Global Privacy Policy
Nomis Solutions, Inc. and its subsidiaries and affiliates (collectively “Nomis”) provide products and solutions that enable retail banks and other financial services companies to improve customer engagement and financial product offerings (“Solutions”). We deliver our exceptional Solutions, in part, by gathering and processing information about individuals with whom we interact (“Personal Data”). Nomis also processes Personal Data in its capacity as a service provider for other companies.
When you use our Solutions and interact with us, you trust us with your Personal Data. We want to keep that trust by being transparent about our privacy practices – including how and why we collect, use, store, manipulate, disclose, transfer and share (collectively ‘process’) your Personal Data. We also want you to understand the choices you have for your Personal Data under various privacy regulations around the world.
To make this Privacy Policy easier to understand, we have provided a summary to the left-hand side of each section. We also encourage you to contact Nomis if you have any questions or concerns.
If you have a disability and need this policy provided to you in a different format, please email legal@nomissolutions.com or call our office at +1 650-588-9800.
Last Modified: September 24, 2021
1. SCOPE OF THIS PRIVACY POLICY
This Privacy Policy applies to Individuals, anywhere in the world, who interact with Nomis or use our Solutions.
2. YOUR RIGHTS AND PREFERENCES
Nomis allows you to exercise your privacy rights and manage how we use your information.
This Privacy Policy applies to Individuals, anywhere in the world, who interact with Nomis or use our Solutions.
3. TYPES OF INFORMATION WE COLLECT
We collect information that relates to you and your interactions with Nomis.
4. HOW WE USE YOUR INFORMATION
We use your Personal Data to develop and provide our products and services to you, and to personalize, improve and promote our interactions with you.
5. HOW WE SHARE YOUR INFORMATION
We will only share your information as we have described in this Privacy Policy, and only (i) in accordance with your consent and elections, (ii) to comply with legal obligations, (iii) to protect and defend Nomis, (iv) as part of a corporate transaction, or (v) as de-identified or aggregated information.
6. DATA TRANSFERS AND PRIVACY SHIELD
7. CONNECTING WITH THIRD PARTIES
Nomis may work with third parties to enhance your experience.
8. MANAGING YOUR DATA AND PRIVACY
You have a choice about the use of information that identifies you, marketing communications you receive from us, and our use of cookies and other tracking technologies.
You can review and change your information or deactivate your account in your account settings, but we may retain certain information.
While you have the right to select whether you receive promotional messages, you may still receive other non-promotional messages from us.
9. DATA RETENTION AND YOUR ACCESS RIGHTS
You may have the right to exercise certain data protection rights, including the right to request the deletion of, amendment of or access to your information.
These rights may depend on the country or region in which you are resident.
You may always contact your local data protection authority regarding the use of your information.
Nomis will not discriminate against you for exercising your privacy rights.
10. SECURITY OF YOUR INFORMATION
We provide reasonable and appropriate security measures in connection with securing Personal Data we collect.
11. ADDITIONAL COUNTRY/REGIONAL CONSIDERATIONS
We provide our products and services in many different countries and regions. Our Privacy Policy sets out the privacy principles and procedures we adhere to globally, but other laws may apply to you based on the country or region in which you are located or from which you are interacting with Nomis.
12. CHANGES TO OUR PRIVACY POLICY
We may make changes to our Privacy Policy or our supporting privacy procedures at any time.
13. CONTACT NOMIS SOLUTIONS
UNITED STATES (U.S.) – CALIFORNIA PRIVACY CONSIDERATIONS
Back to Regional Privacy Options
In addition to the terms of our global Privacy Policy, Nomis wants Individuals with whom it interacts that are located in the State of California to understand the following additional privacy and data protection measures which may be applicable (“California Privacy Terms”) apply to the processing by Nomis of personal information related to identified or identifiable individuals and households located in the State of California.
We include this additional information to comply with the California Consumer Privacy Act of 2018 (“CCPA”) and any terms defined in the CCPA have the same meaning when used in this section. These California Privacy Terms do not apply to personal information that is exempt from the CCPA.
The Nomis entity responsible for the processing of your Personal Information will depend on the unique circumstances of your interactions with us.
