Bottomline - US Employee & Candidate Privacy Notice
What is the purpose of this document?
This is an Employee and Candidate Privacy Notice for Bottomline Technologies, Inc (“Bottomline”, “we” and “us”). Bottomline is committed to protecting the personal information of current and former employees, contractors, and job applicants. This Privacy Notice describes how we collect, use, disclose, and protect personal information in accordance with applicable state and federal privacy laws, where the employee, intern, contractor, volunteer, and applicant (or their emergency contact, where relevant) resides in a state which provides relevant data protections.
Personal information does not include:
- Publicly available information that is lawfully made available from government records, that an individual has otherwise made available to the public.
- De-identified or aggregated information.
- Information excluded from the scope of applicable state legislation, such as:
o Health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data.
o Personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (CFIPA) and the Driver’s Privacy Protection Act of 1994.
The data we collect:
In each case as permitted by applicable law, we may collect the following categories of personal information for the purposes described below:
- Personal identifiers, such as your name, preferred name, postal address, unique personal identifiers (such as device identifiers, cookies, beacons, pixel tags, mobile ad identifiers and similar technology), telephone number, online identifier, Internet Protocol address, email address, Social Security number, driver’s license number, passport number, date of birth, signature, physical characteristics or description, state identification card number, insurance policy number, education, bank account number, credit card number, debit card number, other financial information, medical information and health insurance information.
- Characteristics of protected classifications, such as race, color, national origin, religion, age, sex, gender, marital status, medical condition, disability, citizenship status and military or veteran status. We only collect this information if you voluntarily disclose it and as permitted by applicable law, and we will not use this information to make hiring decisions.
- Online activity, such as your browsing history, search history, IP address and information regarding your interaction with a website, application, or advertisement or Bottomline device.
- Geolocation data that indicates your precise location.
- Sensory data, such as audio and visual information that we may obtain if you use video interviewing as part of the application process. If you visit, work, or perform services in Bottomline’s facilities or facilities in which we operate, your entry, exit and actions in or around those facilities may be monitored by CCTV.
- Professional or employment-related information, such as your employment history, job application or resume, employment contract, references, information about skills and abilities, accomplishments and awards, training and development information, performance evaluation information and employment termination information.
- Non-public education information, such as your education history, education records (such as grades, transcripts, and class lists) and other information included in your resume or cover letter.
- Inferences drawn from other personal information, including any information referenced above to create a profile about you reflecting your preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
- Sensitive personal information, such as race/ethnicity, disability status, health information (where permitted and applicable), biometric data (e.g., for security or timekeeping).
- Emergency Contact and Dependent Information: For benefits and emergency response purposes
Bottomline may also collect personal information included in job interview notes, responses to screening questions, information provided from background checks, assessment results and any other information you provide in connection with the recruitment process.
How do we collect your personal information?
We usually collect personal data from candidates using an application tracking system. We may also automatically collect certain information, such as IP addresses and device identifiers. Should it not be collected during your initial application process, we may use the following sources to collect your personal information:
- You, the candidate or employee;
- Our HR Operations team may collect the following information for onboarding and employee record maintenance purposes; resume, photo, title, name, preferred name, address, telephone number, email address, emergency contact details, date of birth, gender, marital status, ID number and expiry, disability, ethnicity, citizenship status, and banking and tax information, as appropriate and required for the location of the role.
- Any recruitment agency through which you apply or are recommended by, from which we collect the following categories of data: including name, title, address, telephone number, personal email address, date of birth, gender, employment history, qualifications, remuneration, benefits information, proof of identity, proof of address any other information deemed relevant to the role for which you are being considered;
- Our background check provider, from which we collect the following categories of data: identity and right to work confirmation, criminal history, global sanctions and politically exposed persons (PEP) screening, education and employment verification, credit and financial background (where relevant), directorships and conflict of interest checks, and adverse media searches. All checks are conducted only where necessary and appropriate for the position, in accordance with applicable laws and with your explicit consent;
- Our i-9 processing vendor, from which we collect the following categories of data: legal name, Social Security Number, date of birth, identity and right to work documentation;
- Prior employers and professional references;
- Educational institutions;
- Credentialing and licensing organizations;
- Publicly available sources, such as public social media profiles on LinkedIn, X (Twitter) or Facebook;
- Emails/conversations with HR/your manager relating to your employment (e.g. leave due to sickness);
- Through Bottomline’s online systems (e.g. holiday booking system, sick leave booking system, office desk systems, training tools and monitoring Bottomline systems such as email, and internet usage);
- CRM systems for sales performance and commission and payment processing;
- Applications to other roles within Bottomline;
- Employee vetting processes; and
- Other sources as directed by you.
