تخط إلى المحتوى

سياسة الخصوصية

آخر تحديث الإصدار 1.0

1. Purpose and Scope

This Privacy & Data Protection Policy (the “Policy”) sets out the principles and framework governing the collection, use, processing, storage, and disclosure of personal data by Beirut Brokerage Corporation SAL (the “Company”, “we”, “us”, or “our”).

The Company acts as the data controller in relation to the personal data it processes.

As a licensed financial institution operating under the supervision of the Banque du Liban and the Capital Markets Authority, the Company is subject to strict regulatory obligations, particularly in relation to anti-money laundering and counter-terrorism financing (AML/CFT). These obligations require the collection and processing of personal data as part of client onboarding, risk assessment, and ongoing monitoring.

The Company processes personal data in accordance with applicable Lebanese laws and regulations, including the regulatory requirements of the Banque du Liban, notably those relating to data confidentiality, information security, and electronic services.

This Policy aims to:

  • Ensure transparency in how personal data is handled
  • Define internal standards for data protection and confidentiality
  • Inform clients and users of their rights and how their data is used

This Policy applies to:

  • Clients and prospective clients
  • Users of the Company’s website and digital onboarding systems
  • Any individual whose personal data is processed in the course of the Company’s activities

This document serves both as the Company’s internal data protection policy and its external privacy notice.

2. Data Protection Principles

The Company adheres to the following core data protection principles:

2.1 Lawfulness, Fairness and Transparency

Personal data is processed in a lawful manner, based on valid legal grounds, and in a way that is clear and understandable to clients.

2.2 Purpose Limitation

Data is collected only for specific and legitimate purposes, primarily related to regulatory compliance and the provision of financial services, and is not used in ways incompatible with those purposes.

2.3 Data Minimization

Only personal data that is necessary for the intended purpose is collected and processed. The Company avoids excessive or unnecessary data collection.

2.4 Accuracy

Reasonable steps are taken to ensure that personal data is accurate, complete, and kept up to date.

2.5 Storage Limitation

Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, including compliance with legal and regulatory obligations.

2.6 Integrity and Confidentiality

Personal data is protected against unauthorized access, loss, misuse, or disclosure through appropriate technical and organizational safeguards.

3. Categories of Personal Data

In the course of its activities, the Company may collect and process various types of personal data, depending on the nature of the relationship with the client.

3.1 Identity and Verification Data

This includes basic identifying information necessary to establish the identity of clients:

  • Full name, date and place of birth
  • Nationality and identification numbers
  • Copies of official identification documents (passport, national ID, etc.)

This data is essential for verifying identity and meeting regulatory requirements.

3.2 Contact Data

This includes information used to communicate with clients:

  • Residential or mailing address
  • Email address
  • Telephone number

3.3 Financial and Economic Data

This category includes information required to understand the financial profile of the client:

  • Source of funds and source of wealth
  • Employment status and professional information
  • Bank account details and payment information

This data supports both regulatory compliance and suitability assessments where applicable.

3.4 KYC / AML Data

This includes information generated or assessed as part of compliance processes:

  • Risk classification and client profile
  • Politically Exposed Person (PEP) status
  • Sanctions screening and verification results

3.5 Technical and Usage Data

When interacting with the Company’s systems or website, certain technical data may be collected:

  • IP address
  • Device and browser information
  • Website usage patterns and access logs

This data is used for security, system performance, and analytics purposes.

3.6 Biometric and Verification Data

As part of digital onboarding, the Company may process:

  • Facial recognition and liveness detection data
  • Identity verification results

This data is collected through specialized providers such as Sumsub, and is used solely for identity verification and fraud prevention.

4. Methods of Data Collection

Personal data is collected through various channels, depending on the interaction with the Company:

4.1 Direct Collection

Data is collected directly from clients when they:

  • Complete onboarding or application forms
  • Communicate with the Company
  • Request services

4.2 Digital Onboarding Systems

The Company uses digital onboarding platforms to streamline identity verification and compliance processes.

4.3 Third-Party Sources

To meet regulatory requirements, data may be obtained from:

  • Identity verification providers
  • Public registries and official records
  • Compliance and screening databases

4.4 Automated Technologies

When using the Company’s website, certain data is collected automatically through:

  • Cookies
  • System logs
  • Analytics tools

5. Purpose of Processing and Legal Basis

In most cases, the processing of personal data is required by law or is necessary for the Company to provide its services.