Collection, use, and disclosure of California personal information:
In the preceding twelve (12) months, Nomis collected all the personal information in SECTION 3 of our Privacy Policy about California residents. The table below provides more details and indicates the categories of sources from where personal information was collected, examples of Nomis’ use of personal information and third parties to whom we disclosed the data during the 12 months leading up to the effective date of this Privacy Policy.
CCPA Classification and Examples | Categories of Sources | Examples of Uses | Categories of Third Parties to Whom we Disclosed it |
---|---|---|---|
Identifiers Such as real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol (IP) address, email address, account name, Social Security Number (SSN), driver’s license number, passport number, or other similar identifiers | You, if you choose to provide to us
Your use of our services/automatically collected from you Affiliates Third parties (such as service providers and other users who, for example, may refer you to use the Services) Events, such as conferences Public records databases |
Providing products and services, including registration and customer service
Fixing and improving products and services Facilitating payment Personalizing content and your experience Our marketing and third party marketing and advertising purposes Bug detection and error reporting Analyzing and improving products and services Safety, security, fraud and legal compliance |
Affiliates
Service providers Other individuals or companies at your request Analytics providers Third parties relating to legal requests, if required by law or if we believe in good faith that it is reasonably necessary Third parties for sales of transfers of our business or assets |
Device information and identifiers Such as IP address; browser type and language; operating system; platform type; device type; software and hardware attributes; and unique device, advertising, and app identifiers | You (through your device)
Advertising providers Analytics providers Cookies and tracking technologies |
Same as above | Same as above |
Internet or other similar network activity
Browsing history, search history, information on a interactions with a website, application, or advertisement See “Cookies and other electronic technologies” in our Privacy Policy for more information about how we collect and use this information |
You (through your device)
Advertising providers Analytics providers Cookies and tracking technologies Marketers Our affiliates |
Same as above | Same as above |
Location information General location, and, if you provide permission, precise GPS location | You, if you choose to provide to us
Your use of our services/automatically collected from you Third parties (such as service providers) |
Same as above | Same as above |
Social media information May include personal identifiers, photos, location, user generated content, demographic information
If you link your account or access products and services through a third-party connection or log-in, we may have access to information you provide to that social network depending on your privacy settings |
You, if you choose to provide to us
Social media networks, in accordance with your privacy preferences on such services |
Same as above | Same as above |
Commercial information Records of your purchases and transaction data | You, if you choose to provide to us
Your use of our services/automatically collected from you Affiliates Third parties (such as service providers) |
Same as above | Same as above |
Financial information May include credit or debit card number, verification number, and expiration date, to process payments and information about your transactions and purchases with us | You, if you choose to provide to us
Third parties (such as service providers and third parties confirming payments made on your behalf) Affiliates |
Providing products and services
Facilitating payment Fixing and improving products and services Analyzing use of products and services Security, fraud and legal compliance |
Affiliates
Service providers Other individuals or companies at your request Third parties relating to legal requests, if required by law Third parties for sales or transfers of our business or asset |
Protected classification characteristics under California or federal law Age, race, national origin, citizenship, marital status, sex (including gender, gender identity, gender expression),military or veteran status, nationality, ancestry or ethnicity, and political opinions | You, if you choose to provide to us | Providing products and services, including registration and customer service
Fixing and improving products and services Facilitating payment Analyzing and improving products and services Security, fraud and legal compliance |
Affiliates
Service providers Other individuals, services, and partners at your request Third parties relating to legal requests, if required by law or if we believe in good faith that it is reasonably necessary Third parties for sales of transfers of our business assets |
Professional or employment-related information Current or past job history or performance evaluations | You, if you choose to provide it to us
Affiliates |
As described in our Employee Handbook | See our Employee Handbook |
Inferences drawn from other personal information | You, if you choose to provide to us
Your use of our services/automatically collected from you Affiliates |
Providing the Services, including registration and customer service
Fixing and improving products and services Personalizing content and your experience Our marketing and third-party marketing and advertising purposes Analyzing and improving products and services Security, fraud and legal compliance |
Affiliates
Third parties (such as service providers) |
Health information Personal information related to site health and safety | You, if you choose to provide to us | Health and safety measures
Security, fraud and legal compliance |
Affiliates
Service providers Other individuals, services, and partners at your request |
CCPA right to access or delete personal information:
If you are a California resident, California law may also permit you to request that we:
- Provide you with a list of the categories of personal information we have collected or disclosed about you in the last twelve months; the categories of the sources of the personal information; and the categories of the third parties with whom we share that personal information.
