Privacy 
Recognizing Your Right to Privacy
NBT Bancorp Inc. is a financial holding company headquartered in Norwich, N.Y. The company primarily operates through NBT Bank, N.A., a full-service community bank with two divisions, and through two financial services companies. NBT Bank, N.A., based in Norwich, N.Y., has NBT Bank offices in upstate New York and northwestern Vermont and Pennstar Bank offices in northeastern Pennsylvania. NBT Bank is based in Norwich, N.Y., and Pennstar Bank is based in Scranton, Pa. EPIC Advisors, Inc., based in Rochester, N.Y., is a full-service 401(k) plan recordkeeping firm. Mang Insurance Agency, LLC, based in Norwich, N.Y., is a full-service insurance agency.NBT Bank (“we,” “us” or “our”) is committed to providing you (“consumer” or “customer”) with responsive, personalized service and to keeping you informed about new services that may be of interest to you. As we assist you in working toward your financial goals, we want to assure you that protecting your privacy is important to us. We want you to understand what information we collect, how we collect that information and how we use that information. This document contains the following sections:
- Making information security a priority
- Collecting your information
- Managing your information
- Honoring your information preferences
- Actions you can take about your information preferences
- Other privacy commitments that may affect you
- NBT Bancorp Inc. companies
1. MAKING INFORMATION SECURITY A PRIORITY
Keeping financial information secure is one of our most important responsibilities. We maintain physical, electronic and procedural safeguards to protect Customer Information. Applicable employees are authorized to access Customer Information for business purposes only. Our employees are bound by a code of ethics that requires confidential treatment of Customer Information; our employees are subject to disciplinary action if they fail to follow this code. For details on what you can do to safeguard your personal information, please visit www.nbtbank.com/security.html.2. COLLECTING YOUR INFORMATION
We collect your Customer Information from the following categories:Identification Information. This is information that identifies you. Examples include your name, address, telephone number and Social Security number.
Application Information. This is information you provide to us on applications (or through other means) that help us determine if you are eligible for the products or services you request. Examples include your assets, income and debt.
Transaction and Experience Information. This is information about your transactions with us, your account experience with us and our communications with you. Examples include your account balances, payment history, account usage and inquiries. Also included are our responses to your inquiries.
Consumer Report Information. This is information from a consumer reporting agency. Examples include your credit score and credit history.
Information From Outside Sources. This is information from outside sources about your employment, credit and other relationships that will help us determine if you are eligible for products or services you request. Examples include your employment history, loan balances, credit card balances, property insurance coverage and other verifications.
Other General Information. This is information from outside sources, such as data from public records, that is not assembled or used for the purpose of determining eligibility for products or services. As required by the federal law known as the USA PATRIOT Act, we collect information and take the necessary actions to verify your identity.
3. MANAGING YOUR INFORMATION
Within Our CompanyNBT Bancorp, our parent company, is composed of a number of companies, including financial and nonfinancial companies. We occasionally receive medical or health information from a customer if, for example, he or she applies for insurance from us. We may also obtain information from nonaffiliated insurance-support organizations that prepare and provide reports to us and other companies. We do not share medical or health information among NBT Bancorp companies—except, as permitted by law, to maintain or collect on accounts, process transactions, service customer requests or perform insurance functions.
With Third-Party Companies That Work for Us
We may share information from any of the above-mentioned Customer Information categories with third-party companies that work for us. All nonaffiliated companies that act on our behalf and receive Customer Information from us are contractually obligated to: (1) keep the information we provide to them confidential and (2) use the Customer Information we share with them only to provide the services we ask them to perform. These companies may include financial service providers (such as payment-processing companies) and nonfinancial companies (such as check-printing and data-processing companies).
In addition, we may share information from any of the Customer Information categories with third-party companies that work for us to provide marketing support and related services (such as a service provider that distributes marketing materials). These companies may help us market our own products and services or other products and services that we believe may be of interest to you. Some NBT Bancorp companies may also provide marketing support and related services for us.
