Bottomline Technologies, Inc. ("the company," "we," "us," or "our") respects individual privacy and values the confidence of our customers, employees, consumers, business partners, and others. Bottomline Technologies complies with the U.S.-EU Safe Harbor Framework and the U.S.-Swiss Safe Harbor Framework, as set forth by the U.S. Department of Commerce, concerning the transfer of personal data from the European Union and Switzerland to the United States of America. Accordingly, we follow the Safe Harbor Principles published by the U.S. Department of Commerce ("Principles") with respect to all such data. This statement outlines our general policy and practices for implementing the Principles, including the types of information the company gathers, how we use it, and the choices affected individuals have regarding our use of, and their ability to correct, that information.
This statement applies to all personal information we handle, including on-line (except as noted below), off-line, and manually processed data. For purposes of this statement, "personal information" means information that:
- is transferred from the European Union or Switzerland to the United States;
- is recorded in any form;
- is about, or pertains to, a specific individual or can be linked to that individual;
- It does not include information that pertains to a specific individual, but from which that individual could not reasonably be identified.
Principles Protecting Individuals' Privacy
Notice and Choice
To the extent permitted by the Safe Harbor Frameworks, we reserve the right to process personal information: i) in the course of our internal business operation; and ii) if provided by a third party, in the course of processing data for such third party, in each case without the knowledge of individuals involved.
Where the company receives personal information from its subsidiaries, affiliates, or other entities in the EU or Switzerland, the company will use and disclose such information in accordance with the purposes for which it was originally collected, or in accordance with the notices provided by such entities.
The company will provide notice and provide individuals with an opportunity to "opt-out" if such personal information is to be disclosed to a third party or used for a purpose incompatible with the purpose for which it was originally collected. For sensitive information, affirmative or explicit, the company will provide notice and individual choice will be given to "opt-in" if such sensitive information is to be disclosed to a third party or used for a purpose other than the purpose for which it was originally collected.
We collect personal information from individuals only as permitted by the Principles or with the consent of the individual affected. Consent for personal information to be collected, used, and/or disclosed in certain ways may be required in order for an individual to obtain or use our services.
Disclosures and Transfers
We do not disclose an individual's personal information to third parties, except when one or more of the following conditions is true:
Permitted transfers of information, either to third parties or within Bottomline Technologies, or between subsidiaries of Bottomline Technologies, include the transfer of data from one jurisdiction to another, including transfers to and from the United States of America. Because privacy laws vary from one jurisdiction to another, personal information may be transferred to a jurisdiction where the laws provide less or different protection than the jurisdiction in which the information originated.
- We have the individual's permission to make the disclosure;
- The disclosure is required by law or mandatory professional standards;
- The disclosure is reasonably related to the sale or other disposition of all or part of our business;
- The information in question is publicly available;
- The disclosure is reasonably necessary for the establishment of legal claims; or
- The disclosure is to another Bottomline Technologies entity or to persons or entities providing services on our or the individual's behalf (each a "transferee"), consistent with the purpose for which the information was obtained, if the transferee, with respect to the information in question:
- is subject to law providing an adequate level of privacy protection;
- has agreed in writing to provide an adequate level of privacy protection; or
- subscribes to the Principles.
Data Security, Integrity and Access
We employ various physical, electronic, and managerial measures, designed to provide personal information with reasonable protection from accidental loss or destruction, improper use, alteration, or disclosure. However, we cannot guarantee the security of information on or transmitted via the Internet.
We process personal information only in ways compatible with the purpose for which it was collected or authorized by the individual. To the extent necessary for such purposes, we take reasonable steps to make sure that personal information is accurate, complete, current, and otherwise reliable with regard to its intended use.
If an individual becomes aware that information we maintain about that individual is inaccurate, or if an individual would like to update or review his or her information, the individual may contact us using the contact information below. The individual will need to provide sufficient identifying information. We may request additional identifying information as a security precaution. In addition, we may limit or deny access to personal information where providing such access would be unreasonably burdensome or expensive in the circumstances, or as otherwise permitted by the Safe Harbor Agreement. In some circumstances, we may charge a reasonable fee, where warranted, for access to personal information.
Accountability and Enforcement
We have established a self assessment program to monitor our adherence to the Principles and to address questions and concerns regarding our adherence. This program will include a statement, at least once a year, signed by an authorized representative of the company, verifying that this policy is accurate, comprehensive for the information intended to be covered, prominently displayed, completely implemented, and accessible. We encourage interested persons to raise any concerns with us using the contact information below.
With respect to any dispute relating to this policy that cannot be resolved through our internal processes, we will cooperate with competent European Union and Swiss data protection authorities and comply with the advice of such authorities. In the event that we or such authorities determine that we did not comply with this policy, we will take appropriate steps to address any adverse effects and to promote future compliance.
Personnel who violate our privacy policies will be subject to disciplinary process.
This policy may be amended from time to time, consistent with the requirements of the Safe Harbor Principles. If we amend this policy, a revised policy will be posted on our Web site.
For further information, please contact us.
Privacy Office/Human Resources
325 Corporate Dr.
Portsmouth, NH 03801
To learn more about the Safe Harbor program, and to view Bottomline Technologies’ certification, please visit http://www.export.gov/safeharbor/.
Effective Date: August 1, 2005