Personal Data Protection Policy

In accordance with Regulation (EU) 2016/679 and Law 4624/2019

Middle Office Services S.A. (hereinafter referred to as «Middle Office»), which operates in the provision of supporting processes or activities on behalf of credit and financial institutions, and any other legal entity, undertakes to protect the personal data and to implement the general Data Protection Regulation of the EU 2016/679 (hereinafter referred to as “GDPR”), Law 4624/2019 and other national and European legislation on the protection of personal data of individuals. In the context of its activity, Middle Office provides, either in accordance with the provisions of Act No. 178/02.10.2020 of Bank of Greece either out of the Act’s scope, Administrative, Consulting and Management services, through execution of any service and/or activity, including organization of internal processes, to its Customers (indicatively and not limited to Credit / Financial Institutions, Companies for the acquisition of claims of Article 1 par. 1b of Law 4354/2015 as in force.

  1. Scope

The Policy defines the terms and conditions to which Middle Office adheres for the protection of individuals, whose personal data are processed for the execution of its work in accordance with the purpose of its operation.

Middle Office reserves the right to amend and readjust this Policy whenever it is deemed necessary, and the changes are made effective from the date of their posting on its website: www.middleoffice.gr.

In the event that any of these terms is considered invalid, unlawful or unfair for any reason, the other terms will remain valid and effective as in force as far as they do not contradict with this Policy.

The Personal Data protection Policy and the Cookies Policy of the Webpage “middleoffice.gr” constitute the overall agreement between Middle Office and personal data subject.

  1. Definitions

 

“Personal Data” means any information relating to an identified or identifiable individual (“data subject”). An identifiable individual is one who can be identified, directly or indirectly, in particular by reference to an identifier, such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that individual.

 

“Processing of Personal Data” means any operation or set of operations which is performed on personal data, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

 

“Controller” means the individual or legal entity, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

“Processor” means an individual or legal entity, public authority, agency of other body which processes personal data on behalf of the controller.

“Recipients of Personal data” means an individual or legal entity, public authority, agency or another body to which the personal data are disclosed, whether a third party or not.

“Webpage” means the website «middleoffice.gr», hereinafter referred to as «Webpage».

“Users” or “User” means the visitor of the webpage.

 

  1. Legal Bases for the Processing of Personal Data and Processing Purposes

Middle Office collects and processes personal data by virtue of the following legal bases and to achieve the following purposes:

3.1.  Where processing is necessary for the monitoring or investigation of a contract, of which the data subject is a contracting party or the processing of the data serves to fulfill the contractual obligations of Middle Office to its customers for the purposes of:

  • Supporting loan administration activities.

3.2. Where processing is necessary for the compliance with Middle Office legal obligation as Processor, for the purposes of:

  • Compliance with the obligations imposed by the applicable legal and regulatory framework (as described below) and the supervisory authorities, as well as with the decisions of Authorities or courts.

3.3.  Where processing is possible in case the data subject’s consent has been expressly provided in advance for the purposes of:

  • The examination of an application for employment at Middle Office.
  • Understanding how data subjects use and interact with the content of the Website through the use of cookies.

In such cases there is the right to withdraw the consent at any time, but without prejudice to the lawfulness of the processing based on consent prior to its withdrawal.

  1. Collection and Processing of Personal data

 

Personal data are collected for the above specific, explicit and legitimate purposes. Any processing of personal data is limited, strictly and only, to the data, necessary for the purposes of such processing (“minimization of data”) and is carried out on the basis of the principles of lawfulness, objectivity and transparency.

 

In particular, the following are collected and processed:

4.1. The personal data of debtors and other parties involved and/or any other individuals in files managed by Middle Office are those that have been transferred by the credit and financial institutions that granted the loan and / or the credit, or any other legal entity, as well as those collected from the following sources:

  • The beneficiaries to whom the claims from loans and credits from Financial Institutions were sold and transferred.
  • Credit Servicers of law 5072/2023 as in force.
  • Lawyers, law firms, court bailiffs and notaries.

