FrankCrum Employee

Privacy Policy and CA Notice at Collection  

Last Updated: July 7, 2026

We review and update this Policy at least annually and whenever there are material changes to our data practices or applicable law.

Scope of Applicability

FrankCrum and/or our affiliate companies (collectively, “FrankCrum,” “Company,” “we,” “our,” or “us”) respect your privacy and are committed to protecting it through our compliance with this FrankCrum Employee Privacy Policy and CA Notice at Collection (collectively, “Policy”). We have developed this Policy out of respect for the privacy of our FrankCrum Employees (herein referred to as “Employee” or “Employees”) and, where provided for employment-related purposes, their family members, dependents, beneficiaries, and emergency contacts. This Policy describes the Personal Information (“PI”) we collect, both online and offline, about Employees in connection with the employment relationship, the purposes for which we use and disclose it, how long we retain it, and whether we sell it or share it for cross-context behavioral advertising purposes. References to “Site(s),” “Service(s),” “website,” “portal,” “application,” or “system” in this Policy mean Company-controlled or Company-authorized resources used in the employment context. This Policy also incorporates and serves as our California Residents: Notice at Collection and disclosures required under the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (herein referred to as “CCPA”).

This Policy is intended only for FrankCrum Employees and does not apply to job applicants, independent contractors, temporary workers, Covered Employees, Client Employees, website visitors acting outside the employment context, or other non-employee individuals unless a separate written notice expressly states otherwise.

Please refer to the following policies if needed:

California Residents: Notice at Collection

Collection of Personal Information and Sensitive Personal Information

Based on your interactions, transactions, and use of our website, we collect - and have collected during the preceding 12 months - the following categories of Personal Information ("PI") about Employees. For each category, the chart identifies examples of PI, sources, business purposes, categories of recipients to whom we disclose PI, whether we sell or share PI, and retention criteria. In jurisdictions where required by law, we limit our collection, use, disclosure, and retention of PI to what is reasonably necessary and proportionate for the employment-related purposes disclosed in this Policy or otherwise disclosed to you at the time of collection. The examples provided for each category are not exhaustive and are intended to give you a meaningful understanding of the types of information that may be collected within each category.

Where Employees access Company websites, portals, applications, or systems, we use limited analytics, logging, and security tools solely to operate, secure, debug, maintain, and improve those systems and to understand employment-related system performance and navigation. These tools are configured without advertising features, including disabled ad personalization and remarketing. Analytics data is not sold or shared and is disclosed only to contracted Service Providers for legitimate employment-related business purposes. We do not use these tools to target advertising.

Categories of Personal Information Collected and Source

Business Purpose

Third parties with whom Personal Information is disclosed, shared or sold

Retention Criteria

Identifiers. e.g. contact information including first name, last name, alias, date of birth, postal address, telephone number, unique personal identifier, online identifier, Internet Protocol ("IP") address, email address, Social Security number, driver’s license, state identification card number, or passport number provided by you.

 

Source: Directly from you, Service Providers, automatically through Company-controlled or Company-authorized employment-related websites, portals, applications, devices, systems, or networks, or internally.

  • Administer employment, payroll, compensation, and benefits.
  • Analytics and service improvement.
  • Authentication and Session Management.
  • Comply with applicable laws.
  • Communicate with you regarding your employment.
  • Conduct workplace investigations.
  • Control and monitor Site access.
  • Debug, identify, and repair errors that impair existing intended functionality of Site.
  • Detect and investigate security incidents. 
  • Manage workers’ compensation claims.
  • Perform human resources management services and  Employee support services.
  • Manage and process payroll.
  • Marketing and sales activities.
  • Respond to law enforcement, subpoenas, and court orders.
  • Support internal business operations related to employment relationships.
  • Verify and respond to Employee requests.  
Disclosed:
  • Affiliated entities.
  • Benefits administrators.
  • Communication Services Providers. 
  • Consulting/Investigation Firm.
  • Consumer Reporting Agencies. 
  • Data Analytics providers.
  • Financial institutions.
  • Government agencies.
  • IT, cybersecurity, and risk vendors.
  • HRIS.
  • Law enforcement, courts, and attorneys.
Sold or Shared:
  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising.

Retained as long as necessary to fulfill the purposes stated for this category, for the duration of our relationship, and for any additional period required or permitted by applicable legal, regulatory, contractual, security, fraud prevention, or recordkeeping obligations.

Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)) ("California Customer Records"). e.g. name, signature, Social Security number, physical characteristics or description, photograph, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, membership in professional organizations, professional licenses and certifications, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information.

 

Some Personal Information included in this category may overlap with other categories.

 

Source: Directly from you or internally.

  • Administer employment and benefits.
  • Business operations and service delivery.
  • Comply with applicable laws.
  • Communicate with you regarding your employment.
  • Manage and process payroll.
  • Manage workers’ compensation claims.
  • Perform human resources management services and  Employee support services.
  • Respond to inquiries. 
  • Respond to law enforcement, subpoenas, and court orders.
  • Support internal business operations related to employment relationships.
  • Verify and respond to Employee requests.
Disclosed:
  • Affiliated entities.
  • Benefits administrators.
  • Communication Services Providers. 
  • Consulting/Investigation Firms.
  • Consumer Reporting Agencies. 
  • Financial institutions.
  • Government agencies.
  • IT, cybersecurity, and risk vendors.
  • HRIS.
  • Law enforcement, courts, and attorneys.
Sold or Shared:
  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

Retained for so long as necessary to fulfill the purposes stated for this category, for the duration of our relationship, and for any additional period required or permitted by applicable legal, regulatory, contractual, security, fraud prevention, or recordkeeping obligations.

Account Information. e.g. username and password and any required security or access code, password, or credentials allowing access to your account.

 

Source: Directly from you or internally.

