Effective Date: May 26, 2021
nCino, Inc. and its subsidiaries and affiliates (“nCino,” “we,” “us,” “our,” or the “Company”) are committed to respecting your privacy. This Privacy Statement describes nCino’s privacy practices in relation to the websites, products, services and programs owned and operated by nCino. In addition, this policy states how you can control the collection, correction and/or deletion of information. We will not use or share your information with anyone except as described in this Privacy Statement.
We urge you to read this Privacy Statement so that you understand our commitment to you and your privacy, and how you can participate in that commitment. When you visit our websites, or provide personal information to us through other means, you consent to the use of your information as described in this Privacy Statement.
To see more information about the following aspects of nCino privacy practices, please click on the links below:
- Web sites covered
- Personal information we collect
- How we use and disclose personal information
- International data transfers; Privacy Shield Participation
- Privacy Shield Inquiries, Complaints, Recourse, and Enforcement
- Customer data
- How nCino protects your data
- Collection of information from children
- Modern Slavery Policy (UK)
- Access and Choice
- Conflicts with this Privacy Statement
- How to contact us
- Cookie Preference Center
nCino may review and update this Privacy Statement periodically to reflect changes to our privacy practices. We will provide notification of material changes to this Privacy Statement through the Company’s websites or via email prior to the change becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices.
1. Web sites covered
This Privacy Statement covers information practices, including how the Company collects, uses, shares and secures the personal information you provide, of websites that link to this Privacy Statement.
nCino’s websites may contain links to other websites. The information practices or the content of such other websites is governed by the privacy statements of such other websites. nCino encourages you to review the privacy policies of other websites to understand their information practices.
Please also note that co-branded websites (i.e., websites where nCino presents content together with one or more of our business partners) may be governed by additional or different privacy statements. Please refer to the privacy statement on those websites for more information about applicable privacy practices.
2. Personal information we collect
This Privacy Statement applies to personal information and other information collected by nCino or its service providers from or about:
- Visitors to, or users of, its websites;
- Prospective and current customers using nCino products or services;
- Service providers and business partners;
- Job applicants; and
- Other third parties that it interacts with.
The personal information nCino collects includes the following:
Web registration information. When (i) expressing an interest in obtaining additional information about nCino’s products or services, (ii) registering to use our websites or other services, or (iii) registering for an event, nCino may require you to provide us with personal contact information such as your name, company name, address, phone number, and email address.
Job applications. When you apply for a position with nCino through the careers section of nCino’s website, we may collect personal information such as your name, email address, physical address, LinkedIn profile, phone number, compensation expectations and work history. You also have the option to upload your resume that may include additional personal information.
nCino also utilizes third party recruitment firms for certain recruiting activities. Such firms may send us potential candidate information such as name, email address, physical address, compensation expectations and work history.
Website navigational information. nCino may collect certain information about you from your web browser when you visit our websites. This information may include your Internet Protocol ("IP") address, browser type, browser language, and the date and time of your request. This information could indirectly identify you and gathering this information from you helps us ensure our websites and other services work correctly in support of our customer analytic efforts.
Email communication. We use pixel tags or web beacons in our marketing emails so that we can track your interaction with those messages, such as when you open the email or click a URL link that’s embedded within them. When recipients click on one of those URLs, they pass through a separate web server before arriving at the destination page on an nCino website. We use these tools to determine potential interest in particular topics, as well as measure and improve the effectiveness of our communications with you.
Some web browsers provide settings that allow you to control or reject cookies or to alert you when a cookie is placed on your computer, tablet or mobile device. Although you are not required to accept cookies, if you block or reject them, you may not have access to all features available through our services.
Google Analytics. nCino uses Google Analytics' third-party audience data to better understand the behavior of our visitors and work with companies that collect information about your online activities to provide advertising targeted to suit your interests and preferences. For example, you may see certain ads on this or other websites because we contract with Google and similar companies to target our ads based on information we or they have collected, including information that was collected through automated means (such as cookies and web beacons).
Employee information. When you join nCino as an employee, we collect personal information such as your name, national identification, physical address, email address, phone number, ethnicity, gender, background check information, dependent information, benefit information and bank information for payroll purposes.
Third party sources. nCino may also collect information about you from other sources to help us correct or supplement our records, improve the quality or personalization of our services to you, and prevent or detect fraud. We work closely with third parties (for example, business partners, service providers, sub-contractors, analytics providers and search information providers) and may receive information about you from them.
Public forums, blogs and the customer reference program
nCino websites may feature bulletin boards, blogs or forums. Any personal information that you choose to submit via such a forum may be read, collected, or used by others who visit these forums, and may be used to send you unsolicited messages. nCino is not responsible for the personal information you choose to submit in these forums.
