYSTEM
The bank is performing video surveillance only in the premises as sufficient for fulfilling the purposes for which video surveillance was installed, that is, to protect the life and health of people, protect the property, protect the life and health of employees, and/or ensure control of the entry and exit from the office premises.
The manner of performing video surveillance is regulated in more detail by the Rulebook on the method of conducting video surveillance in SB. This Rulebook was prepared based on the Law on personal data protection and the relevant by-laws adopted based on this Law.
The recordings made during video surveillance are kept until the purpose is fulfilled for which video surveillance is performed, but not longer than 30 days. After expiration of this period, recordings are automatically deleted from the video surveillance system. Video surveillance recordings can be stored for a longer period if the storage is in accordance with the law that contains protective measures and other measures to protect the rights and liberties of subjects of personal data, but not longer than the fulfillment period of the purpose. Also, recordings can be stored for a longer period when it is necessary to realize the Bank's legitimate interest in conducting appropriate procedures in accordance with the law, and in accordance with internal procedures for the method of storing and deleting recordings. Video recordings that are not deleted automatically, that are kept for a longer period and for which the purpose is fulfilled, are destroyed by a special Commission for the destruction of video material.
In a visible and clear place where the video surveillance is installed, the Bank has an appropriate notification (sticker) that highlights that video surveillance is being carried out, as well as data on the name of the Controller, the purpose of video surveillance, the storage period of the video recordings, the rights of the subjects of personal data, as well as the way to obtain additional information.
11.RECORDING PHONE CALLS
SB is using technical means to record telephone conversations with customers in connection with the execution of transactions by customers within certain organizational units of the Bank, at realization and providing appropriate activities in connection with execution of transactions and requests/ complaints from customers in accordance with the applicable legal framework. In such cases, adequate notification is provided to clients and SB business partners prior to any recording of any telephone call.
12. DIRECT MARKETING
The Bank may use personal data of subjects for the purposes to inform them about products/ services of the Bank or other similar promotional activities that may be of interest to them, only upon receiving explicit consent. The Bank is not selling nor providing personal data for this purpose to uninvolved third parties for their marketing purposes.
We would like to mention that the consent provided for this purpose might be withdrawn at any time without compensation, via three channels:
i. directly in the Branches with the update of the Application for client registration,
ii. via the online services m-banking and e-banking, in the part „My profile“, respectively
13. SECURITY AND PROCESSING OF PERSONAL DATA
Confidentiality of banking and personal data of SB clients is of special importance for all units of the Bank.
SB undertakes all necessary technical and organizational measures to ensure that personal data are protected from accidental loss or disclosure, destruction or misuse. For this purpose, a large set of technical and organizational measures are applied by which the Bank guarantees that personal data are processed strictly in accordance with the Law on Personal Data Protection and that they are processed by well-trained persons with limited and controlled access to them and via secure and modern IT systems.
Each employee is responsible for complying with the Bank's internal personal data protection policies and the Bank has zero tolerance for cases that may jeopardize the trust and privacy of customers and the public in general.
A breach of personal data security may occur in the event of accidental or intentional destruction, loss, alteration, disclosure or access to personal data. In such situations, the Bank notifies the Agency for personal data protection immediately after learning about the breach of security and within 72 hours at the latest. If it considers that it is a situation that is likely to cause high risk to the rights and liberties of customers, and if legal requirements of the Law on Personal Data Protection are met, it also informs all affected individuals accordingly.
14.REVISION OF PERSONAL DATA PRIVACY POLICY
The Bank has the right to update/ amend i.e. supplement this Personal Data Privacy Policy on the website of Stopanska Banka AD – Skopje for the purposes to reconcile with the enforceable legal framework or the standards of NBG Group, in case they are stricter in relation to the stipulated ones in accordance with the national legislation.
In such cases, the Bank shall publish the updated version of the Policy on the website of the Bank www.stb.com.mk, which shall also be available in the Branches of the Bank.
