IMG_POLITICA_PRIVACIDADE

Privacy policy

1. GENERAL FRAMEWORK
Atrium Investimentos – Sociedade Financeira de Corretagem S.A. (“Atrium”) is an investment company based on Avenida da República, No. 35, 2nd floor, 1050-186, Lisbon, legal person number 504.312.189, registered at the Lisbon Commercial Registry Office, with a share capital of 3.742.109,00 Euros, registered with the securities market commission (“CMVM”) and the Bank of Portugal with the registration number 269 and 231, respectively.

In view of the new legal framework, ATRIUM has adopted internal measures that are considered appropriate in order to protect the personal data being processed. These include personal data, such as, names, the identification numbers, location data or even personal contacts. The activities of collection, registration, alteration, consultation, use, transmission and destruction represent data processing operations.

ATRIUM is mainly engaged, albeit not exclusively, in the activity of portfolio management for others and investment advice.

ATRIUM is still authorized and registered with the CMVM to – in addition to the activities mentioned above – provide the following services:

  1. Execution of orders on behalf of others;
  2. Reception and transmission of orders for others;
  3. Currency exchange services and the rental of safes related to the provision of investment services;
  4. Trading on its own behalf;
  5. Registration and deposit of financial instruments;
  6. Consultancy on capital structure, industrial strategy and related issues, as well as on mergers and the acquisition of companies;
  7. Granting of credit, including the lending of securities, to carry out transactions on financial instruments in which the credit grantor intervenes;
  8. Assistance in public offering relating to securities;
  9. Underwriting and placement with or without guarantee in a public distribution offer.

This Privacy Policy and Protection of Personal Data (“Policy”) is applicable to all the processing of personal data carried out by ATRIUM, namely as regards the following data subjects:

  1. Clients;
  2. Collaborators;
  3. Contractual counterparties.

The processing of personal data based on the performance of a contract to which the data holder is a party, or the processing of personal data under pre-contractual steps at the request of the data subject, is carried out by ATRIUM under the following contracts:

  1. Advisory Contract for investment;
  2. Portfolio Management Contract;
  3. Registration and Deposit Contract;
  4. Financial Intermediation Contract for Open Accounts with Custodian Financial Institutions;
  5. Employment Contracts;
  6. Other types of contracts celebrated with ATRIUM employees and/or suppliers.

2. ACCOUNTABLE FOR PROCESSING
ATRIUM is the entity accountable for processing, since it is ATRIUM that defines the purposes and means of processing personal data.

3. TYPE OF DATA PROCESSED BY ATRIUM
The personal data collected by ATRIUM corresponds to the data that is provided by the Customers themselves by the filling out of forms when opening an account or, still, personal data that results from the established business relationship, such as carried out transactions, products and/or services subscribed or transmitted instructions/orders. It should be noted that under the Law on Combating Money Laundering and the Financing of Terrorism (Law No. 83/2017, of August 18th), the establishment of any business relationship or the carrying out of an occasional transaction, are subject to the collection and processing of the following personal data and respective evidence:

  1. Photograph;
  2. Full name;
  3. Signature;
  4. Date of birth;
  5. Nationality shown on the identification document;
  6. Type, number, expiration date and issuing entity of the identification document;
  7. Tax identification number, or equivalent number issued by a competent foreign authority;
  8. Profession and employer;
  9. Full address of permanent residence and tax residence (if different);
  10. Place of birth;
  11. Other nationalities not included on the identification document.

Equally, ATRIUM is obliged – under the terms of DMIF II (Directive 2014/65 / EU of the European Parliament and of the Council of May 15th 2014) – to assess whether a particular investment in products, services or financial instruments is or not appropriate to the Customer’s personal circumstances. The adequacy assessment requires the collection and processing of information on:

  1. Knowledge and experience in the field of financial investments;
  2. The financial situation and the ability to tolorate losses;
  3. Investment goals;
  4. Risk tolerance.

4. PROCESSING PURPOSE AND PROCESSING BASED ON HOLDER’S CONSENT
ATRIUM only processes personal data if, and to the extent that, at least one of the following situations occurs:

  1. The data holder has given consent for the processing of personal data, for one or more specific purposes;
  2. Processing is necessary for the performance of a contract to which the data holder is a party, or for pre-contractual steps at the request of the data holder;
  3. Processing is necessary to fulfill a legal obligation to which ATRIUM is subject;
  4. Processing is necessary to defend the vital interests of the data holder or another singular person;
  5. Processing is necessary for the purpose of the legitimate interests pursued by ATRIUM or by third parties, unless the interests or fundamental rights and freedoms of the data holder that require the protection of personal data prevail, especially if the data holder is a child .

The purpose of the processing of personal data is determined, with the respective legal basis, in accordance with the provisions of Article 6, No. 3 of Regulation (EU) 2016/679 (“GDPR”).

