Security and Privacy Statement

Version 2.2 – Modified 15 May 2025

It is Bahrain Islamic Bank (BisB)'s policy to respect your privacy regarding any information we may collect while operating our website, mobile app, interacting with us through our other physical or electronic channels. This Privacy Policy applies to Bahrain Islamic Bank (BisB) (hereinafter, "us", "we", or "BisB"). We respect your privacy and are committed to protecting personal data and information you may provide us through the channels. We have adopted this privacy policy ("Privacy Policy") to explain what information may be collected on our channels, how we use this information, and under what circumstances we may disclose the information to third parties. This Privacy Policy applies only to information we collect through the channel and does not apply to our collection of information from other sources. This Privacy Policy, together with the Terms and conditions posted on our Website, set forth the general rules and policies governing your use of our channels. Depending on your activities when visiting our channels, you may be required to agree to additional terms and conditions.

Website Visitors

Like most website operators, BisB collects non-personally identifiable information of the sort that web browsers and servers typically make available, such as the browser type, language preference, referring site, and the date and time of each visitor request. BisB’s purpose in collecting non-personally identifiable information is to better understand how BisB’s visitors use its website. From time to time, may release non-personally identifiable information in the aggregate, e.g., by publishing a report on trends in the usage of its website.

Gathering of Personal Data

Certain visitors to BisB’s websites choose to interact with BisB in ways that require BisB to gather personal data. The amount and type of information that BisB gathers depends on the nature of the interaction. For example, we ask visitors who sign up for services through our channels to provide a username, email address, contact number, Card number or PIN, for validation and verification.

Biometrics

We allow customers to login to our mobile app through smartphone or device biometrics, as Trusted Devices, which can be either a device registered fingerprint or facial recognition. We do not store the actual biometric information, but we depend on device stored validation to verify your identity. This feature is available if customers opt-in to enable it and is not enabled by default. Customers can view and delete Trusted Devices registered in their accounts through our E-Banking channels.

For new customers wishing to enroll through our mobile app and self-service devices, we require them to use their device camera or the installed cameras to capture photos of their national ID to retrieve data and information required to open an account as part of the Know Your Customer (KYC) process mandated by the Central Bank of Bahrain (CBB), through integration with the National Electronic Know Your Customer (eKYC) platform (Wathiq). To verify the user, we also take photos and videos and match them with the photos in the supplied IDs. Matching is performed automatically. A video recording is taken throughout the document capturing session to support the identification of potential fraud. The bank and its verification partner perform verifications and checks of new applications for quality and security purposes. In cases where mandatory information is not found in Wathiq, customers may be asked to provide their Driving License or/and Passport to retrieve information needed for regulatory purposes. The identity verification process could be triggered for services or transactions requiring advanced authentication or verification of user identity.

Protection of Personal Data

BisB will not rent or sell personal data and information to anyone. Other than to its employees, contractors and affiliated organizations, as described above, BisB discloses personal data only in response to a regulatory, court order or other governmental request, or when BisB believes in good faith that disclosure is reasonably necessary to protect the property or rights of BisB, third parties or the public at large.

BisB will not disclose any personal data it collects about users to third parties except:

  • To the extent that it is required to do so by any applicable law or regulation;
  • Where there is a duty to the public to disclose;
  • Where BisB interests require disclosure;
  • At a user's request or with a user's consent;
  • To the extent that it is required to do so by any competent court, Central Bank of Bahrain or any other official authority.

Not with standing the above, BisB may disclose personal data about users to those who provide services to BisB or act as BisB's agents, to any person to whom BisB transfers or proposes to transfer any of its applicable rights or obligations and to licensed credit reference agencies or other organizations that help BisB and others make credit decisions and reduce the incidence of fraud or in the course of carrying out identity, fraud prevention or credit control checks. BisB may also transfer information collected and held about users to any country, including countries without data protection laws, for any of the purposes described in this part.

If you are a bank customer or registered user of https://www.ebisb.com and have supplied your email address, BisB may occasionally send you an email to tell you about new features, solicit your feedback, or just keep you up to date with what's going on with BisB and our products. BisB takes all measures reasonably necessary to protect against the unauthorized access, use, alteration or destruction of personal data. You may choose to stop receiving our marketing emails by following unsubscribe instructions included in the emails sent or you may contact us on privacy@bisb.com.

Information We Collect Automatically

We may also automatically collect information about you when you access or use the Site or transact business with Us, including:

  • Transaction Information: We collect information about the transaction, such as product, service or transaction details, and the date and location of the transaction.
  • Log Information: We obtain information about your use of our channels, including the type of browser you use, access times, pages viewed, your IP address and the page you visited before navigating to this Site.
  • Device Information: We collect information about the computer or mobile device you use to access Our Services, such as the hardware model, operating system and version, unique device identifiers, mobile network information, and browsing behavior.
  • Location Information: We may collect information about the precise location of your device when you consent to the collection of this information. We may also collect information about your approximate location each time you access this Site.
  • Information Collected by Cookies and other Tracking Technologies: We may use cookies, web beacons, and other tracking technologies to collect information about you and your interaction with this Site, including information about your browsing behavior, purchase behavior, and other engagement with the Services. Most web browsers are set to accept cookies by default, but you can usually change your browser settings to remove or reject cookies.

We do not collect, process or store sensitive information identified in the Personal Data Protection Law, without explicit consent or in compliance with Central Bank of Bahrain (CBB) regulations.