15. CONTACT DATA OF THE BANK AND THE PERSONAL DATA PROTECTION OFFICER
For any issues related to this Privacy Policy of Stopanska Banka AD – Skopje, as well as in relation to the Policies referred to in the Annexes enclosed to this Policy, please contact the Personal Data Protection Officer, in one of the following manners:
- in writing, with a letter that you may submit to SB at the address „Filip Vtori Makedonski” Street no. 6, 1000 Skopje, to the attention of the „Personal Data Protection Officer“;
- electronically, at the e-mail address: privacy@stb.com.mk; or
- at the phone number: (02) / 3295 – 538.
ANNEX number 1: PERSONAL DATA PRIVACY POLICY ON THE WEBSITE AND THE ONLINE SERVICES OF STOPANSKA BANKA AD – SKOPJE
The Bank is collecting data about the visitors/ users of its website (hereinafter: „users“), available at the following link: www.stb.com.mk, in accordance with a prior approval provided by users, and by users of digital services of the Bank (for ex. e-bank, i.e. internet banking, m-banking, the mobile application that includes the TOPSI PAY Service, as well as other services related to requests of users for information about products or services, as well as for submitting comments, objections and complaints on part of users).
The website may include links to other websites that are under responsibility of third parties (individuals and legal entities). SB is in no case responsible for the protection measures and for management of personal data in relation to the abovementioned websites of third parties.
Personal data collected via the website and the internet services of the Bank are needed at the moment the user requires a service or visits the website. SB may process all or part of the provided personal data from users for the purposes to provide the e-services as well as for statistical/ analytical purposes for improvement of the services and the user experience.
SB may collect personal identification data from users in various ways, and in connection with the activities, services, features or resources available on the website and the online services of the Bank.
Users can visit the site anonymously via the web browser's "incognito" mode.
SB collects personal identification data from users only if they themselves agree to submit them to the Bank. They may at any time decline to provide personally identifiable information.
Personal data that the Bank may collect and process when you visit the website or other online services are: name and surname, email address, location information (for example, in order to point you to the nearest ATM or for disclosure or prevention of fraud at initiating payment transactions), username and password, payment card information in physical or digital – tokenized form, etc.
Digitalized (tokenized) form of payment card represents a safe, electronic replacement of the data from the physical payment card (Visa, Mastercard etc.), used for digital payments.
For the purpose of realization of online payments, in accordance with the concluded agreement for payment services with the Bank, clients may, via their mobile devices, use digitalized (tokenized) form of card. With previous registration and consent for use of the services of the digital wallet Apple Pay of Google Pay, comparison is made of the data from the payment card (name and surname, card number, CVV etc.) directly with the abovementioned service providers or directly via the mobile banking application of the Bank.
Tokenization is a process in which the real card number (PAN) is replaced with a unique digital “token” in order for the data to remain kept safe with the bank or the payment system, and not to be exchanged at payments. As additional protection, protection measures are used - encryption of payment data, as well as measures for authentication of the ultimate services beneficiary (for example biometry, PIN, codes etc.) in order to prevent frauds and unauthorized transactions from mobile devices of users.
The Bank may process personal data at the use of the service for electronic identification – oneID, for the purposes of electronic identification and confirmation of the identity of the client, to enable access to bank services, for fulfillment of legal and regulatory obligations, as well as for upgrading the security and for prevention of misuses. Services users previously download the mobile application of the service provider and create user account, based on their previously provided consent.
The oneID service is registered in the Register of providers of confidential services and schemes for electronic identification, kept with the Ministry for information society and administration. Within the frame of the service, identification and contact data may be processed, data for authentication (digital oneID identifier), as well as technical and log data related to the login and the use of the service. The data are processed in accordance with enforceable regulations for personal data protection and by applying appropriate technical and organizational security measures.
The bank does not collect, store, or otherwise process users' biometric data (e.g., fingerprint, face recognition, etc.) when using services for online payments, digital wallets, or electronic identification. Such data remains entirely under the control and ownership of the users of the devices.
