Website Policies
1. Copyright Policy
• Copyright policy - Moderate
This website and its content are the intellectual property of UCO Bank. All materials, including text, graphics, logos, images, audio, video, and software, are protected by applicable copyright laws. The user can use the content for personal, educational, or non-commercial purposes, provided proper attribution is given and the use does not infringe on the rights of the Bank.
However, the user cannot:
• Copy, reproduce, republish, upload, post, transmit, or distribute any content without prior written permission.
• Use content for commercial purposes.
• Modify or create derivative works based on the content.
Contact Email: ucobank.website@ucobank.co.in
2. Hyper Linking Policy
Purpose and Scope
This Hyperlinking Policy governs the use of hyperlinks to and from the website www.ucobank.com. It applies to all users, organizations, and third parties who wish to link to our website or access external links provided on our platform.
• Links to external websites/portals
The website may contain links to external websites or third-party resources. These links are provided solely for informational and convenience purposes.
• No Control or Responsibility:
Bank do not control the content or availability of external sites and are not responsible for any loss or damage that may arise from your use of such sites.
• No Endorsement:
The inclusion of a link does not imply endorsement or recommendation of the third-party site, its content, or its operators. Users are advised to review the terms and privacy policies of any third-party websites they visit.
• Broken Links:
The Website is scanned fortnightly using the tools ( https://ahrefs.com/broken-link-checker and https://www.drlinkcheck.com/) for any broken links, if any broken links are found, these are removed from the website.
• Links to web application www.ucobank.com by other websites:
Hyperlinks to the website can be used under the following conditions:
• Accuracy and Integrity:
The link must accurately represent the destination and must not be misleading in any way. • Non-Endorsement:
The link must not imply any form of endorsement, approval, or partnership with www.example.com unless explicitly authorized in writing.
• Content Standards:
The linking website must not contain content that is unlawful, defamatory, obscene, offensive, or otherwise inappropriate.
• Technical Compliance:
Links must not use framing techniques or in-line linking that alter the visual presentation or appearance of our website.
We reserve the right to revoke linking permission at any time, without prior notice, and to take appropriate legal action if necessary
3. Privacy Policy
Purpose
This Privacy Policy explains how the data is collected, used, disclosed, and safeguards user’s data when user visits website.
Information collected
Website may collect the following types of information:
• Personal Information:
Name, email address, phone number, and other contact details when voluntarily submitted via forms or registrations.
• Usage Data:
IP address, browser type, operating system, pages visited, time spent on pages, and other analytical data.
• Cookies and Tracking Technologies:
Website uses cookies and similar technologies to enhance user experience and analyse website traffic.
How the Information is used
Website uses the collected information to:
• Provide and maintain our website and services.
• Respond to inquiries and provide customer support.
• Improve website functionality and user experience.
• Comply with legal obligations.
Sharing of Information
Bank do not sell, rent, or trade any personal information to third parties for marketing or other commercial purposes.
Data Security
Bank implements appropriate technical and organizational measures to protect user personal data from unauthorized access, disclosure, alteration, or destruction.
Use of Cookies
To enhance user experience and ensure optimal functionality, Bank’s website utilizes cookies—small text files stored on user’s device when a user access Website. These cookies are generated by the web server and can only be read or retrieved by that server. Cookies help to facilitate smooth navigation across pages. They do not contain personal information and cannot be used to identify individual users.
4. Content Contribution, Moderation & Approval Policy (CMAP)
• Policy Statement for 3-tiered CMAP structure (for large websites)
Policy statement
This policy establishes a three-tiered CMAP (Contribution, Moderation, Approval) framework for website content lifecycle activities to ensure quality, accessibility, security, lifecycle management, and auditability. Scope
The policy applies to all content types on the Bank’s public-facing website, including text, documents, images, audio/video, datasets, UI labels, metadata, downloadable forms, transactional content, and announcements, across all languages and channels.
Definitions
• Contributor:
Initial creation or update proposals of content received from various departments of Bank.
• Moderator:
Review for accuracy, quality, accessibility, security, legal compliance, metadata completeness, and policy alignment prior to publication in Website.
• Approver:
Formal authorization by designated approvers for publication or withdrawal. Objectives
• Check for spelling and grammatical accuracy using automated tools and manual proofreading.
• Review content for offensive, discriminatory, or culturally insensitive language. Any such content must be flagged and returned to the contributor for revision.
• Ensure accuracy of content, current, accessible (as per WCAG norms), secure, and consistent with statutory and organizational mandates, meeting GIGW 3.0’s quality and lifecycle requirements assessed during audit.
• Maintain traceable, time-bound workflows and records enabling audit of backend processes, including conformity matrix mapping.
