Privacy Policy

Last Updated: November, 2024

Recognition of your expectation of privacy

We recognize and respect the privacy expectations of our clients. To meet those expectations, City National Bank of Florida, Total Bank, and BciCapital (the “Bank”, “we”, “us”, or “our”) maintains policies and procedures to safeguard your personal information. All consumer personal information collected, processed, or disclosed is pursuant to the Federal Gramm-Leach-Bliley Act (Public Law 106-102) and implied regulations. Please read this Privacy Policy carefully to understand how we handle user privacy.

Protecting online applications

When you apply online for accounts or services, enroll in online banking, and/or download the Bank’s application, which may be available on platforms that include but are not limited to, Google Play and Apple’s App Store, you provide personal information that is necessary for us to process your application, and/or provide features of our online bank and mobile app to you. This includes but is not limited to, getting real time balances for your accounts, managing your account, viewing your transactions and statements, making transfers, managing/paying your bills, and depositing checks. To ensure that your application remains confidential, the information is sent to us in a "secure session". After you have submitted your application online, we recommend that you end your browser session before leaving your computer. We, along with the outside companies with which we work, if applicable, may keep the information you provide to us, along with information we collect from outside sources, so that we can offer you accounts and services related to your financial needs.

How we use your information

In general, we use the information collected through your use of and interaction with our banking services, online banking services, and mobile application, to respond to any requests that you submit, provide you services that you request, and to help serve you better. This includes but is not limited to, the creation of and maintaining your account, identifying you as a legitimate user when accessing our online banking services or mobile application, improving the quality of our banking services, sending you administrative notifications, and sending surveys and promotions offers.

Our online banking services and/or mobile application may create de-identified information records from personal information by excluding certain information (such as your name) that makes the information personally identifiable to you. We may use this information in a form that does not personally identify you to analyze request patterns and usage patterns to enhance our products and services. We reserve the right to use and disclose non-identifiable information to third parties in our discretion.

Disclosure of personal information

We also reserve the right to access, read, preserve, and disclose any information as we reasonably believe is necessary to (i)satisfy any applicable law, regulation, legal process or governmental request, (ii) enforce this Privacy Policy and our Terms of Service, including investigation of potential violations hereof, (iii)detect, prevent, or otherwise address fraud, security or technical issues, (iv) respond to support requests, or (v) protect our rights, property or safety, and the public. This includes exchanging information with other companies and organizations for fraud protection and spam/malware prevention. We may employ and contract with people and other entities that perform certain tasks on our behalf and who are under our control (our “Agents”). We may need to share personal information with our Agents in order to provide products or banking services to you. Unless we tell you differently, our Agents do not have any right to use personal information or other information we share with them beyond what is necessary to assist us. You hereby consent to our sharing of personal information with our Agents.

How we handle email

We preserve the content of your e-mail, your e-mail address and our response so that we can more efficiently handle any follow-up questions you may have. We also do this to meet legal and regulatory requirements. If we think that a particular Bank account or service might apply to your situation, we may occasionally contact you at your e-mail address to inform you of potential benefits and availability.

What we do with online surveys

The information you provide on surveys and promotions on our website will be used for internal marketing purposes, including developing website information and services that you may find helpful. In addition, we may inform you of new accounts and services from the Bank based on the information you provide to us.

No "data" capture with planning tools

There are many planning tools throughout the site to help you make the financial decisions that are right for you in the privacy of your home. We encourage you to try all of your "what-if" scenarios as often as you like. Examples include the mortgage principal and interest calculator and the savings goal calculators. When you use various planning tools on our website, the calculations run on your PC or our server. We do not capture the personal information you provide on these planning tools.

Maintenance of accurate information

We have standards and procedures to ensure that your financial information is accurate, current and complete in accordance with commercial standards. We will respond to your request to review and correct inaccurate information in a timely manner.

