Last Updated: 25th October 2021

Privacy Notice for Ecobank Mobile App

Ecobank Group recognizes the importance of privacy and security of our customers' personal information. We value the trust you place in us to protect your personal information and respect your right to privacy. While new technologies have dramatically changed the way information is gathered, used and stored, preserving customer trust and the privacy of personal information at Ecobank remains a core objective. We believe it is important to make clear to our customers how information is being collected, used and shared at Ecobank, the benefits such use provides, and the protections put in place against unauthorized access and use. We respect your privacy and the confidentiality of your personal information, and we appreciate the opportunity to do business with you.

1. Our Privacy Principles

We will only collect, transfer, process and store your personal information with your express permission unless legally required to do so, and will only use such information for the lawful purpose for which it is required.

• We will disclose the specific purpose for which we use, request and store your personal information.

• We will also keep a record of that personal information and the specific purpose for which we collect it.

• We will not use your personal information for any other purpose, other than that which we disclosed to you, unless you give us your express consent to do so, or unless we are permitted to do so by law.

2. Information we collect

2.1 We may collect information from you when you register on our mobile app. We may collect your name, e‐mail address, phone number, date of birth, gender, residential address, ID number, device ID, and device location depending on how you choose to register on our mobile app.

2.2 We will collect your bank card details including the numbers displayed on the card (Primary Account Number), the Expiry Date, the CVV2 (normally found at the back of the card) and or Card PIN from you during registration using an Ecobank Card or Non-Ecobank Card. For registration using Ecobank Online, we will collect your Ecobank Online Username and Password from you. Generally, we may also collect other personal information from our core banking system as part of your registration profile creation in the mobile app

2.3 We may collect and combine information when you register for our mobile banking services including information you provide to us, device IDs, cookies, and other signals, including information obtained from third parties, to associate accounts and/or devices with you. We collect information about you when we receive it from third parties and affiliates.

2.4 We collect information from devices such as mobile phones and tablets about how you interact with our services and those of our third-party partners and information that allows us to recognize and associate your activity across devices and services. This information includes device specific identifiers and information such as IP address, cookie information, mobile device and advertising identifiers, browser version, operating system type and version, mobile network information, device settings, and software data.

3. How do we use the information we collect?

3.1 Services

We use your data we have collected to authenticate you and authorize access to our Services on the mobile app. Typical services include customer registration, performing financial transactions, subscribing to insurance products, card management services, account management services, payment of bills among others. We use your personal data to enable you perform the services listed below among others;

i. Customer Registration using an Ecobank Card, Non-Ecobank Card, Ecobankonline Credentials, Ecobank Xpress Account or Mobile Money Wallet.

ii. Payment of Bills

iii. Airtime Purchase

iv. Funds Transfer to a Telco Mobile Money Wallet

v. Funds Transfer from an Ecobank account to another Ecobank Account within the same country or any country with an Ecobank presence

vi. Funds Transfer from an Ecobank account to a non-Ecobank bank account within the same country or any country with an Ecobank presence

vii. Funds Transfer from Customer Visa card to another Visa card

viii. International Funds Transfer from an Ecobank Account using SWIFT

ix. Create and TopUp Ecobank Virtual Cards

x. Pay Ecobank Credit Card bills

xi. TopUp Ecobank Prepaid Cards

xii. Cheque Services

xiii. Loans & Term Deposits

xiv. Location of Ecobank Branches, ATMs and Xpress Points

3.2 Communication

We will contact you through email, short message services (SMS), phone call, and other ways through our Services, including text messages and push notifications. We will send you messages about the availability of our Services, security, or other service-related issues. We also send messages about how to use the Services and network updates.

3.3 Advertising

We serve you tailored advertisements both on and off of our Services. We target advertisements to our customer both on and off of our Services through a variety of ad networks and exchanges, using data from advertising technologies on and off of our service and information from advertising partners, publishers and data aggregators.

3.4 Marketing

We use data and content about our customers for invitations, promotions and communications solely for promoting our services.

3.5 Customer Support

We use the data needed to investigate, respond to and resolve complaints and Service issues

3.6 Security, Fraud and Investigations

We use your data (including your communications) if we think it’s necessary for security purposes or to investigate possible fraud or other violations of our User Agreement or this Privacy Policy and/or attempts to harm our Members or Visitors.

4. Legal Basis for Collecting and Processing Data

Ecobank collects and processes personal data only when we have a legal basis for doing so. Data protection legislation gives us a list of possible legal bases we can choose from. Due to the myriad of laws and regulations a financial institution like Ecobank is subject to, we rely on different legal basis depending on the type of processing we are doing. The following are the legal bases we rely on in processing personal data on the mobile app in Ecobank.

