HSBC UK Business Banking app Privacy Notice

Privacy Notice

At HSBC, we take the privacy of your information seriously and are committed to ensuring that your information is secure. If you are using your mobile device in the United Kingdom, you should read our main Privacy Notice at http://www.business.hsbc.uk/en-gb/gb/generic/legal-information. If you are based in Jersey, Guernsey, or the Isle of Man ("CIIOM"), then you should read our Channel Islands Privacy Notice at https://www.business.ciiom.hsbc.com/en-gb/regulations/privacy-policy

You should read the Privacy Notice relevant to your location as it explains what information we collect about you, how we'll use that information, who we'll share it with, the circumstances when we'll share it, and what steps we'll take to make sure it stays private and secure.

You can contact our Data Protection Officer (DPO) by writing to Customer Service Centre, BX8 1HB, marking your letter for the attention of DPO. You can exercise your rights by writing to DPO (HBUK CMB), HSBC UK Bank plc, Customer Service Centre, BX8 1HB, and marking the letter for the attention of Rights of Individuals Fulfilment (ROIF). Alternatively, you can contact us via the HSBC Mobile Business Banking App where you can chat to us 24/7, via telephone banking, or in branch.

When you use the HSBC Mobile Business Banking App

When you use the HSBC Mobile Business Banking App (the "App"), we will collect information about the device the App is installed on (e.g. device identification numbers). We will collect this information directly from you, e.g. when you enter information into the App.

We use the above information to deliver the services offered in the App, and we need to process it in order to carry out the agreement we have with you. We may also use that information, together with information about your location (country or region, not your precise location) and information about your usage of the App (e.g. how long you spend on particular pages), for the following purposes. The lawful basis for this usage is that we have a legitimate business interest to improve our products and services to best meet our customers' needs, and to provide products and services we think are relevant to them.

  • Tailoring the content and the services that you're offered through the App.
  • Understanding how our customers use their accounts.
  • Monitoring trends in product offerings.
  • Developing propositions and products and target them appropriately.
  • Identifying products and offers which may be of interest to you.
  • Making the App services better for you.

The App may store all the above information securely on your device, and access it when required using cookies. Some types of cookies are optional, and you can set our App not to permit them. Please use the Manage Cookie Settings in the More menu of the App for more information and to change your settings.

We may use other HSBC Group companies, and/or third parties, to provide the App on our behalf.

Location Data

The Mobile Cheque Deposit service needs to access your location to confirm where you and your mobile device are located. Your mobile device may ask you to authorise the App to access your location before you can deposit a cheque, but you can disable this access at any time once you deposit your cheque.

If you use the Mobile Cheque Deposit service in the App, the lawful basis for collection of your location data is that we have a legitimate business interest to process your location information so that we can determine your location to allow you to deposit the cheque within the UK or CIIOM. We will always process your location information in accordance with the relevant Privacy Notice and/or the EULA governing the use of the App.

Access to Google Maps /Google Earth

APIs through the App is subject to separate Google terms and conditions available at:

  • Maps Terms: http://maps.google.com/help/terms.html
  • Legal Notices: http://maps.google.com/help/legalnotices/maps.html
  • AUP: http://www.google.com/enterprise/earth/maps/legal/us/maps_aup.html
  1. Services such as ATM/Branch Finder and Mobile Cheque Deposit require the App to have access to your mobile devices location settings which may need to be turned on in your devices settings.
  2. You may withdraw this consent at any time by turning off the location services settings on your mobile device.
  3. You acknowledge and agree that HSBC has no control over the content of Google Maps.

Our security software may check your mobile device for information including:

  • Whether your device has been jailbroken or rooted,
  • Your device's operating system version, and
  • It may also assign to your device a unique identifier that will survive a device reset and uninstallation/reinstallation of the App.

Please note that whilst these checks are conducted to protect the security of your mobile banking sessions and reduce the risk of fraud, you cannot rely on the App as an anti-virus or security program in its own right. The App will not report any detected malware or other security threats to you, and it remains your responsibility to ensure that your device remains free of such malware and threats.

We'll keep your information in line with our data retention policy. For example, we'll normally keep your main banking information for a period of seven years from when our relationship with you ends. This allows us to comply with legal and regulatory requirements or use it where we need to for our legitimate purposes such as managing your account and dealing with any disputes or concerns that may arise. We may need to keep your information for longer where we need the information to comply with regulatory or legal requirements, help detect or prevent fraud and financial crime, answer requests from regulators etc. If we don't need to keep information for this length of time, we may destroy, delete, or anonymize it sooner.

The table below explains what information HSBC collects from your device, how it uses it, and whether it shares it. In some cases, e.g. when accessing the contacts stored on your device, or photos that you take with your device, HSBC will first ask your permission. HSBC may share your information with other HSBC group companies and any sub-contractors, agents, or service providers who work for us or other HSBC group companies (including their employees, sub-contractors, service providers, directors, and officers) to provide you with products or services that you ask for (such as bank accounts and payments) and as explained in our main privacy notice - this type of data sharing is not included in the table.

Permissions we request that need your data

What information does it collect?

Devices

What is it used for?

How is it used?

