Data Protection

Privacy Policy 

1. Data protection at a glance

General

The following information is intended to provide a simple overview of what happens to your personal data when you visit our website as a user. Personal data are all the data that can be used to identify you personally. Detailed information on data protection can be found in the privacy policy following this general section.

Definitions

The terms “personal data” and “processing” have the following meaning:

  • Personal Data: means any information relating to a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, or an online identifier.

  • Processing: means any operation which is performed on personal data, such as collection, recording, organisation, structuring, storage, adaptation or any kind of disclosure or other use.

Data collection on our website

  • Who is responsible for the collection of data on this website?

Data are processed on this website by us, the VTB Bank (Europe) SE (also referred to as “us”, “we” or “our”). Our contact details can be found under sec. 2 of this privacy policy. The contact details of our data protection officer can be found under sec. 3 of this privacy policy. 

  • How do we collect your data?

One way your data are collected is when you make details known to us.

Other data are collected automatically by our IT systems. Most of these are technical data (e.g. internet browser, operating system or the time of day the website is accessed). This automatic process is activated as soon as you reach our website. 

  • What do we use your data for? 

Some of the data are collected so as to make our website fully and easily available to you. Other data can be used in order to analyze your user behavior. 

  • What rights do you have over your data? 

As a data subject, you have different rights when it comes to your personal data. You have the right, for example, to receive information whether your personal data are retained and to request removal of your personal data. See for more details and all your rights sec. 10 of this privacy policy.

You can contact us or our data protection officer about these and other questions related to data protection at the address given under sec. 2 and sec. 3 of this privacy policy. 

  • Analysis tools and the tools of third-party providers 

Your surfing behavior can be analyzed statistically when you visit our website. This is mostly done with cookies and so-called analysis programs. Your surfing behavior is normally analyzed anonymously, in the sense that the surfing behavior cannot be traced back to you individually. You can object to such analysis or prevent it by not using certain tools. Detailed information on this can be found in the following privacy policy.

You can object to such analysis. You will find information on the objection possibilities in the privacy policy below (see for example sec. 5 and 10). 

2. General information (e.g. on the data controller)

Data protection 

We take the protection of your personal data very seriously. We treat your personal data in strict confidence and in compliance with the provisions of data protection law, in particular the General Data Protection Regulation (GDPR), and this privacy policy. 

Various personal data are collected if and when you use this website. Personal data are data relating to you as an identifiable person. The present privacy policy explains which data we collect and what we use it for. It also explains how and for what purpose this is done. 

We must point out that data transmission on the internet (e.g. for communication by email) can involve security gaps. Complete and absolute protection of data against access by third parties is not possible. 

Note on the data controller (meaning the responsible entity) 

The data controller pursuant to Article 4 No. 7 GDPR for the processing of data on this website is: 

VTB Bank (Europe) SE 
Rüsterstrasse 7-9 
60325 Frankfurt am Main 
Telephone: +49 (0) 69 2168 0 
Email:service@vtb.eu 

The data controller is the natural or legal person who decides, alone or jointly with others, on the purpose and means of the processing of personal data (e.g. name, email address and the like). 

3. Data protection officer 

The VTB Bank (Europe) SE's data protection officer:  

Dr. Karsten Kinast, LL.M. 
Externer Datenschutzbeauftragter 
KINAST Rechtsanwaltsgesellschaft mbH
Hohenzollernring 54 
50672 Köln (Germany)
Tel: +49 221 - 222 183 0  
Fax: +49 221 - 222 183 10 
Email: dpo@vtb.eu 

4. Data collection on our website (informational use and registration)

Data processing in case of informational use of the website 

When you visit our website for informational reasons, i.e. without registering, and without providing us with personal data in any other form, we may automatically collect additional information about you which will contain personal data only in limited cases and which is automatically recognised by our server, such as:

    • Browser type and browser version 
    • Operating system used  
    • URL referrer 
    • Host name of accessing computer 
    • Time of day of server enquiry 
    • IP address 

These data are also stored in so-called server log files, which your browser transfers to us automatically. The data are not combined with any other data sources. 

We use such information only to assist us in providing an effective service (e.g. to adapt our website to the needs of your end user device or to allow you to log in to our website), and to collect broad demographic information for anonymized, aggregate use.

