Privacy Policy

How IECCU collects, uses, shares and stores your Personal Data

Introduction

The Insurance Employees Co-operative Credit Union Limited, (“IECCU”, “we”, “us”, “our”) is a member-centric, financially-sound and technologically-enhanced Credit Union, with a mission to improve the quality of life of its members and their families, through the provision of personalized financial solutions and advice.

At IECCU, we are committed to protecting your privacy. We ensure that the processing of your Personal Data is compliant with the Jamaica Data Protection Act (JDPA) and regulations, and any country-specific data protection laws and regulations to the extent applicable to IECCU. We have also implemented a number of technical, organizational and physical measures to ensure the most complete protection of Personal Data processed through the Site or use of our Services.

We have prepared this Privacy Notice to describe to you our practices regarding the personal information we collect from our members and users of our website.

This Privacy Notice describes how IECCU collects, uses and shares and stores your Personal Data, and informs you of your rights regarding your Personal Data. This Privacy Notice applies to data we collect when you use our website, when you subscribe to our newsletter, take part in a survey, access our products and services, or any other marketing initiatives.

When you visit our website, you are free to explore without providing any Personal Data about yourself. We only collect Personal Data from you when you register, subscribe to a service or fill out a form.

“Personal Data” means any information that allows someone to identify you, such as: your name, address, telephone number, e-mail address, as well as any other non-public information about you that is associated with any of these.

“Anonymous Data” means data that is not associated with or linked to your Personal Data and which does not, by itself, permit the identification of individual persons.

We collect Personal Data and Anonymous Data, as described above.


How we Collect Data

We may collect your Personal Data through the following means:

Information you provide via our Website, Social Media Networks or Events:
We may collect any Personal Data that you choose to send to us or provide to us via our website, social media network or when registering or attending an event.

Information you provide when accessing our Services
We receive and store information you provide directly to us to access our products and services. For example, when applying to become a member, opening an account or transacting at our offices.

Third Parties
In some instances, we may collect Personal Data from public and non-public sources and third parties for regulatory purposes or to better serve you. These include: credit bureaus, references, other financial institutions, regulatory bodies and related entities.

Types of Data We Collect:

We collect a wide range of Personal Data to allow us to conduct business with you.

The types of Personal Data we may collect directly from our members, prospective members, visitors and users of our website include:
  • Valid Photo ID, for example a Passport, Driver’s Licence or ID card
  • Taxpayer’s Registration Number (TRN)
  • National Insurance Number (NIS, NIN)
  • Social Security Number (SSN) / Tax Identification Number (NIN)
  • Social Insurance Number (SIN)
  • Proof of Employment
  • Proof of address, current and past addresses
  • Email address
  • Character references
  • Birth Certificate
  • Marriage Certificate
  • Declaration of US citizenship, Tax residency, if appropriate
  • Mother’s maiden name
  • Employment Status & Details
  • Politically Exposed Person Status
  • Financial Information
  • Transaction Records
  • Image Capture via CCTV, printed materials or webinar recording

In operating our website, we may also collect the following types of Personal Data:

Log Data - This data may be processed for the purposes of operating our website, providing our services, ensuring the security of our website and services, maintaining back-ups of our databases and communicating with you.

Google Analytics - We collect this data so that we can improve our website and access to it.

Cookies - We may also use cookies and URL information to gather information regarding the date and time of your visit and the information for which you searched and which you viewed. “Cookies'' are small pieces of information that a website sends to your computer’s hard drive while you are viewing a web site. Upon your initial visit to the website, you will have the option of accepting or refusing cookies and you will be able to choose the type of cookie you accept or reject. You may also configure your browser to ensure no cookies are stored on your hard drive.

We may use both session Cookies (which expire once you close your web browser) and persistent Cookies (which stay on your computer until you delete them) to provide you with a more personal and interactive experience on our Site. Persistent Cookies can be removed by following Internet browser help directions. Cookies may enable automatic logins when you visit in the future and may enable content customization.

Bases for Collecting Personal Data:

User Consent - We will always obtain your clear, informed, specific and freely given consent before processing your Personal Data, except in circumstances where it is not possible to obtain your consent but your Personal Data still needs to be processed (for example, due to legal obligations we may have or to protect your vital interests, the public interest or to aid in the administration of justice). You may withdraw your consent at any time by the same method it was provided to us or by contacting our Privacy Officer identified below.

Contractual Obligation - We may process your Personal Data in contemplation of entering into a contract with you or to fulfill our existing contractual obligations to you.

Legitimate Interest - We process your Personal Data in order to efficiently provide and market our services to you. However, we will not process your Personal Data where doing so poses a risk to your rights and freedoms and vital interests.

Legal Obligation- There may be instances when we will have to process your Personal Data in order to comply with the law. This may require us to process information about criminal convictions to investigate and gather intelligence on suspected financial crimes, fraud and threats and to share data with law enforcement and regulatory bodies. We are also legally obliged to assess affordability and suitability of credit for loan and other credit applications and throughout the duration of the relationship.

How We Use Your Personal Data

We may use the information we collect from you in connection with the services we provide for a range of reasons, including to:
  • provide our products and services;
  • process and complete transactions, and send related information, including transaction confirmations and records;
  • manage our members’ use of the services, respond to enquiries and comments and provide customer service and support;
  • send alerts, updates, security notifications, and administrative communications;
  • verify your identity, creditworthiness and the accuracy of the information provided.
  • prevent criminal activity, fraud and money laundering;
  • trace debtors and recover debts;
  • investigate and prevent fraudulent activities, unauthorized access to our services, and other illegal activities; and
  • for any other purposes about which we notify members and users.
  • Third Parties and International Data Transfers


Our website may contain links to other sites that are not operated by us. We have no control over and assume no responsibility for the content, privacy policies or practices of any third party site or service. We may disclose your Personal Data to third parties to whom you expressly ask us to send your Personal Data or to third parties for whom you consent to us sending your personal information. Third parties include our partners, affiliates, service providers and professional advisors. Personal Data may also be shared with regulators in order to demonstrate compliance with legal obligations. Personal Data will only be shared with third parties to provide our services to you and/or to comply with legal obligations. These third parties do not retain, share, use or process Personal Data beyond the defined purpose of providing our services to you.

