We appreciate the confidence that you place in BDI and understand
the responsibilities it demands of us. Our objective will always
remain the same -- to serve your needs with integrity throughout
every process BDI performs for your organization.
At the center of this commitment is the Privacy and Security Policy
outlined in this document. It describes the safeguards in place
to protect the personal information you provide to us and how we
seek to protect your interests in this area.
Accountability
Our organization is responsible for your members' personal information
under our control and has designated individuals who are held accountable
for compliance with the Policies described in this notice.
Maintaining Safeguards
BDI will protect your members' personal information by using appropriate
security safeguards. We will remain alert and prepared to adapt
these measures to address potential threats, hazards or unauthorized
access.
- We restrict access to information to persons who need
to know the information to provide products or services to your
members.
- We maintain physical, electronic, and procedural safeguards
to protect your members' personal information.
- We impose contractual
commitments and procedures that require our service providers to
adhere to privacy and security policies consistent with our own.
Limiting Disclosure
Personal information is retained and disclosed as necessary to
serve our customers, their members and otherwise only in accordance
with applicable law. Personal information about our customers or
their members is not used or disclosed to any third parties except:
- As required in rendering the services that you have requested
- As required by subpoena or law
- As may be appropriate to protect
against fraud or illegal activity, for the safety of customers and
their members, employees, or property, or is otherwise permitted
by law
- If you elect to disclose, or specifically direct us to
disclose for you, any members' personal information to a third party
Information Security and Quality
We intend to protect the quality and integrity of your personally
identifiable information. We have implemented appropriate technical
and organizational measures, such as using encryption for transmission
of IDs and passwords, to help us keep your information secure and
accurate.
Cookies
We sometimes collect anonymous information from visits to our
sites to help us provide better customer service. For example, we
keep track of the movement within our domain and measure member
activity, but we do so in ways that keep the information anonymous.
This anonymous information is sometimes known as "clickstream data."
BDI may use this data to analyze trends and statistics and to help
us provide better customer service.
We collect this anonymous information through the use of various
technologies, including one called "cookies". A cookie is an element
of data that a Web site can send to your browser, which may then
be stored on your system. All BDI pages use cookies, sent by BDI
or third party vendors, or other technologies.
Internet Security
Below is a high-level diagram of the BDI eStatement Web application.
This diagram reveals that BDI's eStatement application has security
safeguards at several strategic locations.
128-bit SSL is used to encrypt any sensitive information transmitted
to, or received from, the member over the Internet. SSL makes spying
a tremendously difficult task and alleviates identity spoofing,
information disclosure, and data tampering. Equifax Secure issues
our SSL-required X.509 certificates.
BDI has installed several firewalls, both externally and internally.
The external firewalls monitor all incoming traffic and filters
out any data requests that are suspect (i.e., hackers). The internal
firewalls protect the data-sensitive Database Servers from unauthorized
access from within BDI's private network.
Super-sensitive data, such as member passwords, are encrypted using
a strong cryptographic routine before being stored in the database.
VLSystems of Irvine, CA (www.vlsystems.com) designed our network
from the ground up with the primary goal of providing a secure enterprise
network. VLSystems is a leader in network design and security with
extensive experience in the financial industry.
Notice
We will provide you with a written notice before making any material
change to this Policy.
Questions Regarding this Statement
Questions regarding this statement should be directed to:
Information Privacy Policies
Business Data, Inc.
321 N. Oak St.
Inglewood, CA 90302
|