  • Authentication and Session Management.
  • Control and monitor Site(s) access.
  • Detect and investigate security incidents.
  • Respond to law enforcement, subpoenas, and court orders.
Disclosed:
  • Affiliated entities.
  • IT, cybersecurity, and risk vendors.
  • Law enforcement, courts, and attorneys.
Sold or Shared:
  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

Retained until completion of the purposes stated for this category, plus any applicable legal, regulatory, or contractual retention period.

Protected classification characteristics under California or federal law ("Protected Classes"). e.g. age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, reproductive health decision-making, military and veteran status, or genetic information (including familial genetic information).

 

Source: Directly from you, Service Providers, government agencies, or internally, if voluntarily disclosed by you or collected for legally required equal employment opportunity, accommodation, work authorization, background screening, or similar employment-related purposes.

  • Administer employment and benefits.
  • Comply with applicable equal employment opportunity, anti-discrimination, accommodation, immigration, background-screening, and other applicant-related legal obligations.
  • Evaluate and administer requested accommodations.
  • Perform human resources management services and Employee support services.
  • Respond to law enforcement, subpoenas, and court orders.

Disclosed:

  • Affiliated entities.
  • Benefits administrators.
  • Government agencies.
  • HRIS.
  • Law enforcement, courts, and attorneys.
Sold or Shared:
  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

Retained only for as long as necessary to comply with federal and state equal employment opportunity laws and reporting requirements.

Commercial  Information. e.g. benefit elections, plan selections, and client account history.

 

Source: Directly from you, Service Providers, or internally. 

  • Administer employment and benefits.
  • Respond to law enforcement, subpoenas, and court orders.

Disclosed: 

  • Affiliated entities.
  • Benefits administrators.
  • Government agencies.
  • HRIS.
  • Law enforcement, courts, and attorneys.
Sold or Shared:
  • Not sold for monetary or other valuable consideration.
  • Not shared for cross-context behavioral advertising.

Retained only as long as reasonably necessary to administer employment-related benefit selections, reimbursements, payroll, accounting, tax, audit, and legal compliance obligations.

 

Internet or other similar network activity. e.g. date and time of your visit to our Site(s); webpages visited; links clicked on our Site(s); session identifiers; browser ID; browser type and characteristics; device ID and characteristics or attributes; referring URLs; mobile phone make, model and serial number; mobile service provider; operating system; form information downloaded; domain name from which our site was accessed; search history; interaction-level telemetry; cookies; and internet or other electronic network activity information related to usage of FrankCrum networks, servers, intranet, or shared drives, as well as FrankCrum-owned computers and electronic devices, including system and file access logs, security clearance level, browsing history, search history, and usage history.

 

Source: Automatically through Company-controlled or Company-authorized employment-related websites, portals, applications, devices, systems, or networks.

  • Business operations and service delivery.
  • Control and monitor Site access.
  • Debug, identify, and repair errors that impair existing intended functionality. 
  • Detect security incidents.
  • Understand and track website usage, improve website performance, analyze trends, and enhance the user experience.

Disclosed: 

  • Affiliated entities.
  • Communication Services Providers. 
  • Data Analytics providers.
  • Investigator/Auditor.
  • IT, cybersecurity, and risk vendors.
  • Law enforcement, courts, and attorneys.

Sold or Shared:

  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

Retained only as long as reasonably necessary for security, system administration, debugging, internal analytics, investigations, legal compliance, and applicable recordkeeping obligations.

 

Geolocation data. e.g. physical location or movements, such as your zip code, the time and physical location related to use of our Site(s) or mobile application, or other information about your location or locations you visited.

 

IP addresses are mapped to inferred geographic attributes.

 

Source: Automatically through Company-controlled or Company-authorized employment-related websites, portals, applications, devices, systems, or networks, or from information provided by you where required for employment-related purposes.

  • Control and monitor Site(s) access.
  • Debug, identify, and repair errors that impair existing intended functionality. 
  • Detect and investigate security incidents.
  • Operate, secure, and improve Site(s).
  • Provide limited internal analytics to improve navigation/performance.
  • Respond to law enforcement, subpoenas, and court orders.
Disclosed: 
  • Affiliated entities.
  • Communication Services Providers. 
  • Company Intranet.
  • Data Analytics providers.
  • IT, cybersecurity, and risk vendors.
  • Law enforcement, courts, and attorneys.
Sold or Shared:
  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

Retained only as long as reasonably necessary for employment-related security, authentication, system administration, debugging, internal analytics, investigations, legal compliance, and applicable recordkeeping obligations.

 

Sensory data. e.g. photographs of you (including badge photos, event photos, or photos you share with us); your image when recorded or captured in surveillance camera footage; and audio recordings of calls and virtual meetings when disclosed to you or otherwise permitted by law.

 

Source: Directly from you, via physical locations, Service Providers, or internally.

  • Business operations and service delivery.
  • Comply with applicable laws.
  • Conduct workplace investigations.
  • Detect security incidents.
  • Protect individuals or property.
  • Respond to law enforcement, subpoenas, and court orders.
Disclosed:
  • Affiliated entities.
  • Communication Services Providers. 
  • IT, cybersecurity, and risk vendors.
  • Law enforcement, courts, and attorneys.
  • Video content hosts and platforms.
Sold or Shared: 
  • Not sold for monetary or other valuable consideration.
  • Not shared for cross-context behavioral advertising. 

Security/call recordings are kept only as necessary for security, quality assurance, investigations, and compliance. 

Professional or employment-related information. e.g. new hire or onboarding records, tax forms, current or past job history or performance evaluations, such as employment application information (work history, academic and professional qualifications, educational records, references, and interview notes, background check, drug testing results, work authorization, performance and disciplinary records, salary, bonus, commission, and other similar compensation data, benefit plan enrollment, participation, and claims information, time and attendance records, non-medical leave of absence records, leave of absence information including religious, military and family obligations, health data concerning Employee and their family members).

 

Source: Directly from you, Service Providers, or internally.

