MFT2GO Privacy Statement
This privacy statement was last updated on 10th February 2023
This privacy statement describes our reasons for collecting personal data through MFT2GO and provides information about individuals’ legal rights in relation to their own personal data. We may use the personal data provided through MFT2GO for any of the reasons set out in this privacy statement.
This privacy statement relates only to MFT2GO. It does not relate to other products, services or sites of PwC or any other party.
Data controller information
The data controller is the entity with primary responsibility for making sure your personal data is handled and processed in accordance with applicable data protection laws.
The data controller of the personal information collected in connection with this application is the PwC member firm responsible for delivering professional services to you or your organization.
If you are not receiving professional services from any PwC firm then the data controller of your personal information is the PwC member firm in the location from which you normally access this application.
Each member firm in the PwC Network is a separate legal entity. For information, see https://www.pwc.com/gx/en/about/corporate-governance/network-structure.html.
For a list of PwC member firms, see https://www.pwc.com/gx/en/about/corporate-governance/legal-entities.html.
For countries and regions in which PwC member firms operate, see https://www.pwc.com/gx/en/about/office-locations.html.
In this privacy statement, “PwC”, “us”, and “we” means the PwC member firm that is the data controller of your personal information.
In this privacy statement, we refer to information about you or information that identifies you as “personal data” or “personal information”. We also sometimes collectively refer to handling, collecting, protecting, transferring, or storing your personal information as “processing” such personal information.
Your acknowledgement/consent for processing
By using this application and providing personal information to us, you acknowledge you have read this privacy statement, and, to the extent your consent is necessary and valid under applicable laws, you consent to the collection, use and disclosure of such personal information by PwC and any third party recipients in accordance with this privacy statement.
The purpose of MFT2GO
The purpose of MFT2GO is to transfer electronic files to and from PwC. The electronic files are encrypted in transit and at rest, and are automatically purged from the application after 14 days.
We do not collect sensitive personal data through MFT2GO (and please do not provide any when using this application)
We do not require or collect from you, and we ask you not to provide, sensitive personal data through this application. Sensitive personal data, also known as special category personal data, covers information relating to, among other things, race, ethnicity, political opinions, religious, philosophical or similar beliefs, biometric or genetic data when used to uniquely identify you, information about health, sexual life, and criminal acts. If you provide sensitive personal data the act of providing it constitutes your explicit consent for us to collect and use that information for the purposes described in this privacy statement.
We do not pass personal information to third parties for direct marketing purposes
We do not sell personal information and we will not pass your information to third parties outside the PwC Network for consumer marketing purposes.
Personal Information We Collect
Providing personal data to us is not a statutory or contractual requirement. However, failing to provide personal data may mean we are unable to properly deliver the services requested by you or your organization.
We collect the following personal information in connection with MFT2GO.
Use of Personal Data
We use personal data provided in connection with MFT2GO for the following purposes.
Third Party Links
The application may link to third party sites not controlled by PwC and which do not operate under PwC privacy practices. When you link to third party sites, PwC privacy practices no longer apply. We encourage you to review each third party site's privacy policy before disclosing any personal information.
Our legal grounds for processing personal data
Applicable laws may require us to set out in this privacy statement the legal grounds on which we rely in order to process your personal information. In connection with MFT2GO, we rely on the following processing conditions:
International transfers of personal data
Cross-border transfers
If we process your personal information, your personal information may be transmitted and stored outside the country where you are located. This includes countries outside the European Economic Area (EEA) and countries that do not have laws that provide specific protection for personal information.
Where we collect your personal information within the European Economic Area, transfer outside the European Economic Area will be only:
Recipients of personal data
Recipients of personal data: other PwC Member Firms
For PwC Member Firm locations, see https://www.pwc.com/gx/en/about/office-locations.html
We may share personal data with other PwC member firms where necessary in connection with the purposes described in this privacy statement. For example, when providing professional services to a client, we may share personal information with PwC Member Firms in different territories that are involved in providing those services to that client.
Recipients of personal data: Third Party Providers
We may transfer or disclose the personal data we collect to third party contractors, subcontractors, and/or their subsidiaries and affiliates. Third parties support the PwC Network in providing its services and help provide, run and manage IT systems. Examples of third party contractors we use are providers of identity management, website hosting and management, data analysis, data backup, security and cloud storage services. The servers powering and facilitating our IT infrastructure are located in secure data centres around the world, and personal data may be stored in any one of them.
The third party providers may use their own third party subcontractors that have access to personal data (sub-processors). It is our policy to use only third party providers that are bound to maintain appropriate levels of security and confidentiality, to process personal information only as instructed by PwC, and to flow those same obligations down to their sub-processors.
Other recipients of personal data
We may also disclose personal information under the following circumstances:
Security
We adhere to internationally recognized standards of technology and operational security in order to protect personal information from loss, misuse, alteration and destruction. Only authorized persons are provided access to personal information. These individuals have agreed to maintain the confidentiality of this information. We have a framework of policies and procedures in place covering data protection, confidentiality and security and regularly review the appropriateness of the measures we have in place to keep the data we hold secure.
Although we use appropriate security measures once we have received your personal data, the transmission of data over the Internet (including by email) is never completely secure. We endeavor to protect personal data, but we cannot guarantee the security of data transmitted electronically over the Internet.
Retention
We will retain your personal information only for as long as we need it for the purposes described in this privacy statement unless we are required by law, regulation or our professional obligations to retain it for a longer period.
Children
Our applications are not intentionally designed for or directed at children, and our terms and conditions of use require all users to be above the age of majority in their local country. We never knowingly collect or maintain personal information about individuals under the age of 18 years.
Changes to this privacy statement
We may update this privacy statement at any time by publishing an updated version on this page. So you know when we make changes, we will amend the last revision date at the top of this page. The new modified privacy statement will apply from that revision date. Therefore, we encourage you to review this privacy statement periodically to be informed about how we are protecting your information.
How to Deactivate Your Account
Users of this application may request their account be deactivated at any time by sending their request to their PwC contact.
Your legal rights in relation to your personal data
You may have certain rights under your local law in relation to the personal information we hold about you.
You may have the rights listed below.
Contact Us
Please submit a request to exercise a legal right in relation to your personal data, or an enquiry if you have a question or complaint about handling of your personal data.