SB may also collect identification data of users of technical nature, evert time they visit the website or the online services of the Bank, like for example:
Data tracking, i.e. the name of the Internet browser, the type of device and operating system of the user, technical information about the connection used by the user when visiting the website, presence of malevolent software/ code and/or risky application in the device, data about the internet service provider and the like,
Duration of the visit and duration of a particular problem encountered when using the website or online services,
Pseudonym ID (unique identification number) stored in order to identify the user when he/she revisits the website and online services,
Marketing data, i.e. data that informs the Bank about the advertisements and promotions the user has viewed, etc.,
Geolocation information (IP address), i.e. data about the location from which the website was opened or the online services were accessed.
All these information are collected in order to create a pseudonym user profile and to define an assessment of the risk from fraud in the course of payments via online services. In this manner, the user's personal data are protected and fraud is prevented, as well as misuse of the personal data and the funds of the user.
“Cookies”
The website of SB may use cookies to improve the user experience, to improve the access to certain services of SB, to identify the most visited areas and to evaluate the effectiveness of the website. Cookies are small text files that are sent to the user's computer in order to provide technical functionality of the website and to personalize the user experience (e.g. a cookie that remembers the user's preferences at the next visit to the website).
SB uses „cookies“ that belong to three categories:
· Strictly necessary cookies. These cookies are always active because of the functionality of the website, but also for providing the necessary level of protection and safety via identification and prevention of frauds.
· Analytical cookies. Data processed with these cookies are related to the manner in which the website is used by the users (where does the user come from, which pages he/she visits etc.). These data are not used for marketing or other purposes except for improvement of the user experience of the visitor.
· Marketing cookies. These are „cookies“ set by third parties (for ex. Youtube, Facebook etc.) that enable not only functionality of the service, but also monitoring of interactions, personalization and advertising.
Please find below a review of the cookies used on the website of SB:
For all standard pages:
„Cookie“ | Purpose | Type | Period |
_cookieConsent | Used for the purposes to remember the visitor's choice regarding cookies at the subsequent visit. | Strictly necessary | 3 months |
mobileapp_popup | Remembers that the visitor was already presented the mobile application information (only mobile device). | Strictly necessary (mobile) | 1 day |
_ga | Used by Google Analytics 4 in order to register a unique visitor ID which then generates statistical data about how the visitor uses the website. | Analytical | 2 years |
gaVNYDDYL1MY | Used by Google Analytics 4 for maintenance of the status of the session and to differentiate the sessions of the visitor. It represents a cookie specifical for the measured flow (measurement ID) of the Bank. | Analytical | 2 years |
_fbp | Used by Facebook (Meta) Pixel for identifying visitors and measuring the efficiency of advertising campaigns, as well as to present relevant advertisements to third platforms (Facebook/ Instagram). | Marketing | 3 months |
For pages with application forms:
„Cookie“ | Purpose | Type | Period |
_RequestVerificationToken | Protection against forged requests (anti-CSRF) at submitting forms. HttpOnly. | Strictly necessary | Per session |
_gid | Google Analytics (Universal, via analytics.js) – making difference between visitors. | Analytical | 1 day |
_gat | Google Analytics (Universal) – limiting the requests (throttling). | Analytical | 1 minute |
gaDF9KVYE31V | Second (special GA4 ownership (G- DF9KVYE31V) for monitoring the application process. | Analytical | up to 400 days* |
_zzatgib-w-stopanska | Google -IB (third party) – preventing frauds/ protection of forms. | Security | = 1 year |
cfidsgib-w-stopanska | Google -IB (third party) – identifying the device for prevention of frauds. | Security | = 1 year |
Google reCAPTCHA | Protection of bot-adjustments; setting cookies in the domain google.com | Security | various |
For pages with integrated video:
„Cookie“ | Purpose | Type | Period |
VISITOR | YouTube – measures bandwidth and statistics of visit. | Marketing (third party) | 6 months |
YSC | YouTube – unique ID for statistics of visited videos. | Marketing (third party) | Per session |
VISITOR_PRIVACY_METADATA | YouTube – information related to consent/ privacy. | Marketing (third party) | 6 months |
_Secure-YNID | YouTube/ Google – identification and preferences. | Marketing (third party) | 6 months |
_Secure-ROLLOUT – TOKEN | YouTube – technical cookie for functionality of the player. | Marketing (third party) | 6 months |
For e-banking:
„Cookie“ | Purpose | Type | Period |
ASP.NET_SessionId | Identifying the session in e-banking (HttpOnly, Secure) | Strictly necessary | Per session |
ARRAffinity | Balancing the overload/ directing to the same server. | Strictly necessary | Per session |
agentroutestate | Technical cookie for routing the requests in the session. | Strictly necessary | Short term |
_zzatgib-w-stopanska, cfidsgib-w-stopanska, gcfids | Group – IB (third party, domain eu.id.group-ib.com) – preventing frauds and identification of the device, | Security | = 1 year |
ga, ga_VNYDDYL1MY | Google Analytics 4 – transferred also in the announced part. | Analytical | up to 400 days |
In accordance with the above-mentioned, the Bank uses functional-analytical "cookies" from Google Analytics that enable better technical functionality of the website, i.e. help the Bank to monitor and improve the effectiveness of the website and improve the user experience of visitors. The information generated by the "cookies" about the use of the website (including the IP address) is transmitted to "Google" in anonymized form. This information is used to evaluate the use of the website by users and to make statistical reports about the Bank's website activity.
