Legacy Privacy Policy

LifeWorks GLOBAL LEGACY PRIVACY POLICY 

Section 1. About this Policy
LifeWorks (“LifeWorks,” “we,” “us,” and “our”) is committed to protecting your privacy.  This Privacy Policy (this “Policy”) describes how LifeWorks collects, uses, shares, and secures the information that LifeWorks collects from users who visit and use LifeWorks websites (the “Website”), its mobile application (the “App”), and the LifeWorks services provided through these platforms (the “LifeWorks Services”), which are described below.

Depending on your employer’s subscription you may have access to all or some of the following LifeWorks Services through our Website and/or App:

  • A social environment and news feed where you can interact with co-workers, post content and messages, provide feedback, and receive content (including articles and blog posts) (the “News Feed”);

  • A rewards and perks platform through which you can access discounts and offers on a range of products provided by our network of third party partners (“Work & Perks”); and

  • A counselling and well-being service (the “EAP & Wellness Services”) through which you can access various wellness resources, assessments, and our Employee Assistance Program, which may include counseling sessions with trained health professionals, (collectively, “EAP Counsellors”).

This Policy covers only LifeWorks practices with respect to your use of the LifeWorks Services.  We do not control the privacy practices of third parties, including your employers or any insurers that offer access to the LifeWorks Services through your employer.

LifeWorks collects, uses, shares, and secures information in accordance with applicable data protection laws, including but not limited to: the Health Insurance Portability and Accountability Act (“HIPAA”), the Personal Information Protection and Electronic Documents Act (“PIPEDA”), and the EU General Data Protection Regulation (“GDPR”).

Section 2. Contact Details
EU Users - For users in the EU (including the UK), our full details are:

Full name of legal entity:

Work Angel Technologies Ltd, t/a LifeWorks

(Reg. No. 08223675)

 

Email address:

privacy@lifeworks.com

 

Postal address:

c/o LifeWorks

The Glassmill, 4th Floor

1 Battersea Bridge Road

London, SW11 3BZ

United Kingdom

 

Telephone number:

+44 (0) 20 3567 5900

 

Name or title of DPO:

Aphaia Ltd (which can be contacted at privacy@lifeworks.com)

 

Studio 5
155 Commercial St
London E1 6BJ

 

+44 (0) 20 3290 4231

For the purposes of EU data protection law, including the GDPR, LifeWorks US Inc. is the data controller and responsible for your Personal Information.

US Users - For users in the United States of America, our full details are:

Full name of legal entity:

LifeWorks US Inc.

Email address:

privacy@lifeworks.com

Postal address:

201 17th Street NW, Suite 630

Atlanta, Georgia  30363

USA

Telephone number:

+1 (877) 409-9287

Canadian Users - For users in Canada, our full details are: 

Full name of legal entity:

LifeWorks Canada Ltd.

MieuxVivre Canada Ltée

Email address:

privacy@lifeworks.com

Postal address:

675 Cochrane Drive

5th Floor – North Tower

Markham, Ontario L3R 0B8

Canada

Telephone number:

+1 (866) 267-6255

If you wish to make a complaint to the relevant regulatory authority for data protection issues, please see Section 16. We would, however, appreciate the opportunity to review and address your concerns before you approach any regulatory authority so please contact us in the first instance.

Section 3. Changes to this Policy and Your Duty to Inform us of Changes
It is important that the Personal Information we hold about you is accurate and current. Please keep us informed if the Personal Information you provided changes during your relationship with us.

LifeWorks may update this Policy to reflect changes to our information practices.  If LifeWorks makes any material changes to our Policy, those changes will apply to information we have already collected from you unless we are required to obtain your consent before making those changes.  LifeWorks will endeavor to notify you of material changes; nevertheless we encourage you to periodically review this page for the latest information on this Policy.

Section 4. Third Party Links and Other Sites
Our Website, App, and email communications may link to third party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share information about you. When you leave our Website or App, we encourage you to read the privacy policies of every website or application you visit.  The websites or email communications of third parties may also link to our Website. LifeWorks is not responsible for the user terms, privacy policies or data practices of third parties, and information collected by third parties is not governed by this Policy. 

Section 5. What Information Does LifeWorks Collect About You?
LifeWorks collects both Personal and Anonymous Information from you:

  • Personal Information” means any information about an individual from which that person can be directly or indirectly identified and includes, where applicable, Sensitive Personal Information (as defined below).

