Last Updated: October 1, 2023
The California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its implementing regulations (collectively, the “CCPA”), gives California residents certain rights and requires businesses to make certain disclosures regarding their Collection, use, and disclosure of Personal Information. This California Workforce Privacy Policy (the “Policy”) provides such notice to Thomas Scientific LLC’s (“Thomas”, “we,” “us,” “our”) California job applicants (“Applicants”) and California employees, independent contractors, and other individuals who interact with Thomas in an employment-related capacity (collectively, “Employees”).
Please note that this Policy only addresses Thomas’s Collection, use, and disclosure of employment-related Personal Information and only applies to residents of California. This Policy does not apply to individuals who are residents of other U.S. states or other countries and/or who do not interact with Thomas in an employment-related capacity. For further details about our privacy practices pertaining to non-Applicant/Employee Personal Information, please see our Consumer Privacy Policy.
As an Applicant or Employee, you have the right to know what categories of Personal Information Thomas Collects, uses, discloses, Sells, and Shares about you. This Policy provides that information and other disclosures required by California law.
A. DEFINITIONS
- Personal Information: As used in this Policy, “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Consumer or household. Personal Information includes Sensitive Personal Information, but does not include protected health information covered by the Health Insurance Portability and Accountability Act (“HIPAA”), nonpublic personal information under the Gramm-Leach-Bliley Act (“GLBA”), or any other information which is exempt from the CCPA.
- Sensitive Personal Information: As used in this Policy, “Sensitive Personal Information” includes Personal Information that reveals, among other things, social security number, driver’s license number, state identification card number, passport number, racial or ethnic origin, union membership, or the contents of a Consumer’s mail, email, and text messages, unless Thomas is the intended recipient of the communication. Sensitive Personal Information also includes information concerning the Applicant or Employee’s health, sex life, or sexual orientation.
- Other CCPA Definitions: As used in this Policy, the terms “Collect,” “Processing,” “Service Provider,” “Third Party,” “Sale,” “Share,” “Consumer,” and other terms defined in the CCPA and their conjugates, have the meanings afforded to them in the CCPA, whether or not such terms are capitalized herein, unless contrary to the meaning thereof.
B. APPLICANTS
- Collection & Processing of Personal Information
We, and our Service Providers, may have Collected and Processed the following categories of Personal Information from Applicants in the preceding 12 months:
- Identifiers, such as name, alias, online identifiers, account name, physical characteristics or description;
- Contact and financial information, including phone number, address, email address, financial information
- Characteristics of protected classifications under state or federal law, such as age, gender, race, physical or mental health conditions, and marital status;
- Internet or other electronic network activity information, such as browsing history and interactions with our websites or advertisements;
- Audio, electronic, visual and similar information, such as call and video recordings;
- Professional or employment-related information, such as work history and prior employer;
- Education information, as defined in the federal Family Educational Rights and Privacy Act, such as student records and directory information;
- Inferences drawn from any of the Personal Information listed above to create a profile or summary about, for example, an individual’s preferences and characteristics; and
- Sensitive Personal Information, including:
- Personal Information that reveals:
- Social security, driver’s license, state identification card, or passport number;
- Racial or ethnic origin
- Contents of a Consumer’s email and text messages, unless the business is the intended recipient thereof
- Categories of Applicant Personal Information We Disclose to Service Providers & Third Parties
In the past twelve months, we have disclosed the following categories of Applicant Personal Information to Service Providers and Third Parties for a business purpose:
- Identifiers, such as name, alias, online identifiers, account name, physical characteristics or description;
- Contact and financial information, including phone number, address, email address, financial information, medical information, health insurance information;
- Characteristics of protected classifications under state or federal law, such as age, gender, race, physical or mental health conditions, and marital status;
- Commercial information, such as transaction information and purchase history;
- Internet or other electronic network activity information, such as browsing history and interactions with our websites or advertisements;
- Audio, electronic, visual and similar information, such as call and video recordings;
- Professional or employment-related information, such as work history and prior employer;
- Education information, as defined in the federal Family Educational Rights and Privacy Act, such as student records and directory information;
- Inferences drawn from any of the Personal Information listed above to create a profile or summary about, for example, an individual’s preferences and characteristics; and
- Sensitive Personal Information, including:
- Personal Information that reveals:
- Social security, driver’s license, state identification card, or passport number;
- Account log-in, financial account number, debit card number, or credit card number in combination with any required security or access code, password, or credentials for allowing access to an account;
- Racial or ethnic origin
- Contents of a Consumer’s email and text messages, unless the business is the intended recipient thereof; or
- Personal Information Collected and analyzed concerning a Consumer’s health; and
- Purposes for Processing & Disclosing Applicant Personal Information
We, and our Service Providers, Collect and Process Applicant Personal Information (excluding Sensitive Personal Information) described in this Policy to:
- Evaluate a potential Employee relationship with you;
- Perform background checks and verify past employment, educational history, professional standing, and other qualifications;
- Evaluate, determine, and arrange compensation, payroll, and benefits;
- Assess your fitness and physical capacity for work; and
- Contact you regarding your application and potential Employee relationship with us.