The basis for this automated data processing is Article 6 (1) lit. b GDPR, which allows data to be processed for the performance of a contract or for taking steps prior to entering into a contract, and our legitimate interest to guarantee the website’s stability and security, Article 6 (1) lit. f GDPR.

Personal data that is collected automatically is retained for one (1) month and properly erased afterwards. 

Registration on this website 

You can register on our website so as to use additional functions available there. We use the data entered for that purpose only to supply the particular offer or provide the particular service for which you registered. The information requested and marked as obligatory for registration must be provided in full. Otherwise we will have to reject the registration. 

We will use the email address you give us while registering to inform you about any important changes, for example in the scope of our offer or technically necessary modifications. 

The data entered during registration are processed on the basis of Article 6 (1) lit. b GDPR, which allows data to be processed for the performance of a contract or for taking steps prior to entering into a contract. 

The data collected via your registration will be stored by us for as long as you are registered on our website, after which they will be deleted. Statutory data retention periods continue to apply. 

Cookies 

Our website uses cookies – text files which are stored on your computer and enable your use of the website. Most of the cookies we use are so-called session cookies, which are automatically deleted at the end of your visit to the website. Other cookies stay on your terminal until you delete them. These cookies enable us to recognize your browser on your next visit. 

You can set your browser to inform you of the presence of cookies and to ensure that you only allow cookies in individual cases, that you accept them for specific cases, that you exclude them altogether or that they are automatically deleted when you close the browser. Deactivating the cookies may mean that the functionality of the website is restricted.  

Cookies which are necessary for carrying out electronic communications or for providing specific functions requested by you (e.g. the shopping basket function) are stored in compliance with Article 6 (1) lit. f GDPR. We have a legitimate interest in storing cookies so as to ensure technically flawless and optimized provision of its services. Other cases where cookies are stored (e.g. cookies to analyze your surfing behavior) are explained under sec. 5 of this privacy policy. 

5. Analysis tools and advertising 

a) Google Analytics 

This website uses functions from the Google Analytics web analysis service. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). 

Google Analytics uses so-called cookies – text files which are stored on your computer and enable your use of the website to be analysed (see also sec. 4 of this privacy policy). The information generated by the cookie on such use is normally transferred to a Google server in the USA and stored there. 

The Google Analytics cookies are stored on the basis of Article 6 (1) lit. f GDPR. We have a legitimate interest in analyzing user behavior so as to optimize both its website offering and its advertising. 

IP anonymizing 

We have activated the IP anonymizing function (“gtag('config', 'UA-33179576-1', { 'anonymize_ip': true }) ”) on this website. The effect is that your IP address is abbreviated by Google in member states of the European Union or in signatory states to the agreement on the European Economic Area before it is transmitted to the USA. Only in exceptional cases is the complete IP address transferred to a Google server in the USA and abbreviated there. Under commission from us, Google uses this information to compile reports on website activities and to perform other services for us that are related to the use of the website and the internet. The IP address transmitted by your browser as part of Google Analytics services is not combined with other Google data.  

Browser settings and plug-in 

You can prevent the storage of the cookies by means of the relevant setting on your browser software. Please note however that in this case you will possibly not be able to make full use of all the functions of this website. You can moreover prevent the transfer to Google of the data generated by the cookie and related to your use of the website (including your IP address) and the processing of the said data by Google by downloading and installing the browser plug-in available at the following link: https://tools.google.com/dlpage/gaoptout?hl=de

Objection to collection of data 

You can also prevent data collection by Google Analytics by clicking on the following link. This will result in installation of an opt-out cookie, which will prevent the collection of your data on future visits to this website: http://vtb.eu/#disable-ga

Further information on Google Analytic's handling of user data can be found in Google's privacy policy at: https://support.google.com/analytics/answer/6004245?hl=de

Data processing agreement

We have entered into a data processing agreement with Google. 

Demographic features at Google Analytics 

This website uses the "demographic features" function of Google Analytics. It enables reports to be compiled containing statements on the age, gender and interests of the users of the website. These data come from interest-related advertising by Google and from visitor data supplied by third-party providers. The data cannot be assigned to any particular individual. You can deactivate this function at any time via the display settings in your Google account or prohibit the collection of your data by Google Analytics in every case, as set out in the section headed "Objection to collection of data".  

b) Google Analytics remarketing 

Our websites use the Google Analytics remarketing function in conjunction with the cross-device functions of Google AdWords and Google DoubleClick. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). 