  • Comply with applicable laws.
  • Conduct permissible background, education, and employment checks.
  • Manage workers’ compensation claims.
  • Perform human resources management services and  Employee support services.
  • Respond to law enforcement, subpoenas, and court orders.

Disclosed:

  • Affiliated entities.
  • Benefits administrators and vendors.
  • Communication Services Providers. 
  • Consumer Reporting Agencies. 
  • Consulting/Investigation Firms.
  • Government agencies.
  • HRIS.
  • Law enforcement, courts, and attorneys.
Sold or Shared:
  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

Retained for so long as necessary to fulfill the purposes stated for this category, for the duration of our relationship, and for any additional period required or permitted by applicable legal, regulatory, contractual, security, fraud prevention, or recordkeeping obligations.

Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99) ("FERPA Information")).

Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.

 

Source: None.

  • Not Collected.

Disclosed:
  • Not Disclosed.
Sold or Shared:
  • Not sold for monetary or other valuable considerations.
  • Not shared for cross-context behavioral advertising. 

Not Applicable.

Financial Information. e.g. bank account number for direct deposit, routing number, and other financial account information.

 

Source: Directly from you.

  • Comply with applicable laws.
  • Direct Deposit.
  • Manage and process payroll.

Disclosed:

  • Affiliated entities.
  • Communication services providers.
  • Financial institutions.
  • Transactional support vendors.
  • HRIS.
  • Law enforcement, courts, and attorneys.

Sold or Shared:

  • Not sold for monetary or other valuable considerations.
  • Not shared for cross-context behavioral advertising. 

Retained only for as long as necessary to fulfill payroll, benefit administration, accounting, and legal compliance purposes.

Physical Characteristics or Description. e.g. information on your Driver’s License (such as eye color, hair color, height, weight), as well as information collected to the extent relevant for workplace investigations or for enforcement of Company policies on appearance and grooming (such as tattoos, piercings).

 

Source: Directly from you.

  • Comply with applicable laws.
  • Conduct workplace investigations.
  • Respond to law enforcement, subpoenas, and court orders.

Disclosed:

  • Affiliated entities.
  • Benefits administrators.
  • Consulting/Investigation Firms.
  • Government agencies.
  • HRIS.
  • Law enforcement, courts, and attorneys.

Sold or Shared:

  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

Retained only for as long as necessary to comply with applicable laws and for workplace investigation needs, including any required retention under legal hold.

 

Family Information. e.g. contact information for family members listed as emergency contacts, contact information for dependents, and other dependent information.

 

Source: Directly from you.

  • Communicate with emergency contacts and dependents where appropriate.
  • Comply with applicable laws.
  • Respond to law enforcement, subpoenas, and court orders.
Disclosed:
  • Affiliated entities.
  • Benefits administrators.
  • Communication Services Providers. 
  • Government Agencies.
  • HRIS.
  • Law enforcement, courts, and attorneys.
Sold or Shared:
  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

Retained until completion of the purposes stated for this category, plus any applicable legal, regulatory, or contractual retention period.

 

Medical and Health Information. e.g. medical information contained in such documents as doctor’s notes for absences or work restrictions, medical leave of absence records, requests for accommodation, interactive process records, ergonomic assessments and accommodation records, and correspondence with you and your medical or mental health provider(s) regarding any request for accommodation or medical leave of absence, as well as information in post-hire drug test results. This includes medical information and health benefits information for dependents and beneficiaries if provided to FrankCrum.

 

Source: Directly from you, Service Providers, medical or benefits administrators, health care providers where authorized or permitted by law, or internally.

  • Administer employment and benefits.
  • Comply with applicable laws.
  • Evaluate and administer accommodation requests.
  • Manage workers’ compensation claims.
  • Perform human resources management services and  Employee support services.
  • Respond to law enforcement, subpoenas, and court orders.

Disclosed:

  • Affiliated entities.
  • Benefits administrators.
  • Communication Services Providers. 
  • Consulting/Investigation Firms.
  • Government agencies.
  • HRIS.
  • Law enforcement, courts, and attorneys.

Sold or Shared:

  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

Retained only as long as necessary to evaluate or administer Employee accommodation requests, medical leave, benefits, workplace safety, workers’ compensation, disability, health, safety, background-screening, audit, litigation, and recordkeeping obligations, and to protect rights and safety as permitted by law.

 

Travel and Expenses Information. e.g. business travel or work-related expenses.

 

Source: Directly from you or internally.

  • To administer, process, document, and reimburse approved expenses. 

Disclosed:

  • Affiliated entities.
  • Communication Services Providers. 
  • Financial institutions.
  • HRIS.

Sold or Shared:

  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

Retained only for as long as reasonably necessary to administer business travel, process reimbursements, maintain accurate financial records, and satisfy legal, tax, and audit requirements.

Biometric Data. e.g. biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as fingerprints and palm/handprint reading.

 

Source: None.

  • FrankCrum does not collect biometric identifiers or biometric information from Internal Employees unless separately disclosed and authorized where required by law.

Disclosed:

  • Not Disclosed.
Sold or Shared:
  • Not sold for monetary or other valuable consideration.
  • Not shared for cross-context behavioral advertising.

Not Applicable.

Inferences drawn from other information. e.g. profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.  

 

Source: Internally, from employment-related records, or from Company-controlled or Company-authorized employment-related websites, portals, applications, devices, systems, or networks.

  • To collect, analyze, and review assessment results that evaluate a candidate's work preferences, behavioral tendencies, and suitability for a position as part of the recruitment, selection, and hiring process.

Disclosed:

  • Data analytics providers.
  • Transactional Providers.
  • HRIS.
Sold or Shared:
  • Not sold for monetary or other valuable considerations. 
  • Not shared for cross-context behavioral advertising. 

Retained only as long as reasonably necessary to support the documented employment-related purpose for which the inference was created, and not used for legal or similarly significant employment decisions unless disclosed and permitted by applicable law.