Disclosing Information in Other Situations
We may disclose information from any of the Customer Information categories to credit bureaus and similar organizations—and when required or permitted by law. For example, Customer Information may be disclosed in conjunction with fraud prevention or investigations, risk management and security actions and recording mortgages in public records.
4. HONORING YOUR INFORMATION PREFERENCES
You have choices when it comes to how we share and use your information. In regard to information sharing among NBT Bancorp companies, you may:- Limit our affiliates in the NBT Bancorp companies (such as our insurance affiliates) from marketing their products or services to you based on your personal information that we collect and share with them. This information includes your income, account history with us and credit score.
- Inform us about your preferences individually or you may inform us about the preferences of any other customers who are joint account holders with you.
5. ACTIONS YOU CAN TAKE ABOUT YOUR INFORMATION PREFERENCES
To limit marketing offers, you can call us toll-free at 1-866-4STAR-PA (1-866-478-2772). You can also speak with a customer service representative at your local branch or with your client relationship manager. Please allow 30 days for your request to take effect. Once your request has been processed, it will remain in effect until you ask us to change it.6. OTHER PRIVACY COMMITMENTS THAT MAY AFFECT YOU
This notice constitutes our Do Not Call policy under the federal Telephone Consumer Protection Act for all consumers and is pursuant to state law. When you speak with us by telephone, your conversation may be monitored or recorded by us. You may have other privacy protections under state laws, such as those in effect in Vermont and California. To the extent these state laws apply, we will comply with them in regard to our Customer Information practices. Applicable state-specific laws are detailed below:Residents of Nevada
We are providing you this notice pursuant to Nevada state law. You may be placed on our internal Do Not Call list by following the directions in Section 5 above (“ACTIONS YOU CAN TAKE ABOUT YOUR INFORMATION PREFERENCES”). Nevada state law also requires that we provide you with the following contact information for your reference: Bureau of Consumer Protection, Office of the Nevada Attorney General, 555 E. Washington Street, Suite 3900, Las Vegas, NV 89101; phone number: 702-486-3132; e-mail: BCPINFO@ag.state.nv.us.
Residents of Vermont, California and New Mexico
The information-sharing practices described above are in accordance with federal law. Residents of the states of Vermont, California and New Mexico are provided with additional rights under their respective state laws. These rights are outlined below.
Vermont. In accordance with Vermont state law, we will not share information we collect about Vermont residents with companies outside of NBT Bancorp except as permitted by law. Permitted information sharing includes servicing a customer’s account (with the consent of that customer) and working with other financial institutions that have joint marketing agreements with us. We will not share Application Information, Consumer Report Information and Information From Outside Sources about a Vermont resident among NBT Bancorp companies except with the authorization or consent of that Vermont resident.
California. In accordance with California state law, we will not share information we collect about California residents with companies outside of NBT Bancorp except as permitted by law. Permitted information sharing includes servicing a customer’s account (with the consent of that customer) and meeting our commitments to fulfilling rewards or benefits that a customer has earned. We will limit sharing among NBT Bancorp companies to the extent required by California state law.
New Mexico. Residents of New Mexico do not have to take any action to limit our sharing of information with companies outside of NBT Bancorp. Such limits are already in place under New Mexico state law. Unless a customer authorizes us to do so, we will not share any of that customer’s nonpublic personal financial information with companies outside of NBT Bancorp except as permitted by law.
7. NBT BANCORP INC. COMPANIES
This privacy policy applies to the following NBT Bancorp-owned companies that have consumer or customer relationships with NBT Bancorp:Banks and Trust Companies. NBT Bank, N.A., based in Norwich, N.Y., is a full-service community bank that has two divisions. NBT Bank, N.A. has NBT Bank offices in upstate New York and northwestern Vermont and Pennstar Bank offices in northeastern Pennsylvania.
Insurance and Annuities. Mang Insurance Agency, LLC, based in Norwich, N.Y., is a full-service insurance agency. Hathaway Agency Inc., based in Gloversville, N.Y., is a full-service insurance agency.
IMPORTANT INFORMATION ABOUT CREDIT REPORTING — We may report information about your account to credit bureaus. Late payments, missed payments or other defaults on your account may be reflected in your credit report.
