<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=866287713846251&amp;ev=PageView&amp;noscript=1">

 

Covered Employee Privacy Policy and CA Notice at Collection  

Last Updated: July 15, 2026

We review and update this Policy at least annually and whenever there are material changes to our data practices or applicable law.

Scope of Applicability

FrankCrum and/or our affiliate companies (collectively “FrankCrum,” “Company,” “we,” “our,” or “us”) respect your privacy and are committed to protecting it through our compliance with this Covered Employee Privacy Policy and California Notice at Collection (collectively “Policy”). We have developed this Policy out of respect for the privacy of Covered Employees, their family members, dependents, and beneficiaries, where applicable. This Policy describes the Personal Information (“PI”) we collect, both online and offline (through our “Site(s)” or “Service(s)”), about Covered Employees, for what purposes we use and disclose it, how long we retain it, and whether we sell it or share it for cross-context behavioral advertising purposes. For purposes of this Policy, “Covered Employees” is defined below. Except where California law applies or another law expressly provides employment-context rights, many U.S. state consumer privacy laws exclude or limit personal information processed solely in an employment, benefits, payroll, or business-to-business context. This Policy also incorporates and serves as our California Residents: Notice of Collection and disclosures required under the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (herein referred to as “CCPA”).

This Policy applies only to:

  • “Covered Employee(s)” are defined as client worksite employees who have timely received and accepted all onboarding documents required by FrankCrum and have been accepted by FrankCrum as Covered Employees, including, as applicable, their family members, dependents, beneficiaries, emergency contacts, and other individuals whose information is provided to us for employment-related administration.
  • “Client Employee(s)” are defined as individuals hired, supervised, disciplined, paid, and terminated solely by Client, for whom FrankCrum Administrative Services, Inc. provides administrative services at Client’s direction.

Please refer to the following policies if needed: 


California Residents: Notice at Collection

Collection of Personal Information and Sensitive Personal Information

Based on your interactions, transactions, and use of our website, we collect - and have collected during the preceding 12 months - the following categories of Personal Information ("PI") about Covered Employees. For each category, the chart identifies examples of PI, sources, business purposes, categories of recipients to whom we disclose PI, whether we sell or share PI, and retention criteria. In jurisdictions where required by law, we limit our collection, use, disclosure, and retention of PI to what is reasonably necessary and proportionate for the employment-related purposes disclosed in this Policy or otherwise disclosed to you at the time of collection. The examples provided for each category are not exhaustive and are intended to give you a meaningful understanding of the types of information that may be collected within each category.

Where Covered Employees access Company websites, portals, applications, or systems, we use limited analytics, logging, and security tools solely to operate, secure, debug, maintain, and improve those systems and to understand employment-related system performance and navigation. These tools are configured without advertising features, including disabled ad personalization and remarketing. Analytics data is not sold or shared and is disclosed only to contracted Service Providers for legitimate employment-related business purposes. We do not use these tools to target advertising.  

Categories of Personal Information Collected and Source

Business Purpose

Third parties with whom Personal Information is disclosed, shared or sold

Retention Criteria

Identifiers. e.g. real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol (“IP”) address, email address, Employer name, Social Security number, driver’s license, state identification card number, or passport number if provided by you.

Source: Directly from you, Service Providers, automatically through our Site(s)/Service(s), or Internally within FrankCrum.

  • Administer employment and benefits.
  • Authentication and Session Management.
  • Comply with applicable laws.
  • Conduct workplace investigations.
  • Control and monitor Site access.
  • Debug, identify, and repair errors that impair existing intended functionality of Site.
  • Detect and investigate security incidents. 
  • Manage and process payroll.
  • Manage workers’ compensation claims.
  • Perform human resources management services and support services.
  • Respond to law enforcement, subpoenas, and court orders.
  • Support clients using our services.
  • Verify and respond to consumer requests.  

Disclosed:

  • Affiliated entities.
  • Benefits administrators.
  • Communication Services Providers. 
  • Consulting/Investigation Firm.
  • Consumer Reporting Agencies. 
  • Data Analytics providers.
  • Financial institutions.
  • Government agencies.
  • HRIS.
  • Law enforcement, courts, and attorneys.
  • Your Employer.

Sold or Shared:

  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

 

Retained for so long as necessary to fulfill the purposes stated for this category, for the duration of our relationship, and for any additional period required or permitted by applicable legal, regulatory, contractual, security, fraud prevention, or recordkeeping obligations.  

Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)) ("California Customer Records"). e.g. name, signature, Social Security number, physical characteristics or description, photograph, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, membership in professional organizations, professional licenses and certifications, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information.

Some PI included in this category may overlap with other categories.

Source: Directly by you or Your Employer.

  • Administer employment and benefits.
  • Comply with applicable laws.
  • Control and monitor Site(s) access.
  • Manage and process payroll.
  • Manage workers’ compensation claims.
  • Perform human resources management services and support services.
  • Respond to inquiries.
  • Respond to law enforcement, subpoenas, and court orders.  
  • Verify and respond to consumer requests.

Disclosed:

  • Affiliated entities.
  • Benefits administrators.
  • Communication Services Providers. 
  • Consulting/Investigation Firms.
  • Consumer Reporting Agencies. 
  • Data Analytics providers.
  • Financial institutions.
  • Government agencies.
  • HRIS.
  • Law enforcement, courts, and attorneys.
  • Your Employer.

Sold or Shared:

  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

Retained for so long as necessary to fulfill the purposes stated for this category, for the duration of our relationship, and for any additional period required or permitted by applicable legal, regulatory, contractual, security, fraud prevention, or recordkeeping obligations.

