|

Privacy and Information Security Principles
Citizens Bank of Northern California (CBNC) has adopted the following principles:
Exclusive and Proprietary Network
Access and use of our network is for authorized persons only. If you are not authorized to access or use this network, exit this network now. For the protection of the network and its authorized users, all activities on the network may be monitored and recorded. Unauthorized or improper access or use of this network may subject the user to both criminal prosecution and civil liability.
Recognition of a Customer's Expectation of Privacy
CBNC recognizes and respects the privacy expectations of customers. CBNC has established policies and procedures to prevent misuse of customers' nonpublic personal information.
What is "Nonpublic Personal Information"?
Nonpublic personal information is personally identifiable financial information such as 1) information provided by a customer on a form or application, 2) information about a customer's transactions, or any other information that CBNC has obtained about a customer which is otherwise unavailable to the general public.
Collection and Retention of Information
CBNC collects and retains nonpublic personal information about customers only where CBNC reasonably believes it is useful (and allowed by law) in administering the business and in providing products, services, and other opportunities to the public.
Disclosure of Consumer Information with CBNC
The CBNC employees, departments, business units, affiliates, etc. share nonpublic personal information about individual consumers only where CBNC reasonably believes it is useful (and allowed by law) in administering the CBNC business and in providing products, services, and other opportunities to our consumers. For example, our New Accounts Department may inform our Marketing Department about a new customer to offer the new customer other products and services which might be of interest to the consumer.
Disclosure of Consumer Information to Nonaffiliated Third Parties
In some instances it is impractical for CBNC not to disclose a consumer's nonpublic personal information to nonaffiliated third parties. For example, our New Accounts Department may share your checking account number and address with our check-printing vendor to print your checks. Nonpublic personal information may be disclosed to nonaffiliated third parties:
- To effect, administer, or enforce a transaction that a customer requests or authorizes
- At the customer's request
- To comply with a legal requirement such as a subpoena
- To help administer the bona fide business of CBNC.
Except as indicated above, CBNC does not currently disclose nonpublic personal information to nonaffiliated third parties. Additionally, CBNC does not have any future plans to change this policy on disclosing data. In the event CBNC does change this policy on disclosing data, the consumer will be notified and given a reasonable opportunity to "opt out" whereupon that individual's nonpublic personal data will not be disclosed.
Whenever CBNC does provide specifically identifiable consumer information to a third-party, CBNC insists that the third-party adhere to similar privacy and information security principles that provide for keeping such information confidential.
Limiting Employee Access to Information
CBNC limits access to our customers' confidential and private information to employees with a legitimate business reason for knowing such information. CBNC will educate our employees about the importance of confidentiality and customer privacy. Employees will be appropriately disciplined for any failure to comply with these privacy and information security principles.
Protection of Information via Established Security Procedures
CBNC has established security procedures regarding unauthorized access to customer information.
Disclosure of Privacy and Information Security Principles to Customers
CBNC will make these privacy and information security principles available to our customers so that our customers can get a better understanding of our commitment to safeguarding our customers' confidential and private information.
Special Information Applicable to Electronic (Internet) Banking
The CBNC privacy and information security principles will apply to customers' confidential and private information with regard to both traditional and non-traditional (i.e. Internet) banking activities. However, due to the unique nature of the internet and the ease with which information can be exchanged, CBNC feels it is important for its customers to be aware of the unique issues surrounding internet banking.
To Better Serve Legitimate Internet Banking Customers:
CBNC collects generic information about visitors to our website. This information includes the date and time of access, the internet service provider's address, the web browser used and the visitor's physical location.
CBNC requires customers to utilize multi-factor authentication in addition to customer specific passwords to access that customer's confidential and private information. CBNC reminds customers that it is their responsibility to safeguard their login identifications and passwords. Further, commercial customers should carefully screen those employees to whom user identifications and passwords are to be granted.
CBNC utilizes encryption, firewall, router, third-party verification procedures, multi-factor authentication and other security software and hardware to help prevent the unauthorized eavesdropping of the access to customer's confidential and private information.
CBNC utilizes virus protection software to help prevent the spread of computer viruses.
CBNC utilizes "cookies" to help authenticate our customers' identity and to help facilitate the exchange of information between CBNC systems and our customers' systems.
CBNC reminds all of our customers that links to other sites within the CBNC website are not under our control. These websites may not comply with the CBNC Privacy and Information Security principles and security standards.
CBNC reminds all of our customers that confidential and private information may be compromised in both traditional and non-traditional banking activities. CBNC can only establish policies and procedures to help restrict the use and access to confidential and private information. If any CBNC customer believes their confidential and private information has been compromised, please contact CBNC immediately so that the potential breach can be investigated.
Comments or Complaints by Customers
Any comments or complaints about this policy or any privacy-related issue can be made by contacting:
Citizens Bank of Northern California
Attn: Michael Behn, EVP/CIO
P.O. Box 1420
Nevada City, CA 95959
530-478-6000
|