  • Anonymous Information” means information that does not and cannot directly or indirectly identify you. This includes Personal Information which has been anonymized or de-identified.

This Policy informs you about how we collect Personal Information about you.  In order to operate our Website and App, LifeWorks collects, uses, stores and transfers different kinds of Personal Information about you which may include the following categories of information:

  • Identity Information includes first name, maiden name, last name, username, employee number or similar identifier, marital status, job title, hire date, date of birth and reported gender. 

  • Contact Information includes billing address, postal address, email address and telephone numbers.

  • Financial Information includes bank account, Paypal email address and payment card details.

  • Transaction Information includes details about payments to and from you and other details of products and services you have purchased through our Website and/or our App.

  • Technical Information includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our Website and/or our App.

  • Profile Information includes your username and password, purchases or orders made by you through our Website or App, your interests, preferences, feedback, comments and survey responses within our Website and/or App.

  • Usage Information includes information about how you use our Website, our App, and our products and services.

  • Sensitive Personal Information means:

  • Health Information such as information regarding your physical and/or mental health which we receive including in connection with your use of the EAP & Wellness Services;

  • Claims Information such as information disclosed to us by your insurance or health plan provider regarding claims you have made under your policy, which may include Health Information; and

  • Other Sensitive Personal Information you disclose to us about your race, ethnicity, sexual orientation, sex life, genetic data, biometric data (including data from wearable technology such as pedometers, heart rate monitors, etc.), religious or philosophical beliefs, political opinions or trade union membership.

Please note that the above list is a summary description of the types of data we may collect from you, or about you.  Whether or not we actually obtain any such information depends on what LifeWorks Services your employer chooses to make available to you, what LifeWorks Services you choose to participate in, and what information you choose to provide to us by using the LifeWorks Services available to you.

We also collect, use and share “aggregated information” such as statistical or demographic information for any purpose. Aggregated information may be derived from your Personal Information but is not considered Personal Information in law as this information does not directly or indirectly reveal your identity. However, if we combine or connect aggregated information with your Personal Information so that it can directly or indirectly identify you, we treat the combined information as Personal Information which will be used in accordance with this Policy.

Section 6. What If You Choose Not to Provide Personal Information?
Where we need to collect Personal Information by law, or under the terms of a contract we have with you and you fail to provide that information when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with the LifeWorks Services). In this case, we may have to cancel the relevant LifeWorks Services you have with us but we will notify you if this is the case at the time.

Section 7. Personal Information of Minors 
LifeWorks Website and App are not directed toward children. We do not knowingly collect, use or post Personal Information from children under the age of thirteen (13). If we determine upon collection that a user is under this age, we will not use or maintain his or her Personal Information without parent or guardian/custodian consent. If we become aware that we have unknowingly collected Personal Information from a child under the age of thirteen (13), we will make commercially reasonable efforts to delete such information from our records. In order for any child under the age of thirteen (13) to access any of our EAP & Wellness Services, the parent or guardian/custodian of such child must contact LifeWorks on their behalf.

Section 8. How Does LifeWorks Collect Your Personal Information?
LifeWorks collects Personal Information only for the purposes of providing and promoting the LifeWorks Services, including initiating, maintaining, enhancing, and terminating the employee-employer relationship (please see Section 9)

We use different methods to collect information from and about you including: 

  • Direct interactions: You may give us your Personal Information by filling in forms (including online forms) or by corresponding with us by conventional post (or mail), phone, email or otherwise. This includes Personal Information you provide when you:

  • create an account through our Website or App
  • make booking requests or perform other transactions through our Website or App, including Work & Perks products and rewards;
  • report a problem or submit queries, concerns or comments regarding the content on our Website or App;
  • enter a competition, promotion or survey that LifeWorks may from time to time run on the Website or App or through a separate service;
  • post on our Website or App, including in the form of comments or contributions to discussions;
  • request sessions with an EAP Counsellor;
  • request to participate in a chat and/or video sessions;
  • give us feedback; or
  • request marketing materials to be sent to you.

Automated technologies or interactions: As you interact with our Website or App, we may automatically collect Technical Information (including your location) about your equipment, browsing actions and patterns. We collect this Personal Information by using cookies, server logs and other similar technologies. We may also receive Technical Information about you if you visit other websites employing our cookies. Please see our cookies policy.

