your Security and Privacy

UtilityBillCo exists to provide intelligent advanced metering solutions while respecting our customer’s privacy expectations. At UtilityBillCo, we are dedicated to protecting your privacy and safeguarding the personal information you have entrusted to us.

Scope

This privacy policy applies to utilitybillco.com and its subdomains (the “site”), all of which are owned and operated by UtilityBillCo. It does not apply to any third-party websites, which have their own policies. Throughout this policy, when we say UtilityBillCo, we mean our company, and when we say services, we mean the various products and services that we make available to you through our site, including accounting, invoicing services, and other business–related services and support.

By “personal information” we mean information about an identifiable individual. That’s what this policy is about – our collection, protection, use, disclosure, retention, and other processing of personal information and your rights relating to these activities. We use personal information in order to provide you and your business with the services. Our Privacy Policy is based on the following 10 fair information principles:

  • Accountability
  • Identifying purposes
  • Consent
  • Limiting collection
  • Limiting use, disclosure, and retention
  • Accuracy
  • Safeguards
  • Openness
  • Individual access
  • Challenging compliance

Accountability and Challenging Compliance
UtilityBillCo has named a Privacy Officer who is responsible for privacy at UtilityBillCo. This includes our policies and procedures that are designed to keep your information safe. If you have any questions about our privacy practices or this policy, you can contact us at:
UtilityBillCo
Privacy Officer
105 – 573 Sherling Place,
Port Coquitlam, BC
V3B 0J6

If you’re not satisfied with our response, you have the option of contacting the Office of the Privacy Commissioner of British Columbia:
Office of the Information and Privacy Commissioner for British Columbia
4th Floor, 947 Fort Street
Victoria B.C.
V8V 3K3
(250) 387-5629

Identifying Purposes
UtilityBillCo may collect, use, store, or disclose your personal information for the purposes described below. In order to provide you with services, which includes the following:

  • We collect information directly from you but may also collect information from third parties when you connect your UtilityBillCo account to them. These integrations may pull data into or share data out of UtilityBillCo. In some cases, we use a service provider to connect you to a third-party service
  • We may also collect your name and email address from third parties when you sign up and login to our site using single sign-on (SSO)
  • When you connect your UtilityBillCo account with a third-party service, their terms and policies apply
  • To promote or offer your products or services, and to determine your eligibility for new services we may offer from time to time
  • To contact you for the purposes of service updates and system and account notifications
  • To provide you with support in connection with the services
  • To comply with any laws, regulation, court orders, warrants, inquiries, subpoenas or other legal processes or investigations, and to protect ourselves, other individuals, or property from harm.

We will never sell your personal information to other companies.

Consent
UtilityBillCo takes a consent-based approach to the collection, use, and disclosure of personal information.

Submitting the personal information of others
If you submit the personal information of your customers or employees to us, you are responsible for informing such customers and employees about UtilityBillCo, and for obtaining any necessary consent or authority from them.

Closing your UtilityBillCo account
At any time, and without penalty, UtilityBillCo users can withdraw their consent to the continued use or disclosure of their personal information by closing their UtilityBillCo account. Please ensure that you complete the account closure process which includes a confirmation email. Otherwise, your account may not be closed.

Email and communications consent
At any time, you can opt-out of commercial email communications from us by clicking on the unsubscribe link in such emails, or via the Email Preferences settings in your account. Certain non-commercial communications may still be sent to you that are required to provide you with our services. For example, system notifications, major product changes, changes to our Terms of Use, or other news that we believe will materially affect how you interact with UtilityBillCo.

Limiting Collection
UtilityBillCo only collects the personal information necessary to provide our services to you. The services you use will determine which information UtilityBillCo collects. We’ll also provide you with the option of sharing additional information to enhance your UtilityBillCo experience.

UtilityBillCo may also use third-party services to supplement or enrich our understanding of our customers. This includes cross-referencing information like a name, business name, email address, or IP address in third-party databases, and using the information there to improve our understanding of you and your business.

