This Privacy Statement explains in a simple and transparent way how Primo Advisors Limited (in this Privacy Statement, “us”, “we” and “our”) collects, uses and discloses your personal data, and your rights in relation to the personal data it holds. Our approach can be summarized as: the right people use the right data for the right purpose.
We are the data controller of your personal data and are subject to the DIFC Data Protection Law (DIFC Law no 5 of 2020) and DIFC Data Protection Regulations (hereafter referred to as the “Data Protection Law”).
This Privacy Statement supersedes any previous Privacy Statement or equivalent which you may have been provided with or seen prior to the effective date stated above.
1. Scope of this Privacy Statement
This Privacy Statement applies to the following individuals (“you”):
• Our past, present and prospective customers; and
• Anyone involved in any transaction or interaction with us, whether it is in your personal capacity or as a representative of a legal entity (for example, director, a company manager, agent, legal representative, operational staff, other authorized representative, etc.)
2. How do we obtain your personal data?
We obtain your personal data as follows:
• From the information you provide to us when you meet or interact with us;
• From information about you provided to us by your company or an authorized intermediary;
• When you communicate with us by telephone, email, web form or other forms of electronic communication. In this respect, we may monitor, record and store any such communication;
• When you complete (or we complete on your behalf) client on-boarding or application or other forms;
• From your agents, advisers, and intermediaries; or
• From publicly available sources or from third parties, most commonly where we need to conduct background checks about you.
3. What types of personal data do we process?
We collect the following categories of personal data about you:
• Your name and contact information such as your home or business address, email address, telephone number and social media contact details;
• Biographical information which may confirm your identity including your date and place of birth, your passport number or national identity card and visa details, country of domicile and/or your nationality;
• An understanding of your goals and objectives in procuring our services;
• Information about your employment, education, family or personal circumstances, and interests, where relevant; and
• Where applicable and legally permissible audio-visual data such as surveillance videos, recording of phone or video calls or chats with our employees or offices.
Special categories of personal data are data relating to your religious beliefs, genetic or biometric data.
We may process your special categories of personal data if:
• We have your explicit consent to do so; or
• We are required or allowed to do so by applicable local law (for instance to comply with money laundering and terrorism financing monitoring: we monitor your activity and may report it to the competent regulatory authorities).
4. What do we do with your personal data?
Processing means every activity that can be carried out in connection with personal data such as collecting, recording, storing, adjusting, organizing, using, disclosing, transferring or deleting it in accordance with applicable laws.
We only use your personal data under one of the following legal grounds:
· To conclude and carry out a contract with you;
· To comply with our legal obligations;
· When we have your consent. In this case, you may withdraw your consent at any time.
We may process your data for the following purposes:
For example, when you wish to become our customer we are legally obliged to collect personal data that verifies your identity (such as a copy of your ID card or passport) and to assess whether we can accept you as a customer. We also need to know your postal, e-mail address or phone number to contact you.
Performance of agreement to which you are a party or taking steps prior to entering into agreements
We use information about you when you enter into an agreement with us or when we have to contact you. We analyze information about you to assess whether you are eligible for our products and services.
Relationship management and marketing
We may ask you for feedback about our products and services, or record your conversations with us online, by telephone or in our office. We may share this with certain members of our staff to improve our offering or to customize products and services for you. If you don’t wish to receive these offers you have the right to object or to withdraw your consent by sending an email or telephoning us (see section “Our Contact Details” below).
Safety and security
We have a duty to protect your personal data and to prevent, detect and contain any breaches of your data. This includes personal data we are obliged to collect about you, for example to verify your identity when you become a customer.
Compliance with legal obligations to which we are subject
We process your data to comply with a range of legal obligations and statutory requirements.
5. With whom do we share your personal data and for which reasons?
To provide you with our services, we share certain personal data externally with third parties.
Whenever we share your personal data externally with third parties in countries without a deemed adequate level of protection for personal data, we ensure the necessary safeguards are in place to protect it. We rely hereby upon, amongst others:
· The conclusion or the execution of an agreement in your favor;
· Requirements based on applicable local laws and regulations;
· When applicable, we use standardized contractual clauses in agreement with service providers to ensure personal data transferred to countries without an adequate level of protection for personal data comply with the DIFC Data Protection Law or GDPR, as applicable.
· Your explicit consent;
· International treaties that protects personal data transferred to certain service providers abroad.
When we use other service providers or third parties to carry out certain activities in the normal course of business, we may have to share personal data required for a particular task. The service providers include:
· IT service providers who may provide application or infrastructure (such as cloud) services;
· Marketing activities or events and managing customer communications;
· Preparing reports and statistics, printing materials and designing products;
· Placing advertisements on apps, websites and social media;
· Legal, auditing or other special services provided by lawyers, notaries, trustees, company auditors or other professional advisors;
· Identifying, investigating or preventing fraud or other misconduct by specialized companies.