Content types and classification
• Mandatory content: Organization profile, services, schemes, contact details, RTI, tenders/notifications and policies (Copyright, Privacy, Hyperlinking, Terms of Use, CMAP, CAP, CRP), with defined update cycles per GIGW.
• Sensitive/regulatory content: Legal notices, eligibility/benefit terms, financials, security-related advisories; requires heightened moderation and dual approval per risk level.
• Media and UI content: Images, icons, videos, alt text, transcripts, captions, and language variants; require accessibility conformance and metadata completeness.
5. Content Review Policy (CRP)
Purpose
Every piece of content on the Bank’s Website (www.ucobank.com) must be periodically reviewed to ensure accuracy, relevance, and timeliness. This policy establishes a uniform, systematic framework to maintain content currency and uphold public trust.
Scope
This policy covers all content displayed on the website/portal/application, including (but not limited to):
• Static pages (e.g., About Us, Contact, Organization Structure)
• Dynamic content (e.g., news, press releases, events, circulars)
• Legal/regulatory content (e.g., policies, terms, acts, notifications)
• Media (e.g., images, videos, downloadable forms) • Metadata, hyperlinks, and accessibility aids.
Policy Statement
Bank’s Website (www.ucobank.com) disseminates official product information and services. This CRP is formulated to keep all content current and up-to-date. Review timelines are established for each content type, consistent with its validity, relevance, and archival policy.
Review Framework
• All website content is subject to review based on the content element's classification, defined by relevance, update frequency, and regulatory needs.
• In case of content that becomes obsolete or inaccurate before its scheduled review, it may be flagged for immediate review.
Content Review Timelines
UCO Bank Website Content Review Policy
Review Framework
- All website content is subject to review based on the content element’s classification, defined by relevance, update frequency, and regulatory needs.
- In case of content that becomes obsolete or inaccurate before its scheduled review, it may be flagged for immediate review.
Content Review Timelines
SECTION | REVIEW PERIODICITY |
---|---|
Home Page | Daily |
News, Announcements, Tenders | Daily |
Contact Details | As and when required |
Policies | Annually or upon change |
Schemes, Services, Forms | As and when required |
Circulars, Notifications, Orders | On each new issuance |
Static Information Pages | As and when required |
Archived/Outdated Content | As per Archival Policy |
Responsibilities
- Website Information Manager (WIM) assigns content owners to review contents for each category.
- Content owners initiate scheduled or ad-hoc reviews and share necessary observations or suggestions to improve the available contents.
- Content owners ensure timely completion, escalate overdue items, and certify compliance with GIGW review mandates.
Responsibilities
• The Web Information Manager (WIM) assigns content owners to review contents for each category.
• Content owners initiate scheduled or ad-hoc reviews and share necessary observations or suggestions to improve the available contents.
• Content owners ensure timely completion, escalate overdue items, and certify compliance with GIGW review mandates.
Review Process
1. Reviewers assess each content item for accuracy, validity, accessibility, security, and legal compliance.
2. Content found inaccurate, outdated, or non-compliant is updated, replaced, or archived as per the Content Archival Policy (CAP).
Compliance & Audit • The WIM ensures regular audits of review records and corrective actions.
• Review metrics and exceptions are included in Website Quality Manual submissions during periodic STQC certification and GIGW compliance audits.
6. Content Archival Policy (CAP)
Purpose
The purpose of this Content Archival Policy is to establish guidelines for the systematic archiving of digital content published on www.ucobank.com. This ensures content is preserved for historical reference, legal compliance, and operational continuity.
Scope
This policy applies to all content types hosted on www.ucobank.com, including but not limited to:
- Web pages
- Multimedia (images, videos, audio)
- Documents (Tender/ Notices/ Policies)
Objectives
- Ensure long-term preservation of valuable content
- Maintain accessibility to archived content
- Support legal and regulatory compliance
- Optimize website performance by removing outdated content
Criteria for Archival
Content will be considered for archival based on the following criteria:
- Age of Content: Typically older than 10 years
- Relevance: No longer relevant to current operations or audience
- Regulatory Requirements: Content required to be retained for legal reasons
Archival Process
1. Identification: Content flagged for archival through automated tools or manual review.
2. Review: Content reviewed by the content management team for archival eligibility.
3. Archiving: Eligible content is moved to a secure archival repository.
4. Access: Archived content remains accessible via a dedicated archive section on Website.
Retention Period
Archived content will be retained for a minimum of 10 years, unless otherwise required by law or business needs.
Sr No | Content Element | Entry Policy | Exit Policy |
---|---|---|---|
1. | Tenders / Notices | Date of Publication | As per specified time period |
2. | Banners / Images | Displayed on inception | The image is removed |
3. | FX Rate Card | Daily | Daily |
4. | Rate of Interests | As approved by Board | On updation of relevant circulars |
7. Security Policy
This policy defines the security measures and protocols to protect Bank’s Website www.ucobank.com from unauthorized access, data breaches, and other cyber threats. It ensures the confidentiality, integrity, and availability of the website and its associated services.