Account Information. e.g. username and password and any required security or access code, password, or credentials allowing access to your account.

Source: Directly from you or Internally within FrankCrum.

  • Authentication and Session Management.
  • Control and monitor Site(s) access.
  • Detect and investigate security incidents.
  • Respond to law enforcement, subpoenas, and court orders.

Disclosed:

  • Affiliated entities.
  • IT, cybersecurity, and risk vendors.
  • Law enforcement, courts, and attorneys.

Sold or Shared:

  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

Retained until completion of the purposes stated for this category, plus any applicable legal, regulatory, or contractual retention period.  

Protected classification characteristics under California or federal law ("Protected Classes"). e.g. age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, reproductive health decision-making, military and veteran status, or genetic information (including familial genetic information).

Source: Directly from you.

  • Administer employment and benefits.
  • Comply with applicable laws.
  • Perform human resources management services and support services.
  • Respond to law enforcement, subpoenas, and court orders.

 

Disclosed:

  • Affiliated entities.
  • Benefits administrators.
  • Government agencies.
  • HRIS.
  • Law enforcement, courts, and attorneys.
  • Your Employer.

Sold or Shared:

  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

Retained only for as long as necessary to comply with federal and state equal employment opportunity laws and reporting requirements.

Commercial Information. e.g. benefit elections, plan selections, and client account history.

Source: Directly from you, Service Providers, internally within FrankCrum, or Your Employer. 

  • Administer employment and benefits.
  • Respond to inquiries. 
  • Respond to law enforcement, subpoenas, and court orders.

Disclosed: 

  • Affiliated entities.
  • Benefits administrators.
  • HRIS.
  • Law enforcement, courts, and attorneys.
  • Your Employer.

Sold or Shared:

  • Not sold for monetary or other valuable consideration.
  • Not shared for cross-context behavioral advertising.

Retained for the life of the account and for a reasonable period thereafter to comply with security and legal obligations.   

 

Internet or other similar network activity. e.g. date and time of your visit to this website; webpages visited; links clicked on the website; session identifiers; browser ID; browser type and characteristics; device ID and characteristics or attributes; referring URLs; mobile phone make, model and serial number; mobile service provider; operating system; form information downloaded; domain name from which our site was accessed; search history; interaction-level telemetry; cookies; and internet or other electronic network activity information related to usage of FrankCrum networks, servers, intranet, or shared drives, as well as FrankCrum-owned computers and electronic devices, including system and file access logs, security clearance level, browsing history, search history, and usage history.

Source: Automatically through our Site(s).

  • Control and monitor Site(s) access.
  • Debug, identify, and repair errors that impair existing intended functionality of MFC. 
  • Detect and investigate security incidents.
  • Operate, secure, and improve Site(s).
  • Provide limited internal analytics to improve navigation/performance.
  • Respond to inquiries. 
  • Respond to law enforcement, subpoenas, and court orders.

Disclosed: 

  • Affiliated entities.
  • Communication Services Providers. 
  • Data Analytics providers.
  • Government agencies.
  • Investigator/Auditor.
  • IT, cybersecurity, and risk vendors.
  • Law enforcement, courts, and attorneys.

Sold or Shared:

  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

Retained only as necessary for security (e.g., logs), debugging, analytics controls, and complying with legal obligations.

 

Geolocation data. e.g. physical location or movements, such as your zip code, the time and physical location related to use of our internet website or mobile application, or other information about your location or locations you visited. IP addresses are mapped to inferred geographic attributes.

Source: Automatically through our Site(s).

  • Control and monitor Site(s) access.
  • Debug, identify, and repair errors that impair existing intended functionality. 
  • Detect and investigate security incidents.
  • Operate, secure, and improve Site(s).
  • Protect individuals or property.
  • Provide limited internal analytics to improve navigation/performance.
  • Respond to law enforcement, subpoenas, and court orders.

 

Disclosed: 

  • Affiliated entities.
  • Communication Service Providers.
  • Data Analytics providers.
  • IT, cybersecurity, and risk vendors.
  • Law enforcement, courts, and attorneys.

Sold or Shared:

  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

 Retained only as necessary for security (e.g., logs), debugging, and analytics controls.  

 

Sensory data. e.g.  your image when recorded or captured in surveillance camera footage or pictures of you taken on our premises or that you share with us; audio recordings of calls and virtual meetings as disclosed to you at the time of the call.

Source: Via Physical Locations, Service Providers, or Your Employer.

  • Comply with applicable laws.
  • Conduct workplace investigations.
  • Detect and investigate security incidents.
  • Protect individuals or property.
  • Respond to law enforcement, subpoenas, and court orders.

 

Disclosed:

  • Affiliated entities.
  • Communication Services Providers. 
  • IT, cybersecurity, and risk vendors.
  • Law enforcement, courts, and attorneys.
  • Your Employer.

Sold or Shared: 

  • Not sold for monetary or other valuable consideration 
  • Not shared for cross-context behavioral advertising. 

Security/call recordings are kept only as necessary for security, quality assurance, investigations, and compliance.   

Professional or employment-related information. e.g. new hire or onboarding records, tax forms, current or past job history or performance evaluations, such as employment application information (work history, academic and professional qualifications, educational records, references, and interview notes, background check, drug testing results, work authorization, performance and disciplinary records, salary, bonus, commission, and other similar compensation data, benefit plan enrollment, participation, and claims information, time and attendance records, non-medical leave of absence records, leave of absence information including religious, military and family obligations, health data concerning Covered Employees and their family members).

Source: Directly from you, Service Providers, or Your Employer.