 

The Personal data of the debtors and other parties involved, or any other individuals concern the following:

 

  • Certification of Identity
  • Data from the keeping and servicing of the contracts, included in the portfolios available to Middle Office by its Customers.
  • Payment history of debts and data of payment transactions and payment services.
  • Background of legal actions and litigation of claims.
  • Letters of extrajudicial letters exchanged, in respect of debts.
  • Data that may refer to any kind of personal data, as mentioned herein, with regard to the identity of individuals.

4.2. Information collected during the use of the website:

Personal data are collected only if disclosed. No registration is required for the use of the Webpage.
Like most sites, the site of Middle Office uses Google Analytics (GA) to track user activity. We use this data to determine the number of our site visitors to better understand how they find and use our web pages. Although GA records data such as your geographic location, your device, your web browser, and your operating system, none of this information identifies you to us. GA also records your computer’s IP address, which could be used to identify you, but Google does not provide access to it.

 

If you choose to contact us using a contact form or an email link, none of the data you provide will be stored on our site or transferred or processed by any third-party data processor as defined below in the section «Our third-party data processors». Instead, these data will be sent to us via an SMTP protocol (Simple Mail Transfer Protocol). Our SMTP servers are protected by a TLS security protocol (also known as SSL), meaning that email content is encrypted before being sent over the Internet. The content of the email is decrypted by our local computers and devices.

4.3. Especially for job applicants – prospective employees, the personal data processed by Middle Office are determined by the applicable legislation and generally include the name and contact details, data on previous employment, education, skills and any other data included in the curriculum vitae or cover letter to Middle Office. In case the candidate is invited for an interview, some additional personal data as well as special category of personal data may be collected, if this is absolutely necessary for the evaluation of the suitability for specific positions. Finally, the information received from the candidates interviewed may be retained by the interviewers.  

 

  1. Recipients of Personal data

5.1. For the purposes of services provided by Middle Office the following may be the recipients of the data: 

  • Lawyers and law firms, court bailiffs.
  • Service providers appointed by Middle Office for specific services, such as service providers of storage, archiving, data and file management or IT service providers and/or service providers of support of all kinds of information systems and networks or consulting service providers, or providers of audit and accounting/tax services (certified auditors, accountants, etc).
  • Employees of Middle Office who are responsible for the implementation of the services provided by Middle Office.

5.2. Especially for job applicants – prospective employees, their personal data processed by Middle Office are determined by the applicable legislation and generally include the name and contact details, data on previous employment, education, skills and any other data included in the curriculum vitae or cover letter to Middle Office. In case the candidate is invited for an interview, some additional personal data as well as special category of personal data may be collected, if this is absolutely necessary for the evaluation of the suitability for specific positions. The personal data for job applicants is available only to the duly authorized employees of Middle Office, who are in charge of human resources management tasks. Personal data may be sent to cooperating companies as well as to Middle Office partners, who undertake work related to the operation of the contract between them, indicatively, payroll services companies, employment agencies cooperating with Middle Office, seminar and training companies, for participation in an evaluation process and for conducting cognitive tests and / or technical skills assessment tests through cooperating platforms and providing their data to them, tax and legal advisors, third parties carrying out audits at Middle Office under the regulatory obligations of the Company or obligations arising from the applicable legislation. Access to the data of job applicants – prospective employees is provided only after their consent and if they are aware of this Policy and have accepted it when submitting the CV. The cooperating companies as well as the authorized Middle Office external partners will act either as joint controllers of the processing, defining the means and purposes of the processing, or will act as processors on behalf of Middle Office, in both cases bound by the terms hereof on the processing of data, always on the basis of appropriate guarantees and in accordance with the applicable data protection legislation, in order to maintain the required level of data protection. The information received from the candidates retained for one year.

5.3. Middle Office, for personal data provided to third parties for their own use and for which it is recipient, does not sell or transfer them for marketing purposes. Middle Office shall retain the right to use or disclose the information provided if required by law or if it is reasonably considered that such use or disclosure is required to protect the rights of Middle Office and / or to comply with a mandate of a competent authority or any other obligation to disclose or transmit personal data or to implement this Policy, in order to protect the rights, assets or security of Middle Office, its customers or third parties.  The above includes the exchange of information with other companies and organizations for the purposes of protection against fraud and credit risk mitigation.