Protecting your online banking

When you bank online with us and/or access our mobile app, we, along with the outside companies we work with to bring these services to you, have access to your information. Information is retained on our system or the system of the appropriate outside company, depending on what is required to serve you. We use state-of-the-art Internet technology, supported by the outside companies we work with, to make online banking secure and to protect your personal information. We also require a username and password and, as applicable, we may require an out of band authentication code delivered to you via text, email, voice/voicemail, or generated via an Authenticator in order to access your accounts. If you do not provide this information, we cannot establish an online banking service for you. You can also help maintain the security of your banking information by not sharing your username or password with anyone, by changing your password regularly, and by remembering to sign off.

When information is collected and not collected

Some areas of our website and/or mobile app require personally identifiable information, such as your name, e-mail address, phone number, physical address, financial information, social security number, your account number, or access to your contacts to enable you to perform certain tasks (for example, review your accounts or correspond with us). In these cases, we collect your information if necessary to interact with you and/or provide our banking services. In addition, we will collect financial and transactional information necessary to provide you with our banking services. This includes but is not limited to, payment card identification, payment card expiration date, verification numbers, and transaction and payment history.If you do not interact with us, you browse our website anonymously, any personal information, such as your e-mail address, is not collected. If you provide feedback or contact us via email, we will collect your name, email address, as well as any other content included in the email or contact form, to send you a reply. We gather and analyze data regarding usage of our website and/or mobile app, including domain name, number of hits, pages visited, length of user session, etc., to evaluate the usefulness of our services.Personally identifiable information and non-public contact information will not be disclosed other than for purposes described herein.

Information collected from third parties

We may collect certain information from identity verification services and consumer reporting agencies, including credit bureaus, in order to provide our banking services.

Location data

Your precise location (linked to your identity) and/or approximate location may be collected to help target advertisements and for internal marketing purposes based on your location. If you have enabled location services on your mobile device and agree to the collection of your location when prompted, we will collect location data when you use the Bank’s mobile application, or when the mobile application is closed. If you do not want us to collect location data, you may decline the collection of the data when prompted or adjust the location service settings on your mobile device.

About "cookies" and "unique identifiers"

To provide better service and a more effective website, we use "cookies" as part of our interaction with your browser. A "cookie" is a small text file placed on your hard drive by our web page server. These cookies do not collect personally identifiable information, and we do not combine information collected through cookies with other personal information to determine who you are or your e-mail address.Cookies are commonly used on websites and do not harm your system. By configuring your preferences or options in your browser, you determine if and how a cookie will be accepted. We use cookies to determine if you have previously visited our web site and for a number of administrative purposes.

In addition, our mobile app may use unique identifiers, including but not limited to, a string of characters specific to your mobile device, GPS location, camera and/or photos access, and information about the network your mobile device is connected to, and your IP address. Any time you access the mobile app we collect and receive information about the different devices you use and how you use them. We may use this information to measure the frequency of users accessing specific features and/or functions of the mobile app, to help us make the app more useful for users, fraud prevention, as well as security and compliance purposes.

Online activity data

Data such as pages or screens you viewed, how long you spent on a page or screen, the website you visited before accessing our online banking services, navigation paths between pages and screens, or information about your activity on a page or screen, access times, and duration of access may be tracked and collected. Local storage technologies, like HTML5 and Flash, provide cookie-equivalent functionality but can store larger amounts of data, including on your device outside of your web browser in connection with mobile applications. Web beacons, also known as pixel tags or clear GIF’s, may be used to track that a webpage or email was accessed or opened, or that certain content was viewed or clicked on.

Third parties and links

This privacy policy does not apply to the practices of third parties that we do not own or control, including but not limited to any third-party websites, services, and applications (“Third-Party Services”) that you elect to access through. While we attempt to facilitate access only to those Third-Party Services that share our respect for your privacy, we cannot take responsibility for the content or privacy policies of those Third-Party Services. We encourage you to carefully review the privacy policies of any Third-Party Services you access. You may also access links to other websites. These links and plug-ins are for your convenience. The linked websites are not necessarily under our control, and we shall have no responsibility or liability whatsoever for the content or privacy practices of any linked websites, or any link or linking program at any time.