3. How we use and disclose personal information
nCino may use your personal information to provide you products and services, such as to fulfill your requests for products or to help us personalize our offerings to you. We also use your personal information to support our business functions, such as sales, marketing, services, recruitment and legal functions. For example, we may use this information to:
- Fulfill requests;
- Send product and services updates;
- Respond to customer service requests;
- Send marketing communications;
- Improve our websites and marketing efforts;
- Conduct research and analysis;
- Comply with legal and/or regulatory requirements;
- Respond to questions and concerns; and
- Process employment applications and background checks.
Apart from using your personal information to support our own business functions, we may disclose your personal information under the following conditions:
Disclosure of personal information to third parties. nCino will not rent or sell your personal information to others but may disclose personal information with third-party vendors and service providers that work with nCino. We will only share personal information to these vendors and service providers to help us provide a product or service to you. Examples of third parties we work with are background check agencies, benefits providers, financial institutions and other service providers that provide corporate functions to us such as human resources and customer relationship management. These third parties only have access to personal information necessary for them to perform their services.
Disclosure of personal information for business purposes. In the event of corporate divestures, mergers, acquisitions, bankruptcies, dissolutions, reorganizations, liquidations, or general business transactions or proceedings, nCino may buy, sell, divest or transfer your personal information.
Disclosure of personal information for legal and safety reasons. nCino may be required to disclose personal information to regulatory authorities, law enforcement agencies or government agencies. We may disclose information to:
- comply with valid legal process including subpoenas, court orders or search warrants, and as otherwise authorized by law;
- respond to lawful requests by public authorities, including to meet national security or law enforcement requirements;
- in the event of an emergency that threatens an individual's life, health, or security; or
- to the extent permitted by applicable law, in special cases in which we believe it is reasonably necessary to investigate, identify, or take preventive measures or bring legal action against someone who may commit or cause harm, fraud, abuse, or illegal conduct, such as a threat of harm to you or anyone else, interference with our rights or property, or interference with U.S. homeland or national security or public safety anywhere in the world.
Disclosure of personal Information via links to third party services and applications. Using our websites or services may link you to third party websites, services, and applications. nCino is not responsible for any personal information collected by such third parties which use is governed through the third party's website's privacy policies. Any interactions you have with these websites, services, or applications are beyond the control of nCino. When you post information to or through such services, those websites' privacy policies apply. We urge you to read the privacy and security policies of any external websites before providing any personal information while accessing those websites.
4. International data transfers; Privacy Shield participation
nCino is a global organization, with legal entities, business processes, and technical systems that operate across borders. nCino may transfer your personal information to other nCino entities in the United States and elsewhere. The United States and other countries may not have the same data protection laws as the country from which you initially provided the information. By accessing nCino’s websites, registering for an account or service, or otherwise providing nCino with your personal information, you consent to this transfer of your personal information. When transferring your personal information internationally, nCino will protect your personal information as provided in this Privacy Statement.
nCino participates in and has certified to the U.S. Department of Commerce that it complies with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework (collectively, the “Privacy Shield Framework”) as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States. nCino is committed to subjecting to the Principles of the Privacy Shield Framework all personal information received from EU member countries and Switzerland in reliance on the Privacy Shield Framework. If there is any conflict between the policies in this Privacy Statement and the Privacy Shield Framework Principles, the Privacy Shield Framework Principles shall govern. To learn more about the Privacy Shield program, and to view our certification page, please visit https://www.privacyshield.gov/.
5. Privacy Shield inquiries, complaints, recourse, and enforcement
In compliance with the Privacy Shield Framework, nCino commits to resolve inquiries and complaints about our collection or use of your personal information. EU and Swiss individuals with inquiries or complaints regarding our Privacy Shield practices should first contact nCino using the information in the “How to contact us” section, below. If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third-party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.
With regard to unresolved Privacy Shield complaints concerning both human resources and non-human resources data transferred from the EU or Switzerland, nCino has committed to cooperate with the EU data protection authorities for citizens and residents of the EU and the Swiss Federal Data Protection and Information Commissioner for citizens and residents of Switzerland.
Under certain conditions, more fully described on the Privacy Shield website, https://www.privacyshield.gov/article?id=ANNEX-I-introduction, you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.
With respect to personal information that nCino receives pursuant to the Privacy Shield Framework, nCino will remain liable for processing of that personal information by nCino’s agents, unless nCino establishes that it is not responsible for the event giving rise to the damage.
The Federal Trade Commission has jurisdiction over nCino’s compliance with the Privacy Shield Framework.
6. Customer data
nCino's customers may electronically submit data or information to us for hosting and processing purposes ("Customer Data"). In accordance with the nCino policy, nCino will access Customer Data only for providing our products and services or for preventing or addressing service or technical problems (at a customer's request in connection with customer support matters), or as may be required by law. nCino will not otherwise review, share, distribute, or reference any Customer Data except as authorized by the applicable customer.
nCino may transfer personal information to third party companies that help us provide our products and services. Transfers to subsequent third parties are covered by the provisions in this Privacy Statement regarding notice and choice and the service agreements with our customers. nCino maintains contracts with these third parties restricting their access, use and disclosure of personal data in compliance with our Privacy Shield obligations, including the onward transfer provisions, and nCino remains liable if they fail to meet those obligations and we are responsible for the event giving rise to damage.
nCino acknowledges that you have the right to access your personal information. If personal information pertaining to you as an individual has been submitted to us by an nCino customer and you wish to exercise any rights you may have to access, correct, amend, delete, or limit uses or disclosures of such data, please inquire with our customer directly. Because nCino personnel have limited ability to access data our customers submit to our products and services, if you wish to make your request directly to nCino, please provide the name of the nCino customer who submitted your data to our products and services. We will refer your request to that customer and will support them as needed in responding to your request within a reasonable timeframe.