  • Third parties: We may receive Personal Information about you from various third parties, including EAP Counsellors in relation to your use of our EAP & Wellness Services and web traffic analytics providers such as Google Analytics.

  • Surveys: When you visit LifeWorks Website or App, LifeWorks may ask you to complete a survey telling LifeWorks about your experience. All survey responses are anonymous, but you may choose to provide your name and contact information so that LifeWorks can follow up with you on any comments.

  • Web Server Logs: The internet connected device that delivers our Website to you (for example, a computer, tablet or smartphone) records information about your visit.  For example, the web server log records your IP address, your Internet browser type, version and language, your operating system, your display’s screen size, the date and time of your visit and the pages you visit on our Website.

Section 9. How and Why Does LifeWorks Use Your Personal Information?
We only use your Personal Information when the law in your jurisdiction allows us to. We use your Personal Information for the purposes set out in the chart below (see “Purpose/Activity”).

EU data protection law requires us to be specific about our reasons or legal grounds for using your Personal Information. Accordingly, for EU users only, we identify the following grounds for using your Personal Information:

  • where we need to perform the contract we are about to enter into or have entered into with you (“Contract Performance”) (for example, the User Terms you agree to when you create an Account is a contract between you and LifeWorks);

  • where it is necessary for our legitimate interests (i.e. we have a legitimate business or commercial reason for using your information), and your interests and your fundamental rights do not override those interests (our “Legitimate Interests”);

  • where we need to comply with a legal or regulatory obligation (our “Legal Obligation”); and/or

  • where you have provided your general consent (“Consent”) or, in the case of Sensitive Personal Information, when you have provided your explicit consent to our collection of that Sensitive Personal Information (“Explicit Consent”).

Set forth below is a description of the ways we will use your Personal Information and, for EU users only, the grounds we may rely on to do so, including our Legitimate Interests. Please note that we may process your Personal Information for more than one ground depending on the specific purpose for which we are using your information. Please contact us if you need details about the specific ground we are relying on to process your Personal Information where more than one ground has been set out in the table below. 

Except for the purposes for which we use your Personal Information set out in the “Purpose/Activity” column, nothing in the chart below is intended to bind LifeWorks in respect of its non-EU users.

Purpose/Activity

(All users)

Reason/Legal Ground

(EU users only)

Legitimate Interest

(EU users only)

Create and administer your account when you register

•  Contract Performance

•  Legitimate Interests

•  Efficiently fulfilling our legal and contractual duties

•  Providing high quality customer service

Identify you when you sign in to your account for authentication purposes, including matching you with your employer information in order to confirm that you are employed with them

•  Contract Performance

•  Legitimate Interests

•  Efficiently fulfilling our legal and contractual duties

•  Providing high quality customer service

To communicate with you and respond to your inquiries, including responding to and resolving complaints

•  Contract Performance

•  Legitimate Interests

•  Legal Obligation

•  Complying with regulations that apply to us

•  Efficiently fulfilling our legal and contractual duties

•  Providing high quality customer service

To enable LifeWorks to process your orders through our Website or App, including in relation to Work & Perks, and to provide you with the services and information which you request

•  Contract Performance

•  Legitimate Interests

•  Efficiently fulfilling our legal and contractual duties

•  Providing high quality customer service

•  Providing our customers with high quality products, services and features

To administer auditing, billing and reconciliation activities and other financial and payment-related functions (including verification) in relation to payments you make through our Website or App

•  Contract Performance

•  Legitimate Interests

•  Legal Obligation

•  Efficiently fulfilling our legal and contractual duties

To exercise our rights in agreements and contracts to which we are a party

•  Contract Performance

•  Legitimate Interests

•  Efficiently fulfilling our legal and contractual duties

To collect your real-time location to provide location services requested by you

•  Consent

•  Contract Performance

•  Legitimate Interests

•  Providing our customers with high quality products, services and features

•  Keeping our products, services and features updated and relevant

To collect information relating to the recognition of other users and colleagues (NOTE: such information can be viewed by other users and your employer)

•  Legitimate Interests

•  Contract Performance

•  Providing high quality customer service

•  Providing our customers with high quality products, services and features

•  Keeping our products, services and features updated and relevant

To send you information LifeWorks thinks you (or your employer, in the case of authorized administrators) may find useful or which you have requested from LifeWorks, including receipt of marketing communications such as our periodic newsletter and information about our products and services

•  Consent

•  Explicit Consent

•  Contract Performance

•  Legitimate Interests

•  Developing products and services, and adjusting what we charge for them

•  Defining types of customers for new products or services.