  • Comply with applicable laws.
  • Conduct permissible background, education, and employment checks.
  • Manage workers’ compensation claims.
  • Perform human resources management services and support services.
  • Respond to law enforcement, subpoenas, and court orders.

 

Disclosed:

  • Affiliated entities.
  • Benefits administrators and vendors.
  • Communication Services Providers. 
  • Consumer Reporting Agencies. 
  • Consulting/Investigation Firms.
  • Financial institutions.
  • Government agencies.
  • HRIS.
  • Law enforcement, courts, and attorneys.
  • Your Employer.

Sold or Shared:

  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

Retained per contractual and legal requirements and only as long as necessary to evaluate eligibility and maintain required employment records.  

Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99) ("FERPA Information")).

Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.

Source: N/A

Not Collected

N/A

N/A

Financial Information. e.g. bank account number for direct deposit, routing number, and other financial account information.

Source: Directly from you.

  • Comply with applicable laws.
  • Direct Deposit.
  • Manage and process payroll.
  • Respond to law enforcement, subpoenas, and court orders.

 

Disclosed:

  • Affiliated entities.
  • Financial institutions.
  • Transactional support vendors.
  • HRIS.
  • Law enforcement, courts, and attorneys.
  • Your Employer.

Sold or Shared:

  • Not sold for monetary or other valuable considerations.
  • Not shared for cross-context behavioral advertising. 

Retained only for as long as necessary to fulfill payroll, benefits administration, accounting, and legal compliance purposes.  

Physical Characteristics or Description. e.g. information on your Driver’s License (such as eye color, hair color, height, weight), as well as information collected to the extent relevant for workplace investigations or for enforcement of Company policies on appearance and grooming (such as tattoos, piercings).

Source: Directly from you.

  • Comply with applicable laws.
  • Conduct workplace investigations.
  • Respond to law enforcement, subpoenas, and court orders.

Disclosed:

  • Affiliated entities.
  • Benefits administrators.
  • Consulting/Investigation Firms.
  • Government agencies.
  • HRIS.
  • Law enforcement, courts, and attorneys.
  • Your Employer.

Sold or Shared:

  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

Retained only for as long as necessary to comply with applicable laws and for workplace investigation needs, including any required retention under legal hold.  

 

Family Information. e.g. contact information for family members listed as emergency contacts if provided to FrankCrum. Contact information for dependents and other dependent information if provided to FrankCrum.

Source: Directly from you or Your Employer.

  • Communicate with emergency contacts and dependents where appropriate.
  • Respond to law enforcement, subpoenas, and court orders.

Disclosed:

  • Affiliated entities.
  • Benefits administrators.
  • Communication Services Providers. 
  • Government Agencies.
  • HRIS.
  • Law enforcement, courts, and attorneys.
  • Your Employer.

Sold or Shared:

  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

Retained until completion of the purposes stated for this category, plus any applicable legal, regulatory, or contractual retention period.  

 

Medical and Health Information. e.g. medical information contained in such documents as doctor’s notes for absences or work restrictions, medical leave of absence records, requests for accommodation, interactive process records, ergonomic assessments and accommodation records, and correspondence with you and your medical or mental health provider(s) regarding any request for accommodation or medical leave of absence, as well as information in post-hire drug test results. This includes medical information and health benefits information for dependents and beneficiaries.

Source: Directly from you, Service Providers, or Your Employer.

  • Administer employment and benefits.
  • Comply with applicable laws.
  • Manage workers’ compensation claims.
  • Perform human resources management services and support services.
  • Respond to law enforcement, subpoenas, and court orders.

 

Disclosed:

  • Affiliated entities.
  • Benefits administrators.
  • Communication Services Providers. 
  • Government agencies.
  • HRIS
  • Law enforcement, courts, and attorneys.
  • Your Employer.

Sold or Shared:

  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising.

 Retained for as long as necessary to administer benefits, leaves, accommodations, and workers’ compensation, plus applicable legal or regulatory retention periods.  

 

Travel and Expenses Information. e.g. business travel or work-related expenses.

Source: Directly from you or Your Employer.

  • Arrange and manage business travel.
  • Reimbursement for company expenses.
  • Perform human resources management services and support services.
  • Reimbursement for company expenses.

Disclosed:

  • Affiliated entities.
  • Communication Services Providers. 
  • Government Agencies.
  • HRIS.
  • Your Employer.

Sold or Shared:

  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

Retained only for as long as reasonably necessary to administer business travel, process reimbursements, maintain accurate financial records, and satisfy legal, tax, and audit requirements.

Biometric Data. e.g., biological characteristics or activity patterns used to extract a template or other identifier or identifying information, such as fingerprints or palm/hand geometry.

Please Note: Only if UKG biometric time clocks are utilized by Client and consented to by Covered Employee. 

Where biometric timekeeping is used, collection and use must be supported by any legally required written notice, written consent or release, vendor/client-specific biometric policy, retention schedule, and destruction procedure, including requirements that may apply under state biometric privacy laws.

Source: Employer’s timekeeping system.

 Administer timekeeping, attendance, payroll, scheduling, workforce administration, compliance, and related employment-administration services using non-biometric timekeeping outputs.  

Disclosed:

  • Timekeeping vendor if used by client.

Sold or Shared:

  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

FrankCrum does not retain biometric templates or biometric identifiers for its own purposes. Non-biometric timekeeping outputs are retained only as necessary for payroll, timekeeping, attendance, wage-and-hour compliance, tax, benefits, workers’ compensation, litigation holds, audits, and other legal, regulatory, contractual, security, or recordkeeping obligations. If biometric information is stored on a client selected time clock or vendor system, please refer to the Client-specific and/or vendor specific biometric policy.  