How is your personal information used?
We may use the personal information we collect about you for the following business purposes:
- Recruitment of Employees and Processing and Managing Job Applications: We use your personal information to process your job application, create an applicant profile, evaluate your qualifications, schedule, and conduct interviews and communicate with you.
- Conducting Pre-Employment Screening and Background Checks: In accordance with applicable law, we use your personal information to conduct employment screening, re-screening (where required for your role) and background checks.
- Compensation and Expense Management: We use your personal information to conduct payroll processing, salary administration, expense reimbursement, manage Bottomline’s corporate credit card program and other compensation purposes such as determining bonuses, equity, and other forms of employee compensation.
- Benefits Administration: We use your personal information we collect to administer benefits we provide, such as medical, dental, vision, disability insurance, and other employee benefit programs.
- General Human Resources Management: We use your personal information we collect to provide general HR management services, including managing employee on-boarding, termination and separation, travel administration and return-to-work screening (including any medical screening as required or permitted by applicable law).
- Training and Professional Development: We use your personal information to provide employment-related training, assisting with professional licensing and development.
- Internal Employment Purposes: We use your personal information to conduct internal investigations, conduct surveys, analyse resources, resolve disputes, prevent, or detect fraud or security incidents, conduct employee performance reviews, enforce policies and the code of conduct, protect the rights and safety of employees or others, and manage whistleblower programs.
- Compliance with Legal Requirements and Enforcement of Legal Rights: We use your personal information to comply with applicable laws, regulations, and legal processes (such as responding to subpoenas or court orders), and to respond to legal claims, resolve disputes, enforce legal rights contained in employment or other contracts and comply with legal or regulatory recordkeeping requirements including audits.
We retain personal information as long as needed to fulfil the purposes outlined in this notice, or as required by law, including after the end of employment or withdrawal of an application. Retention periods are based on applicable legal, regulatory, tax, accounting, and operational requirements.
Sharing your personal information
We may share your personal information with third parties, for the business purposes described in this notice, with the following parties:
- Affiliates and Subsidiaries: We may share your personal information with Bottomline’s affiliates and subsidiaries.
- Service Providers: We may share your personal information with service providers, such as recruiters, pre-employment screening services, third-party benefits administrators, payroll processors, background check providers and others for a business purpose. When we disclose personal information for a business purpose, we enter a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract.
- Governmental Authorities: As required by law or legal process, we may share your personal information with federal or state regulatory agencies, law enforcement, courts, and other governmental authorities.
- Professional Advisors: We may share your personal information with our professional advisors, such as auditors and law firms.
- Parties Involved with Business Transfers: We may share your personal information to third parties in the event we sell or transfer all or a portion of Bottomline’s business or assets (including in the event of a merger, acquisition, joint venture, reorganization, divestiture, dissolution, or liquidation).including third-party service providers and other entities in the group, where required by law, where it is necessary to administer the application process or where we have another legitimate interest in doing so.
Bottomline does not sell any personal information to third parties.
Your rights and obligations
It is important that the personal information we hold about you is kept up to date. Please use the applicable processes to inform us of any updates to your personal information.
Under certain circumstances and where applicable state legislation requires, you have the right to:
- Request information on the categories of personal information, sources used, purposes for processing and categories of third parties with whom your personal information is shared.
- Request access to your personal information. This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.
- Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
- Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it.
- Object to profiling of your personal information which is used to make decisions with legal or similarly significant effects.
- Request the transfer of your personal information to another party.
If you want to exercise these rights, please contact Bottomline’s Data Protection Officer in writing. You will need to provide enough information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative and you will need to describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. We will only use personal information provided in a verifiable request to confirm the requestor’s identity or authority to make the request.
We endeavor to respond to a verifiable request within forty-five (45) days of its receipt. If we require more time, we will inform you of the reason and extension period in writing. We will deliver a written response by mail or electronically, at your option. Any disclosures we provide will only cover the 12-month period preceding the verifiable request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance, specifically by electronic mail communication.
We do not charge a fee to process or respond to your verifiable request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
Data Protection Officer contact details
If you have any questions about this notice or your personal information, then please contact Bottomline’s Data Protection Officer - DataProtectionOfficer@bottomline.com.
You also may have the right to make a complaint to the data privacy regulator in your state of residence.
Changes to this Privacy Notice
We may update this notice at any time. This notice was published on May 19, 2025.