5.1 Regulatory Compliance (Legal Obligation)

The primary purpose of processing is to comply with AML/CFT laws and regulatory requirements. This includes:

  • Verifying client identity (CDD/KYC)
  • Assessing risk and client profiles
  • Monitoring transactions and activities
  • Reporting suspicious transactions to authorities

5.2 Provision of Services (Contractual Necessity)

Personal data is processed to:

  • Evaluate client applications
  • Onboard clients
  • Provide brokerage or arranging services
  • Maintain ongoing relationships

5.3 Operational Purposes (Legitimate Interests)

The Company processes data to:

  • Maintain accurate records and audit trails
  • Improve systems and services
  • Manage communications
  • Prevent fraud and enhance security

5.4 Consent-Based Processing

In certain limited situations, the Company may process personal data based on the client’s consent. This typically applies to processing that is not strictly required by law or for the provision of core services, such as:

  • Marketing communications
  • Optional services or features

Clients may withdraw their consent at any time. However:

  • Withdrawal of consent will not affect the lawfulness of processing carried out prior to such withdrawal
  • It does not apply to processing required by law (such as AML/KYC)

6. Data Sharing and Disclosure

Personal data may be shared with third parties where necessary and appropriate.

6.1 Service Providers

The Company works with specialized providers to support its operations, including:

  • Sumsub, for identity verification, fraud prevention, and compliance checks
  • IT and system providers responsible for infrastructure, hosting, and security

These providers are contractually bound to maintain confidentiality and protect personal data.

6.2 Partner Brokers

Where services involve arranging or facilitating account opening, personal data may be shared with partner brokers.

The Company may share personal data with partner brokers, including entities that may be under common ownership or management with the Company.

Such partner brokers may be located in jurisdictions outside Lebanon, and by engaging with the Company’s services, clients acknowledge and accept that their personal data may be transferred and processed in such jurisdictions for the purpose of service provision.

6.3 Regulatory Authorities

Personal data may be disclosed where required by law, including to:

  • Special Investigation Commission (SIC)
  • Banque du Liban
  • Capital Markets Authority
  • Law enforcement agencies

6.4 Professional Advisors and Financial Institutions

Data may also be shared with:

  • Banks and payment providers
  • Auditors, legal advisors, and consultants

7. International Data Transfers

Due to the nature of the Company’s operations, personal data may be transferred to jurisdictions outside Lebanon.

Where such transfers occur:

  • Transfers are limited to what is necessary
  • The receiving parties are required to apply appropriate data protection and confidentiality standards
  • Contractual and organizational safeguards are applied

8. Data Retention

Personal data is retained in line with legal and operational requirements.

In particular:

  • AML/CFT-related data is retained for the minimum period required by law
  • Data may be retained for audit and legal purposes
  • Once no longer needed, data is securely deleted or anonymized

9. Automated Decision-Making and Profiling

The Company may use automated systems as part of onboarding and compliance processes.

These may include:

  • Identity verification tools
  • Risk assessment models
  • Eligibility checks

Such processes may involve the use of profiling based on financial or identification data, strictly for compliance and risk assessment purposes.

Where applicable, clients may request a review of these assessments and decisions.

10. Data Subject Rights

Clients may have the following rights:

  • Access to their personal data
  • Correction of inaccurate data
  • Deletion of data (subject to regulatory and legal constraints)
  • Restriction or objection to processing
  • Data portability (where applicable)
  • Withdrawal of consent (where applicable)
  • File a complaint with a competent authority, where applicable

Requests are handled within a reasonable timeframe, typically within 10 days.

11. Data Security and Confidentiality

The Company maintains strong security measures, including:

  • Controlled access to systems and data
  • Secure Storage and encrypted communications (where applicable)
  • Monitoring mechanisms
  • Staff confidentiality obligations

These measures are designed to prevent unauthorized access or misuse of personal data. While the Company implements robust technical and organizational measures to protect personal data in accordance with applicable regulatory requirements. However, no system or transmission can be guaranteed to be completely secure.

To the fullest extent permitted by applicable law, the Company shall not be held liable for any unauthorized access, data breaches, loss, or alteration of personal data resulting from cyber incidents, system failures, or acts or omissions of third parties, where such events occur beyond the Company’s reasonable control, provided that the Company has complied with its legal and regulatory obligations and implemented appropriate safeguards

12. Cookies and Website Technologies

Cookies and similar technologies may be used to:

  • Enhance user experience
  • Analyse website performance
  • Improve security

Users can manage cookie settings through their browser.

13. Governance and Responsibility

The Compliance Function is responsible for overseeing data protection practices and ensuring compliance with this Policy.

All employees are required to:

  • Handle personal data responsibly
  • Maintain confidentiality
  • Follow internal procedures

14. Contact Information

For any inquiries regarding this Policy:

Compliance Department

Beirut Brokerage Corporation SAL

Email: compliance@bbcorpfx.com

Address: Beirut, Verdun, Diamond Building, 8th floor

Phone: +9611789101

15. Policy Updates

This Policy may be updated periodically to reflect legal or operational changes.

The latest version will always be made available through the Company’s official channels.