Privacy & Confidentiality Statement
RIMS Benchmark Survey
This confirms that Advisen is a licensee of the TRUSTe Privacy Program. This privacy statement discloses the privacy practices for Advisen with respect to the RIMS Benchmark Survey ("the Survey").
TRUSTe is an independent, non-profit organization whose mission is to build users' trust and confidence in the Internet by promoting the use of fair information practices. Advisen is committed to preserving its users' privacy. To this end, it has agreed to disclose its information practices and have its privacy practices reviewed for compliance by TRUSTe. By displaying the TRUSTe trustmark, this web site has agreed to notify its users of:

1. What personally identifiable information of the users or third party's personal identification is collected through the web site

2. The organization collecting the information

3. How the information is used

4. With whom the information may be shared

5. What choices are available to the users regarding collection, use and distribution of information

6. The kind of security procedures that are in place to protect the loss, misuse or alteration of information under Advisen's control

7. How the users can correct any inaccuracies in the information.

If users feel that Advisen is not abiding by its posted privacy policy, they should first contact Tom Ruggieri at 212-897-4777 or truggieri@advisen.com. If the website users do not receive any acknowledgment of their inquiry or their inquiry has not been satisfactorily addressed, they can contact TRUSTe at http://www.truste.org. TRUSTe will then serve as a liaison with the Web site to resolve users' concerns.

Information Collections and Confidential Use

Advisen collects information from its users at several different points on this website. The confidentiality and use of the information collected is governed by an agreement between RIMS and Advisen. The provisions of this agreement extend to users of the Survey. RIMS is the sole owner of the information collected for the Survey. RIMS has contracted with Advisen to collect and manage the data from the Survey and has granted Advisen an exclusive license to use the data collected from the Survey. RIMS has retained limited rights to use data collected from the Survey for the purpose of developing educational programs. RIMS and Advisen will not sell, share, or rent the user's personally identifiable information or third party personally identifiable information.
Registration

In order to contribute data to the Survey or use Advisen's interactive data benchmarking services, a user must fill out a registration form. During registration a user is required to provide the following personal information: name, phone, email address, business title, and physical address. This information is used to contact the Survey participant and more closely tailor services to the users' profile.

Log Files

Advisen uses Internet Protocol (IP) addresses to analyze trends, administer the site, and track users' movement for aggregate usage. IP addresses are not linked to personally identifiable information.

Sharing

Advisen will share aggregated user information such as pricing, losses, program structure data, and top concepts with its partners. This is not linked to any personal information that can identify an individual person or company. Aggregated user information will only be shared when there are more than ten (10) primary sources, or three (3) secondary sources, so that statistics cannot be traced back to any one individual source.

Surveys

From time-to-time this web site will request information from its users via surveys. Participation in these surveys is completely voluntary. Survey information will be used for purposes of monitoring and improving the use and satisfaction of this web site.

Security

This web site has built-in precautions to protect its users' information. When users submit sensitive information via the web site, the information is protected both online and off-line.

All Advisen systems are behind a firewall with specific ports authorized for access to all machines. Web servers are authorized from the Internet in general. Other machines such as database servers, application servers, and file servers explicitly allow access only from specific source addresses.

The users' information is encrypted in 128 encryption and protected with the best encryption software in the industry, SSL (Secure Sockets Layer). Access to the production web servers is provided by an industry standard key mechanism from Verisign. SSH2 (Secure Shell 2) has access only to back end machines. Telnet access is NOT allowed.

While in a secure page on this web site, such as Project Template, the lock icon on the bottom of Web browsers ( e.g., Netscape Navigator and Microsoft Internet Explorer) becomes locked, unlike when the user is just 'surfing' where the lock icon is un-locked, or open. To learn more about SSL, follow this link: http://www.openssl.org.

While Advisen uses SSL encryption to protect sensitive information online, it also does everything in its power to protect user-information off-line. All of its uses are restricted to Advisen's offices. Only Advisen employees who need the information to perform a specific job, like customer service, are granted access to personally identifiable information. ALL Advisen employees are kept up-to-date on current security and privacy practices, and are well aware of the importance of user privacy. Additionally, Advisen servers storing personally identifiable information are kept in a secure environment, where only authorized personnel have access. If there are any questions or concerns about the security of this web site, please send an email to security@advisen.com.

Supplementation of Information

In order for this web site to properly fulfill its obligation to its users, it is necessary to supplement the information received from its users with information from 3rd party data sources like D&B and S&P. Third party data sources are combined with analytics tools to create a personalized user profile.

Site and Service Updates

This web site will occasionally contain site and service announcement updates. Users are not able to un-subscribe from these announcements because they contain important information about the web site and service. User's specific service requests and inquiries relating to their account will be responded to via email or phone.

Correction/Updating Personal Information:

If a user's personally identifiable information, such as an email address or phone number, changes, the user's personal data will be corrected or updated. This can be done by emailing Advisen's Customer Support or Account Management group.
Notification of Changes

Information will be used in accordance with the privacy policy under which it was collected. If Advisen decides to change its privacy policy, it will post the changes on its Homepage so that users are always aware of what information is collected, how it's being used, and under what circumstances, if any, it is disclosed. If at any point Advisen decides to use personally identifiable information in a manner different from that stated at the time it was collected, users will be notified via email. Users will have a choice as to whether or not to allow their information to be used in a different manner.


Copyright Advisen Ltd. 2008 All Rights Reserved