UtilityBillCo is not intended for children and we do not knowingly or intentionally collect information about individuals under the age of thirteen (13).

Where required, business partners may have access to information in your UtilityBillCo account, including personal information, and may perform various tasks on your behalf. You take full responsibility for any collection, use, or disclosure of your personal information by our business partners.

Limiting Use, Disclosure, and Retention
We will use your personal information as described in this policy and we will share your personal information with third parties only as described in this policy. We will retain your information for the period necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law or regulation. To be clear, that means that we’ll retain your personal information while you have an active account, and afterward if we need to do so to meet our legal obligations. If you choose to close your UtilityBillCo account, we will destroy your personal information in accordance with our data retention policies.

Accuracy
UtilityBillCo relies on you to provide us with information that is accurate and complete. We provide you the mechanisms and rely on you to keep your information up to date. You can request updates or corrections of any inaccuracies in your personal information at any time by contacting us at the contact information listed in the policy. We will respond to your request within a reasonable timeframe.

Safeguards
UtilityBillCo uses a combination of reasonable and appropriate safeguards designed to protect your information. These safeguards are administrative controls (things like policies, procedures, and training), technical controls (things like encryption, firewalls, and secure coding frameworks), and physical controls (secured hosting environments). We ensure that any third party acting on our behalf maintains reasonable and appropriate safeguards in respect of your personal information. Additional information about our third parties’ privacy practices is
available upon request.

If you have questions about security on our site, you can contact us at [email protected].

You are also responsible for helping to protect the security of your personal information. For instance, never give out your email account information or your password for the services to third parties. Our team will never request your password or PIN, and we ask that you never post account or credit card numbers to our support channels.

Openness
This policy outlines our privacy practices. If you have questions about it, please contact our Privacy Officer. This policy is available publicly at https://utilitybillco.com/privacy.

Individual Access
You may access, update, and correct your personal information that’s in our custody or control at any time, subject to limited exceptions prescribed law. You can download or export data you input into the site at any time. Or, to correct inaccuracies, simply login to your account and make the necessary changes. You can also request access, corrections, or updates to all of your personal information, including information that’s not available through your account, by contacting us as set out in the Challenging Compliance section of this document. We may request certain personal information for the purpose of verifying the identity of the individual seeking access to their personal information records.

Additional Details
Public Content and Social Media
From time to time UtilityBillCo may have public forums and blogs. Any information submitted there may be read and collected by anyone.

You may request removal of personal information from forum or blog posts and comments by contacting us at [email protected].

If you provide us with a testimonial, with your consent, we may post it on our site or in other materials and
media, along with your name. If you want your testimonial removed, please contact us
at [email protected].

You may engage with us through social media sites. When you engage with us on these sites, we may have access to certain information about your account (e.g., name, username). These sites may collect your IP address, how you’re engaging with us, and may use cookies to enable the site to function properly. We may use this information to personalize your experience and to provide you with other products or services you may request.

Service Providers
We may transfer (or otherwise make available) your personal information to third parties who provide services on our behalf. For example, we may use service providers to host our website and to process payments. Your personal information may be maintained and processed by these third parties in other jurisdictions, like the U.S. When your information is in another jurisdiction, it will be subject to their laws.

We only share the information that these service providers need to do their job and we don’t authorize
them for any other use or disclosure of personal information.

We may use service providers to verify bank account information you provide to us in providing our services to you.

We may also use services provided by third-party platforms (such as social networking sites) to serve targeted ads on such platforms to you or others, and we may provide a hashed version of your email address or other information to the platform provider for such purposes. To opt-out of the sharing of your information with such platforms, please send an email to [email protected].

Visiting the Site and Using the Mobile Apps
In general, you can visit the site without telling us who you are or submitting any personal information. However, we and/or our service providers (such as Google Analytics) collect information such as how often users visit the websites, what pages they visit, and what other sites they used prior to visiting. The data collected is used to track and examine the use of the website and to prepare reports on its activities. We may use the data collected on the websites to contextualize and personalize the ads.