•  Seeking your consent when we need it to contact you

To conduct research and analysis to improve the quality of our marketing and the experience of and relationships with our customers

•  Consent

•  Explicit Consent

•  Legitimate Interests

•  Developing products and services, and adjusting what we charge for them

•  Keeping our products, services and features updated and relevant

To provide anonymized aggregate transaction data to your employer (subject to our contract with your employer) for the purpose of informing the employer about its employees’ preferred retailers and offers

 

•  Contract Performance

•  Legitimate Interests

 

•  Providing high quality customer service

•  Efficiently fulfilling our legal and contractual duties

 

To log EAP & Wellness Services activities and provide anonymized summaries to LifeWorks employer clients for reporting purposes

 

•  Contract Performance

•  Legitimate Interests

•  Legal Obligation

•  Efficiently fulfilling our legal and contractual duties

•  Providing high quality customer service

•  Providing our customers with high quality products, services and features

To provide you with counselling and well-being treatment as part of our EAP & Wellness Services

•  Explicit Consent

•  Contract Performance

•  Legal Obligation

•  Providing our customers with high quality products, services and features

To analyse your Personal Information, including Sensitive Personal Information which we may receive through your use of our EAP & Wellness Services or which we may predict about you from other Personal Information about you or based on your use of our Website or the App, to provide you with personalized content and recommended features on LifeWorks News Feed

•  Explicit Consent

•  Legitimate Interests

•  Providing our customers with high quality products, services and features

•  Keeping our products, services and features updated and relevant

To analyse your Personal Information, including Sensitive Personal Information which we may receive through your use of our EAP & Wellness Services or which we may predict about you from other Personal Information about you or based on your use of our Website or the App, to provide you with offers and rewards as part of our Work & Perks service

•  Explicit Consent

•  Legitimate Interests

• Providing our customers with high quality products, services and features

•  Keeping our products, services and features updated and relevant

To analyse your Claims Information (which you may permit LifeWorks to receive from your insurance provider) to provide you with personalized content and recommended features on LifeWorks News Feed and as part of our Work & Perks services, including combining your Claims Information with other information about you, to predict content and features which are most relevant to you across the LifeWorks Services

•  Explicit Consent

•  Legitimate Interests

•  Providing our customers with high quality products, services and features

•  Keeping our products, services and features updated and relevant

To administer and protect the security of our business and the LifeWorks Website and App (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)

•  Contract Performance

•  Legitimate Interests

•  Legal Obligation

•  Developing and improving the network security, efficiency and technical specification of our IT systems and infrastructure

To develop, manage and improve the LifeWorks Services (including conducting research and analysis) and to test new products, services, and features of the Website or the App

•  Contract Performance

•  Legitimate Interests

•  Legal Obligation

•  Providing our customers with high quality products, services and features

Keeping our products, services and features updated and relevant.

To run our business in an efficient and proper way, including in respect of our financial position, business capability, corporate governance, audit, strategic planning and communications

•  Legitimate Interests

•  Legal Obligation

•  Complying with regulations that apply to us

•  Efficiently fulfilling our legal and contractual duties

Your Choices
Please see the subject headings below for more information about how and when LifeWorks uses your Personal Information:

  • Marketing: We strive to provide you with choices regarding certain Personal Information uses, particularly around marketing and advertising. One of the ways we use your Personal Information is to form a view on what we think you may want or need, or on what may be of interest to you and you may receive personalised content, including marketing communications, from us. We will provide you with the appropriate opt-out.  In addition, we will obtain your consent before we share your Personal Information with any person or entity outside the LifeWorks group of companies for marketing purposes.  You can ask us to stop sending you transactional messages at any time by logging into the Website or the App and checking or unchecking relevant boxes to adjust your preferences. You can ask us to stop sending you marketing emails by following the opt-out links on any marketing message sent to you or by contacting us at any time.

  • Cookies: You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of the LifeWorks Services may become inaccessible or not function properly. For more information about the cookies we use, please see our cookies policy.