  1. Transfers of Personal Data to Third Countries or International Organizations.

Middle Office may transfer personal data to third countries outside the EU and the European Economic Area. In this case, the level of protection of the rights of the data subjects and the appropriate safeguards set by the GDPR will be ensured through the application of the standard contractual clauses as defined by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 “on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council” and its Annex, as well as by other relevant Implementing Decisions of the Regulation and any Annexes thereto.

Middle Office may also store Personal Data in countries or areas of jurisdiction outside the place of establishment of the data subjects. By disclosing personal data on its Website, the Users consent to the aforementioned cross-border transfer and storage of their data to third countries.  Middle Office undertakes to take all reasonably necessary measures to ensure that the data is subject to secure processing and always in accordance with the Greek & EU legal and regulatory framework.

In any such case, Middle Office may transfer the personal data to third countries if: (a) an adequate level of protection is ensured in accordance with the European Commission from the third country, from territory or from one or more specific sectors in that third country; or (b) appropriate safeguards have been provided for processing by the recipient on the basis of the legal and regulatory framework on personal data protection. If none of the above conditions apply, the transfer may be made if one the following conditions is met: i) the transfer is necessary for the establishment or exercise of legal claims or the defense of the rights of Middle Office; or ii) there is a relevant obligation of Middle Office from a provision of law or transnational agreement iii) the data subject has expressly consented to the proposed transfer, after having been informed of the possible risks; iv) the transfer is necessary for the performance of a contract between the data subject and Middle Office or for the implementation of pre-contractual measures taken at the data subject’s request; v) the transfer is necessary for the conclusion or performance of a contract which was concluded in the interest of the data subject between  Middle Office and another natural or legal person.

  1. Security of Personal data

Middle Office has taken and is implementing the appropriate technical and organizational measures (i.e. 2 Factor Authentication in critical systems, definition of roles/responsibilities of Middle Office personnel) in order to ensure the implementation of the legislation and the appropriate level of security of personal data and has duly trained its staff and binds all its associates, with contracts governed by the guarantees and safeguards of Regulation (EU) 2016/679. In particular, Middle Office’s Website Users should take into consideration that the Website may also contain links to other websites in respect of which Middle Office does not bear any responsibility for the practices and conditions of data protection or their content.

  1. Rights of Data Subjects

Legislation on the protection of personal data provides the following rights, which are, in principle, exercised without financial burden, on the basis of the provisions of the legal framework, provided that there are no restrictions on their exercise provided for by the legal framework:

– Right of access, i.e. confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, information on which data has been collected and processed by Middle Office, their origin, the purposes and the legal basis for their processing, any recipients or categories of recipients of personal data, in particular in third countries and the period for which the personal data will be stored.

– Right to rectification of any inaccurate personal data by submitting to Middle Office a statement of correction or completion of any incomplete personal data in order to become complete and accurate.

– Right to erasure of personal data in the following cases:

  1. the personal data are no longer necessary, in relation to the purposes for which they were collected or otherwise processed
  2. the consent on which the processing of personal data was based is withdrawn, without retroactive effect, and there is no other legal ground for the processing
  3. the personal data have been processed without the existence of the necessary legal base
  4. where the law provides for the obligation to erase personal data
  5. where personal data of a child have been collected through the provision of information society services, with the consent of the child if he / she is over 16 years of age or, if the child is under 16 years of age, with the consent given or authorized by the holder of parental responsibility over of the child.

– Right to restriction of processing of personal data in the following cases:

  1. the accuracy of the personal data is contested and until Middle Office verifies the accuracy of the personal data
  2. where the conditions for erasure of the previous paragraph are met and instead of erasure, the restriction of processing of personal data shall be requested
  3. where personal data are no longer needed for processing purposes, but such personal data are required for the establishment, exercise or defense of legal claims
  4. where there are objections to the processing and the right of objection may be exercised until Middle Office verifies whether the legitimate grounds for the processing override those of the data subject.