Cookies, Tags and Web Beacons
Technologies such as cookies, web beacons, tags, and scripts may be used by UtilityBillCo, our advertising and analytics service providers (such as Google analytics), and affiliates to analyze usage trends, administer the site, and to gather demographic information about our user base.

A cookie is a small piece of data that our site can send to your browser, which may then be stored on your device so that we can recognize you when you return. We use cookies for session tracking to make it possible to navigate the secure environment inside our site. These cookies (1) may let us know who you are, (2) are necessary to access your account, and (3) will give us information that we can use to personalize our site according to your preferences. You can control the use of cookies in your browser. If you disable cookies, you will not be able to access your account or take advantage of all of the features of the site and mobile apps.

Notification of Privacy Policy Changes
We may revise this privacy statement from time to time to reflect changes to our information practices. If we make any material changes, we will provide notification by means of a notice on our website prior to the change becoming effective. We encourage you to periodically review our Privacy Policy for the latest information on our privacy practices.

Data Security
PCI-DSS compliant: UtilityBillCo is a Level 1 PCI-DSS compliant. This means that every year we have a third-party audit to validate our practices and make sure that we’re doing the right things for our customers.

Secure data transmission: When you load a page in your browser, or upload something to UtilityBillCo, all of that information is encrypted while it’s moving over the internet. We lock up your data with up to 256-bit TLS encryption, the strength of protection you get with online banking and shopping. We also support a wide variety of cyphers — another kind of code — for our communications, to ensure the highest level of encryption possible based on your browser.

Tokenization: UtilityBillCo doesn’t store credit card numbers. Credit card information is sent directly from your browser to our payment processor, and UtilityBillCo receives a secure token back. This token is a code that authorizes UtilityBillCo to complete the activity securely and efficiently without storing or exposing your credit card information.

Secure data storage: Your data is stored on servers that have strict physical access protocols. The facilities are controlled with 24/7 monitoring and the technology is digitally protected.

Security testing: UtilityBillCo uses many layers of security testing. We test our systems internally. We also bring in third-party security firms to perform vulnerability assessments and penetration tests against our systems.

Transparency: We want you to understand the measure that we have in place to protect and secure your information. That’s why we’ve written a very clear and understandable Privacy Policy.

Mobile Security
Passwords are encrypted when they’re sent to our servers. We never store them without encrypting them first. In fact, all communications between our apps and our servers are encrypted using Transport Layer Security (TLS) (the replacement for Secure Sockets Layer (SSL)) the highest level of security protocols available. Beyond that, we don’t store any sensitive information, such as credit card numbers, on the device.

Fraud Prevention
UtilityBillCo has an internal risk system that uses a wide variety of tools and insights to protect our customers from fraud. We take a layered approach to risk detection for the highest level of protection and we monitor high risk and out-of-pattern behaviour to keep our platform safe.

Do you have additional questions about the security of UtilityBillCo? Please contact us. We’d be happy to tell you more about the steps we take to ensure the security of your information.


UtilityBillCo and General Data Protection Regulation (GDPR),
California Consumer Privacy Act (CCPA)

UtilityBillCo’s internal policies are aligned with the objectives of GDPR and the CCPA. For example, under GDPR:

  • You have a right to understand the terms of use that you’re agreeing to.
  • Our plain-English Terms of Use and Privacy Policy satisfies this requirement.
  • You have a right to close your account and have personally identifiable information deleted.
  • You can close your UtilityBillCo account, and when you do, we delete personally identifiable information.
  • You have a right to take your data with you.
  • You own all of your data and you can export or request data files at any time.
  • You have a right to turn off direct marketing messages.
  • We respect your email preferences and make it easy for you to opt out.
  • Companies must provide a ‘reasonable’ level of protection for personal data.
  • As a company that handles financial information, including credit card transactions, UtilityBillCo only uses data centers in secure facilities that meet the industry standards.

We are working to meet GDPR and CCPA requirements and will keep you informed as we implement additional functionality to support your privacy rights.

Effective Date: 07/13/2020 11:13