- Provide access to and/or a copy of personal information that we hold about you.
- Delete certain personal information that we hold about you, unless Nomis is legally required to retain it.
To exercise a request regarding your California privacy rights, please contact us.
As we will need to verify your identity to fulfill these requests, please send an email to legal@nomissolutions.com and we will attempt to verify your identity via encrypted email.
- We will respond to properly submitted and verified requests for disclosure, access and deletion within 45 days, but it may take up to 90 days in some cases.
- You will receive a confirmation by email of either the completion of your request or a return response with your requested data. If we are unable to verify your identity, we will not be able to process access or deletion requests.
Requests made by agents: If you unable to make a request directly (or in the case of death of the consumer), you may legally designate an agent by providing a notarized authorization, power of attorney or other legally binding designation of assignment of rights. Please provide proof of this agency along with your request and we will process your request as quickly as possible.
Contact Nomis Solutions:
If you have questions or comments about this Privacy Policy, you may contact us by email, telephone, or direct mail.
A. Via Email:
B. Via Telephone:
C. Via Direct Mail:
Nomis Solutions, Inc., 611 Gateway Blvd., Suite 276, South San Francisco, CA 94080
CANADA PRIVACY CONSIDERATIONS
Back to Regional Privacy Options
In addition to the terms of our global Privacy Policy, Nomis wants Individuals with whom it interacts that are located in Canada to understand the following additional privacy and data protection measures which may be applicable (“Canada Privacy Terms”) and apply to the processing by Nomis of personal information related to identified or identifiable individuals and households located in Canada.
We include this additional information to comply with The Personal Information Protection and Electronic Documents Act (PIPEDA) and any terms defined in the PIPEDA have the same meaning when used in this section. These Canada Privacy Terms do not apply to personal information that is exempt from the PIPEDA and other substantially similar Canadian privacy laws.
The Nomis entity responsible for the processing of your personal information will depend on the unique circumstances of your interactions with us.
Your rights:
If you are a resident of Canada, Canadian law may permit you to request to:
Access and update your information: You have the right to review and amend any personal information stored in our system.
We will provide you with copies of your personal information that is in our possession, subject to certain exceptions, including data that is referenced to another individual’s personal information that we cannot sever, or information subject to solicitor-client privilege, or other legal restrictions that may prevent us from fulfilling your access request.
Request cancellation: You have the right at any time to withdraw your consent to the use of your personal information in the future.
Exercising your rights: To exercise your rights, please contact us.
- As we will need to verify your identity to fulfill these requests, please send an email to legal@nomissolutions.com and we will attempt to verify your identity via encrypted email.
- We will respond to properly submitted and verified requests within 30 days, but it may take longer in some cases.
- You will receive a confirmation by email of either the completion of your request or a return response with your requested information. If we are unable to verify your identity, we will not be able to process requests.
Opt-out of interest-based advertising: If you no longer with to participate in the services offered through these solutions, you can opt-out of this activity by visiting the following websites:
- Network Advertising Initiative at http://www.networkadvertising.org/choices/
- Digital Advertising Association of Canada at http://youradchoices.ca/choices/
If you opt-out, please note you may still receive ads from Nomis, but such ads will not be a part of targeted advertising.
Opt-out of promotional communications: In the event you wish to unsubscribe from receiving promotional communications from us you may opt-out by updating your preferences or revoking your consent. You may unsubscribe at any time by clicking the unsubscribe link in the footer of all Nomis email messages.
If you opt-out of receiving marketing-related emails from us, we may still send you important administrative messages, such as notifications regarding our business relationship with you, important notices regarding our products and services, or as otherwise consistent with applicable law.
Contact Nomis Solutions in Canada:
If you wish to know what information we have in our files about you, ask a question about the information in your file, or request a change to the information in your file, you may contact us by email, telephone, or direct mail.