In addition to the purposes identified above, Thomas may use and disclose any and all Applicant Personal Information that we Collect as necessary or appropriate to:
- Comply with laws and regulations, including, without limitation, applicable tax, health and safety, anti-discrimination, immigration, labor and employment, and social welfare laws;
- Monitor, investigate, and enforce compliance with and potential breaches of Thomas policies and procedures and legal and regulatory requirements;
- Comply with civil, criminal, judicial, or regulatory inquiries, investigations, subpoenas, or summons; and
- Exercise or defend the legal rights of Thomas and its employees, affiliates, customers, contractors, and agents.
C. EMPLOYEES
- Collection & Processing of Personal Information
We, and our Service Providers, may have Collected and Processed the following categories of Personal Information from Employees in the preceding 12 months:
- Identifiers, such as name, alias, online identifiers, account name, physical characteristics or description;
- Contact and financial information, including phone number, address, email address, financial information, medical information, health insurance information;
- Characteristics of protected classifications under state or federal law, such as age, gender, race, physical or mental health conditions, and marital status;
- Commercial information, such as transaction information and purchase history;
- Internet or other electronic network activity information, such as browsing history and interactions with our websites or advertisements;
- Geolocation data, such as device location;
- Audio, electronic, visual and similar information, such as call and video recordings;
- Professional or employment-related information, such as work history and prior employer;
- Education information, as defined in the federal Family Educational Rights and Privacy Act, such as student records and directory information;
- Inferences drawn from any of the Personal Information listed above to create a profile or summary about, for example, an individual’s preferences and characteristics; and
- Sensitive Personal Information, including:
- Personal Information that reveals:
- Social security, driver’s license, state identification card, or passport number;
- Account log-in, financial account number, debit card number, or credit card number in combination with any required security or access code, password, or credentials for allowing access to an account;
- Precise geolocation;
- Racial or ethnic origin, religious or philosophical beliefs, or union membership;
- Contents of a Consumer’s email and text messages, unless the business is the intended recipient thereof; or
- Personal Information Collected and analyzed concerning a Consumer’s health; and
- Categories of Employee Personal Information We Disclose to Service Providers & Third Parties
In the past twelve months, we have disclosed the following categories of Employee Personal Information to Service Providers and Third Parties for a business purpose:
- Identifiers, such as name, alias, online identifiers, account name, physical characteristics or description;
- Contact and financial information, including phone number, address, email address, financial information, medical information, health insurance information;
- Characteristics of protected classifications under state or federal law, such as age, gender, race, physical or mental health conditions, and marital status;
- Commercial information, such as transaction information and purchase history;
- Internet or other electronic network activity information, such as browsing history and interactions with our websites or advertisements;
- Geolocation data, such as device location;
- Audio, electronic, visual and similar information, such as call and video recordings;
- Professional or employment-related information, such as work history and prior employer;
- Education information, as defined in the federal Family Educational Rights and Privacy Act, such as student records and directory information;
- Inferences drawn from any of the Personal Information listed above to create a profile or summary about, for example, an individual’s preferences and characteristics; and
- Sensitive Personal Information, including:
- Personal Information that reveals:
- Social security, driver’s license, state identification card, or passport number;
- Account log-in, financial account number, debit card number, or credit card number in combination with any required security or access code, password, or credentials for allowing access to an account;
- Precise geolocation;
- Racial or ethnic origin, religious or philosophical beliefs, or union membership;
- Contents of a Consumer’s email and text messages, unless the business is the intended recipient thereof; or
- Genetic data.
- Personal Information Collected and analyzed concerning a Consumer’s health; and
- Purposes for Processing & Disclosing Employee Personal Information
We, and our Service Providers, Collect and Process Employee Personal Information (excluding Sensitive Personal Information) described in this Policy to:
- Manage your Employee relationship with us;
- Manage and provide compensation, payroll, tax, and benefits planning, enrollment, and administration;
- Provide you access to Thomas systems, networks, databases, equipment, and facilities;
- Manage our workforce and its performance, including personnel planning, productivity monitoring, and evaluation;
- Manage workforce development, education, training, and certification;
- Monitor, maintain, and secure Thomas systems, networks, databases, equipment, and facilities;
- Authenticate your identity and verify your access permissions;
- Arrange, confirm, and monitor work-related travel, events, meetings, and other activities;
- Assess your working capacity or the diagnosis, treatment, or care of a condition impacting your fitness for work, and other preventative or occupational medicine purposes (including work-related injury and illness reporting);
- Contact and communicate with you regarding your employment, job performance, compensation, and benefits, or in the event of a natural disaster or other emergency;
- Contact and communicate with your designated emergency contact(s) in the event of an emergency, illness, or absence; and
- Contact and communicate with your dependents and designated beneficiaries in the event of an emergency or in connection with your benefits.