  • Location Information: You may opt out at any time from allowing location access by LifeWorks to your location information in “Location Services” under the “Settings” tab in your account. You can also stop all information collection by uninstalling our App. You may use the standard uninstall processes as may be available as part of your mobile device or via the App market place network. 

  • Do Not Track Mechanisms: California law requires this Policy to address how we respond to any “Do-Not-Track (“DNT”) signal” delivered by your browser. Because of the changing state of technology and indecision within the industry regarding the meaning of DNT signals, we currently do not make any guarantee that we will honour DNT signals.

  • Change of Purpose: We will only use your Personal Information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.  If we need to use your Personal Information for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. 

PLEASE NOTE THAT WE MAY PROCESS YOUR PERSONAL INFORMATION WITHOUT YOUR KNOWLEDGE OR CONSENT WHERE THIS IS REQUIRED BY LAW.

Section 10. How Does LifeWorks Share Your Personal Information?
We require all third parties to respect the security of your Personal Information and to treat it in accordance with the law. We do not allow our third-party service providers to use your Personal Information for their own purposes and only permit them to process your Personal Information for specified purposes and in accordance with our instructions.

LifeWorks may have to share your Personal Information with the parties set out below for the purposes set out in the table above. In relation to the EAP & Wellness Services, LifeWorks will only disclose such Personal Information as is strictly needed for such services (e.g. name to start a live chat session).

  • LifeWorks Family: LifeWorks may disclose your Personal Information to any other LifeWorks entity, subject to applicable law. We may also disclose your Personal Information to our agents and contractors, who will only use your information to the extent necessary to perform their function. 

  • EAP Counsellors: LifeWorks shares your Personal Information, including your Sensitive Personal Information with EAP Counsellors who may provide you with wellbeing and counselling services and/or treatment as part of the EAP & Wellness Services.

  • Work & Perks Partners: LifeWorks may share your Personal Information with the companies that participate in LifeWorks Work & Perks service offering. These third parties provide products or services which may be of interest to you through LifeWorks Website and App.

  • Service Providers: LifeWorks may share your Personal Information with companies or individuals that provide us with services. These services may include, among other things, providing products or services to you or your employer on our behalf, creating or maintaining our databases, researching and analyzing the usage and performance of the Website or the App, preparing and distributing communications, and responding to inquiries. In relation to the EAP & Wellness Services, LifeWorks only shares anonymized information with such service providers.

  • General Public and Other Website or App Users: LifeWorks may decide to allow users to share comments, blog postings, testimonials, or other similar information.  If you choose to submit such information to LifeWorks, the information that you submit may be available generally to the public.  Information you provide in these areas of the Website and/or the App may be read, collected, and used by others who access them. LifeWorks may make the chat rooms, message boards, news groups and/or other forums on its Website and App available to all its users. Any information that is disclosed in these areas may be visible to others within your network (company). You should exercise caution when using these and never disclose your Personal Information or make any statement that you would not wish others to see.

  • Successor Organisations following a Business Transition: In the event that LifeWorks, or any portion of our assets, are acquired by a third party, LifeWorks may share your Personal Information with the acquiring company or business subject to applicable law.

  • Law Enforcement Agencies: LifeWorks may report to law enforcement agencies any activities that we are obligated to disclose under mandatory reporting rules, that we reasonably believe to be unlawful, or that we reasonably believe may aid a law enforcement investigation into unlawful activity. In addition, subject to applicable law, LifeWorks reserves the right to release your Personal Information to law enforcement agencies if LifeWorks determines that you have violated our policies or terms of use, or the release of your Personal Information may protect the rights, property, or safety of LifeWorks, its employees and agents or any other person. We may be required to disclose Personal Information in response to a legal inquiry by public authorities, including but not limited to meeting national security or law enforcement requirements. 

  • Government, Regulatory or Court Authorities: LifeWorks may share your Personal Information with governmental entities, regulatory authorities or third parties in response to subpoenas, court orders, other legal process, or as LifeWorks believe is necessary to exercise our legal rights, to defend against legal claims that have been brought against LifeWorks, or to defend against possible legal claims that LifeWorks determine might be brought against LifeWorks.

  • Third Party Operators of Online Applications and Tools available through our Website or App: LifeWorks offers tools and applications on our Website and App, such as chat and video technology, health assessments and calculators, wearable devices and financial calculators, that are powered by third parties. If you use those applications or tools, any Personal Information that you provide may be shared with the third party that provides that functionality.  The third party’s use of any Personal Information they collect is subject to their privacy policy.