 

 

What Sensitive Personal Information We Collect

Of the above categories of PI, the following are categories of Sensitive PI we collect from or about Employees:
  • Identifiers (SSN, driver's license, state ID, passport).
  • California Customer Records (financial, health, and government ID data).
  • Account Information (login credentials).
  • Protected Classes (race, ethnicity, religion, citizenship, sexual orientation, genetic data, etc.).
  • Professional/Employment Information (to the extent it includes health, religious, immigration, or drug-testing information).
  • Financial Information.
  • Credit/Financing Application Data.
  • Medical and Health Information.
We process SPI only for the limited purposes permitted under CCPA:
  • To perform the Services reasonably expected by an average Employee who requests those Services. 
  • To detect security incidents that compromise the availability, authenticity, integrity, and confidentiality of stored or transmitted PI. 
  • To resist malicious, deceptive, fraudulent, or illegal actions directed at the business and to prosecute those responsible for those actions. 
  • To ensure the physical safety of natural persons. 
  • For short-term, transient use.  
  • To perform Services on behalf of Company. 
  • To purposes that do not involve inferring characteristics about consumers. 
Personal Information does not  include:
  • Publicly available information from government records. 
  • Information that a business has a reasonable basis to believe is lawfully made available to the public by the Employee or from widely distributed media.  
  • Information made available by a person to whom the Employee has disclosed the information if the Employee has not restricted the information to a specific audience.  
  • De-identified or aggregated information. 

Sensitive Personal Information Categories Chart 

Sensitive Personal Information (“SPI”) is a subtype of PI consisting of the specific information categories listed in the chart below. FrankCrum does not use or disclose SPI for purposes that would require a “Limit the Use of My Sensitive Personal Information” link under the CCPA. We use SPI only for employment-related, compliance, security, safety, benefits, payroll, accommodation, and other purposes permitted by law, and not to infer characteristics about Employees unless expressly disclosed and permitted by applicable law. Of the above categories of PI, the following are categories of SPI FrankCrum may collect from or about Employees: 

Sensitive Personal Information Category 

Collected to Infer Characteristics? 

Retention Criteria 

Government identifiers. e.g. as your Social Security number (SSN), driver's license, state identification card, or passport number

No 

N/A 

Complete account access. Credentials. e.g. usernames, account logins, account numbers, or card numbers combined with required access/security code or password.

No 

N/A 

Precise geolocation. e.g. GPS data from an Employee’s mobile device that can provide its location in a geographic area, with an approximate radius of 1,850 feet. 

No 

N/A 

Racial or ethnic origin. 

No 

N/A 

Citizenship or immigration status. 

No 

N/A 

Religious or philosophical beliefs. 

No 

N/A 

Union membership. 

No 

N/A 

Mail, email, or text messages not directed to the Company. 

No 

N/A 

Genetic data. 

No 

N/A 

Neural Data. e.g. information generated by measuring an Employee’s central or peripheral nervous system's activity that is not inferred from nonneural information.

No 

N/A 

Unique identifying biometric information. 

No 

N/A 

Health information. 

No 

N/A 

Sex life or sexual orientation information. 

No 

N/A 

Children's Personal Information (under age 16). 

No 

N/A 

Categories of Sensitive Personal Information Collected or Processed

We process SPI only for disclosed employment-related purposes and, where applicable, for purposes permitted under CCPA:
  • Administering employment, payroll, benefits, tax, accommodation, leave, workplace safety, security, investigations, and other employment-related operations.
  • Performing actions that are necessary for our employment relationship and that an average Employee in an employment relationship with us would reasonably expect, including for many of the purposes listed.
  • To detect security incidents that compromise the availability, authenticity, integrity, and confidentiality of stored or transmitted PI.  
  • To resist malicious, deceptive, fraudulent, or illegal actions directed at the business and to prosecute those responsible for those actions.  
  • To ensure the physical safety of natural people.  
  • Short-term, transient use that is necessary for employment-related system functionality, security, authentication, or display of non-advertising Company content, if we do not:
    • disclose SPI to another third party for advertising or profiling purposes; or
    •  use it to build a profile about the Employee or otherwise alter the Employee's experience outside the employment relationship with the Company.
  •  Services performed for the Company, including maintaining or servicing accounts, providing human resources and Employee benefits administration, processing or fulfilling transactions, verifying Employee information, processing payments, providing financing, analytic services, storage, or similar services for the Company.
  •  Collecting or processing SPI, not for the purpose of inferring characteristics about an Employee.

California Residents: Notice at Collection 

f you are a California resident, the CCPA may provide you with the following rights regarding PI we collect, use, disclose, and retain about you in the employment context, subject to applicable exceptions and limitations. These rights do not override legal, regulatory, payroll, tax, benefits, litigation-hold, security, workers’ compensation, occupational health and safety, or employment-record retention obligations.