In the event that ATRIUM processes personal data for purposes other than those for which the personal data has been collected, and if the processing is not carried out based on the consent of the holder of personal data, nor on any applicable legal or regulatory provisions which constitute a necessary and proportionate measure to safeguard the objectives referred to in the No. 1 of the 23th Article of the GDPR, ATRIUM, in order to verify whether processing for other purposes is compatible with the purpose for which the personal data was initially collected, has, takes into account and in particular (Article 6, No. 4 of the GDPR):

  1. Any link between the purpose for which the personal data was collected and the purpose of the subsequent processing;
  2. The context in which personal data was collected, in particular with regard to the relationship between data holders and ATRIUM;
  3. The nature of the personal data, especially if processing of personal data related to criminal convictions and offenses under the 10th article of the RGPD is at stake;
  4. The possible consequences of the intended subsequent processing for the data holders;
  5. The existence of adequate safeguards, e.g. encryption or pseudonymization.

Provided that processing of personal data is carried out on the basis of the holder’s of personal data consent, ATRIUM retains the necessary documents to be able to demonstrate that the data holder has given consent for the processing of personal data.

If the consent of the data holder is given in the context of a written statement that also concerns other matters, the request for consent is presented in a way that clearly distinguishes that from those other matters, in an intelligible and easily accessible way and in clear and simple language.

The data holder has the right to withdraw consent at any time, although the withdrawal of consent does not compromise the lawfulness of the processing carried out on the basis of previously given consent, a fact of which the data holder is informed before giving consent.

ATRIUM applies the appropriate procedures in order to ensure that consent is as easy to withdraw as it is to give.

Consent is not considered free in the case of the execution of a contract, including the provision of a service, if it is subject to the consent for the processing of personal data that is not necessary for the execution of that contract (Article 7, No. 4 and considering (43) of the GDPR).

In assessing the validity of the holder of personal data consent, ATRIUM takes into account the provisions of the Guidelines of the Working Party 29th Article on Data Protection about consent under the GDPR.

5. PERSONAL DATA HOLDER RIGHTS
Under the applicable legislation, the data holder shall be entitled the following rights:

  1. Right of Access: the Customer’s right to access the respective personal data and treatment. The provision of information by ATRIUM to Customers must be made, in particular, without restrictions, without delays or excessive costs;
  2. Right of Rectification: the Customer’s right to demand the correction or updating of their data in order for it to be accurate and current;
  3. Right to Termination: the Customer’s right to demand the termination of their personal data when, for example, It is no longer used for the purposes for which it was collected, without prejudice to the content of the retention periods imposed by law;
  4. Right to Limitation of Treatment: the Customer’s right have to, in certain circumstances, request ATRIUM to limit the processing of their data, namely (i) when they contest the accuracy of personal data, during a period that allows ATRIUM to verify its accuracy; (ii) The processing of the data is illegal and has been opposed to the deletion of personal data, requesting, in return, the limitation of its use; (iii) ATRIUM no longer requires personal data for processing purposes, but such data has been required for the purposes of declaring, exercising or defending a right in a judicial process.
  5. Data Portability Right: The data holder has the right to receive the personal data concerning him/her and that he/she has provided to ATRIUM, in a structured format, for current use and automatic reading, and the right to transmit this data to another person in charge of processing without ATRIUM being able to prevent it, under the terms of the 20th Article of the GDPR.
  6. Opposition right: the right to oppose to the processing of data under the provisions of the 21th Article of the GDPR.

For the exercise of any right, below are ATRIUM’s contacts.

6. INFORMATION SHARING
As a rule, ATRIUM does not transfer or share information with third parties relating to personal data, unless required to do so due to legal or regulatory requirements.

ATRIUM is obliged by law, to communicate the personal data of its customers to the regulatory entities that supervise it and to other public entities, including the following:

  1. Bank of Portugal, in accordance with the provisions of the current legal and regulatory regime;
  2. Securities Markets Commission, in accordance with the provisions of the legal and regulatory regime for the markets in financial instruments;
  3. Tax and Customs Authority;
  4. Central Department of Investigation and Criminal Action (DCIAP), Financial Intelligence Unit and other judicial and police authorities under the terms of the Anti-Money Laundering and Terrorist Financing Act.

7. PERSONAL DATA SECURITY
ATRIUM uses organizational and security measures in order to protect personal information in such a way as to ensure its integrity, availability and confidentiality. Therefore, all ATRIUM employees are required to keep personal data confidential.

8. RETENTION OF PERSONAL DATA
The data will be kept for the period of time strictly necessary for the purposes of its processing or by legal or regulatory determination.

9. COOKIES POLICY
You can consult our cookies policy here.

10. CONTACTS
For any questions related to the processing of your data, you can contact ATRIUM at the following addresses:

ATRIUM Investimentos – SFC, SA

Address: Av. da República n.º 35, 2nd floor, 1050-186 Lisbon, Portugal
Phone: +351 217 928 800
Fax: +351 217 928 801
E-mail: privacidade@atrium.pt

ATRIUM undertakes to make every effort to resolve any claims regarding the processing of personal data that are submitted, however, you can always submit a complaint to the competent authority – National Data Protection Commission (https://www.cnpd.pt).