Inferences drawn from other information. e.g. profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.  

Source: Automatically through our Site(s).

  •  Engage in human capital analytics. 

Disclosed:

  • Data analytics providers.
  • Transactional providers.

Sold or Shared:

  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

 Retained only while necessary to support the documented purpose for which the inference was created.

 

 

What Sensitive Personal Information We Collect

Of the above categories of Personal Information, the following are categories of Sensitive Personal Information we collect from or about Covered Employees:

  • Identifiers (SSN, driver's license, state ID, passport)
  • California Customer Records (financial, health, and government ID data)
  • Account Information (login credentials)
  • Protected Classes (race, ethnicity, religion, citizenship, sexual orientation, genetic data, etc.)
  • Geolocation Data (if precise)
  • Professional/Employment Information (to the extent it includes health, religious, immigration, or drug-testing information)
  • Financial Information
  • Medical and Health Information

Personal Information does not include:

  • Publicly available information from government records. 
  • Information that a business has a reasonable basis to believe is lawfully made available to the public by the Covered Employee or from widely distributed media.  
  • Information made available by a person to whom the Covered Employee has disclosed the information if the Covered Employee has not restricted the information to a specific audience.  
  • De-identified or aggregated information. 

Sensitive Personal Information Categories Chart 

 Sensitive Personal Information (“SPI”) is a subtype of PI consisting of the specific information categories listed in the chart below. FrankCrum does not use or disclose SPI for purposes that would require a “Limit the Use of My Sensitive Personal Information” link under the CCPA. We use SPI only for employment-related, compliance, security, safety, benefits, payroll, accommodation, and other purposes permitted by law, and not to infer characteristics about Covered Employees unless expressly disclosed and permitted by applicable law. Of the above categories of PI, the following are categories of SPI FrankCrum collects from or about Covered Employees: 

Sensitive Personal Information Category 

Collected to Infer Characteristics? 

Retention Criteria 

Government identifiers. e.g. as your Social Security number (SSN), driver's license, state identification card, or passport number

No 

N/A 

Complete account access. Credentials. e.g. usernames, account logins, account numbers, or card numbers combined with required access/security code or password.

No

N/A

Precise geolocation. e.g. GPS data from an Employee’s mobile device that can provide its location in a geographic area, with an approximate radius of 1,850 feet. 

No 

N/A 

Racial or ethnic origin. 

No 

N/A 

Citizenship or immigration status. 

No 

N/A 

Religious or philosophical beliefs. 

No 

N/A 

Union membership. 

No 

N/A 

Mail, email, or text messages not directed to the Company. 

No 

N/A 

Genetic data. 

No 

N/A 

Neural Data. e.g. information generated by measuring an Employee’s central or peripheral nervous system's activity that is not inferred from nonneural information.

No 

N/A 

Unique identifying biometric information. 

No 

N/A 

Health information. 

No 

N/A 

Sex life or sexual orientation information. 

No 

N/A 

Children's Personal Information (under age 16). 

No 

N/A 

 

Categories of Sensitive Personal Information Collected or Processed

We process SPI only for the limited purposes permitted under CCPA: 

  • Administering employment, payroll, benefits, tax, accommodation, leave, workplace safety, security, investigations, and other employment-related operations.
  • Performing actions that are necessary for our employment relationship and that an average Covered Employee in an employment relationship with us would reasonably expect, including for many of the purposes listed.
  • To detect security incidents that compromise the availability, authenticity, integrity, and confidentiality of stored or transmitted PI.  
  • To resist malicious, deceptive, fraudulent, or illegal actions directed at the business and to prosecute those responsible for those actions.  
  • To ensure the physical safety of natural people.  
  • Short-term, transient use that is necessary for employment-related system functionality, security, authentication, or display of non-advertising Company content, if we do not:
    • disclose SPI to another third party for advertising or profiling purposes; or
    • use it to build a profile about the Covered Employee or otherwise alter the Covered Employee's experience outside the employment relationship with the Company.
  • Services performed for the Company, including maintaining or servicing accounts, providing human resources and Covered Employee benefits administration, processing or fulfilling transactions, verifying Covered Employee information, processing payments, providing financing, analytic services, storage, or similar services for the Company.
  • Collecting or processing SPI, not for the purpose of inferring characteristics about a Covered Employee.

California Residents: Your Rights Under CCPA 

If you are a California resident, the CCPA may provide you with the following rights regarding personal information we collect, use, disclose, and retain about you in the employment context, subject to applicable exceptions and limitations. These rights do not override legal, regulatory, payroll, tax, benefits, litigation-hold, security, workers’ compensation, occupational health and safety, or employment-record retention obligations.