In addition to the purposes identified above, Thomas may use and disclose any and all Employee Personal Information that we Collect as necessary or appropriate to:
- Comply with laws and regulations, including (without limitation) applicable tax, health and safety, anti-discrimination, immigration, labor and employment, and social welfare laws;
- Monitor, investigate, and enforce compliance with and potential breaches of Thomas policies and procedures and legal and regulatory requirements;
- Comply with civil, criminal, judicial, or regulatory inquiries, investigations, subpoenas, or summons; and
- Exercise or defend the legal rights of Thomas and its employees, affiliates, customers, contractors, and agents.
D. PROCESSING SENSITIVE PERSONAL INFORMATION
We, and our Service Providers, Collect and Process the Sensitive Personal Information described in this Policy only as reasonably necessary for:
- Performing the services or providing the goods reasonably expected by an average Consumer who requests those goods or services (including offering benefits to employees and their beneficiaries);
- Preventing, detecting, and investigating security incidents that compromise the availability, authenticity, integrity, or confidentiality of stored or transmitted Personal Information;
- Resisting malicious, deceptive, fraudulent, or illegal actions directed at us and prosecuting those responsible for those actions;
- Ensuring the physical safety of natural persons;
- Short-term, transient use, including, but not limited to, nonpersonalized advertising shown as part of a Consumer’s current interaction with us, provided that we will not disclose the Consumer’s Personal Information to a Third Party and/or not build a profile about the Consumer or otherwise alter the Consumer’s experience outside the current interaction with the business;
- Performing services on our behalf, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on our behalf;
- Verifying or maintaining the quality or safety of a product, service, or device that is owned, manufactured, manufactured for, or controlled by us, and to improve, upgrade, or enhance the service or device that is owned, manufactured by, manufactured for, or controlled by us;
- Collecting or processing Sensitive Personal Information where such collection or processing is not for the purpose of inferring characteristics about a consumer.
E. SOURCES FROM WHICH WE COLLECT APPLICANT AND EMPLOYEE PERSONAL INFORMATION
We Collect Personal Information directly from all Applicants and Employees, including Personal Information about Employees’ beneficiaries or dependents. We also Collect Personal Information from joint marketing partners, public databases, providers of demographic data, publications, professional organizations, educational institutions, social media platforms, Service Providers and Third Parties that help us screen and onboard individuals for hiring purposes, and Service Providers and Third Parties when they disclose information to us.
F. CATEGORIES OF ENTITIES TO WHOM WE DISCLOSE APPLICANT AND EMPLOYEE PERSONAL INFORMATION
- Affiliates & Service Providers. We may disclose each of the categories of Applicant and Employee Personal Information described above to our affiliates and Service Providers for the purposes described in Sections B and C, respectively, of this Policy. Our Service Providers provide us with Applicant selection and related hiring services, benefits and wellness services, website services, as well as other products and services, such as web hosting, data analysis, customer service, infrastructure services, technology services, email delivery services, legal services, and other similar services. We grant our Service Providers access to Personal Information only to the extent needed for them to perform their functions, and require them to protect the confidentiality and security of such information.
- Third Parties. For each category of Personal Information identified in Sections B and C under the headers “Categories of Applicant Personal Information We Disclose to Service Providers & Third Parties,” and “Categories of Employee Personal Information We Disclose to Service Providers & Third Parties,” we disclose such Personal Information to the following categories of Third Parties:
- At Your Direction. We may disclose your Personal Information to any Third Party with your consent or at your direction.
- Business Transfers or Assignments. We may disclose your Personal Information to other entities as reasonably necessary to facilitate a merger, sale, joint venture or collaboration, assignment, transfer, or other disposition of all or any portion of our business, assets, or stock (including in connection with any bankruptcy or similar proceedings).
- Legal and Regulatory. We may disclose your Personal Information to government authorities, including regulatory agencies and courts, as reasonably necessary for our business operational purposes, to assert and defend legal claims, and otherwise as permitted or required by law.
G. DATA SUBJECT RIGHTS
- Data Subject Rights Available to You. As an Applicant or Employee, you have the following rights regarding our Collection and use of your Personal Information, subject to certain exceptions:
- Right to Receive Information on Privacy Practices: You have the right to receive the following information at or before the point of Collection:
- The categories of Personal Information to be Collected;
- The purposes for which the categories of Personal Information are Collected or used;
- Whether or not that Personal Information is Sold or Shared;
- If the business Collects Sensitive Personal Information, the categories of Sensitive Personal Information to be Collected, the purposes for which it is Collected or used, and whether that information is Sold or Shared; and
- The length of time the business intends to retain each category of Personal Information, or if that is not possible, the criteria used to determine that period.
