Logo or Image

Privacy Policy

Purpose & Scope

SouthEast Country Bank, Inc. (A Rural Bank) respects and values your privacy and the secrecy of your account information with us.

This Privacy Policy (“Policy”) informs you how we collect, use, store, and process your personal data in SouthEast Country Bank Mobile Banking (SECBank Mobile Banking App). We adhere to the data privacy principles of (1) legitimate purpose – we only process upon your consent, in compliance with law or contract; (2) transparency – we notify everything that happens to your data; and (3) proportionality – collection is limited based on purpose.

This Policy applies to data subjects of SECBank Mobile Banking App whether as: (1) clients – current, past and prospective customers as individuals or corporations; or (2) non-clients – payees or payors or bank products and services we provide; visitors or inquirers at our branches and online channels; ultimate beneficial owners, directors or representatives of corporate clients; and such other persons involved in transactions with us or with our customers. (“Data Subjects”)

Collection of your Personal and Sensitive Personal Data

Personal Data refers to any information that identifies or is linkable to a natural person. On the other hand, Sensitive Personal Data is any attribute that can distinguish, qualify or classify a natural person from the others such as data relating to your ethnicity, age, gender, health, religious or political beliefs, genetic or biometric data.

We collect your Personal and Sensitive Personal Data when you register, sign-up or use SouthEast Country Bank’s products and services or contact us about them. We also collect through your organization whether private corporation or government instrumentality you authorized. We may also obtain your information from other sources (i.e. publicly available platforms, financial institutions, credit agencies, payment gateway processors, public authorities, and other registers) for purposes of identity verification and regulatory requirements by the Bangko Sentral ng Pilipinas (BSP).

Kinds of Data We Process
Data Processing

Processing means any activity pertaining to the collection, recording, organization, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure or destruction of Customer Data.

We process Customer Data only for legitimate purposes and with lawful basis such as your express consent, terms and conditions of product or service you signed up with us, and as required by law and regulation. We ensure that only authorized employees and third-party service providers, who satisfy our stringent risk management, governance, information security, and data privacy requirements, can process your data.

1. Data Storage

  • a. We store Customer Data in secure and encrypted Bank-managed environments, devices, and media. For third-party managed environments such as cloud service providers, we employ BSP-sanctioned security protocols and procure BSP approval prior deployment.
  • b. We store physical copies of documents containing Customer Data in physical secure vaults.

2. Data Access

  • a.Customer Data can only be accessed by authorized personnel on a role-based manner following the proportionality principle that authorized personnel can only access Customer Data they need for their role and purpose in the Bank.

3. Data Use

  • a. Customer Engagement
    i) We use your contact details with us to communicate with you about your relationship with
    ii) We may ask for feedback, surveys or polls about our products and services.
    iii) We may send you email or mobile notifications, telephone calls, or newsletters about product and services enhancements and account security reminders.
    iv) You have the right to opt out from this form of communications with you or choose another means for which we can contact you.
  • b. Marketing
    i) We may use your information for us to send out campaigns of commercial products and services we hope you find interesting, relevant, and useful.
    ii) We want to establish a more personalized relationship with you by providing you offers that would suit your lifestyle and needs.
    iii) We perform data analysis on results of our marketing campaigns to measure their effectiveness and relevance
    iv) You have the right to withdraw your consent or unsubscribe from receiving personalized offers.
  • c. Due Diligence and Regulatory Compliance
    i) We may use Customer Data to evaluate your eligibility for Bank products and services.
    ii) In assessing your ability to repay your loans, we conduct credit risk and investigation and reporting on your credit history and account updates
    iii) We use your account details when you instruct us to make a payment or fulfill an investment order.
    iv) We use automated processes and data science solutions for faster decision-making in granting loan products.
    v) We process Customer Data in compliance with legal obligations and statutory requirements by BSP, and other regulatory agencies.
  • d.Business Insights
    i)We perform data analysis and reporting based on your Customer Data and how we operationalize to aid our management make better decisions.
    ii)We analyze your behavioral data, your interactions with our products and services, and our communications with you to aid us understand the areas for improvement and development.
    iii)We analyze transactional data performed through our third-party service providers and partners in order to determine how we can jointly improve our products and services for you.
  • e. Data Quality
    i) We shall process your Customer Data in compliance with the data quality standards imposed by We shall obtain additional information about you from government institutions or credit bureaus to improve the quality of your Customer Data with us. We may contact you to ensure accuracy and integrity of your information in our data processing systems.
  • f. Protection and Security
    i)We process Customer Data for your account protection against cybercrime, identity theft, estafa, fraud, financial crimes such as money laundering, terrorism financing, and tax fraud.
    ii)We use your Personal Data such as name, age, nationality, IP address, home address, and other Transactional Data to conduct profiling for detection of suspicious activity on your account.
    iii)We may employ artificial intelligence and machine learning in real- time detection of suspected fraudulent activities on your account.
    iv)We may reset your password or temporarily hold your mobile banking account to protect you from detected suspected fraudulent activities.

4. Data Retention

  • a. Pursuant to BSP Regulations, retention period for transaction records shall be five (5) years from the date of transaction except where specific laws and/or regulations require a different retention period, in which case, the longer retention period is observed.
  • b. For financial data and documents which indicate taxable transactions, data shall be preserved for ten (10) years per BIR Regulation.
  • c. We keep your data as long as it is necessary:
    • a) for the fulfillment of the declared, specified, and legitimate purposes, or when the processing relevant to the purposes has been terminated;
    • b) for the establishment, exercise or defense of legal claims; or
    • c) for legitimate business purposes, which shall be in accordance with the standards of the banking industry.

5. Data Disposal

  • After the expiration of the imposed retention period, we dispose personal data in a secure manner in order to prevent further processing, unauthorized access, or disclosure to any other party.

Data Sharing and Purpose

When you consent to the processing of your Customer Data with us, you also agree to help us comply with our statutory and contractual obligations with other financial institutions. We may also share Customer Data externally with our partners, upon your written and/or electronic consent, for value added services you may find useful and relevant on top of your account with us. For contractual and value-added service data sharing agreements, we employ standardized model clauses as recommended by National Privacy Commission to ensure data protection of Customer Data. Below are the disclosures required by the government entities, other regulatory authorities and financial institutions:

1. Bangko Sentral ng Pilipinas (BSP), Anti-Money Laundering Council (AMLC)

  • a. We are subjected to mandatory disclosures to the AMLC under Republic Act 9160 or the Anti-Money Laundering Act of 2001, as amended, when there is probable cause that the deposits or investments involved are in anyway related to unlawful activities or money laundering offenses.
  • b. BSP mandates disclosures and reporting in compliance with its issuances for the protection of the integrity of the banking sector.

2. Bureau of Internal Revenue (BIR)

  • We may conduct random verification with the BIR in order to establish authenticity of tax returns submitted to us.
  • BIR may inquire into bank accounts of the following:
    • a) a decedent in order to determine his gross estate;
    • b) a taxpayer who has filed an application to compromise his tax liability on the ground of financial incapacity; and
    • c) a taxpayer, information on whose account is requested by a foreign tax authority.

3. Credit Information Corporation (CIC)

4. Judicial and Investigative Authorities

5. Other Regulatory Authorities

6. Financial Institutions

7. Value Added Services

Rights of Data Subjects

Under the Data Privacy Act of 2012, you have the following rights:

Contact our Data Protection Officer

For inquiries and concerns, you may address them to SouthEast Country Bank’s Data Protection Officer at 4 P. Bustamante St., Santo Domingo Poblacion, Camaligan, Camarines or through email at [email protected].