6. What are your rights and how do we respect them?
We respect your individual rights to determine how your personal data is used. These rights include:
Right to access information
You have the right to ask us for an overview of your personal data that we process.
Right of rectification
If your personal data is incorrect, you have the right to request us to rectify it. If we shared data about you with a third party and that data is later corrected, we will also notify that party accordingly.
Right to object processing
You can object us using your personal data for our own legitimate interests (for example, marketing). We will consider your objection and stop processing your data unless we assess that we have legitimate and imperious reasons that justify processing your data.
You can also object to receiving commercial messages from us (by e-mail, mail and phone) or for statistical purposes. When you become our customer, we may ask you whether you want to receive personalized offers. Should you later change your mind, you can choose to opt out of receiving these messages by sending an email to us (see section “Our contact details” below).
Right to object to automated decisions
You have the right not to be subject to decisions which may legally or significantly affect you and that were based solely on automated processing using your personal information. In such cases you may ask to have a person to make the decision instead.
Some of our decisions are the result of automated processes for which you gave us explicit consent, or these decisions are necessary to perform or fulfil a contract with you. In both cases, you may ask for human intervention and contest the resulting decision.
Your right to object and to contest may be impeded if automated decisions are made for legal reasons.
Right to restrict processing
You have the right to ask us to restrict using your personal data for the period necessary to us for our verifications if:
• You believe the information is inaccurate;
• we are processing your personal data unlawfully;
• you have objected to us processing your personal data for our own legitimate interests;
• you have the same right if we no longer need your personal data, but you want us to keep it for use in a legal claim.
Right to data portability
You have the right to ask us to transfer some of your personal data directly to you or to another company. This applies to personal data we process by electronic means and with your consent or because of a contract with you. Where technically feasible, we will transfer your personal data.
Right to erasure (also known as right to be forgotten)
Unless required by law, you may ask us to erase your personal data if:
• We no longer need it for its original purpose;
• You withdraw your consent for processing it;
• You object to us processing your data for our own legitimate interests (except for legitimate and compelling interests) or for commercial messages; or
• we unlawfully process your personal data.
Right to complain
Should you not be satisfied with the way we have responded to your concerns you have the right to submit a complaint to us. You can also contact the DIFC Protection Commissioner (DIFC the Gate, Level 14, PO Box 74777, Dubai, T.: +971 4 362 2600)
Exercising your rights
You can also exercise your rights by contacting us (see section “Our contact details” below).
We aim to respond to your request as quickly as possible. In some instances, this could take up to one month. Should we require more time to complete your request, we will let you know how much longer we need and provide reasons for the delay. In certain legal cases, we may deny your request. If it’s legally permitted, we will let you know in due course why we denied it.
7. Are you obliged to provide us with your personal data?
In some cases, we are legally required to collect personal data, or your personal data may be needed before we may perform certain services and provide certain products. We undertake to request only the personal data that is strictly necessary for the relevant purpose. Failure to provide the necessary personal data may cause delays or lead to refusal of certain products and services.
8. How do we protect your personal data?
We take appropriate technical and organizational measures (policies, procedures, IT security, etc.) to ensure the confidentiality and integrity of your personal data and the way it’s processed. We apply an internal framework of policies and minimum standards across our business to keep your personal data safe. These policies and standards are periodically updated to keep them up to date with regulations and market developments.
In addition, our employees are subject to confidentiality obligations and may not disclose your personal data unlawfully or unnecessarily. To help us continue to protect your personal data, you should always contact us if you suspect that your personal data may have been compromised.
9. How long do we keep your personal data?
We will only retain your personal data for as long as we have a lawful reason to do so. In particular, we will in most cases retain your personal data for a period of ten years after the termination of our contractual or other relationship with you in case any claims arise out of the provision of our services to you.
When your personal data is no longer necessary for a process or activity for which it was originally collected, we delete it, or bundle data at a certain abstraction level, render it anonymous and dispose it in accordance with the applicable laws and regulations.
10. Changes to this Privacy Statement
We may amend this Privacy Statement to remain compliant with any changes in law or to reflect how our business processes personal data. This version was created and published on 23 January 2023 and entered into force on the same date. The most recent version is available on our website www.primoadvisors.com.
11. Our contact details
You can address your queries regarding this Privacy Statement to:
Primo Advisors Limited
Emirates Financial Towers, South Tower, Office 308
DIFC, Dubai, UAE