This function makes it possible to link the advertising target groups set up by Google Analytics remarketing with the cross-device functions of Google AdWords and Google DoubleClick. In this way interest-related and personalized advertising messages which were adapted to you in response to your previous use and surfing behavior on one terminal (e.g. mobile phone) can also be displayed on another terminal of yours (e.g. tablet or PC). 

If you have given the necessary consent, Google will, for the above purpose, link your web and app browser history with your Google account. In this way the same personalized advertising messages can be run on every terminal where you log in with your Google account. 

In order to support this function, Google Analytics collects Google-authenticated IDs of the users who are temporarily linked with our Google Analytics data, so as to define and create target groups for cross-device advertising. 

You can permanently prevent cross-device remarketing/targeting by deactivating personalized advertising in your Google account. Just follow this link: https://www.google.com/settings/ads/onweb/

The collected data are compiled in your Google account exclusively on the basis of your consent, which you grant Google and can withdraw (Article 6 (1) lit. a GDPR). In the base of data collections which are not brought together in your Google account (e.g. because you have no Google account or have objected to such combination) the collection of the data is based on Article 6 (1) lit. f GDPR. The legitimate interest derives from the fact that we have an interest in the anonymized analysis of the website users for advertising purposes. 

More detailed information and the data protection rules can be found in Google's privacy policy at: https://www.google.com/policies/technologies/ads/

c) Google AdWords and Google conversion tracking 

This website uses Google AdWords. AdWords is an online advertising program of Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). 

We use so-called conversion tracking as a component of the Google AdWords program. If you click on an advertisement run by Google, a cookie is set for conversion tracking. Cookies are small text files which the internet browser deposits on the user's computer (see also sec. 4 of this privacy policy). The cookies become invalid after 30 days and cannot be used to identify the individual user. If the user visits certain pages on this website and the cookie has not yet expired, Google and we can notice that the user clicked on the advertisement and was moved on to this particular page. 

Every Google AdWords customer firm gets a different cookie. The cookies cannot be tracked back via the websites of AdWords customers. The information obtained with the help of conversion cookies serves the purpose of compiling conversion statistics for AdWords customers which have decided in favor of conversion tracking. The customer firms are told the total number of users who have clicked on their advertisement and were moved on to a page furnished with a conversion tracking tag. But the firms do not get any information by means of which individual users can be identified. If you do not wish to be involved in the tracking, you can prevent this use by simply deactivating the Google conversion tracking cookie by means of the user settings on your internet browser. You will then not be included in the conversion tracking statistics. 

Conversion cookies are stored on the basis of Article 6 (1) lit. f GDPR. We have a legitimate interest in analyzing user behavior so as to optimize both its website offering and its advertising. 

Further information on Google AdWords and Google conversion tracking can be found in Google's privacy policy: https://www.google.de/policies/privacy/

You can set your browser to inform you of the presence of cookies and to ensure that you only allow cookies in individual cases, that you accept them for specific cases, that you exclude them totally or that they are automatically deleted when you close the browser. Deactivating the cookies may mean that the functionality of the website is restricted. 

6. Information sharing

We may disclose anonymous aggregate statistics about users of the website in order to describe our services to prospective partners, advertisers and other reputable third parties and for other lawful purposes, but these statistics will include no personal data. 

We may disclose your personal data to contractors who assist us in providing the services we offer through the website. In particular, we disclose your personal data to host providers and IT service providers. 

Such a transfer will be based on data processing agreements. Therefore, our contractors will only use your personal data to the extent necessary to perform their functions and will be contractually bound to process your personal data only on our behalf and in compliance with our requests. 

In the event that we undergo re-organisation or are sold to a third party, any personal data we hold about you may be transferred to that re-organised entity or third party in compliance with applicable law.

We may disclose your personal data if legally entitled or required to do so (for example if required by law or by a court order).