Customer Profiling

Customer profiling is the practice of analyzing and categorizing customer data to create a profile of their interests, preferences, and behavior. We may use customer profiling to improve our products and services, personalize your experience, and provide you with relevant offers and promotions. We may also share this information with third-party service providers who help us analyze and interpret customer data. Customer profiles are handled with utmost privacy similar to customer financial transaction data. We will use aggregated data and anonymized data where possible to protect your privacy. If you have any questions or concerns about our customer profiling practices, please contact us.

Information We Collect from Other Sources

We may also receive information about you from other sources and combine or link that with information we have about you. For example, we may collect demographic and change-of-address information from the Bank’s associated entities within NBB Group as well as third party sources and information from third parties including government approved sources, including the Central Bank of Bahrain, the Benefit Co. and other government agencies and financial institutions/licensees authorized by the CBB.

We are mandated by the CBB and Personal Data Protection Law to keep the information we have on file about you up to date. To streamline the update process without needing you to visit a branch, we may periodically retrieve and store your information from the National Electronic Know Your Customer (eKYC) platform (Wathiq) and from entities within NBB Group. The following information about you will be periodically retrieved and stored:

  1. Personal and ID Information
  2. Contact Information
  3. Account Details
  4. Employment Details
  5. Residency Information

Your rights

Your principal rights under Personal Data Protection Law are:

  • the right to access - you can ask for copies of your personal data;
  • the right to rectification - you can ask us to rectify inaccurate personal data and to complete incomplete personal data;
  • the right to erasure - you can ask us to erase your personal data;
  • the right to restrict processing - you can ask use to restrict the processing of your personal data;
  • the right to object to processing - you can object to the processing of your personal data and direct marketing;
  • the right to complain to a supervisory authority - you can complain about our processing of your personal data; and
  • the right to withdraw consent - to the extent that the legal basis of our processing of your personal data is consent, you can withdraw that consent.

These rights are subject to certain limitations and exceptions. You can learn more about the rights of data subjects by visiting

http://www.pdp.gov.bh/en/regulations.html

You may exercise any of your rights in relation to your personal data by written notice to us or contacting us by submitting a letter to Complaints officer PO Box 5240 Manama, Bahrain. Or emailing privacy@bisb.com

Links to External Sites

Our Service may contain links to external sites that are not operated by us. If you click on a third party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy and terms and conditions of every site you visit.

We have no control over, and assume no responsibility for the content, privacy policies or practices of any third party sites, products or services.

Mobile App Permissions

Our mobile app will request the below permissions to enable certain functionalities and services:

  • Camera: Used for regulatory Identity verification services for new and existing clients required to perform the Know Your Customer (KYC) process through the Electronic Know Your Customer (eKYC) platform (Wathiq).
  • Location: Used for locating branches and ATMs, and when regulatory Identity verification services for Know Your Customer (KYC) process for new and existing clients is invoked.
  • Microphone: Used for regulatory Identity verification services for Know Your Customer (KYC) process for new and existing clients through video calls.
  • Contacts: Used to enable sending payments through phone number, through integration with national BenefitPay service.
  • Notification: Used for sending app notifications and alerts.
  • Phone: Used to enable clients to call support numbers.
  • Image / Files: Used for submission of supporting documents for services.

Cookies

To enrich and perfect your online experience, BisB uses "Cookies", similar technologies and services provided by others to display personalized content, appropriate advertising and store your preferences on your computer.

A cookie is a string of information that a website stores on a visitor's computer, and that the visitor's browser provides to the website each time the visitor returns. BisB uses cookies to help BisB identify and track visitors, their usage of https://www.ebisb.com, and their website access preferences. BisB visitors who do not wish to have cookies placed on their computers should set their browsers to refuse cookies before using BisB’s websites, with the drawback that certain features of BisB’s websites may not function properly without the aid of cookies.

By continuing to navigate our website without changing your cookie settings, you hereby acknowledge and agree to BisB’s use of cookies.

Cookies used by our service providers

Our service providers use cookies and those cookies may be stored on your device when you visit our website.

App Third Party Collection

Our mobile app does use third party services that may collect information used to identify you.

Link to privacy policy of third party service providers used by the app

Managing cookies

Most browsers allow you to refuse to accept cookies and to delete cookies. The methods for doing so vary from browser to browser, and from version to version. You can however obtain up-to-date information about blocking and deleting cookies via these links:

  • https://support.google.com/chrome/answer/95647 (Chrome);
  • https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences (Firefox);
  • https://help.opera.com/en/latest/security-and-privacy/ (Opera);
  • https://support.microsoft.com/en-gb/help/17442/windows-internet-explorer-delete-manage-cookies (Internet Explorer);
  • https://support.apple.com/en-gb/guide/safari/manage-cookies-and-website-data-sfri11471/mac (Safari); and
  • https://privacy.microsoft.com/en-us/windows-10-microsoft-edge-and-privacy (Edge).

Blocking all cookies will have a negative impact upon the usability of many websites. If you block cookies, you will not be able to use all the features on our website.

Business Transfers

If BisB, or substantially all of its assets, were acquired, or in the unlikely event that BisB goes out of business or enters bankruptcy, user information would be one of the assets that is transferred or acquired by a third party. You acknowledge that such transfers may occur, and that any acquirer of BisB may continue to use your personal information as set forth in this policy.

Privacy Policy Changes

Although most changes are likely to be minor, BisB may change its Privacy Policy from time to time, and in BisB’s sole discretion. BisB encourages visitors to frequently check this page for any changes to its Privacy Policy. Your continued use of this site after any change in this Privacy Policy will constitute your acceptance of such change.

Contact Information

If you have any questions about this Privacy Policy, please contact us via privacy@bisb.com or phone by calling our contact center +973 17515151.