We have provided such information in this Policy, and you may request further information about our privacy practices by contacting us as at the contact information provided below.
- Right to Deletion: You may request that we delete any Personal Information about you that we Collected from you.
- Right to Correction: You may request that we correct any inaccurate Personal Information we maintain about you.
- Right to Know: You may request that we provide you with the following information about how we have handled your Personal Information:
- The categories of Personal Information we Collected about you;
- The categories of sources from which we Collected such Personal Information;
- The business or commercial purpose for Collecting, Selling, Sharing, or disclosing Personal Information about you;
- The categories of Third Parties with whom we disclosed such Personal Information; and
- The specific pieces of Personal Information we have Collected about you.
- Right to Receive Information About Onward Disclosures: You may request that we disclose to you:
- The categories of Personal Information that we have Collected about you;
- The categories of Personal Information that we have Sold or Shared about you and the categories of Third Parties to whom the Personal Information was Sold or Shared; and
- The categories of Personal Information we have disclosed about you for a business purpose and the categories of persons to whom it was disclosed for a business purpose.
- Right to Non-Discrimination: You have the right not to be discriminated against for exercising your data subject rights. We will not discriminate against you for exercising your data subject rights. For example, we will not make hiring, firing, promotion, or disciplinary decisions based on or in consideration of your exercise of your data subject rights. We also will not deny goods or services to you, charge you different prices or rates, or provide a different level of quality for products or services as a result of you exercising your data subject rights.
- Rights to Opt-Out of the Sale and Sharing of Your Personal Information and to Limit the Use of Your Sensitive Personal Information: You have the right to opt-out of the Sale and Sharing of your Personal Information. You also have the right to limit the use of your Sensitive Personal Information to the purposes authorized by the CCPA. We have not Sold or Shared Personal Information in the past twelve months. Further, we do not use Sensitive Personal Information for purposes beyond those authorized by the CCPA. Relatedly, we do not have actual knowledge that we Sell or Share Personal Information of California Consumers under 16 years of age. For purposes of the CCPA, a “Sale” is the disclosure of Personal Information to a Third Party for monetary or other valuable consideration, and a “Share” is the disclosure of Personal Information to a Third Party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration.
- Opt-Out Preference Signals. We do not sell or share Personal Information, or use or disclose Sensitive Personal Information for purposes other than those authorized by the CPRA and its implementing regulations, as listed in Section D. Accordingly, we do not process opt-out preference signals. If we process opt-out preference signals in the future, we will update this policy to provide details about how we do so.
- Exercising Data Subject Rights. Applicants and Employees may exercise your data subject rights or submit a request by contacting Elizabeth Nolan, SVP, Human Resources at [email protected], by calling 1-833-544-7447, or by clicking Thomas Scientific - Contact Us. You may also authorize an agent to make a data subject request on your behalf, and the authorized agent may do so via the above-listed submission methods.
- Verification of Data Subject Requests. We may ask you to provide information that will enable us to verify your identity in order to comply with your data subject request. In particular, if you authorize an agent to make a request on your behalf, we may require the agent to provide proof of signed permission from you to submit the request, or we may require you to verify your own identity to us or confirm with us that you provided the agent with permission to submit the request. In some instances, we may decline to honor your request if an exception applies under the CCPA. We will respond to your request consistent with applicable law.
H. OTHER DISCLOSURES
- Retention of Personal Information: We retain each of the above-listed categories of Personal Information listed in Sections B and C for the duration of your Applicant and/or Employee relationship with us, as applicable, and longer as may be required by applicable laws or necessary for our legitimate business purposes.
- Financial Incentives for California Consumers. Under California law, we do not provide financial incentives to California Consumers who allow us to Collect, retain, Sell, or Share their Personal Information. We will describe such programs to you if and when we offer them to you.
- Changes to this Policy. We reserve the right to amend this Policy at our discretion and at any time. When we make material changes to this Policy, we will notify you by posting an updated Policy on our website and listing the effective date of such updates.
- Contact Us: More information about our privacy practices can be found in our Consumer Privacy Policy, available at https://www.thomassci.com/privacy. If you have any questions regarding this Policy or Thomas’s Collection and use of your Personal Information, or would like to exercise your data subject rights or submit a request under the CCPA, please call or email Elizabeth Nolan, SVP, Human Resources, or by calling at 1-833-544-7447, or email [email protected], or by clicking Thomas Scientific - Contact Us. If you are unable to review or access this notice due to a disability, you may contact Thomas’s Elizabeth Nolan, SVP, Human Resources, at [email protected] to access this notice in an alternative format.