[Newbie] What to I have to worry about in my policies

I need some help.

My company makes online banking software for Canadian (primarily) Credit Unions. Our application basically suffles messages from the user to the banking host and formats the response for the user. We also have apps for their websites which is primarily marketing content but includes forms (loan applications, call back/feedback forms etc) the data for which gets temporarily (in the sense that in theory we purge our database from time to time) stores that data as encrypted data until someone at the credit union accesses the data and uses it. 

Now my question is, does the P3P policy have to express what the website does with the data OR must it reflect the behaviour of the banking host and the credit union. 

Basically I need to know where my responsibilties start and end.

Thanks
Adam




__________________________________________________
D O T E A S Y - "Join the web hosting revolution!"
             http://www.doteasy.com

Received on Wednesday, 13 February 2002 19:48:11 UTC