  • Right to Know and Data Portability Requests. You have the right to request that we disclose certain information to you about our collection and use of your PI (the "right to know"), including the specific pieces of PI we have collected about you (a "data portability request"). Our response will cover the 12-month period preceding the request, although we will honor requests to cover longer periods that do not extend past January 1, 2022, unless doing so would be impossible or involves disproportionate effort. You may exercise your right to know twice in any 12-month period. Once we receive your request and confirm your identity see Section: How to Exercise Your Rights, we will disclose it to you: 
    • The categories of: 
      • PI we collected about you; and 
      • sources from which we collected your PI. 
    • The business or commercial purpose for collecting your PI and, if applicable, selling or sharing your PI. 
    • If applicable, the categories of persons, including third parties, to whom we disclosed your PI, including separate disclosures identifying the categories of your PI that we: 
      • disclosed for a business purpose to each category of persons; and 
      • sold or shared to each category of third parties. 
    • When your right to know submission includes a data portability request, a copy of your PI, subject to any permitted redactions. 
  • Right to Delete and Right to Correct. You have the right to request that we delete any of your PI that we collected from you and retained, subject to certain exceptions and limitations (the "right to delete"). Once we receive your request and confirm your identity, we will delete your PI from our systems unless an exception allows us to retain it. We will also notify our Service Providers, contractors, and other recipients to take appropriate action. You also have the right to request correction of PI we maintain about you that you believe is inaccurate (the "right to correct"). We may require you to provide documentation, if needed, to confirm your identity and support your claim that the information is inaccurate. Unless an exception applies, we will correct PI that our review determines is inaccurate and notify our Service Providers to take appropriate action. 
  • Right to Limit Sensitive Personal Information Use and Notice of Rights to Limit the Use of Your Sensitive Personal Information. You have a right to ask businesses that use or disclose your SPI to limit those actions to just the CCPA's Permitted SPI Purposes listed above (the "right to limit"). We do not use or disclose your SPI for purposes that give rise to a right to “Limit the Use of Your Sensitive Personal Information” under CCPA. Because we do not use SPI for purposes that trigger the right to limit under CCPA, a “Limit the Use of My Sensitive Personal Information” link is not applicable currently. If our practices change, we will provide that link and update this Policy. 
  • Personal Information Sales or Sharing Opt-Out and Opt-In Rights. We do not sell or share Covered Employee PI for cross-context behavioral advertising, as defined under CCPA. Because we do not engage in the sale or sharing of Covered Employee PI, Covered Employees do not need to submit opt-out requests, and user-enabled opt-out preference signals (such as Global Privacy Control or cookie-based signals) are not applicable in the employment context. The CCPA also includes restrictions on the sale or share of PI of individuals under the age of 16. As we do not sell or share Covered Employee PI these opt-in requirements do not apply. If our practices change, we will provide advance notice and any rights required under applicable law.
  • ADMT and Profiling. We do not use automated decision-making technology or profiling for decisions that have legal or similarly significant effects on Covered Employees.
  • Right to non-discrimination. You have the right not to be discriminated against or retaliated against for exercising any of your privacy rights under the CCPA. 
  • The right to designate an authorized agent to submit one of the above requests on your behalf. See below how you can designate an authorized agent within Section: Verification Process and Authorized Agents.

Responding to Your Requests to Know, Delete, or Correct 

We will confirm receipt of your request within ten business days. If you do not receive confirmation within the ten-day timeframe, please reach out to privacy@frankcrum.com. We endeavor to substantively respond to a verifiable request within 45 days of its receipt. If we require more time (up to another 45 days), we will inform you of the reason and extension period in writing. We will deliver our written response to your verified email address. Our substantive response will tell you whether we have complied with your request. If we cannot comply with your request in whole or in part, we will explain the reason, subject to any legal or regulatory restrictions. Applicable law may allow or require us to refuse to provide you with access to some or all the PI that we hold about you, or we may have destroyed, deleted, or made your PI anonymous in compliance with our record retention policies and obligations.

Any disclosures we provide will cover information for the 12-month period preceding the request receipt date. We will consider requests to provide longer disclosure periods that do not extend past January 1, 2022, unless providing a longer timeframe would be impossible or involves disproportionate effort. 

For data portability requests, we will select a format to provide your PI that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance. 

We do not charge a fee to process or respond to your verifiable request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.


Notice of Right to Opt-Out of the Selling and Sharing of Your Information  

 We do not sell personal information for monetary or other valuable consideration, and we do not share personal information for cross-context behavioral advertising. As a result, we do not currently engage in practices that would require a “Do Not Sell or Share My Personal Information” link for this Site. Where required by applicable law, consumers may still submit privacy requests using the methods described in this Policy. If our practices change in a way that constitutes a sale or sharing under applicable law, we will update this Policy and provide any required opt-out tools and disclosures. You may contact us using the request methods listed in this Policy if you have questions about our practices or wish to exercise any privacy rights available to you under applicable law.  

Verification Process and Authorized Agents 

If you are a California resident, you can authorize someone else as an authorized agent who can submit a request on your behalf. To do so, you must either:  

  • execute a valid, verifiable, and notarized power of attorney; or    
  • provide other written, signed authorizations that we can then verify. When we receive a request submitted on your behalf by an authorized agent who does not have a power of attorney, that person will be asked to provide written proof that they have your permission to act on your behalf, and we will also contact you and ask you for information to verify your own identity directly with us and not through your authorized agent. We may deny a request from an authorized agent if the agent does not provide your signed permission demonstrating that you have authorized them to act on your behalf.

Notice of Right to Opt-Out of Profiling, Automated Decision Making, and Targeted Advertising

We do not use PI for targeted advertising, and we do not engage in profiling for decisions that have legal or similarly significant effects on you as a Covered Employee. We also do not use automated decision-making to make such significant decisions about Covered Employees. Where required by applicable law, Covered Employees may contact us using the request methods described in this Policy to inquire about rights that may apply to their PI. If our practices change, we will update this Policy and provide any required notices, rights, or opt-out mechanisms.

If FrankCrum begins using automated decision-making technology, profiling, AI-enabled tools, productivity analytics, or similar technologies to make or substantially assist decisions that produce legal or similarly significant effects concerning Covered Employees, FrankCrum will provide any legally required pre-use notice, access rights, opt-out rights, appeal or human-review rights, and risk-assessment disclosures before or at the time required by applicable law. 

