Privacy Policy for Online Time Deposits
I. Statement of Policy
Farmbank, Inc. (A Rural Bank) (“Farmbank”, “the Bank”, “we”, “us”, or “our”) is committed to protecting and respecting your privacy rights under Republic Act No. 10173, the Data Privacy Act of 2012 (the “Data Privacy Act”), its Implementing Rules and Regulations, and all applicable issuances of the National Privacy Commission (“NPC”), and relevant regulations of the Bangko Sentral ng Pilipinas ("BSP") on data protection and information security.
This Privacy Policy explains how Farmbank, together with its shareholders, directors, officers, employees, agents, representatives, consultants, and advisors collects, uses, stores, shares, and protects your personal data across our branches, website, online banking channels, and all other touchpoints. As a bank, Farmbank processes personal data pursuant to general principles of transparency, legitimate purpose, and proportionality, and is committed to instituting fair information practices consistent with the expectations of our clients, depositors, and other data subjects.
II. Who This Policy Applies To
This privacy policy applies to:
This Policy applies to personal data in whatever form it is held (physical or digital) and however it is processed (manual or automated). Where your personal data is also covered by the Secrecy of Bank Deposits Act, the Anti-Money Laundering Act, or other special laws recognized under Section 5 of the Data Privacy Act's Implementing Rules and Regulations, this Policy applies concurrently with, and does not diminish, the protections afforded to you under those laws. Farmbank remains bound to implement appropriate security measures to protect your personal data regardless of any such special treatment.
III. What Data We Collect
The types of personal data we collect depend on the nature of your interaction with us. This may include, but is not limited to:
Information you give us
Information collected when you apply for an account online (e-KYC)
When you apply for a time deposit account through our website, we use an electronic Know-Your-Customer (e-KYC) process to verify your identity. This may involve collecting:
We collect and process biometric data because it is required under applicable BSP and AMLC customer due diligence and e-KYC regulations, and, where applicable, with your consent. Biometric and identity verification data is used solely to confirm your identity, prevent fraud, and comply with these requirements, and is not used for any unrelated purpose without your separate consent.
Information collected automatically through our website
When you visit our website, we and our service providers may automatically collect limited technical information, such as your IP address, browser and device type, pages visited, and session activity. This information is used to keep our website and online banking channels secure, functional, and reliable, and to detect and prevent unauthorized access or fraud. See Section 13 for details on cookies.
IV. Why We Collect Your Data
We collect and process your personal data based on one or more of the following legal grounds:
Where we process sensitive personal information, such as biometric data collected during e-KYC or government-issued identification numbers, we do so only where you have given your consent, or where such processing is required or authorized under banking, e-KYC, or anti-money laundering laws and regulations, in accordance with Section 13 of the Data Privacy Act's Implementing Rules and Regulations.
V. How We Collect Your Data
We collect your personal data when you apply for or maintain an Online Time Deposit account, including when you:
We may also collect or receive your personal data from:
VI. How We Use Your Data
We use your data according to the nature of your relationship with us, including to validate your identity, fulfill our contractual obligations, process transactions, and provide customer care and support. Specific purposes include, but are not limited to:
If we intend to use your personal information for any purpose not disclosed above, we will inform you of that purpose at or before the time we collect the information.
VII. Who We Share Your Data With
Your data is accessed only by Farmbank personnel who are authorized and need to know it to perform their role. Beyond our internal teams, we may disclose your data, on a strictly need-to-know basis and subject to appropriate data sharing or confidentiality agreements, to:
We do not sell your personal data to third parties.
VIII. How We Protect Your Data
We implement reasonable and appropriate organizational, physical, and technical measures to protect your personal data against accidental or unlawful destruction, alteration, unauthorized disclosure, and access, consistent with BSP guidelines on information security and technology risk management. These measures include:
Encryption
Sensitive information stored in our authorized cloud environment is protected by industry-standard encryption for data both in transit and at rest, together with access controls. Sensitive files that must be transmitted outside that environment (for example, by email) are further protected using strong, industry-recognized file-level encryption (such as the AES-256 standard) before transmission.
Access Control
Access to systems containing personal data is granted strictly on a need-to-know and role-based basis, supported where applicable by multi-factor authentication, and is reviewed regularly. Public or unrestricted sharing of files containing personal data is not permitted.
Governance and Oversight
Our Board of Directors and Senior Management maintain overall oversight of data privacy compliance, supported by a designated Data Protection Officer (“DPO”) and Compliance Unit responsible for implementing this Policy, conducting privacy impact assessments, and organizing regular data privacy and information security training for our personnel.