On the first visit to the Bank's website, the visitor receives information about the Bank's "cookie" policy and consents to its use. In this regard, we would like to point out that it is not possible to disable cookies that are technically necessary for users to use the website of the SB. With regard to other types of "cookies", which are not necessary for the general functionality of the website, the possibility is provided to refuse them or to agree to accept them. Users can change their preferences at any time.
In addition, the use of the website of SB is not conditioned by the acceptance of cookies although in this way certain processes may not be technically optimized for the user experience of the visitor.
PURPOSES OF PERSONAL DATA PROCESSING
• To fulfill legal obligations at providing payment services and payment systems, as well as for fulfillment purposes of the agreement with the subjects
In accordance with legal provisions and by-laws in the domain of the Law on Payment Services and payment Systems, in the part of providing services for remote payments (the so-called online payments), the Bank has a legal obligation to provide payment services to its users in accordance with security standards for online payments, as prescribed by NBRNM. For that purpose, the Bank has implemented systems for monitoring transactions for prompt identification, analysis and prevention of the risk from unauthorized and fraudulent payment transactions, which systems are based on processing a part of the abovementioned personal identification and technical data. These data are used by the Bank only for the purpose to prevent fraud and protect the funds of users, and they shall not be used for other purposes.
• To improve the functionality of the website and the online services
The Bank is continuously striving to improve the offer and access to its website and online services, based on feedback received from users.
• To improve the services of SB to clients
Personal data help us to more efficiently respond to users' requests for certain services or support their needs (e.g. transaction processing, identity verification, fraud prevention, analytics, etc.).
• To administer the contents, promotions, polls and other functionalities
The Bank is striving to provide efficient management of the contents visited by users. For that purpose, it organizes and analyzes polls to get feedback from users. Additionally, it conducts promotional activities, games of chance and marketing campaigns. It communicates with users in relation to promotions, events or new functionalities.
SECURITY OF PERSONAL DATA
As described in item number 12 of the Privacy Policy of Stopanska Banka - AD Skopje, the Bank applies security measures when collecting, storing and processing information in order to protect against unauthorized access, change, disclosure or destruction of personal data, as well as data that are not personal, but which are stored on the Bank's websites or online services.
WEBSITES OF THIRD PARTIES
Users may find advertisements or other content on the website of SB with links to other sites and services of our partners, suppliers, advertising firms, sponsors, and other third parties. The Bank does not control the content or links present on those pages and is not responsible for the actions of employees from the pages linked to the website of the Bank. In addition, the sites or services referred to, including the content and links, may change from time to time. These sites or services may have their own Personal Data Privacy Policy on their websites and a separate Customer Relations Policy. Browsing and interaction with any other site, including sites that have links to the SB website, is subject to the specific rules and policies of those sites.