Response and Timing for Privacy Requests

We will process privacy requests in accordance with applicable law and within the timeframes required by the laws that apply to your request. We may take steps to verify your identity and authority before fulfilling certain requests, and we may request additional information where necessary to do so. Where permitted or required by law, we may deny a request in whole or in part, including where an exemption applies or where we are unable to verify the request. If we deny your request, we will explain the basis for the denial to the extent permitted by law. Where applicable law provides an appeal right, we will describe how to appeal a denial in our response.

Please Note: Privacy requests submitted by Covered Employees will be assessed in accordance with applicable law, the nature of the information involved, and the employment relationship. Certain rights described in this Policy may not apply to all Covered Employees or to all categories of employment-related PI.

How to Exercise Your Rights

To exercise your rights described above, please submit a verifiable request to us by either: 

Notice Regarding Sale, Sharing, and Opt-Out Preference Signals

We do not sell Covered Employee PI for monetary or other valuable consideration, and we do not share Employee PI for cross-context behavioral advertising. As a result, we do not currently engage in practices that would require a “Do Not Sell or Share My Personal Information” link for Covered Employee PI. If a California opt-out preference signal or similar signal is received in connection with Company-controlled employment-related resources, we will evaluate and honor it to the extent required by applicable law, but such signals generally are not applicable where no sale or sharing occurs. Where required by applicable law, Covered Employees may still submit privacy requests using the methods described in this Policy. If our practices change in a way that constitutes a sale or sharing under applicable law, we will update this Policy and provide any required opt-out tools and disclosures.

Sources of Personal Information

We collect your Personal Information from the following sources: 

  • Affiliated entities.
  • Automatically through our Site(s) or utilize Service(s) (e.g. session, security logs, and limited internal analytics).
  • Company systems, networks, software applications, and databases you log into or use while performing your job, including vendors the Company engages in managing or hosting such systems, networks, applications or databases.
  • Directly from you, the Covered Employee, when you voluntarily submit information for employment purposes.
  • Internally within FrankCrum (e.g. other Employees, performance reviews, testing, or other observations, surveys, and interactions).
  • Human Resources Information System (“HRIS”) (e.g. Employee tracking and talent management systems).
  • Personal references and former employers.
  • Service providers (e.g. benefits administrators, consumer reporting agencies for background checks, IT/security vendors).
  • Via physical locations (e.g. call recordings, badge logs, and video surveillance). 
  • Your Employer.

To Whom We Disclose Personal Information 

We disclose PI only to the categories of recipients listed below for business and commercial purposes:

  • Affiliated entities.
  • Benefits administrators and vendors (e.g. third-party administrators, 401K administrators, workers' compensation, unemployment administrators, insurance brokers, and wellness vendors).
  • Buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all FrankCrum’s assets. 
  • Communication Services Providers that facilitate, manage, and send/receive communications on our behalf (e.g. email, text/SMS, phone, or record, transcribe, summarize, or process phone calls and video meetings).
  • Consulting and investigation firms (e.g. HR consultants, safety consultants, and workplace investigators).
  • Consumer reporting agencies, background-check providers, or similar recipients only where permitted by law and subject to applicable authorization, disclosure, certification, and adverse-action requirements.
  • Data analytics service providers (internal analytics only; no ads/cross context tracking).
  • Financial institutions.
  • Government or public agencies (as required by law).
  • Human Resources Information System (“HRIS”) (e.g. Employee tracking and talent management systems).
  • Insurance carriers, administrators, and brokers.
  • IT, cybersecurity, and risk vendors. 
  • Law enforcement, courts, and attorneys.
  • Transactional support vendors.  
  • Your Employer.

 We contractually require service providers, contractors, and other recipients that process personal information on our behalf to keep it confidential and use it only for the limited purposes for which we disclose it to them, unless otherwise permitted or required by law.

Reasons Why We Collect, Use, Retain, and Disclose Personal Information

We may collect, use, and disclose your PI for any of the following business purposes:

  • Communicate with you, including responding to inquiries and providing notices, updates, alerts, and operational or servicerelated information.
  • Conduct limited internal analytics and organizational planning, including analyzing aggregated or de-identified data to improve Company systems, security, workforce administration, and service delivery.
  • Engage in business operations, including:
    • Evaluating and managing relationships with vendors, service providers, and contractors.
    • Fulfilling or meeting the purpose for which information was provided.
    • Participating in corporate transactions requiring review or disclosure of Covered Employee related information (e.g., mergers, acquisitions), subject to confidentiality obligations.
  • Ensure the security of our facilities, systems, and workforce, including:
    • Controlling and monitoring access to Company facilities and information systems.
    • Implementing and managing electronic security measures and activity logging.
    • Detecting, investigating, and responding to potential security incidents or unauthorized access.
    • Preventing identity theft, fraud, malicious, or illegal activity, and prosecuting those responsible.
    • Conducting workplace investigations related to safety, security, or misconduct.
  • Provide Human Resources with best practices, consulting services to your Employer including the following topics:
    • Administering employment, payroll, compensation, and benefits.
    • Supporting hiring, onboarding, job placement, and internal job changes for your employer.
    • Managing performance, goals, training, development, discipline, and termination processes for your employer.
    • Maintaining personnel files and complying with record retention requirements.
    • Reaching you, your emergency contacts, or beneficiaries when needed.
    • Administering timekeeping, attendance, scheduling, and expense reimbursements.
    • Managing workers’ compensation, disability, and workplace accident or injury claims.
    • Communicating with you about employment related matters such as benefits enrollment deadlines, required actions, and availability of tax documents.