• Consent given by our customers

• Performance of contract between the Bank and customers or third parties

• Legal Obligation due to Government banking laws and regulations and

• Legitimate interest of Ecobank.

At any point in the data processing cycle for the different services provided to our customers through this mobile app, we rely on a legal basis to do so.

5. How do we secure your information?

Protecting our systems and our users’ information is paramount to ensuring the Ecobank brand, websites, apps, advertising services, products, services or technologies (“Services”) customers enjoy a secure experience and maintaining our users’ trust. We have taken the following measures to protect your information

5.1 Ecobank has technical, administrative and physical safeguards in place to help protect against unauthorized access, use or disclosure of customer information we collect or store.

5.2 We implement a variety of security measures to maintain the safety of your personal information when you enter, submit, or access your personal information.

5.3 We offer the use of a secure transmission, processing and storage services using standardized security safeguards.

5.4 All supplied sensitive/credit information are encrypted via transaction layer security (TLS) technology during transmission to avoid misuse of your data. Card Number (PAN), CVV and expiry date of any bank cards attached to the Mobile App are tokenized and stored on our backend systems at our data processor. We encrypt all sensitive personal and transactional data during processing and storage.

5.5 Your personal information may be accessible by those authorized with special access rights to such systems, and are required to keep the information confidential. Information such as PINs and passwords are not accessible to our authorized personnel.

6. How and whom do we share your information?

When you use or interact with our services, you consent to the data processing, sharing, transferring and uses of your information as outlined in this Privacy Policy. Ecobank Group shall endeavor to comply with all applicable data protection and privacy regulations including EU General Data Protection Regulations (GDPR).

6.1 To provide you with our services, your personal information may be transferred to countries other than your own to process and store data in accordance with our Privacy Policy and to provide you with products and services. We may transfer your data to affiliates or partners, including for outsourced data processing undertaken on Ecobank’s behalf. The primary data processor for Ecobank Group is a shared technology and payments services company known as eProcess International S. A., a member of the Ecobank Group.

6.2 We share information concerning your transactions and experience within the Ecobank Group (the bank), which includes our technology and securities subsidiaries. This sharing of information is intended only to facilitate the servicing of our customers’ accounts and to offer financial products and services we believe would be beneficial to our customers.

6.3 Under all sharing arrangements, Ecobank requires its service providers and marketing partners to keep such information under strict privacy regulations and prohibits them from disclosing such information to anyone for any other purpose.

6.4 We do not, and will not, share customer information with non-financial companies for the purpose of allowing them to market their products and services to our customers. We do not disclose any non-public personal information about our customers to any other third parties, except as permitted or required by law.

6.5 By using our products and services you consent to us transferring your information to countries outside your local jurisdiction, if necessary, for Ecobank’s legitimate business purposes as defined in our Privacy Policy. We are committed to ensuring your information is protected and apply security safeguards in accordance with applicable law.

7. What choices do you have about your information?

7.1 Data Retention

We keep most of your personal data for as long as your account is active. We retain the personal data you provide while your account is in existence or as needed to provide you with our services.

7.2 Rights to Access and Control Your Personal Data

You can access your personal data from our services when you follow our procedures on data subject requests. You can always modify or update your personal data using the applicable menus in the app.

When you wish to deactivate yourself from this mobile app, you are required to send a request to ecobankenquiries@ecobank.com. Ecobank shall contact you within fourteen days to validate the request for processing. A de-activated account may still have transactional history kept on our systems in accordance with financial laws and data retention policies of the Bank.

7.3 Account Closure

We retain your personal data even after you have closed your account if reasonably necessary to comply with our legal obligations (including law enforcement requests), meet regulatory requirements, resolve disputes, maintain security and prevent fraud.

8. Protecting Children’s Privacy

Our services are for a general audience. We do not knowingly collect, use, or share information that could reasonably be used to identify children under age 13 without prior parental consent or consistent with applicable law.

9. How can you contact us?

If we decide to change our privacy policy, we will post those changes on the mobile app for your notice and consent when required. This policy was last modified on August 12, 2021.

If there are any questions regarding this privacy policy or a data breach incident you would like to report on, please contact us by email or write to us using the information provided below;

Address:

Data Protection Manager

eProcess International S. A.

2 Morocco Lane, Off Independence Avenue

P. O. Box AN 16746, Accra-North

Accra, Ghana

Email: groupdataprivacy@ecobank.com