AMENDMENTS TO THE POLICY FOR PRIVACY OF PERSONAL DATA
The bank has the right to update / amend or supplement this Personal Data Privacy Policy on the website of Stopanska Banka - AD Skopje, in order to comply with the applicable legal framework or the standards of NBG Group, in case they are stricter than those provided by the national legislation. In this case, SB will publish a notice on its website indicating the date of amendment and which amendments to the Policy were made.
CONTACT DATA
For any issues related to the protection of personal data, customers can contact the Bank in the manner as described in item number 15 of the Privacy Policy of Stopanska Banka - AD Skopje.
ANNEX number 2: POLICY FOR PRIVACY OF PERSONAL DATA OF EMPLOYEES OF STOPANSKA BANKA AD – SKOPJE
This Policy applies to SB employees, SB interns and volunteers, contract deed employees and engaged persons (hereinafter: "employees"). This Policy determines the types of data processed by the Bank for SB employees, the purposes of processing their personal data, the period of their storing, the protection, etc. Regarding the principles of protection of personal data, the Bank is guided by the principles described in item 2 of the Privacy Policy of Stopanska Banka - AD Skopje.
Categories of personal data of employees that are processed
Based on the Law on recording in the labor domain, the Law on labor relations, the Law on internships, the Law on volunteering and other legal acts and by-laws in this domain, as well as for the purpose of fulfilling the contractual obligations with the employees of SB, the Bank processes the following personal data:
Name, surname and father’s name of the employee;
Personal registration number of the citizen (PRN);
Day, month and year of birth;
Place of birth (municipality, city, country);
gender (male - female);
place of residence and address (city, municipality, name of the street and number, country);
contact data – phone number and e-mail address;
belonging to communities;
religion;
participation in labor unions;
place of work (city, municipality, name of the street and number, country);
degree and type of education (no education, elementary school, high-school, college, university, post-graduate studies);
professional training degree (no education, elementary school, high-school, college, university, post-graduate studies):
- completed programs for professional advancement (training, additional qualification and re-qualification) and
- special skills and knowledge (computer skills, foreign languages and other skills);
code and description of profession;
employer’s working hours (full time or part time);
years of service with paid insurance prior to employment with the current employer;
duration of labor relations:
- permanent employment and
- temporary;
transaction account number;
salary amount;
data about disciplinary procedures or pronounced cash penalties;
whether the employee is disabled (health data);
date of establishing the labor relations;
date of terminating the labor relations;
basis for termination of labor relations.
The Bank may also process other personal data of employees (for ex. card number of the employee, photo, voice, video surveillance recordings, usernames for logging into the business IT equipment, systems and applications, business e-mail, IP addresses and business devices etc.). These data are processed for various purposes, like for example: for the needs to control the entry, movement and exit from the business premises, for preparation of cards- badges for identification, at the use of business platforms for audio-visual and textual communication at business meetings, as protective technical measures (registry of access-logs) to provide IT security of systems, as well as to provide confidentiality and secrecy of personal and business data at the use of business assets and systems of the Bank on part of employees.
Within the frame of providing and upgrading the business and work processes, the Bank may use tools based on AI- artificial intelligence (Microsoft Copilot) within the frame of the business user license. With the use of the tool, limited business and user data may be processed, such as: name and surname, business e-mail address, user identifiers, contents of the business communication, documents and information entered by the user with the use of the tool, as well as technical and log data related to the use of the system.
With the use of Microsoft Copilot, within the frame of the business license, data processed with the tool remain within the frame of the organizational Microsoft 365 domain of the Bank, and they are protected with the current mechanisms for authentication, access control and encryption. The entered data, requests (prompts), responses and contents are not used for training or to improve public versions of AI models, nor do they become available for other organizations and users.
Personal data are processed for the purposes of using AI based functionalities for support of work processes, to improve productivity and efficiency of operations, prepare and process documents, search and organize information etc.
Basis for personal data processing represents the taking of actions that arise from contractual obligations for realization of work and business relations, as well as for protection of the legitimate interest of the Bank for providing a safe and efficient activity process, upgrading business processes and protecting IT systems.