Confidentiality Obligations
Employees, contractors, and third-party service providers with access to personal data are bound by confidentiality obligations that continue even after their employment or engagement ends.
Incident Response
We maintain a data breach response team and incident response procedures to detect, contain, and address security incidents. Where a personal data breach is likely to give rise to a real risk of serious harm, we will notify the National Privacy Commission and affected data subjects within seventy-two (72) hours of discovery, in accordance with the Data Privacy Act and NPC regulations.
IX. Confidentiality of Deposits
In addition to the protections under the Data Privacy Act, your deposit accounts and related information are treated as absolutely confidential. We do not examine, inquire into, or disclose information about your deposits except in limited circumstances allowed by law, such as: with your prior written permission; upon examination specifically authorized by the Monetary Board of the BSP; upon order of a competent court in cases involving bribery or dereliction of duty by a public official, or where the deposit is the subject of litigation; or upon lawful request or order of the AMLC pursuant to its functions under the Anti-Money Laundering Act.
X. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, to comply with legal or regulatory requirements, or to establish, exercise, or defend legal claims. As a general rule, customer identification records, account files, and related correspondence are retained for the duration of your account and for at least five (5) years after account closure, consistent with the Anti-Money Laundering Act and applicable BSP regulations. Records relevant to a reported transaction or an active investigation, litigation, or claim may be retained longer, for as long as necessary for that purpose. Once retention is no longer required, we will securely destroy, de-identify, or anonymize your data.
XI. Your Rights as Data Subjects
Under the Data Privacy Act, you are entitled to the following rights over your personal data:
Right to be informed
To know whether your personal data is being, will be, or has been processed, including the existence of automated decision-making and profiling.
Right to access
To obtain reasonable access to your personal data and confirmation of how it is processed.
Right to object
To object to the processing of your personal data where it is based on consent or legitimate interest, including for direct marketing, automated processing, or profiling.
Right to erasure or blocking
To request the suspension, withdrawal, blocking, removal, or destruction of your personal data from our systems, subject to legal and regulatory retention requirements.
Right to be indemnified
To be compensated for damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of your personal data.
Right to file a complaint
To lodge a complaint with the National Privacy Commission if you believe your personal data has been misused, disclosed without authority, or improperly disposed of, or that your data privacy rights have otherwise been violated.
Right to rectification
To dispute and have us correct any inaccuracy or error in your personal data within a reasonable time.
Right to data portability
To obtain a copy of your personal data in an electronic or structured, commonly used format, and to have it transmitted to another party, where technically feasible.
These rights may be exercised by your lawful heirs or assigns in case of your incapacity or death. To exercise any of these rights, please contact our Data Protection Officer using the details in Section 17.
XII. Your Consent
Before submitting an Online Time Deposit application, the applicant shall be required to acknowledge the Bank's Terms and Conditions and Privacy Policy by clicking "Submit," the applicant confirms that they have read, understood, and agree to be bound by the Bank's Terms and Conditions and Privacy Policy, and consent to the collection, use, storage, and sharing of their personal data for the purposes described therein.
Such consent shall remain valid for the duration of the banking relationship and for the applicable records retention period required by law or regulation, unless withdrawn earlier in writing, subject to applicable legal, regulatory, and contractual requirements. Withdrawal of consent shall not affect the lawfulness of any processing undertaken prior to such withdrawal and may affect the Bank's ability to continue providing the Online Time Deposit product where the processing of personal data is necessary.
XIII. Cookies and Similar Technologies
Our website may use cookies and similar technologies to keep you securely logged in, remember your preferences, understand how our website is used, and help us improve our services. Some cookies are essential for the website and our online banking channels to function and cannot be disabled without affecting your ability to use certain features. You can control or disable non-essential cookies through your browser settings; please note that doing so may limit some website functionality.
XIV. Other Websites
Our website may contain links to sites operated by third parties. These linked websites are not controlled by us, and we are not responsible for their data privacy practices. Before disclosing any personal information on a linked website or mobile app, we recommend that you review its privacy policy and terms of use.
XV. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our products and services, or applicable laws and regulations. Any material changes will be posted on this page with an updated date. We encourage you to review this Policy periodically.
XVI. Contact Us
If you have questions or concerns about this Privacy Policy, wish to exercise any of your rights as a data subject, or would like to inquire about our data protection practices, please contact our Data Protection Officer:
Email: support@farmbankph.com
Head Office: Teodoro R. Arcenas Trade Center, Roxas City, Capiz
Telephone: (6210-619) • (6214-532)
If you believe your data privacy rights have been violated, you may also file a complaint with the National Privacy Commission at complaints@privacy.gov.ph or through its official website.
Effectivity: July 13, 2026