personal data protection policy

1. Who We Are

Servdebt Capital Asset Management, S.A. ("Servdebt") respects the privacy of the data subjects with whom it interacts and is committed to ensuring that personal data is processed lawfully, fairly, transparently, and securely, in compliance with Regulation (EU) 2016/679 ("GDPR") and all other applicable data protection legislation.

Servdebt operates in the areas of asset management, servicing, credit management and debt recovery, as well as the provision of specialised services to financial institutions, investors and other entities.

Within the scope of these activities, Servdebt may act either as a data controller or as a data processor, depending on the nature of the services provided and the applicable contractual framework. In such cases, personal data may be processed on behalf of and under the instructions of its clients, in accordance with applicable data protection laws.


2. Scope

This Privacy and Personal Data Protection Policy applies to the processing of personal data carried out by Servdebt in connection with the provision of asset management, servicing, credit management and debt recovery services, as well as other outsourcing and related services provided to its clients.

The processing activities described in this Policy may be carried out by Servdebt either as a data controller or as a data processor, depending on the nature of the activity performed and the responsibilities assigned under applicable law.

This Policy is addressed to individuals whose personal data is processed by Servdebt within the context of the above-mentioned activities.

This Policy does not apply to personal data processing activities subject to specific privacy notices issued by Servdebt in other contexts, including recruitment processes, employment relationships, internal organisational management, supplier management or any other activities governed by separate privacy notices.


3. What Personal Data We Process

In the course of its business activities, Servdebt may process the following categories of personal data:

  • Identification data;
  • Contact details;
  • Information relating to agreements, credit facilities and managed assets;
  • Financial and asset-related information;
  • Information relating to judicial, enforcement, insolvency or other legally relevant proceedings;
  • Data obtained directly from data subjects;
  • Data received from Servdebt’s clients;
  • Data obtained from publicly available sources or from third parties legally entitled to disclose such information.

Whenever special categories of personal data are processed, Servdebt shall implement the safeguards and measures required under applicable law.


4. Purposes of Processing

Personal data may be processed for the following purposes:

  • Management and monitoring of credit portfolios;
  • Provision of servicing activities;
  • Default management;
  • Debt collection and recovery;
  • Contacting debtors, guarantors, representatives or other parties connected to managed credits or assets;
  • Asset management activities;
  • Performance of services contracted by Servdebt’s clients;
  • Risk assessment and management;
  • Fraud prevention and detection;
  • Compliance with legal, regulatory and supervisory requirements;
  • Audits and internal control procedures;
  • Establishment, exercise or defence of rights in judicial, administrative or arbitral proceedings;
  • Monitoring and improving the quality of services provided.

5. Legal Bases for Processing

The processing of personal data by Servdebt is based, where applicable, on one or more of the following legal grounds:

  • Performance of a contract or implementation of pre-contractual measures;
  • Compliance with legal and regulatory obligations;
  • Legitimate interests pursued by Servdebt or its clients;
  • Consent of the data subject, where applicable;
  • Establishment, exercise or defence of legal claims in judicial, administrative or arbitral proceedings.

6. With Whom We Share Personal Data

Servdebt may disclose personal data to third parties whenever necessary for the purposes described in this Policy or where required by law.

Recipients of personal data may include, among others:

  • Owners or holders of the credits, assets or portfolios under management;
  • Judicial, administrative, tax and supervisory authorities;
  • Lawyers, solicitors, enforcement agents, insolvency practitioners and other professionals involved in credit management or recovery activities;
  • Financial institutions;
  • Auditors, consultants and statutory auditors;
  • Public or private entities where disclosure is required by law or regulation.

Servdebt may also engage external service providers to support its business activities, including providers of technological, administrative, operational, communication, analytical, document management, asset management, servicing, debt collection and debt recovery services.

In this context, personal data may be disclosed to entities contracted or subcontracted by Servdebt for the performance of tasks related to the services provided to its clients, including credit management, monitoring, collection and recovery activities. Such entities shall process personal data under contractual arrangements that ensure appropriate confidentiality, security and data protection safeguards.

Servdebt ensures that all entities processing personal data on its behalf provide sufficient guarantees of compliance with applicable data protection laws and implement appropriate technical and organisational measures.


7. International Transfers of Personal Data

Whenever it is necessary to transfer personal data to countries outside the European Economic Area ("EEA"), Servdebt shall ensure that appropriate safeguards are implemented in accordance with applicable legal requirements.

Such safeguards may include, among others, adequacy decisions adopted by the European Commission, standard contractual clauses approved by the competent authorities or any other legally recognised transfer mechanisms.


8. Data Retention Periods

Personal data shall be retained only for as long as necessary to fulfil the purposes for which it was collected and processed and in accordance with applicable legal requirements.

For servicing activities, personal data shall be retained for a period of five (5) years following the termination of the portfolio management activity, contractual relationship or the purpose that justified the processing.

For outsourcing activities, personal data shall be retained for the periods established in the relevant service agreements, in accordance with instructions provided by Servdebt’s client or for the periods required under applicable law.

Notwithstanding the above, Servdebt may retain certain personal data for longer periods where necessary to comply with legal or regulatory obligations, or for the establishment, exercise or defence of legal claims in judicial, administrative or arbitral proceedings.


9. Data Subjects’ Rights

Under applicable data protection legislation, data subjects are entitled to exercise the following rights:

  • Right of access to personal data;
  • Right to rectification of inaccurate or incomplete personal data;
  • Right to erasure of personal data, where legally applicable;
  • Right to restriction of processing;
  • Right to object to processing;
  • Right to data portability, where applicable;
  • Right to withdraw consent at any time where processing is based on consent.

Requests regarding the exercise of these rights may be submitted to Servdebt using the contact details provided in this Policy.

Servdebt shall respond to such requests within the time limits established by applicable law.


10. Data Security

Servdebt implements appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.

Such measures are reviewed and updated periodically to ensure a level of security appropriate to the risks associated with the processing activities carried out.


11. Complaints

Without prejudice to any other administrative or judicial remedy, data subjects have the right to lodge a complaint with the competent supervisory authority if they believe that the processing of their personal data infringes applicable data protection laws.
For data processing activities carried out in Portugal, complaints may be submitted to the Portuguese Data Protection Authority (Comissão Nacional de Proteção de Dados - CNPD).


12. Contact Details

For any questions regarding this Privacy and Personal Data Protection Policy or the processing of personal data by Servdebt, data subjects may contact:

Servdebt, Capital Asset Management, S.A.
Praça Príncipe Perfeito, Número 2, Piso 5, 1990-278 Lisboa
E-mail: [email protected]
Website: www.servdebt.com


13. Changes to this Policy

Servdebt may update this Privacy and Personal Data Protection Policy from time to time, particularly to reflect legislative, regulatory or operational changes.

The most current version of this Policy will always be available on Servdebt’s website.

top

This website uses cookies to ensure you get the best experience on our website. For more information, click here.

By continuing to browse or by clicking “accept all cookies”, you agree to the storing of cookies in your device to enhance your site experience and for analytical purposes.