– Right to object to the processing of personal data at any time and on grounds relating to the particular situation of the data subject, when the processing is necessary for the performance of a task carried out for reasons of public interest or the legitimate interests pursued by Middle Office or third party, unless there are compelling and legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defense of legal claims of Middle Office.

– Right to data portability, i.e. the right to receive in a structured, commonly used and machine-readable format and to transmit those data to another controller, which have been provided to Middle Office, if the processing of personal data has taken place following consent or was necessary for the performance of a contract.

– Right to withdraw at any time the consent (without retroactive effect) provided to Middle Office, in case the processing of personal data is based on consent.

These rights may be restricted by an obligation of implementation of other laws, for example in the case of a request for restriction, erasure of data or even objection, where Middle Office is obliged to retain and process such data by law.

For the exercise of the above rights as well as to resolve any question regarding the applicable legislation on personal data, you can contact Middle Office as follows:

-Through the electronic contact form at:  Middleoffice.gr – Contact

-By letter to the Data Protection Officer: by post to 330, Venizelou av., Building B, 6th floor, 17675 Kallithea (attn. DPO), Greece or via email dpo@middleoffice.gr.

-At the above address and email you can attach:

  • the form of exercise of your above rights, originating from the GDPR (Template 1)

Middle Office will respond without financial burden to the request, without delay and in any case within one month (30 days) from the receipt of the request, except for exceptional cases, in which case the above deadline may be extended by two more months, if necessary, taking into account the complexity of the request and / or the number of requests. Middle Office informs about any extension of the above deadline within one month from the receipt of the request, as well as the reasons of the delay.

In particular:

– If the submitted request is not satisfied according to the above, there is the possibility of submitting a complaint to the Hellenic Data Protection Authority [Kifissias 1-3, PC 115 23, Athens, tel .: +30 2106475600, www.dpa.gr, e-mail: contact@dpa.gr], as well as filing an appeal before the competent judicial authorities.

– If the request is deemed by Middle Office to be manifestly unfounded or excessive, the payment of a reasonable and proportionate fee may be imposed, taking into account the costs of satisfying the request or not being followed up by a reasoned decision of Middle Office.

  1. Personal Data Retention Time

    Middle Office retains the personal data of individuals for as long as provided for in each case from the applicable legal and regulatory framework and in any case for a period of twenty (20) years from the last calendar day of the year of termination of the respective transactional relationship with the Customer of Middle Office. In case any request for cooperation with Middle Office is not accepted, the data will be retained for a period of five (5) years. In case of litigation, personal data will be retained until the end of the pending litigation, even in case of exceeding the maximum period of twenty (20) years.

Especially for job applicants – prospective employees, personal data are retained for the period that is absolutely necessary to achieve the purpose of their collection but also in accordance with the relevant legislation. Where personal data are not necessary for the above purposes, they will be safely destroyed after one (1) year. If the prospective employee accepts a proposal for cooperation with Middle Office, the personal data collected prior to the recruitment will be part of his or her personal file and will be retained throughout his / her employment and for some additional years after the termination of the cooperation, in accordance with applicable law. Finally, for the fulfillment of the legal or contractual obligations of Middle Office or for the establishment, exercise or defense of any legal claims, personal data may be retained for a period exceeding two (2) years.

In case of change of the retention periods of the personal data provided for by law or by regulatory acts, the above retention periods of personal data will be reduced or increased accordingly.

  1. Contact Details

Company Name:  MIDDLE OFFICE SERVICES S.A
Trade Name: MIDDLE OFFICE S.A.
Registered office: 330 El. Venizelou (Thiseos) Av., Building B, 6th floor, 176 75 Kallithea, Greece

Telephone: 219 2190114

Data Protection Officer:
Address: 330 El. Venizelou (Thiseos) Av., Building B, 6th floor, 176 75 Kallithea, Greece

Telephone: 219 2190114
Email: dpo@middleoffice.gr

Latest Update 23.08.2024.