User's network, Wi-Fi connections and cellular network information

Android

  • Connecting app to servers and internet
  • Fraud checks and prevention
  • Uses information to connect to servers and internet
  • Monitors network and Wi-Fi data to conduct fraud checks and prevention

Location data

Android
iOS

Applies restrictions for customers depositing cheques outside of UK and Channel Islands

Uses location information to permit users located in UK or Channel Island to deposit cheques

Paired Bluetooth devices

Android
iOS

Fraud checks and prevention

Uses information from user's paired Bluetooth devices for fraud checks and prevention

Biometric data (Face, fingerprint or other authenticators if available)

Android
iOS

For biometric authentication

Allows user to use fingerprint hardware on their devices for biometric authentication in app

Camera and images

Android
iOS

For scanning and depositing cheques

Uses user's camera image for scanning and depositing cheques

Installed applications that are on your device

Android

  • Fraud checks and prevention
  • Open Banking

Uses information for fraud checks and prevention, and Open Banking features

Permissions we request that don’t need your data

Permissions

Devices

What is it used for?

How is it used?

Allows access to the user's device vibrator

Android

Allows user to connect with an agent on the Chat with us feature and receive push notifications

Accesses user's device vibrator when receiving Push notifications and messages from agents on the Chat with us feature

Allows access to keep processor from sleeping or screen from dimming

Android

Allows user to receive Push Notifications

Allows user to receive Push notifications

Allow access to microphone

Android
iOS

For Chat with us feature

This is used by the Chat with us feature

Allows the app to receive boot complete action broadcast after the system finishes booting

Android

Internal project dependency for Android framework

This is a system related permission. Holding this permission improves user experience, decreases the amount of time it takes the system to start and allows the app to run without the user being aware

Allows the app to run in the foreground and supplying ongoing notification to be shown to the user

Android

Internal project dependency for Android framework

This allows the app to continue running in the background and show notifications to users

Allows access to the list of accounts in the Accounts Service - email address used on phone

Android

Allows access to the list of accounts in the Accounts Service

This is an internal dependency used for fraud checks and prevention

HSBC UK Business Banking app Cookies Policy

What are Cookies?

Cookies are small pieces of data that apps store and access on your device when you use them. We use cookies that are relevant to our app. We do this through software built into our app, for example by accessing technical details about your device, or by recording and sharing information about how and when you use certain features within the app.

How long do cookies last?

Strictly necessary cookies are kept for as long as needed to ensure the app functions properly. For optional cookies, we will ask you for your preferences again after 12 months. If you choose to opt out of optional cookies at any time, we will stop using them but we may still use data already collected.

Cookies and your privacy

The information cookies collect, and how we use that information, may be personal data. You have rights when it comes to how we collect, store and use your personal data. You can learn more about how we use your personal information in our Privacy Notice.

Strictly Necessary Cookies

Strictly necessary cookies are necessary to make the app work properly and therefore cannot be disabled.

Cookies that help you to log on

We use these cookies to remember who you are when you log on to this app. You won't be able to log on without them. We work with service providers who also set these cookies on this app.

Who else sets these cookies?

For what purpose?

Transmit

Mobile 'token' - part of new HSBC security platform (DSP)

Cookies that help us to provide core services and features

We use these cookies to provide core services and features on this app. These services and features won't work without them. We work with service providers who also set these cookies on this app.

Who else sets these cookies?

For what purpose?

Airship

To help us deliver meaningful messages at every stage of the customer lifecycle in the form of push notifications.

AppDynamics

To provide us browser performance information in order that we can keep our websites running smoothly

TIS mobiflow

Image processing, used as part of the cheque image scanning function

Tealium Tag Management

To allow us to control the deployment of tags (software that enhances our website) and also to enable the capture and respect of consent preferences obtained from our users

Cookies that help keep our app secure

We use these cookies to protect the security of this app, for example, to make sure it is only accessed by genuine users. This helps us to keep your information safe. We work with service providers who also set these cookies on this app..

Who else sets these cookies?

For what purpose?

Promon Shield SDK

To help us deliver In-app security and protection.

Cookies that help us to detect fraud or crime

We use these cookies to help us to identify suspicious behaviour on this app so that we can protect both you and ourselves from fraud or other crime. We work with service providers who also set these cookies on this app.

Who else sets these cookies?

For what purpose?

Biocatch

Allows us to check unusual or suspicious activity on your device, such as malware, so that we can prevent payment scams and fraudulent activities

Threatmetrix

Detection of malware on device and providing 'risk score' to assist fraud decisioning

Optional cookies

Cookies that help us to improve this app

We use these cookies to help us understand how you use this app. We can then use this data to improve how the app works. For example, we may track how and when you use this app.

Who else sets these cookies?

For what purpose?

Adobe Analytics

To enable us to understand how you use and engage with our app

Tealium Event Stream

To help us manage incoming data, define event requirements and orchestrate outgoing data

Cookies that support marketing

We and our service providers use these cookies to understand what you're interested in. This is so that we can personalise our marketing to you, including online advertising and through post, email, telephone, text, secure message, or social media.

You can change your mind on how you receive certain types of marketing messages or whether you receive them at all. You can find more details about this in our Privacy Notice.

Who else sets these cookies?

For what purpose?

Adobe (Experience Cloud)

To connect various Adobe Suite technologies together in order to profile audiences and use that segmentation in delivering targeted user experiences including advertising both on our own and third-party sites

Tealium (Audience Stream CDP)

To help us deliver personalization (including advertising) based on segmentation informed by your browsing behaviour and to measure the performance of our digital advertising