  • Right to Know and Data Portability Requests. You have the right to request that we disclose certain information to you about our collection and use of your PI (the "right to know"), including the specific pieces of PI we have collected about you (a "data portability request"). Our response will cover the 12-month period preceding the request, although we will honor requests to cover longer periods that do not extend past January 1, 2022, unless doing so would be impossible or involves disproportionate effort. You may exercise your right to know twice in any 12-month period. Once we receive your request and confirm your identity see Section: How to Exercise Your Rights, we will disclose it to you: 
    • The categories of: 
      • PI we collected about you; and 
      • sources from which we collected your PI. 
    • The business or commercial purpose for collecting your PI and, if applicable, selling or sharing your PI. 
    • If applicable, the categories of persons, including third parties, to whom we disclosed your PI, including separate disclosures identifying the categories of your PI that we: 
      • disclosed for a business purpose to each category of persons; and 
      • sold or shared to each category of third parties. 
    • When your right to know submission includes a data portability request, a copy of your PI, subject to any permitted redactions. 
  • Right to Delete and Right to Correct. You have the right to request that we delete any of your PI that we collected from you and retained, subject to certain exceptions and limitations (the "right to delete"). Once we receive your request and confirm your identity, we will delete your PI from our systems unless an exception allows us to retain it. We will also notify our Service Providers, contractors, and other recipients to take appropriate action. You also have the right to request correction of PI we maintain about you that you believe is inaccurate (the "right to correct"). We may require you to provide documentation, if needed, to confirm your identity and support your claim that the information is inaccurate. Unless an exception applies, we will correct PI that our review determines is inaccurate and notify our Service Providers to take appropriate action. 
  •  Right to Limit Sensitive Personal Information Use and Notice of Rights to Limit the Use of Your Sensitive Personal Information. You have a right to ask businesses that use or disclose your SPI to limit those actions to just the CCPA's Permitted SPI Purposes listed above (the "right to limit"). We do not use or disclose your SPI for purposes that give rise to a right to “Limit the Use of Your Sensitive Personal Information” under CCPA. Because we do not use SPI for purposes that trigger the right to limit under CCPA, a “Limit the Use of My Sensitive Personal Information” link is not applicable currently. If our practices change, we will provide that link and update this Policy. 
  • Personal Information Sales or Sharing Opt-Out and Opt-In Rights. We do not sell or share Employee PI for cross-context behavioral advertising, as defined under CCPA. Because we do not engage in the sale or sharing of Employee PI, Employees do not need to submit opt-out requests, and user-enabled opt-out preference signals (such as Global Privacy Control or cookie-based signals) are not applicable in the employment context. The CCPA also includes restrictions on the sale or share of PI of individuals under the age of 16. As we do not sell or share Employee PI these opt-in requirements do not apply. If our practices change, we will provide advance notice and any rights required under applicable law.
  • ADMT and Profiling. We do not use automated decision-making technology or profiling for decisions that have legal or similarly significant effects on Employees.
  • Right to non-discrimination. You have the right not to be discriminated against or retaliated against for exercising any of your privacy rights under the CCPA.
  • The right to designate an authorized agent to submit one of the above requests on your behalf. See below how you can designate an authorized agent within Section: Verification Process and Authorized Agents.

Responding to Your Requests to Know, Delete, or Correct 

We will confirm receipt of your request within ten business days. If you do not receive confirmation within the ten-day timeframe, please reach out to privacy@frankcrum.com. We endeavor to substantively respond to a verifiable request within 45 days of its receipt. If we require more time (up to another 45 days), we will inform you of the reason and extension period in writing. We will deliver our written response to your verified email address. Our substantive response will tell you whether we have complied with your request. If we cannot comply with your request in whole or in part, we will explain the reason, subject to any legal or regulatory restrictions. Applicable law may allow or require us to refuse to provide you with access to some or all the PI that we hold about you, or we may have destroyed, deleted, or made your PI anonymous in compliance with our record retention policies and obligations.

Any disclosures we provide will cover information for the 12-month period preceding the request receipt date. We will consider requests to provide longer disclosure periods that do not extend past January 1, 2022, unless providing a longer timeframe would be impossible or involves disproportionate effort.

For data portability requests, we will select a format to provide your PI that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance. 

We do not charge a fee to process or respond to your verifiable request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request. 

Verification Process and Authorized Agents  

If you are a California resident, you can authorize someone else as an authorized agent who can submit a request on your behalf.

To do so, you must either:  
  • execute a valid, verifiable, and notarized power of attorney; or
  • provide other written, signed authorizations that we can then verify. When we receive a request submitted on your behalf by an authorized agent who does not have a power of attorney, that person will be asked to provide written proof that they have your permission to act on your behalf, and we will also contact you and ask you for information to verify your own identity directly with us and not through your authorized agent. We may deny a request from an authorized agent if the agent does not provide your signed permission demonstrating that you have authorized them to act on your behalf.

Response and Timing on Rights to Opt-Out

In response to your request to opt-out, we will process your request, as soon as feasibly possible, but no later than 15 business days from the date we receive the request. We will only use Personal Information provided from your request to comply with the request.

We will also notify our service providers, contractors, and certain other downstream recipients of your request to opt-out and instruct them to both:
  • Comply with your request.
  • Forward the request to their own downstream recipients, if applicable.

We may deny opt-out requests if we have a good-faith, reasonable, and documented belief that the request is fraudulent and will clearly explain our denial decision to the requestor. You can confirm that we processed your request to opt-out by going to our website and clicking Cookie Preferences where we will have a toggle button showing what Cookies are active. However, you may change your mind and opt back in at any time by re-toggling your Cookie Preferences.

Notice of Right to Opt-Out of Profiling, Automated Decision Making, and Targeted Advertising

We do not use PI for targeted advertising, and we do not engage in profiling for decisions that have legal or similarly significant effects on you as an Employee. We also do not use automated decision-making technology to replace or substantially replace human decision-making for such significant employment decisions. Where required by applicable law, Employees may contact us using the request methods described in this Policy to inquire about rights that may apply to their PI. If our practices change, we will update this Policy and provide any required notices, rights, or opt-out mechanisms.

If FrankCrum begins using automated decision-making technology, profiling, AI-enabled tools, productivity analytics, or similar technologies to make or substantially assist decisions that produce legal or similarly significant effects concerning Employees, FrankCrum will provide any legally required pre-use notice, access rights, opt-out rights, appeal or human-review rights, and risk-assessment disclosures before or at the time required by applicable law. FrankCrum will also assess whether any such use requires a data protection assessment, cybersecurity audit, or other governance documentation under applicable law.

Response and Timing for Privacy Requests

We will process privacy requests in accordance with applicable law and within the timeframes required by the laws that apply to your request. We may take steps to verify your identity and authority before fulfilling certain requests, and we may request additional information where necessary to do so. Where permitted or required by law, we may deny a request in whole or in part, including where an exemption applies or where we are unable to verify the request. If we deny your request, we will explain the basis for the denial to the extent permitted by law. Where applicable law provides an appeal right, we will describe how to appeal a denial in our response.