7. How nCino protects your data
Security of your information is of the utmost importance to nCino. nCino uses reasonable security practices, including technical and physical safeguards, to protect the security of your personal information from misuse and unauthorized access and disclosure. Nevertheless, such security measures cannot prevent all loss, misuse, alteration, or unauthorized access or disclosure of personal information, and we are not able to guarantee absolute security.
8. Collection of information from children
The Company recognizes the importance of protecting the privacy and safety of children. Our websites and services are directed towards the general audience and are not directed towards children. We do not knowingly collect information about children under the age of 13 or minors otherwise defined in local law or regulation without verifiable parental consent. If we learn that someone under 13 has provided personal information through one of our websites, we will use reasonable efforts to remove that information from our databases.
9. Modern Slavery Policy (UK)
The United Kingdom Modern Slavery Act 2015 requires certain businesses to publish an annual statement specifying the efforts taken to prevent slavery and human trafficking within their own business and their supply chain.
nCino is a pioneer in cloud banking and digital transformation solutions for the global financial services industry. We are committed to the highest standards of business conduct in our relationships with each other, with companies with which we do business, and with our stockholders and others. This requires that we conduct our business in accordance with all applicable laws and regulations in the various countries we operate in and in accordance with the highest standards of business ethics.
The nCino Code of Business Conduct and Ethics outlines the fundamental principles and key policies and procedures that govern the conduct of our business. This Code describes standards of conduct for our employees, officers and directors, and provides guidance on how to follow company policies, applicable laws, rules and regulations. We respect human rights, provide fair working conditions, and strictly prohibit supporting or dealing with any business knowingly involved in slavery or human trafficking.
While we consider our business and supply chains to be low risk for involvement in modern slavery and human trafficking, to ensure members of our supply chain and contractors comply with our values, including our zero-tolerance approach to slavery and human trafficking, our suppliers and business partners are subject to various forms of vetting as part of our due diligence processes including: a) all suppliers are subject to legal terms and conditions with nCino; b) assessments of potential suppliers are completed as part of nCino's supplier on-boarding process; c) nCino reviews the performance of its suppliers based on the supplier's relative risk to the company; d) suppliers deemed highest risk are audited or reviewed on a periodic basis and nCino works closely with such suppliers to develop corrective action plans and carry out all audit findings; and e) nCino performs continuous monitoring of suppliers for changes in policies, environments, contracts and processes.
Should nCino become aware of any issues related to slavery or human trafficking, nCino will consult with its Legal Department to ensure that appropriate measures are taken, which may include reporting this information to the appropriate authorities and terminating our relationship with the supplier.
This statement applies to nCino, Inc and all its affiliates including nCino Global Ltd and is issued for the fiscal year ending January 31, 2023. Although subject to review annually, the statement will also apply to subsequent fiscal years unless and until withdrawn, superseded, or modified by nCino.
/s/ April Rieger
By: April Rieger
Its: General Counsel
10. Access and choice
nCino may retain your information for a period of time consistent with the original purpose of collection, legitimate business interests, to conduct audits, comply with our legal obligations, resolve disputes and enforce our agreements.
We acknowledge that you have the right to access your personal information. Upon request, nCino will provide individuals with reasonable access to their personal information, and in doing so allow individuals the opportunity to, under certain circumstances, correct, amend, update, or delete that information or limit uses and disclosures of that information. A request may be denied under certain circumstances, such as where the burden or expense of providing access would be disproportionate to the risks to the privacy of the individual in the case in question, or where the rights of persons other than the individual would be violated. For requests to access, correct, modify, delete, or limit uses or disclosures of your personal information, please contact us using the information in the “How to contact us” section below. Requests will be addressed within a reasonable timeframe. If you are an employee of nCino, you may also wish to contact your Human Resources group for assistance in correcting or updating your information. As noted above in Section 5, if we are hosting or processing your personal information on behalf of a customer, requests to access, correct, modify, update, delete, or limit uses or disclosures of your personal information should be made through the customer.
11. Conflicts with this Privacy Statement
This Privacy Statement may not apply to the extent it conflicts with other controlling terms and conditions (such as, for example, an agreement for our products and services between nCino and you or your organization) or applicable law or regulation.
Any questions, inquiries, complaints, and requests related to this Privacy Statement can be directed to us by email at email@example.com or by mail at:
6770 Parker Farm Drive,
Wilmington, NC, 28405 USA