Scope
This policy applies to:
• All users accessing www.ucobank.com
• Website administrators and developers
• Third-party service providers
• Hosting and infrastructure partners
Security Objectives
• Protect user data and privacy
• Prevent unauthorized access and data breaches
• Ensure website availability and performance
• Comply with applicable laws and regulations
Access Control
• Role-based access control (RBAC) is enforced.
• Admin access is restricted to authorized personnel only.
• Multi-factor authentication (MFA) is required for administrative accounts.
• WIM shall identify that in which countries the website is required to be accessible keeping in view to mitigate the cyber-attacks and accordingly firewall rules are updated.
Data Protection
• All sensitive data is encrypted in transit (TLS/SSL) and at rest.
• User passwords are hashed using industry-standard algorithms.
• Regular backups are performed and stored securely.
• UCO Bank will not sell, trade, or disclose the personally identifiable information of its website users to any unauthorized third parties.
Application Security
• Regular vulnerability assessments and penetration testing are conducted.
• Secure coding practices are followed (e.g., input validation, output encoding).
• Web Application Firewall (WAF) is deployed to filter malicious traffic.
• The security audit of the Website has been carried out for the known application level vulnerabilities as per CERT-In Guidelines, NIC Guidelines, OWASP standard and other Best Practices and the application security vulnerabilities have been addressed before the launch of the Website.
• The website will be audited by Cert-in empaneled agency periodically. The periodicity shall be one year from the date of issue of certificate or additional changes in the dynamic content carried out whichever is earlier. A periodic check on the requirement of a security certificate is recommended to the web information manager in case there are changes in the functionality or any other environmental changes. Monitoring and Logging
• All access and changes to the website are logged.
• Logs are reviewed regularly for suspicious activity.
• Intrusion detection systems (IDS) are in place.
Incident Response
• A documented incident response plan is maintained.
• Security incidents are reported and investigated promptly.
• Affected users are notified in case of data breaches.
Compliance
• The website complies with relevant data protection laws.
• Regular audits are conducted to ensure policy adherence.
• While reviewing the website if something is found to be inaccurate Bank will make every effort to correct said information as quickly as possible. The information contained on the Bank’s Website is subject to change without prior advance notice.
● Notice and Disclosures
UCO Bank Website will not sell, trade, or disclose the personally identifiable information of its website users to any unauthorized third parties.
● Data Quality and Access
UCO Bank exercises due diligence to ensure the accuracy and reliability of the information published on its official website. All content is reviewed periodically, and any discrepancies identified are addressed promptly. In cases where inaccuracies are detected, corrective actions are initiated without delay to maintain the integrity of the site. If the issue affects the broader system, UCO Bank undertakes immediate remediation to restore seamless functionality and minimize disruption to users.
For security and audit purposes, UCO Bank collects non-personal data such as IP addresses, browser details, and time spent on specific pages. This information is used exclusively to monitor for unauthorized access, detect anomalies, and safeguard the website infrastructure. Any attempt to compromise, extract, or damage data from the UCO Bank website will result in legal action in accordance with applicable laws and cybersecurity protocols.
● Application Security Audit
The UCO Bank website is subject to periodic security audits conducted by agencies empaneled with CERT-In, in accordance with regulatory and cybersecurity standards. These audits are scheduled annually from the date of issuance of the previous security certificate, or earlier if significant changes are made to dynamic content or core functionalities—whichever occurs first.
● Data Security
UCO Bank is committed to ensuring the confidentiality, integrity, and security of customer information across all digital platforms. In alignment with industry best practices and regulatory standards, the Bank has implemented a comprehensive suite of security measures designed to prevent unauthorized access, data loss, theft, or misuse.
These safeguards include multi-layered technical controls, secure authentication protocols, continuous monitoring systems, and periodic vulnerability assessments. All measures are reviewed and updated regularly to address emerging threats and maintain a resilient security posture.
• Website Access Rights
Website is accessible in all countries and necessary firewall rule has been applied in the system. However, Web Information Manager will identify the countries where the website can be accessed or blocked to mitigate the cyber-attacks and accordingly firewall rules are updated.
The access to the Website is provided to the users/ customers for latest information regarding Bank’s products. Bank is allowing its Website to be accessed by people across the country and abroad as well. The access is provided, as the Bank is having pan India presence and also there are NRI customers who are accessing Bank’s services from abroad. However, the access to the Website is revoked at countries, wherever the situations are hostile and there are threats to National Security.