Compulsory Information

The information you provide to us for the purposes of verifying your identity is necessary for us to comply with our legal and regulatory obligations under the Proceeds of Crime Act, Terrorism Prevention Act and any other laws and regulations that fall under the anti-money laundering regime. If you do not provide us with this information or documents, we will not be able to conduct our due diligence (i.e., Know Your Client (“KYC”) procedures or employee screening), and consequently, we will not be able to offer or provide you with access to our products and services, or offer to you employment opportunities (as the case may be).


How we protect your Personal Data

IECCU is committed to protecting the security of your Personal Data. We (and our third party service providers) use a variety of industry-standard security technologies and procedures, as well as organizational measures to help protect your Personal Data from unauthorized access, use, or disclosure, such as:

  • We use vulnerability scanning and/or scanning to PCI standards.
  • We use regular Malware Scanning.
  • Your Personal Data is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems, and are required to keep the information confidential. In addition, all sensitive information you supply is encrypted via Secure Socket Layer (SSL) technology.
  • We implement a variety of security measures when a user enters, submits, or accesses their information to maintain the safety of your personal information.
  • All transactions are processed through a gateway provider and are not stored or processed on our servers.
  • However, no method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, while IECCU uses reasonable efforts to protect your Personal Data, we cannot guarantee its absolute security.


Your Rights


Under the JDPA, data subject enjoy the following rights:
  • Right to be informed – You are entitled to be informed about whether and how the IECCU uses or processes your Personal Data.
  • Right to access your Personal Data – You are entitled to make a written request to us to be provided with information concerning Personal Data that is being processed by the IECCU. You are also entitled to request a copy of your data. You may also request that your Personal Data be transferred to a third party (another data controller).
  • Right to data portability – where you have requested copies of your Personal Data or for your Personal Data to be transferred to another data controller, you have the right to require your data to be provided to you in an intelligible form; or for your information to be transferred to that data controller in a structured, commonly-used and machine-readable format.
  • Right to consent- You have the right to consent to the processing of your Personal Data. Where you have provided us with your consent, you also have the right to withdraw that consent at any time.
  • Right to be informed about automated decision making- You are entitled to not be subject to a decision based only on automated processing the purposes of evaluating, for example, your work performance, creditworthiness, reliability or conduct/behaviour. You may also request in writing that decisions regarding your Personal Data that have been made solely on the basis of automated processing be reconsidered with human involvement.

    Please note however that we do not process your Personal Data by automatic means.

  • Right to prevent processing - You are entitled to make a written request to us to cease or not to begin processing your Personal Data in a specific manner or for a specific purpose.
  • Right to rectification - You may request that inaccuracies in your Personal Data be rectified. “Rectification” means amend, block, erase or destroy, as may be required to correct the inaccuracy. You may request that your Personal Data be erased on the expiration of any applicable retention period.


Retention Policy


We only retain your Personal Data for as long as it is needed to provide our services to you. We also retain Personal Data in line with legal requirements which may stipulate retention periods for different categories of Personal Data. We typically therefore retain members’ Personal Data for a minimum of seven years following the date of transaction or termination of customer relationship.

We may also keep your data for longer than seven years if we cannot delete it for legal, regulatory or technical reasons.


Notifiable data breaches

We take data breaches very seriously. We will endeavour to meet the 72-hour deadline as imposed by the JDPA to report any data breach to the Information Commissioner, as well as to notify you in a timely manner and without due delay, where you have been affected by any data breach.

Our report will inform you of:
  • the nature of the security breach;
  • the measures taken or proposed to be taken to mitigate or address the possible adverse effects of the breach; and
  • the name, address and other relevant contact information of our Data Protection Officer or other designated representative.


We will review every incident and/or breach and take action to prevent future incidents or breaches.

Children's privacy


Our services are not offered to persons under the age of 18 without parental or guardian consent. Any information that is in breach of this provision will be deleted.

If you become aware that a child has provided us with information, please contact our Privacy Officer.

Changes to This Privacy Policy

Data privacy and protection is an ongoing responsibility and so this Privacy Policy is subject to occasional revision to ensure that it remains in line with the ever-evolving regulatory and security landscape. IECCU therefore reserves the right, at its sole discretion, to modify or replace any part of this Privacy Policy. It is your responsibility to check this Privacy Policy periodically for changes. The last date of modification will be noted at the bottom. Continued use of our Site or Services indicates your acknowledgement that it is your responsibility to review this Privacy Policy periodically and become aware of any modifications. Changes to this policy are effective once they have been uploaded to our website.

Contact Information

IECCU welcomes your comments or questions regarding this Privacy Policy. If you have a question or comment regarding this Privacy Notice or you would like to make a complaint, please contact our Data Protection Officer using the details below.


Privacy & Legal Management Consultants Limited
dpo@privacymgmt.org
(876) 561-3713 | (876) 908-3555

If at any time you would like to unsubscribe from receiving future emails, you can email us at info@ieccu.com and we will promptly remove you from ALL correspondence.

Last Update: June 2024