This CORPnet privacy policy ("policy") applies to corporate clients, authorized signatories, and other authorized users ("you", "user") of the CORPnet corporate internet banking portal ("CORPnet", "the portal") of BRAC Bank PLC. The terms "BRAC Bank", "bank", "we", "us", or "our(s)" in this policy refer to BRAC Bank PLC.
BRAC Bank is firmly committed to protecting the privacy of its corporate clients and has taken all necessary and reasonable measures to safeguard the confidentiality of any information transmitted through CORPnet. This online privacy policy explains how we collect, share, use, and protect information when your organization's authorized users access or use CORPnet.
Through CORPnet, authorized users of corporate clients can view account information, initiate and approve transactions, manage trade and treasury instructions, generate statements and reports, and carry out other corporate banking activities online, subject to the mandates and approval workflows set up by the client organization.
As you review this CORPnet privacy policy, here are a few general principles to keep in mind:
Definitions
- Bank (BBPLC): BRAC Bank PLC, having its registered office at Anik Tower, 220/B, Tejgaon-Gulshan Link Road, Tejgaon I/A, Dhaka 1208, Bangladesh.
- Corporate Client: An organization with an account at BRAC Bank that is enrolled in CORPnet.
- Users: Individuals authorized by a Corporate Client to access CORPnet, typically assigned one of three roles — Maker, Checker, or Approver — as set out in the client's Board Resolution.
- 2FA Device: A hardware or software token that generates a one-time password (OTP) for two-factor authentication.
- Instructions: Communications from a Corporate Client to the Bank, submitted through CORPnet in accordance with agreed security procedures.
1. Agreement to Policy
By registering for, logging into, or otherwise using CORPnet through a web browser on any device, you confirm your affirmative consent — on behalf of yourself and, where applicable, your organization — to all the terms of this policy detailed below, and agree to comply with any other security procedures we may establish from time to time.
2. Gathering, Using and Sharing: Information That We Collect
Information we may collect about you and your organization through CORPnet includes information provided during onboarding or by your relationship manager, such as company name, registration and incorporation details, business address, authorized signatory names and designations, contact information (phone, email), account and transaction mandates, and information disclosed for KYC and due diligence purposes. We may also gather additional information from other sources to verify the information provided.
3. Usage of Information
In addition to the information described above, we may collect certain information about your use of CORPnet. For example, we may capture the IP address and browser of the device you use to log in, login timestamps, session duration, transaction and approval activity, and other information about actions taken within the portal.
We use the information discussed above in several ways, such as:
- To verify the identity of the corporate client and its authorized users
- To process transactions, approvals, and requests initiated through CORPnet
- To maintain accurate account and mandate records
- To protect, investigate, and deter against fraudulent, unauthorized, or illegal activity.
4. Disclosure of Information
By enrolling in CORPnet, the Corporate Client authorizes BRAC Bank to use its and its Users' personal and account information where required, for the purposes described in this policy. We will take necessary measures to keep that information confidential, and will disclose it to third parties, with your authorization, only in the following situations:
- To comply with the requirements of the law, or as required by the government or a supervisory or regulatory organization.
- To prevent fraud, or for other reasons required under applicable banking rules and regulations.
- To address, rectify, ameliorate, or mitigate fraud, security, or technical issues.
- With our trusted service providers (when required) who work on our behalf and do not have an independent use of the information we disclose to them; such providers have agreed to adhere to the rules in this privacy policy.
Information exchanged between the Corporate Client and BRAC Bank through CORPnet, including Instructions submitted by Users, is treated as confidential and is used only to verify, process, and execute the requested banking activity.
5. Data Retention
Our operational systems will store organization- and user-provided data for as long as your organization uses the related feature of CORPnet. Please note that some or all of the provided data may be required for CORPnet to function properly, and we may be required by law or regulation to retain certain information beyond the period of use.
6. Updating Your Information
Authorized users can review certain account and profile information through CORPnet. Changes to registered signatories, mandates, or company details must be requested through your relationship manager or branch, in line with the bank's applicable verification procedures.
7. Security Measures
- Protecting the confidentiality of your information is very important to us. We have established appropriate physical, electronic, and procedural safeguards to protect the information we collect from or about CORPnet users. Access to this information is limited to authorized employees and contractors who need it to operate, develop, or improve CORPnet, and these safeguards are reviewed regularly.
- Each User receives a unique User ID by email and a temporary password by SMS to their registered mobile number, and must change this password on first login and periodically thereafter. The User ID and password, together with any 2FA Device, serve as the User's authorized signature for transactions carried out on CORPnet.
- Users are responsible for keeping their credentials and 2FA Devices confidential and must not share them with anyone. If a token is lost or a password is compromised, the User must notify BRAC Bank immediately so the User ID can be deactivated; the Bank may also suspend access on being notified that credentials have been compromised.
- Corporate Clients are responsible for maintaining up-to-date anti-virus and anti-spyware protection on the devices used to access CORPnet, and for taking reasonable precautions where Users access CORPnet using third-party email domains (such as Google, Yahoo, or Hotmail), which carry inherent additional risk.
- We take reasonable security measures to help protect your information, both during transmission and once we receive it. However, no method of electronic transmission or storage is 100% secure, and use of the internet carries inherent risk that Users accept when using CORPnet.
8. Consent to Transfer
If your organization or its authorized users are located outside of Bangladesh, please be aware that the information we collect through CORPnet will be transferred to and processed in Bangladesh. By using CORPnet or providing us with any information, you fully understand and unambiguously consent to this transfer, processing, and storage of your data in Bangladesh.
9. Authorized Use Only
CORPnet is intended solely for use by corporate clients and their duly authorized signatories and representatives acting in a business capacity. Access must not be granted to, or used by, individuals who are not authorized by the client organization, including persons under the age of 18.
10. Anti-Money Laundering
Users agree not to use CORPnet for money laundering or any other illegal or unlawful purpose, and to fully comply with applicable anti-money laundering and anti-terrorism laws. BRAC Bank reserves the right to request an explanation from the Corporate Client regarding any suspicious transaction, and to take appropriate action in line with banking rules, regulations, and applicable law.
11. Termination of Service
A Corporate Client may request termination of CORPnet at any BRAC Bank branch or through their Relationship Manager by giving at least 30 days' written notice; termination takes effect on or before the 30th day after the request is submitted. BRAC Bank may also suspend or terminate CORPnet access, with or without prior notice, where reasonably necessary under applicable banking rules and regulations. Termination does not affect either party's obligations, or any Instructions given, before the effective date of termination — including our obligations regarding information already collected under this policy.
12. Questions and Concerns
If you have any questions about this policy or our privacy practices, please call our 24/7 call center at 16221 or email us at enquiry@bracbank.com.
13. Policy Updates and Effective Date
This policy is subject to change, and any changes will become effective when posted on CORPnet. Continued use of CORPnet after such changes means you accept the revised policy.