A. Via Email:
B. Via Telephone:
C. Via Direct Mail:
Nomis Solutions, Inc., 611 Gateway Blvd., Suite 276, South San Francisco, CA 94080
EUROPE (EU), UNITED KINGDOM (UK) AND SWITZERLAND PRIVACY CONSIDERATIONS
Back to Regional Privacy Options
In addition to the terms of our global Privacy Policy, Nomis wants Individuals with whom it interacts that are located in the European Union and European Economic Area, Switzerland (CH) and the United Kingdom (UK) to understand the following additional privacy and data protection measures which may be applicable (“EU Privacy Terms”). These EU Privacy Terms apply to Nomis’ processing of Personal Data related to identified or identifiable individuals located in the EU, the UK, and Switzerland (“EU Personal Data”).
Controlling law: During your interactions with us, the collection and processing of your EU Personal Data will occur as provided in and under the terms of our Privacy Policy, as modified or supplemented by these EU Privacy Terms.
The Nomis entity responsible for the processing of your EU Personal Data will depend on the unique circumstances of your interactions with us and applicable privacy rules, including as from 25 May 2018, the General Data Protection Regulation 2016/679 (“GDPR”). Nomis has adopted internal policies and implemented measures to ensure that the applicable legal requirements are met and that your EU Personal Data is processed with respect and care using the appropriate technology.
Legal basis: We will only process your EU Personal Data as permitted by applicable law and our policies.
Applicable law and policies may require Nomis to have a “legal basis” for the processing of your Personal Data. In many instances when we interact with you, you may be informed of our legal basis for processing your EU Personal Data as described in these EU Privacy Terms. The applicable legal basis often depends on the types of data and the specific context in which it is processed. We typically rely on ‘legitimate interest,’ ‘consent,’ ‘contract performance’ and ‘legal compliance’ as our primary legal bases to process your Personal Data.
- Legitimate interest. Nomis may process your EU Personal Data where we have a legitimate interest in doing so. For example, we rely on this legal basis when we:
- provide our products and services to you;
- conduct business with you through our platforms, functions or websites;
- conduct diagnostic or troubleshooting activities;
- conduct security or monitoring activities;
- conduct business planning, forecasting and reporting; or
- need to comply with legal obligations and law enforcement requests or support legal claims.
- Consent. In some instances, Nomis may process EU Personal Data based on your consent. For example, we rely on consent when we:
- engage in data collection techniques such as cookies or marketing preferences;
- provide you with specific marketing, promotional or advertising opportunities;
- request your input regarding our products and services;
- seek to improve or personalize your experiences with our company or our products and services;
- conduct research regarding our products and services;
- collect and track data for security and health and safety initiatives;
- engage in troubleshooting or security-related activities; or
- provide services that seek use-specific EU Personal Data.
- Contract performance. Some of the interactions you may have with us involve the performance of a contract and we may process your EU Personal Data to enter into or perform such contracts. For example, we rely on contract performance when we:
- interact with you to provide or receive our Solutions;
- process payments;
- conduct troubleshooting or security-related activities to detect fraud;
- conduct diagnostic and repair activities;
- administer employment related matters; or
- need to support legal obligations or claims related to a contract.
- Legal compliance. Nomis may process your EU Personal Data when we need to comply with legal obligations and certain law enforcement requests or to support legal claims.
Managing your data: If consent is required for us to process your EU Personal Data, you may contact us to withdraw or modify such consent at any time.
You have the right to request access to your EU Personal Data as processed by us and to have it corrected or deleted, unless Nomis is legally required to retain it. You have also the right to restrict or object to our processing of your EU Personal Data.
- We will respond to properly submitted and verified requests within 30 days.
Contact Nomis Solutions in the European Union (EU) and the United Kingdom (UK):
If you are concerned about Nomis’ compliance with laws relating to the privacy of your EU Personal Data, you may also contact your local privacy data protection authority. You may also contact us about your data management or privacy related questions and concerns by email, telephone, or direct mail.
A. Via Email:
B. Via Telephone:
C. Via Direct Mail:
Nomis Solutions, Inc., 611 Gateway Blvd., Suite 276, South San Francisco, CA 94080