Use of Cookies, Pixels, and Other Tracking Technologies 

Our Site collects or store information on your browser or device, primarily in the form of cookies. Cookies are small text files that a website places on your device to help the website function properly and to understand how users interact with the site. Cookies set directly by our Site(s) are referred to as “first party cookies.” We use first-party cookies and similar technologies to support the core functionality of the website and to improve its performance. For example, these technologies help us:

  • Understand how users interact with our Site(s)
  • Analyze which content is most frequently viewed
  • Enable efficient navigation between pages
  • Remember user preferences or login state
  • Identify and resolve our Site(s) performance issues

We also use limited third-party analytics tools that collect information on our behalf to help us measure website usage and improve functionality. These analytics technologies are used solely for internal measurement and performance analysis and are not used for targeted advertising, cross context behavioral advertising, or profiling. You may manage cookie preferences through your browser settings. Please note that disabling certain cookies may affect the functionality and performance of our Site(s).

Essential Cookies

Essential cookies and similar technologies are necessary for Company websites, portals, applications, and systems to function properly and securely. They are usually set in response to actions such as logging in, maintaining a session, setting privacy or accessibility preferences, completing employment-related forms, or accessing secure content. You can set your browser to block or alert you about these cookies, but blocking them may prevent the relevant Company website, portal, application, or system from working correctly.

Non-Essential Cookies

Non-essential cookies are not necessary for core website functionality but support limited internal analytics, performance measurement, preferences, or similar non-advertising purposes:

  • "Performance" cookies (sometimes referred to as analytics cookies) collect information about how visitors interact with our website. These cookies collect online identifiers such as IP address or device information, which are used in aggregated or anonymized form to improve website performance, such as pages visited, clicked links, and general traffic patterns. For Example:
    • Pages visited.
    • Links clicked within the website.
    • General traffic patterns.
    • Traffic sources.
  • "Functional" cookies (sometimes called preference cookies) enable enhanced functionality and personalization, such as remembering your preferences and past choices on the website through secure authentication tokens.
    • Encrypted login session identifiers (not passwords).
    • Masked or tokenized user identifiers.
    • Language or regional preferences.
    • Saved display or accessibility settings.

Because we do not sell or share Covered Employee PI and do not use targeted advertising, advertising opt-out tools and universal opt-out preference signals are not currently applicable to our Site in the employment context. We honor browser- or device-level cookie settings to the extent they affect cookies on the user’s browser or device.

Cookie Management 

You can control and manage cookies through your browser settings. If you are interested in controlling and managing cookies from your browser, including any cookies set by our Site(s), please refer to http://www.allaboutcookies.org/manage-cookies/index.html for information on different ways to configure your browser’s cookie settings.

You may delete or block cookies through your browser settings at any time but doing so may affect the functionality or availability of certain Company websites, portals, applications, or systems. Some features may not be available if cookies are disabled. The following browser guides may be helpful:

Global Privacy Control

The Company does not sell or share Covered Employee PI for cross-context behavioral advertising. Accordingly, Global Privacy Control (GPC) signals and similar opt-out preference signals are not applicable to the Company's processing of Covered Employee PI.

Do Not Track Signals

Do Not Track (“DNT”) is a browser-based privacy preference that allows individuals to indicate a preference not to have information about their online activities collected across websites and online services. The Company does not respond to DNT signals. Because the Company does not sell Covered Employee PI or share Covered Employee PI for cross-context behavioral advertising, DNT, Global Privacy Control (“GPC”), and similar opt-out preference signals generally are not applicable to the Company's processing of Covered Employee PI in the employment context.

U.S. Consumer Privacy Rights 

Depending on your state of residence, the nature of your relationship with the Company, and the type of PI involved, you may have certain rights under applicable U.S. privacy laws, subject to applicable exceptions and limitations. Many state privacy laws do not apply, or apply only in a limited manner, to PI collected and used solely in the employment context. Accordingly, Covered Employees may have limited privacy rights with respect to their employment-related PI, except to the extent otherwise provided by applicable law.

  • Access and Confirmation. You may have the right to confirm whether we process your PI and to access a copy of the PI we maintain about you, subject to applicable legal exceptions.
  • Data Portability.  You may confirm whether we process your PI and access a copy of the PI we process. To the extent feasible and required by state law, depending on your state, data will be provided in a portable format. Depending on your state, you may have the right to receive additional information, and it will be included in the response to your access request. 
  • Correction. You may request that we correct inaccuracies in your PI that we maintain, considering the information's nature and purpose of processing. 
  • Deletion. You may have the right to request that we delete PI we maintain about you, subject to applicable exceptions, including where retention is required or permitted for employment administration, payroll, benefits, tax, security, compliance, or recordkeeping purposes.
  • Opt-out of Certain Processing (Where Applicable). In limited circumstances and only where required by applicable state law, you may have the right to opt out of certain types of PI processing, such as targeted advertising, the sale of PI, or profiling in furtherance of decisions that produce legal or similarly significant effects. FrankCrum does not sell PI for monetary or other valuable considerations or share for cross-context behavioral advertising.
  • Appeal. Appeal our decision regarding your privacy rights request (where required by law). Unless otherwise required by state law, your appeal rights apply to any denied request, and we will provide a written outcome within the period required by your state of residence. If we deny your request, you may appeal by emailing privacy@frankcrum.com with the subject line Privacy Rights Appeal. 

Important: The scope of these rights varies by state and may not apply in all circumstances. Certain PI may be exempt from state privacy laws, including information collected, processed, disclosed, or retained pursuant to applicable federal or state financial privacy laws, insurance laws, or related regulations, as well as information processed solely in the employment, job applicant, benefits administration, or business-to-business context where an applicable law provides an exemption.