Please Note: Privacy requests submitted by Employees will be assessed in accordance with applicable law, the nature of the information involved, and the employment relationship. Certain rights described in this Policy may not apply to all Employees or to all categories of employment-related PI.

How to Exercise Your Rights 

To exercise your rights described above, please submit a verifiable request to us by either: 

Notice Regarding Sale, Sharing, and Opt-Out Preference Signals

We do not sell Employee PI for monetary or other valuable consideration, and we do not share Employee PI for cross-context behavioral advertising. As a result, we do not currently engage in practices that would require a “Do Not Sell or Share My Personal Information” link for Employee PI. If a California opt-out preference signal or similar signal is received in connection with Company-controlled employment-related resources, we will evaluate and honor it to the extent required by applicable law, but such signals generally are not applicable where no sale or sharing occurs. Where required by applicable law, Employees may still submit privacy requests using the methods described in this Policy. If our practices change in a way that constitutes a sale or sharing under applicable law, we will update this Policy and provide any required opt-out tools and disclosures.

Additional Categories or Other Purposes

We will not collect additional categories of PI or use the PI we collected for materially different, unrelated, or incompatible purposes without providing you with notice. If required by law, we will also seek your consent before using your PI for a new or unrelated purpose.

Sources of Personal Information 

We collect your Personal Information from the following sources: 
  • Affiliated entities.
  • Automatically through our Site(s) and utilizing Service(s) (e.g. session, security logs, and limited internal analytics).
  • Company systems, networks, software applications, and databases you log into or use while performing your job, including from vendors the Company engages to manage or host such systems, networks, applications or databases.
  • Directly from you, the Employee, when you voluntarily submit information for employment purposes.
  • Internally (e.g. other Employees, performance reviews, testing, or other observations, surveys, and interactions).
  • Service providers (e.g. benefits administrators, consumer reporting agencies for background checks, IT/security vendors).
  • Via physical locations (e.g. badge logs, and video surveillance). 

To Whom We Disclose Personal Information 

We disclose PI only to the categories of recipients listed below for business and commercial purposes:
  • Affiliated entities.
  • Benefits administrators and vendors (e.g. third-party administrators, 401K administrators, workers' compensation, unemployment administrators, insurance brokers, and wellness vendors).
  • Buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all FrankCrum’s assets. 
  • Communication Services Providers that facilitate, manage, and send/receive communications on our behalf (e.g. email, text/SMS, phone, or record, transcribe, summarize, or process phone calls and video meetings).
  • Consulting and investigation firms (e.g. HR consultants, safety consultants, and workplace investigators).
  • Consumer reporting agencies or credit reporting agencies (where applicable). 
  • Corporate Transfers. Parties to transactions and potential transactions whereby we sell, transfer or otherwise share some or all our business or assets, including your personal information, such as a corporate divestiture, merger, consolidation, acquisition, reorganization or sale of assets, or in the event of bankruptcy or dissolution.
  • Data analytics service providers (internal analytics only; no ads/cross context tracking)
  • Financial institutions.
  • Government or public agencies (as required by law).
  • Human Resources Information System (“HRIS”) (e.g. employee tracking and talent management systems).
  • Insurance carriers, administrators, and brokers.
  • IT, cybersecurity, privacy, and risk vendors. 
  • Law enforcement, courts, and attorneys.
  • Transactional support vendors.  

We contractually require service providers, contractors, and other recipients that process PI on our behalf to keep it confidential and use it only for the limited purposes for which we disclose it to them, unless otherwise permitted or required by law.

Reasons Why We Collect, Use, Retain, and Disclose Personal Information

We may collect, use, and disclose your PI for any of the following business and commercial purposes:
  • Communicate with you, including responding to inquiries and providing notices, updates, alerts, and operational or service‑related information.
  • Comply with applicable laws and regulations, including employment, labor, tax, payroll, immigration, health and safety, and recordkeeping requirements, and respond to verified privacy rights requests.
  • Conduct human capital analytics and organizational planning, including improving workforce productivity and analyzing aggregated or de‑identified data to enhance Company systems and processes.
  • Engage in business operations, including:
    • Evaluating and managing relationships with vendors, service providers, and contractors.
    • Fulfilling or meeting the purpose for which information was provided.
    • Participating in corporate transactions requiring review or disclosure of Employee related information (e.g., mergers, acquisitions), subject to confidentiality obligations.
  • Ensure the security of our facilities, systems, and workforce, including:
    • Controlling and monitoring access to Company facilities and information systems.
    • Implementing and managing electronic security measures and activity logging.
    • Detecting, investigating, and responding to potential security incidents or unauthorized access.
    • Preventing identity theft, fraud, malicious, or illegal activity, and prosecuting those responsible.
    • Conducting workplace investigations related to safety, security, or misconduct.
  • Manage the employment relationship, including:
    • Administering employment, payroll, compensation, and benefits.
    • Supporting hiring, onboarding, job placement, and internal job changes.
    • Managing performance, goals, training, development, discipline, and termination processes.
    • Maintaining personnel files and complying with record retention requirements.
    • Reaching you, your emergency contacts, or beneficiaries when needed.
    • Administering timekeeping, attendance, scheduling, and expense reimbursements.
    • Managing workers’ compensation, disability, and workplace accident or injury claims.
    • Communicating with you about employment related matters such as benefits enrollment deadlines, required actions, and availability of tax documents.
  •  Operate, maintain, and improve Company information systems, including:
    • Authenticating users and managing sessions for our platforms (including our Site(s)).
    • Facilitating efficient and secure use of Company networks, applications, and devices.
    • Debugging, identifying, and repairing errors or functionality issues.
    • Operating, securing, and improving our Site(s) and conducting limited internal analytics.