Legal basis for processing personal data of SB employees
• legal obligation (for ex. at keeping records of work hours of employees, or to fulfill legal obligations for calculation and payment of contributions from salary and taxes, periodical medical examinations, security and health at work),
• contractual obligation (for ex. at disbursement of salary and compensation, policy for private health insurance, providing access to devices and systems for realization of work tasks, use of tools to upgrade efficiency),
• consent (for ex. for participation in events organized by the Bank)
• legitimate interest (for ex. protection of the ownership of Bank employees, protection against frauds, scanning e-mail for malicious threats, scanning business devices and systems for vulnerability or attacks, control of assigned and terminated user privileges in the systems, prevention of misuse of confidential data from business devices and systems of the Bank, upgrading business processes and efficiency of operations etc.)
Purposes of the processing of SB employees’ personal data
With regard to the purposes of processing, they are elaborated in item number 4 of the Privacy Policy of Stopanska Banka AD - Skopje, i.e. for the purposes to fulfil legal obligations on part of the Bank, as well as to fulfil contractual obligations with the employees of SB.
In addition, the Bank processes personal data of SB employees for the purposes to protect the legitimate interests of the Bank in the following situations:
• Passing decisions on internal appointments by division, promotions, etc.;
• Making decisions about salary and other benefits;
• Providing contractual benefits to employees;
• Maintaining a comprehensive, up-to-date record of SB employees in order to ensure, inter alia, establishment of effective correspondence and maintenance of appropriate contact points in the event of an emergency;
• Taking appropriate actions as and when the need arises;
• Assessment of needs for training;
• Effective management of employee sickness and leave;
• Managing the time attendance system for registry of the presence and absence from work, paid and unpaid absences, legal absence from work (such as parental leave, sick leave, unpaid leave, and the like);
• Managing the data system for employees, as well as the salary system;
• Business planning and restructuring;
• Dealing with legal procedures against SB;
• Preventing fraud;
• Creating polls for the employees for analysis of the satisfaction of employees;
• IT security of IT systems of the Bank and protection of the confidentiality and secrecy of business and personal data of clients;
• Protection of the ownership of the assets and employees of the Bank.
Special categories of personal data of SB employees
Special category of personal data processed by SB:
Health data;
Ethnicity;
Religion;
Union membership.
Special categories of data are processed for the purposes of:
· Obeying internal procedures regarding absence from work of employees due to health conditions,
· Performing reasonable adjustments for disabled persons;
· Determining non-working days according to the provided religious beliefs of SB employees;
· Providing financial aid to employees and/ or their closest family members related to medical conditions or some type of accident/ disaster.
Based on the legal regulations for personal data protection, the Bank is not obliged to provide special consent for processing special categories of personal data in order to implement its legal obligations arising from regulations on labor relations and social and health insurance. Depending on the purpose of processing, it is possible in certain situations to require consent for the processing of special categories of personal data. In that case, employees are fully aware of the reasons for the processing.
Data related to criminal charges
The Bank is processing data about convictions for criminal offenses in accordance with the Law on Personal Data Protection, depending on the nature of the work tasks and for those jobs for which the Bank has legal obligation of processing (for example, in accordance with the Law on Banks, the Law on Prevention of Money Laundering and Financing of Terrorism). These data usually appear in the form of No Conviction Certificate, which is issued by the appropriate competent court and is kept in the employee's file with limited access.
Users and transfer of personal data
The Bank, if necessary, may disclose personal data of authorized colleagues within SB, if necessary for the performance of their work tasks; for ex. data of a relevant manager for the performance of the management responsibilities; of employees in HR Division of SB for the purposes of maintaining employee files and/ or entering data into the appropriate systems. Regarding the other possible users of this type of data, as well as the transfer of personal data, the provisions referred to in items 5 and 6 of the Privacy Policy of Stopanska Banka - AD Skopje shall apply.
Security at processing personal data
SB is taking all required technical and organizational measures to make sure that personal data of employees are protected from accidental loss or disclosure, destruction or misuse.
Time for keeping the personal data
In accordance with the principles of personal data protection, SB processes personal data only to the extent necessary to fulfill the purposes of processing. In the course of the duration period of the employment, personal data of employees are kept in the employee records, and after the termination of the employment relationship, in accordance with the Law on archive material, the Instructions for the method and technique of handling archive and documentary material in office and archive operations and the Law on records in the labor domain, they are kept as a document of permanent value. Regarding other data from the file, the data storage period may vary, depending on the purposes of the personal data processing.