To exercise your rights, please submit a verifiable request to us by either:

  • Visiting Your Privacy Choices
  • Call our privacy toll-free line at 1-800-393-0815, Option 21.  
  • Email privacy@frankcrum.com
  • Mailing Address: Attn: Privacy Team 100 S. Missouri Ave. Clearwater, FL 33756 

How We Retain Your Personal Information 

 We maintain retention schedules aligned to legal, regulatory, tax, and contractual requirements and delete or de-identify data when no longer needed. We keep the categories of PI described in this Policy for as long as reasonably necessary to fulfill the purposes described or for as otherwise legally permitted or required, such as maintaining the Services, operating our organization, complying with our legal obligations, resolving disputes, and for safety, security, and fraud prevention. This means that we consider our legal and business obligations, potential risks of harm, and nature of the information when deciding how long to retain PI. At the end of the retention period, PI will be deleted, destroyed, or deidentified. We align retention to data minimization and reasonable expectations for each purpose, and we honor opt-outs for at least 12 months before seeking reauthorization.

Data Minimization 

 We limit our collection, use, and retention of personal information to what is reasonably necessary and proportionate for the purposes described in this Policy.

External Links 

 Our website contains links to other websites. We are not responsible for the privacy practices or the content of such websites. To help ensure the protection of your privacy, we recommend that you review the Policy of any website you visit via a link from our website.  If you access our website through a mobile device, your device or browser may prompt you to grant permission for features such as location, push notifications, or camera access. You can revoke these permissions at any time through your device settings.

Passwords  

Each Covered Employee personal information record is accessible only using unique login credentials. Covered Employees are responsible for safeguarding the confidentiality of their usernames, passwords, and other access credentials and must not disclose such credentials to third parties or unauthorized individuals. Maintaining the security of these credentials is essential to protecting the confidentiality, integrity, and security of the personal information contained in the record.

Automated Decision-making, Profiling, and AI 

We do not use automated decision-making systems, including machine learning or AI tools to make decisions that produce legal or similarly significant effects on you as a Covered Employee. This includes decisions relating to eligibility for, or access to, credit, employment, housing, financial services, essential or federally regulated services, or other outcomes that could meaningfully affect your rights or opportunities.If any automated output could influence how we present content or offer to you on the website, those outputs operate within predefined parameters and are either reviewed or overseen by people or constrained, so they do not produce legal or similarly significant effects. 

We do not engage in profiling in furtherance of decisions that produce legal or similarly significant effects. If we ever begin using profiling in a way that implies additional rights (for example, under the laws of states that provide opt-out rights for certain profiling), we will update this Policy and provide any required opt-out mechanisms. 

If we materially change how we use automated decision-making, profiling, or AI - including if future law requires additional disclosures, access, appeal, or opt-out rights for such processing - we will update this Policy and provide any required tools, disclosures, and instructions at or before the time those changes take effect. 

Compliance With Law and Safety 

We disclose specific personal and/or SPI based on a good faith belief that such disclosure is necessary to comply with or conform to the law or that such disclosure is necessary to protect our Employees or the public.

How We Protect Your Personal Information 

 We use commercially reasonable administrative, physical, and technical measures designed to protect your PI from accidental loss or destruction and from unauthorized access, use, alteration, and disclosure. However, no website, mobile application, system, electronic storage, or online service is completely secure, and we cannot guarantee the security of your PI transmitted to, through use, or in connection with the Services. Email, texts, and chats sent to or from the Services may not be secure, and you should carefully decide what information you send to us via such communications channels. Any transmission of PI is at your own risk. The safety and security of your information also depend on you. You are responsible for taking steps to protect your PI against unauthorized use, disclosure, and access.

Children's and Minors' Data 

We do not knowingly sell or share the PI of Covered Employees under the age of 16. This Policy is not intended for children under 16, except that we collect limited information about dependents, beneficiaries, or emergency contacts when provided by a Covered Employee for benefits administration, emergency-contact, tax, payroll, or similar employment-related purposes. If you are under 16, do not use or provide any information on this website or through its features, create an account, or provide any information about yourself, including your name, address, telephone number, email address, or any username or screen name. If we learn that we have collected or received PI from a child under 16 without the required consent, we will delete that information. If you believe we might have information from or about a child under 16, please contact us at privacy@frankcrum.com.

International Visitors  

Our Site(s) are intended only for U.S. audiences; individuals outside the U.S. should notsubmit PI.

Consent to Terms and Conditions  

This Policy is provided to describe FrankCrum’s privacy practices and applicable Covered Employee privacy rights. Where consent is required by law for a specific activity, FrankCrum will seek consent separately.

Changes to Our Privacy Policy 

We may update this Policy from time to time, and we will provide notice of any such changes to the Policy as required by law. The date the Policy was last updated is identified at the top of the page. We will notify you of changes to this Policy by updating the "last updated" date and posting the updated Policy on our Site. We will email or otherwise communicate reminders about this Policy, but you should check our Services periodically to see the current Policy and any changes we have made to it.

Covered Employees With Disabilities  

This Policy is in the form that is accessible to Covered Employees and other individuals with disabilities.

Contact Information 

To exercise your rights or ask questions or comment about this Policy or our privacy practices, contact us at: privacy@frankcrum.com or via our toll-free number: 1-800-393-0815, Option 21.

Affiliated Entities 

  • FrankCrum Administrative Services, Inc.
  • FrankCrum 1-9
  • FrankCrum 11, 12
  • FrankCrum 14-18