Use of Cookies, Pixels, and Other Tracking Technologies 

When Employees access Company websites, portals, applications, or systems in connection with employment, those systems collect or store information on the Employee’s browser or device, primarily through cookies, authentication tokens, logs, or similar technologies. Cookies are small text files that help a website or application function properly and understand how users interact with the site or system. Cookies set directly by our Site(s) are referred to as “first party cookies.” We use first party cookies and similar technologies to support core functionality, security, authentication, session management, and performance.

For example, these technologies help us:
  •  Understand how users interact with our Site(s)
  •  Analyze which content is most frequently viewed
  • Enable efficient navigation between pages
  •  Remember user preferences or login state
  •  Identify and resolve our Site(s) performance issues

We use limited third-party analytics tools that collect information on our behalf to help us measure website usage and improve functionality. These analytics technologies are used solely for internal measurement and performance analysis and are not used for targeted advertising, cross‑context behavioral advertising, or profiling. You may manage cookie preferences through your browser settings. Please note that disabling certain cookies may affect the functionality and performance of our Site(s).

Essential Cookies

Essential cookies and similar technologies are necessary for Company websites, portals, applications, and systems to function properly and securely. They are usually set in response to actions such as logging in, maintaining a session, setting privacy or accessibility preferences, completing employment-related forms, or accessing secure content. You can set your browser to block or alert you about these cookies, but blocking them may prevent the relevant Company website, portal, application, or system from working correctly.

Non-Essential Cookies

Non-essential cookies are not necessary for core website functionality but support limited internal analytics, performance measurement, preferences, or similar non-advertising purposes:
  • "Performance" cookies (sometimes referred to as analytics cookies) collect information about how visitors interact with our website. These cookies collect online identifiers such as IP address or device information, which are used in aggregated or anonymized form to improve website performance, such as pages visited, clicked links, and general traffic patterns. For Example:
    • Pages visited.
    • Links clicked within the website.
    • General traffic patterns.
    • Traffic sources.

       

  • "Functional" cookies (sometimes called preference cookies) enable enhanced functionality and personalization, such as remembering your preferences and past choices on the website through secure authentication tokens.
    • Encrypted login session identifiers (not passwords).
    • Masked or tokenized user identifiers.
    • Language or regional preferences.
    • Saved display or accessibility settings.

Because we do not sell or share FrankCrum Employee PI and do not use targeted advertising, advertising opt-out tools and universal opt-out preference signals are not currently applicable to our Site in the employment context. We honor browser- or device-level cookie settings to the extent they affect cookies on the user’s browser or device.

Cookie Management 

You can control and manage cookies through your browser settings. If you are interested in controlling and managing cookies from your browser, including any cookies set by our Site(s), please refer to http://www.allaboutcookies.org/manage-cookies/index.html for information on different ways to configure your browser’s cookie settings.

You may delete or block cookies through your browser settings at any time but doing so may affect the functionality or availability of certain Company websites, portals, applications, or systems. Some features may not be available if cookies are disabled. The following browser guides may be helpful:

Global Privacy Control

The Company does not sell or share Employee PI for cross-context behavioral advertising. Accordingly, Global Privacy Control ("GPC") signals and similar opt-out preference signals are not applicable to the Company's processing of Employee PI.

Do Not Track Signals

Do Not Track (“DNT”) is a browser-based privacy preference that allows individuals to indicate a preference not to have information about their online activities collected across websites and online services. The Company does not respond to DNT signals. Because the Company does not sell Employee PI or share Employee PI for cross-context behavioral advertising, DNT, Global Privacy Control (“GPC”), and similar opt-out preference signals generally are not applicable to the Company's processing of Employee PI in the employment context.

U.S. Consumer Privacy Rights 

This section is intended to describe potential rights that may apply to FrankCrum Employees under U.S. privacy laws outside California only where those laws apply to employment-related PI. Depending on your state of residence, the nature of your relationship with the Company, and the type of PI involved, you may have certain rights under applicable U.S. privacy laws, subject to applicable exceptions and limitations. Many comprehensive state privacy laws exclude PI collected and used solely in the employment context or apply only in a limited manner to employment-related PI. Accordingly, Employees may have limited or no rights under those state laws with respect to employment-related PI, except to the extent otherwise provided by applicable law.

  • Access and Confirmation. You may have the right to confirm whether we process your PI and to access a copy of the PI we maintain about you, subject to applicable legal exceptions.
  • Data Portability.  You may confirm whether we process your PI and access a copy of the PI we process. To the extent feasible and required by state law, depending on your state, data will be provided in a portable format. Depending on your state, you may have the right to receive additional information, and it will be included in the response to your access request. 
  • Correction. You may request that we correct inaccuracies in your PI that we maintain, considering the information's nature and purpose of processing. 
  • Deletion. You may have the right to request that we delete PI we maintain about you, subject to applicable exceptions, including where retention is required or permitted for employment administration, payroll, benefits, tax, security, compliance, or record‑keeping purposes.
  • OptOut of Certain Processing (Where Applicable). In limited circumstances and only where required by applicable state law, you may have the right to opt out of certain types of PI processing, such as targeted advertising, the sale of PI, or profiling in furtherance of decisions that produce legal or similarly significant effects. FrankCrum does not sell PI for monetary or other valuable considerations or share for cross-context behavioral advertising.
  • Appeal. Appeal our decision regarding your privacy rights request (where required by law). Unless otherwise required by state law, your appeal rights apply to any denied request, and we will provide a written outcome within the period required by your state of residence. If we deny your request, you may appeal by emailing privacy@frankcrum.com with the subject line Privacy Rights Appeal. 

 Important: The scope of these rights varies by state and may not apply in all circumstances. Certain PI may be exempt from state privacy laws, including information collected, processed, disclosed, or retained pursuant to applicable federal or state financial privacy laws, insurance laws, health privacy laws, employment laws, or related regulations, as well as information processed solely in the employment, benefits administration, or business-to-business context where an applicable law provides an exemption. Nothing in this section is intended to create rights beyond those required by applicable law. 