Limiting employee access to information

We have procedures to limit employee access to your personal information to those with a business reason for knowing such information. We educate our employees to understand the importance of confidentiality and client privacy. We take appropriate disciplinary measures to enforce employee privacy responsibilities.

Protecting our children

We do not knowingly solicit data from and market to children under the age of 13. We recognize that protecting children's identities and privacy online is important and that the responsibility to do so resides with both the online industry and with parents.

California privacy rights

Under California Civil Code sections 1798.83-1798.84, California residents are entitled to ask us for a notice identifying the categories of personal customer information which we share with our affiliates and/or third parties for marketing purposes and providing contact information for such affiliates and/or third parties. If you are a California resident and would like a copy of this notice, please submit a written request to marketing.operations@citynational.com.

Your privacy rights

You may have other privacy protection under the applied State Law and/or your State of residency. To the extent that this is applicable, we will comply with those provisions, including but not limited to your right to request access to personal information that has been collected about you and how it is shared. Additionally, you may have the right to op-out of the sale of your personal information, targeted advertising, profiling, and having your personal information deleted. Please submit all applicable privacy requests to marketing.operations@citynational.com.

GDPR

Our Data Protection Officer is responsible for overseeing what we do with your information and monitoring our compliance with data protection laws. If you have any concerns or questions about our use of your personal data, you can contact our Data Protection Officer by writing to marketing.operations@citynational.com.

Restrictions on the disclosure of account information

We do not reveal specific information about client accounts, including but not limited to, client financial information, payment activities, transactions or other personally identifiable data to unaffiliated third parties for their independent use, except for the exchange of information with reputable information reporting agencies, unless 1) the information is provided to help complete a client-initiated transaction; 2) the client requests it; 3) the disclosure is required by/or allowed by law (e.g., subpoena, investigation of fraudulent activity, etc), or 4) the client has been informed about the possibility of disclosure for marketing or similar purposes through a prior communication and is given the opportunity to decline to necessary.

The Fair Credit Reporting Act requires that we notify you of your right to ask that we not share certain outside credit information with companies affiliated with the Bank. If you do not want such (e.g.,Consumer Credit Reports)shared among the Bank’s affiliates, you may notify us in writing of your instructions at any time. To do so, please send your name and address(as they appear on your account statement), and Social Security number to:

City National Bank of Florida Quality Assurance Department
100 S.E. 2nd Street, 14th Floor Miami, FL 33131.

Your choices regarding your information

You can access, update or correct your information by changing preferences in your account. For additional requests, please contact us. In addition, you can access and delete cookies in your web browser preferences.

Security

The Bank has security measures in place to protect the loss, misuse, and alteration of the information under our control. Nevertheless, transmission via the internet is not completely secure and we cannot guarantee the security of your information.

Opt-out

You may “opt out” of having your personal information shared by providing us written notice identifying which communications you choose not to receive by writing us at: marketing.operations@citynational.com.

If you have signed-up to receive our email marketing communications, you can unsubscribe any time by clicking the "unsubscribe" link included at the bottom of the email or other electronic communication. Alternatively, you can opt out of receiving marketing communications by contacting us.

If you provide your phone number, we may send you notifications by SMS, such as provide a fraud alert. You may opt out of SMS communications by unlinking your mobile phone number through your account settings. If you initially consented to the collection of location data, you could subsequently stop the collection of this information at any time by changing the preferences on your mobile device. Please note, however, that if you withdraw consent to our collection of location data, you may no longer be able to use some features of the App.

Please Note: All accounts with the primary Social Security number noted in the request will be affected.

Count on our commitment to your privacy

You can count on us to keep you informed about how we protect your privacy and limit the sharing of information you provide to us - whether it's at a banking center, via a phone call, through the Internet, or our mobile app. Please note that since we cannot control information on other Internet sites, we are not responsible for the content of sites linked from citynational.com.

Privacy policy updates

We reserve the right to modify the terms of this privacy policy at any time and in its sole discretion, by posting a change notice on this page. Your continued use of our banking services following a notification of change will constitute binding acceptance of those changes.