First National Bank Privacy Policy
Your trust is the cornerstone of our relationship. That is why we work diligently to safeguard your privacy. The information that you provide us is kept in the strictest of confidence. We have no intentions of selling personal information about our customers to third-party businesses. We are proud to make that commitment to you, because your trust is the foundation of our business.
The following privacy policy explains how we use and protect the information about our customers. We ask that you read it carefully.
Notice of Your Financial Privacy Rights
We, our, and us, when used in this notice, mean First National Bank of Byers. This is our privacy notice for our customers. When we use the words "you" and "your" we mean the following types of customers:
- All of our consumer customers who have a continuing relationship with us, such as:
- Deposit account
- Loan account
- Safe deposit box
We will tell you the sources for nonpublic personal information we collect on our customers. We will tell you what measures we take to secure that information. We first define some terms.
Non-Public Personal Information
Is information about you that we collect in connection with providing a financial product or service to you. Nonpublic personal information does not include information that is available from public sources, such as telephone directories or government records.
An affiliate is a company we own or control, a company that owns or controls us, or a company that is owned or controlled by the same company that owns or controls us. Ownership does not mean complete ownership, but means owning enough to have control.
A non-affiliated third party is a company that is not an affiliate of ours.
The Information We Collect
We collect non public personal information about you from the following sources:
- Information we receive from you on applications or other forms
- Information about your transactions with us .Information about your transactions with nonaffiliated third parties
- Information from a consumer reporting agency
The Information We Disclose About You
We do NOT disclose any non public personal information about you to anyone, except as permitted by law.
The Confidentiality, Security, and Integrity of Your Non-Public Personal Information
We restrict access to nonpublic personal information about you to those employees who need to know that information to provide products or services to you. We maintain physical, electronic, and procedural safeguards that comply with federal standards to guard your nonpublic personal information.
Non-Public Personal Information and Former Customers
We do not disclose nonpublic personal information about former customers, except as permitted by law.
Security Statement
Security
AudioTel utilizes the latest computer and security technology to ensure that all customer account information remains secure and accurate. There are two components of TeleWeb; the TeleWeb Controller (residing at the bank) and the TeleWeb Server Network (residing in a secure location at AudioTel Corporation Headquarters). Both components implement strict security controls.
Account Access Controls
TeleWeb maintains controls for the way in which a customer may access accounts. These controls are maintained through settings on the host software, downloaded to TeleBank, and within the TeleBank interface. Restrictions may be placed on account access and transfer rights. TeleWeb adheres to these restrictions on the TeleWeb Server Network and then verifies them on TeleWeb Controller.
Password Protection
A customer is only allowed to access account information on TeleWeb with a valid login consisting of a customer ID and 6 to 15 digit alphanumeric password. Only customers who have been enabled for TeleWeb will be allowed access and only the data for these customers will be transferred to the TeleWeb Server Network. After three simultaneous invalid password entries for a customer, access will be disabled for the customer preventing unauthorized access by a third party. Once disabled, only bank personnel may re-enable access through the TeleWeb interface.
Secure Communication
All communication between the customer and TeleWeb Server Network are conducted using the Secure Socket Lay (SSL) protocol. SSL provides data encryption, server authentication, and message integrity for the entire banking session. This assures that somebody will not be able to eavesdrop on the session, that the customer is connected with the TeleWeb Server Network and not an imposter, and that all information received will be accurate. Account information is transferred from the TeleWeb Controller to the TeleWeb Server Network via the AudioTel Virtual Private Network (AVPN). AVPN is a secure private communication channel established over the public Internet. All data transmitted on AVPN is encrypted using keys known only to TeleWeb Controller and the TeleWeb Server Network. A large private key is used to establish this secure connection. Once this private key has been exchanged, a 128-bit session key is generated and used only for the remainder of the session. After a secure TeleWeb Controller connection has been established, the TeleWeb Server Network authenticates the TeleWeb Controller with a unique Bank ID. These methods insure that all conversions are private between known parties and may not be intercepted or repeated.
Network Security
The TeleWeb Server Network is comprised of several components including a Firewall, Screening Router, Proxy Server, Web Server and Database Server. The Firewall and Screening Router work in tandem ensuring that only authorized requests are allowed to reach the Web Server. Any suspicious activity will result in access being denied and is logged for later review. The Proxy Server acts as an intermediary between the Web Server and the Internet. All requests are passed to the Web Server on behalf of the client and back to the client on behalf of the Web Server. This ensures that access directly to the Web Server is not possible, significantly reducing the possibility of unauthorized access. The Database Server, where all account information is stored, is only accessible through requests made by the Web Server. Access to account information is only allowed through the Web Server Banking interface.