7. Cross border data transfers 

Within the scope of our information sharing activities set out above, your personal data may be transferred to other countries (including countries outside the EEA) which may have different data protection standards than your country of residence. Please note that data processed in a foreign country may be subject to foreign laws and accessible to foreign governments, courts, law enforcement, and regulatory agencies. However, we will endeavour to take reasonable measures to keep up an adequate level of data protection also when sharing your personal data with such countries.

In the case of a transfer outside of the EEA, this transfer is safeguarded by a Commission’s adequacy decision such as the decision regarding the Privacy Shield or the EU Model Clauses. You can receive further information about the aforementioned safeguards by contacting us or our data protection officer under the contact details referred to in section 2 and 3 above.

8. Security

We have reasonable state of the art security measures in place to protect against the loss, misuse and alteration of personal data under our control. Our security and privacy policies are periodically reviewed and enhanced as necessary and only authorised personnel have access to personal data. Whilst we cannot ensure or guarantee that loss, misuse or alteration of information will never occur, we use all reasonable efforts to prevent it. 

We, for example, take the following security measures:

  • SSL or TLS encryption 

For security reasons and for the protection of the transmission of confidential contents, such as orders or enquiries which you send us, this website uses SSL or TLS encryption. You can recognize an encrypted connection from the fact that the browser's address line switches from “http://” to “https://” and from the padlock icon in your browser line. 

If and when the SSL or TSL encryption is activated, the data you transmit to us cannot be read by third parties. 

  • Encrypted payments on this website 

If, after a contract involving payment has been concluded, you become obliged to send us your payment details (e.g. account number in case of direct debit authorization), these data will be needed for the processing of the payment. 

Payments via the usual means of payment (Visa/MasterCard, direct debiting) are made in every single case using an encrypted SSL or TLS connection. You can recognize an encrypted connection from the fact that the browser's address line switches from “http://” to “https://” and from the padlock icon in your browser line. 

The effect of encrypted communication is that the payment data you transmit to us cannot be read by third parties. 

Please note, however, that submission of information over the internet is never entirely secure. We cannot guarantee the security of information you submit via our website whilst it is in transit over the internet and any such submission is at your own risk.

9. Data retention

We strive to keep our processing activities with respect to your personal data as limited as possible. In the absence of specific retention periods set out in this policy, your personal data will be retained only for as long as we need it to fulfil the purpose for which we have collected it and, if applicable, as long as required by statutory retention requirements.

10. Your rights as a data subject

Under the legislation applicable to you, you may be entitled to exercise some or all of the following rights:

The right to 

  • require (i) information whether your personal data is retained and (ii) access to and/or duplicates of your personal data retained, including the purposes of the processing, the categories of personal data concerned, and the data recipients as well as potential retention periods; 

  • request rectification, removal or restriction of your personal data, e.g. because (i) it is incomplete or inaccurate, (ii) it is no longer needed for the purposes for which it was collected, or (iii) the consent on which the processing was based has been withdrawn;

  • refuse to provide and – without impact to data processing activities that have taken place before such withdrawal – withdraw your consent to processing of your personal data at any time;

  • object, on grounds relating to your particular situation, to processing of your personal data, in case such processing is either based on our or a third party’s legitimate interests or on a performance of a task carried out in the public interest. In this case, please provide us with information about your particular situation. After the assessment of the facts presented by you we will either stop processing your personal data or present you our compelling legitimate grounds for an ongoing processing; 

  • take legal actions in relation to any potential breach of your rights regarding the processing of your Personal data, as well as to lodge complaints before the competent data protection authorities; and/or

  • require (i) to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and (ii) to transmit those data to another controller without hindrance from our side; where technically feasible you shall have the right to have the personal data transmitted directly from us to another controller.

You may (i) exercise the rights referred to above or (ii) pose any questions or (iii) make any complaints regarding our data processing by contacting us or our data protection officer under the contact details set out under sec. 2 and 3 of this privacy policy.

11. Automated decision making

We do not use your personal data for automated decision making which produces legal effects concerning you or similarly significantly affects you.

12. Amendments to this Privacy Policy

We reserve the right to change this privacy policy from time to time by updating our website respectively. Please visit the website regularly and check our respectively current privacy policy. This policy was last updated on 02.10.2018.

Let's talk
You can contact us on the site
or by e-mail service@vtb.de
Our managers are also ready
to help you by phone
+49 (0) 69 2168-0