Automated decision making
The Bank is not processing personal data of SB employees for automated decisions related to employees.
Rights in accordance with the Law on Personal Data Protection
Rights of employees related to personal data and the manner of their realization are described in item 8 of the Privacy Policy of Stopanska Banka AD – Skopje.
Contact data
Please contact the Bank in relation to all issues in the domain of this Policy or in relation to other issues, in the manner as described in item 15 of the Privacy Policy of Stopanska Banka AD – Skopje.
ANNEX number 3: POLICY PRIVACY FOR THE EMPLOYMENT CANDIDATES OF STOPANSKA BANKA AD – SKOPJE
This Policy applies to candidates for employment in SB (hereinafter: "candidates"). This Policy determines the types of data that the Bank keeps for candidates for employment in SB, the purposes of their personal data processing, the time of their storage, etc. In relation to the principles of personal data protection, the Bank is guided by the principles described in item number 2 of the Privacy Policy of Stopanska Banka - AD Skopje.
Categories of personal data of employment candidates that SB processes
SB is processing the following personal data of the candidates for employment:
• Name and surname, address, date of birth, telephone number, e-mail;
• A photo only upon expressed consent by the candidate, provided in accordance with the Law on Personal Data Protection;
• Gender;
• Information included in the CV, including education and history of employment;
• Documentation confirming the right of the candidate to work in the Republic of North Macedonia;
• Driver’s license (for specific job positions).
Purposes for personal data processing of employment candidates of SB
Regarding the purposes for processing, they have been elaborated in item 4 of the Privacy Policy of Stopanska Banka AD - Skopje.
Furthermore, the Bank has a legitimate interest in processing personal data of candidates for employment for the following purposes:
• to make decisions on employment of the specific candidate, for internal appointment within divisions, for promoting the personnel etc.;
• to make decisions about the salary and other welfare;
• to assess the needs of training.
If the application is not successful and the candidate is not offered the job, the personal data will not be used for any other reason. They will be destroyed from the database of SB. In the above case, SB may require a consent from the candidate to save his personal data in the database of potential candidates for employment, in case suitable vacancies appear in the organization for which according to their opinion the candidate would like to apply within 1 or 2 years maximum.
Users and transfer of Your personal data
Regarding employment candidates of SB, the Bank is disclosing their personal data to the manager of the Division with SB where the job position that is applied for belongs, as well as to other employees of SB responsible for the interview and selection of candidates. In relation to other possible users of personal data of the candidate, as well as about the transfer of personal data, the provisions referred to in items 5 and 6 shall apply of the Privacy Policy of Stopanska Banka - AD Skopje.
Safety of personal data processing
SB is taking all required technical and organizational measures to make sure that personal data of employees are protected from accidental loss or disclosure, destruction or misuse.
Time period for keeping personal data
In accordance with the principles of personal data protection, SB processes personal data only to the extent necessary to fulfill the purposes of processing, and the same depends on whether the candidate's application will be successful or not.
If the application is unsuccessful, and SB does not have the consent of the candidate to keep his/ her personal data for future open job positions in SB, the personal data will be kept for a maximum of 60 days from the day the selection for the job position is completed.
If SB received a consent to store personal data for future open job positions in SB, it will keep the data for a period of 1 or 2 years, depending on the consent.
After the end of this period, SB will destroy the personal data, except in case the candidate withdraws the consent earlier.
If the application is successful, the personal data will be transferred to the records of SB employees.
Automated decision making
This title is described in item number 4 of the Privacy Policy of Stopanska Banka AD – Skopje.
Rights in accordance with the Law on Personal Data Protection
Rights in relation to personal data are described in item 8 of the Privacy Policy of Stopanska Banka AD – Skopje.
Contact data
For any issues related to this Policy or for other issues related to personal data protection, please contact the Bank in the manner as described in item number 15 of the Privacy Policy of Stopanska Banka AD – Skopje.