Data protection policy

This policy describes the organisational and technical safeguards Trapets has implemented to protect personal data as processor for our customers.

A tall building with a curved glass facade reflecting the sky and clouds.

Data policy

Purpose

Trapets provides services and systems to the global finance industry for transaction monitoring, KYC, customer due diligence, including screening, and market and trade surveillance.

This policy describes the organisational and technical safeguards Trapets has implemented to protect Personal Data processed by Trapets within our service delivery, asa  processor for our customers (the controllers). 

Data protection policy

Definitions

  • Personal data

    Any information relating to an identified or identifiable natural person (data subject).

  • Processing

    Any operation or set of operations performed on personal data, such as collection, recording, organisation, structuring, storage, adaptation alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

  • Controller

    The natural or legal person, public authority or other body, who determines the purposes and means of the processing of personal data, in this case Trapets’ customer(s) or their affiliate(s).

  • Processor (or sub-processor)

    The natural or legal person, public authority or other body that processes personal data on behalf of the data controller, in this case Trapets, including Trapets affiliates and sub-processor(s).

  • Data subject

    An identified or identifiable natural person.

  • Screening data

    Content in the agreed and specified screening lists included in the agreed Screening services. Such lists can be company information and beneficial ownership lists, sanctions lists, PEP lists or other lists, as specified in the applicable customer agreement.

General privacy principles

Personal data shall always be:

  • processed fairly and lawfully (“lawfulness, fairness and transparency”);
  • collected and processed for specific and legitimate purposes (“purpose limitation”);
  • adequate, relevant and limited to what is necessary for the purpose (“data minimisation”);
  • accurate and kept up to date (“accuracy”);
  • kept for no longer than is necessary for the purpose (“storage limitation”);
  • processed using appropriate technical and organisational measures to protect against unauthorised alteration, accidental loss, destruction or damage (“integrity and confidentiality”).

Lawfulness, fairness, and transparency

Trapets as a processor does not determine the scope or purposes for the processing we perform for its customers as controllers.

Purpose limitation

All personal data processed by Trapets as a processor for our customers is processed in accordance with the agreement, including the Data Processing Agreement and applicable instructions, with each customer.

Data minimisation

Trapets may assist customers by providing an overview of the data or categories of data that our products or services require to perform their intended functionality. The data or categories of data that are finally processed for each customer are defined by the customer.

Accuracy

The Controller should take necessary steps to ensure that the information and Personal Data sent to Trapets is correct and up to date. 

Trapets provides Screening Data "as is", it is therefore incumbent on the Customer to check that the Screening Data is of high enough quality for its use of the Customer.

Stage limitation

Depending on the product, Trapets offers a standard configuration and/or the possibility for each Controller to define customised deletion routines or to request deletion on an ad hoc basis in accordance with the Controllers’ internal retention policies.

Integrity and confidentiality

Trapets uses a data classification system that ensures integrity and confidentiality. All personal data processed by Trapets as a processor is subject to the highest level of security, and access is restricted to employees with a need for such access for the performance of Trapets’ services. All Trapets employees are bound by a confidentiality undertaking.

Categories of personal data

In the course of service delivery for its customers, Trapets will process personal data of the following categories of data subjects. 

  • Transaction Monitoring, end customers and transaction counterparties
  • Customer Due Diligence: end customers (incl. prospects), incl. beneficial owners (UBO) and representatives
  • Screening, Trapets KYC and Trapets Broker: end customers (incl. prospects) and counterparties (as applicable), incl. beneficial owners (UBO) and representatives
  • Transaction Screening: sender, beneficiary, intermediaries, and free-text fields
  • Persons listed on Screening Lists (Screening Data)
  • Ultimate beneficial owners (UBO) and representatives with a connection to end customers
  • Market and Trade Surveillance: end customers and trading participants
  • Users in the Instantwatch platform 

A categorisation of each data field has been made if it contains personal data or not in the indata specification for the data being processed. The detailed indata specifications for each product are found on the Trapets documentation site.

A smiling woman with blonde hair, holding a laptop.

Data protection

Security measures

Trapets has technical and organisational measures in place, including but not limited to information security policies and regular training in secure handling of personal data. Trapets is certified according to the ISO 27001 Standard in Information Security Management, which confirms Trapets' ability to uphold a high level of information safety and security. More information can be found in Trapets’ Information Security Policy and other documentation made available by Trapets. 

A person’s hands writing in a notebook with a pen.

Data protection policy

Full documentation

Find the full documentation for the Data protection policy and read more here.

Trust centre

Discover more

  • A person going past a window with colorful reflections.

    Information security and privacy

    We understand that security and customer data are crucial to our solutions and adhere to the highest information security management standards.

  • A modern office setting with a group of people seated around a wooden conference table.

    Code of conduct

    We must observe high ethical principles in all our activities. Each individual is critical in defining and protecting our most valuable asset - trust.