To exercise your rights, please submit a verifiable request to us by either:

How We Retain Your Personal Information 

We maintain retention schedules aligned to legal, regulatory, tax, employment, payroll, benefits, insurance, contractual, audit, security, and litigation-hold requirements and delete, destroy, or de-identify PI when it is no longer reasonably necessary for those purposes. We keep the categories of PI described in this Policy for as long as reasonably necessary to fulfill the employment-related purposes described in this Policy or as otherwise legally permitted or required. When determining retention periods, we consider the amount, nature, and sensitivity of the PI; the potential risk of harm from unauthorized use or disclosure; the purposes for which we process the PI; whether we can achieve those purposes through other means; and applicable legal requirements. We align retention to data minimization, reasonable expectations for each employment-related purpose, and any applicable legal or operational requirements.

Data Minimization 

We limit our collection, use, and retention of PI to what is reasonably necessary and proportionate for the purposes described in this Policy or disclosed to you at the time of collection. 

External Links 

Company websites, portals, applications, or systems may contain links to third-party resources. Unless the third-party resource is operated by or on behalf of FrankCrum in the employment context, FrankCrum is not responsible for that third party’s privacy practices or content. If you access a Company website, portal, application, or system through a mobile device, your device or browser may prompt you to grant permission for features such as location, push notifications, or camera access. You can revoke these permissions through your device settings, but doing so may affect functionality or access to employment-related systems.

Passwords  

Each Employee PI record is accessible only using unique login credentials. Employees are responsible for safeguarding the confidentiality of their usernames, passwords, and other access credentials and must not disclose such credentials to third parties or unauthorized individuals. Maintaining the security of these credentials is essential to protecting the confidentiality, integrity, and security of the PI contained in the record.

Automated Decision-Making, Profiling, and AI 

We do not use automated decision-making systems, including machine learning or AI tools, to make decisions that produce legal or similarly significant effects about you as an Employee. This includes decisions relating to hiring, promotion, termination, compensation, eligibility for benefits, discipline, or other outcomes that could meaningfully affect your employment rights or opportunities. If any automated output is used to support employment-related processes, it will be subject to appropriate human oversight and will not be used as the sole basis for a legal or similarly significant employment decision unless permitted by applicable law and disclosed as required.

We do not engage in profiling in furtherance of decisions that produce legal or similarly significant effects. If we ever begin using profiling in a way that implies additional rights (for example, under the laws of states that provide opt-out rights for certain profiling), we will update this Policy and provide any required opt-out mechanisms. 

If we materially change how we use automated decision-making, profiling, or AI - including if future law requires additional disclosures, access, appeal, or opt-out rights for such processing - we will update this Policy and provide any required tools, disclosures, and instructions at or before the time those changes take effect. 

Communications

We will contact you about employment-related matters, including benefits enrollment, payroll, tax documents, policy updates, required training, security notices, workplace operations, and other administrative or legally required communications. If we send optional employee communications where an opt-out is legally required or operationally available, you may opt out by following the instructions provided in the communication or by contacting us. We may still send transactional, administrative, security, employment-related, or legally required communications.

Compliance With Law and Safety

We disclose specific PI and/or SPI based on a good faith belief that such disclosure is necessary to comply with or conform to the law or that such disclosure is necessary to protect our Employees or the public. 

How We Protect Your Personal Information

We use commercially reasonable administrative, physical, and technical measures designed to protect your PI from accidental loss or destruction and from unauthorized access, use, alteration, and disclosure. However, no website, mobile application, system, electronic storage, or online service is completely secure, and we cannot guarantee the security of your PI transmitted to, through use, or in connection with the Services. Email, texts, and chats sent to or from the Services may not be secure, and you should carefully decide what information you send to us via such communications channels. Any transmission of PI is at your own risk. The safety and security of your information also depend on you. You are responsible for taking steps to protect your PI against unauthorized use, disclosure, and access. 

Children's and Minors' Data 

We do not knowingly sell or share the PI of individuals under the age of 16. This Policy is not intended for children under 16, except that we collect limited information about dependents, beneficiaries, or emergency contacts when provided by an Employee for benefits administration, emergency-contact, tax, payroll, or similar employment-related purposes. Employees should not submit children’s information except where requested or permitted for employment-related benefits, payroll, tax, emergency-contact, or similar lawful purposes. If we learn that we have collected or received PI from a child under 16 without the required consent or lawful basis, we will delete that information unless retention is required or permitted by law. If you believe we might have information from or about a child under 16 that was not provided for a lawful employment-related purpose, please contact us at privacy@frankcrum.com.

International Visitors

This Policy applies to FrankCrum Employees in the United States.

Consent to Terms and Conditions

This Policy is provided to describe FrankCrum’s privacy practices and applicable Employee privacy rights. Where consent is required by law for a specific activity, FrankCrum will seek consent separately.

Changes to Our Privacy Policy 

We may update this Policy from time to time, and we will provide notice of any such changes to the Policy as required by law. The date the Policy was last updated is identified at the top of the page. We will notify you of changes to this Policy by updating the "last updated" date and posting the updated Policy on the Services. We will email or otherwise communicate reminders about this Policy, but you should check our Services periodically to see the current Policy and any changes we have made to it. 

Employees With Disabilities  

This Policy is available in formats accessible to Employees with disabilities. If you need this Policy in an alternative format, please contact us using the contact information below.

Contact Information 

To exercise your rights or ask questions or comment about this Policy or our privacy practices, contact us at: privacy@frankcrum.com or via our toll-free number: 1-800-393-0815, Option 21. 

Affiliated Entities 

  • FrankCrum Corporate Inc. 
  • FrankCrum Insurance Agency, Inc.  
  •  Frank Winston Crum Insurance Company
  • Frank Winston Crum Insurance Holding Corp. 
  • FrankCrum General Agency, Inc.   
  • FrankCrum Staffing Inc.