  • Your Employer and Health Plan Provider: LifeWorks provides aggregated and statistical information to your employer or in some instances (and where applicable) your health plan provider. The aggregate information assists in program planning to improve the overall health of your employer’s employees, and/or to evaluate LifeWorks performance. In addition, your employer may have access to the News Feed and Work & Perks social media environment available to all of your co-workers for the purposes of offering and managing awards, incentives, competitions and similar features open to participants from your company.

Section 11. International Transfers – EU Users Only
We share your Personal Information within the LifeWorks group of companies. For EU residents, this means that we may transfer your data outside the European Economic Area (“EEA”). In addition, many of our external third parties are based outside the EEA so their processing of your Personal Information will involve a transfer of information outside the EEA. Whenever we transfer your Personal Information out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

  • we will only transfer your Personal Information to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission;

  • where we use certain service providers, we may use specific contracts approved by the European Commission which give Personal Information the same protection it has in Europe; or

  • where we use providers based in the US, we may transfer information to them if they are part of the Privacy Shield which requires them to provide similar protection to Personal Information shared between the Europe and the US.

Please contact us if you want further information on the specific mechanism used by us when transferring your Personal Information out of the EEA.

Section 12. LifeWorks Privacy Shield Certification
LifeWorks complies with the EU-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of Personal Information transferred from the European Union to the United States. LifeWorks has certified to the Department of Commerce that it adheres to the Privacy Shield Principles.  In particular, LifeWorks will comply, and will require its third party service providers to comply, with the Accountability for Onward Transfer principle in relation to any onward transfer of your Personal Information after it is transferred to the United States under the Privacy Shield. If there is any conflict between the terms in this Policy and the Privacy Shield Principles, the Privacy Shield Principles shall apply.  To learn more about the Privacy Shield program, and to view our certification, please visit https://www.privacyshield.gov/

In compliance with the Privacy Shield Principles, LifeWorks commits to resolve complaints about our collection or use of your Personal Information.  EU individuals with inquiries or complaints regarding our obligations under the Privacy Shield should first contact LifeWorks at: 

Name:

LifeWorks US Inc.

Address:

201 17th Street

Suite 630

Atlanta, GA 30363

USA

Email:

privacy@lifeworks.com

LifeWorks has further committed to refer unresolved Privacy Shield complaints to JAMS ADR (www.jamsadr.com), an alternative dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please contact or visit JAMS ADR for more information or to file a complaint.  The services of JAMS ADR are provided at no cost to you.

Name:

JAMS ADR

Address:

One Atlantic Center
1201 West Peachtree, NW, Suite 2650
Atlanta, GA 30309 
USA

Telephone:

+1(404) 588-0900

If you are not satisfied with the outcome of the above recourse mechanism, you may seek arbitration with us for certain residual claims (the “Arbitration Option”), to determine whether we as a Privacy Shield organization have violated our obligations under the Principles of the Privacy Shield, and whether any such violation remains fully or partially unresolved. The Arbitration Option is not available in certain circumstances such as disputes concerning the exceptions to the Privacy Shield Principles or claims questioning the adequacy of the Privacy Shield framework. Under the Arbitration Option, the Privacy Shield Panel (consisting of one or three arbitrators, as agreed by the parties) has the authority to impose individual-specific, non-monetary equitable relief (such as access, correction, deletion, or return of the individual’s data in question) necessary to remedy the violation of the Principles only with respect to you. In considering remedies, the arbitration panel is required to consider other remedies that already have been imposed by other mechanisms under the Privacy Shield.  No damages, costs, fees, or other remedies are available.  Each party bears its own attorney’s fees.

If you decide to invoke the Arbitration Option, you must take the following steps prior to initiating an arbitration claim: (1) raise the claimed violation directly with us and afford us the opportunity to resolve the issue within 45 days; (2) make use of the independent recourse mechanism referred to above, which is at no cost to you; and (3) raise the issue through your data protection authority to the Department of Commerce and afford the Department of Commerce an opportunity to use best efforts to resolve the issue within the timeframes set forth in the Letter from the International Trade Administration of the Department of Commerce, at no cost to the individual. 

Section 13. How Does LifeWorks Secure Your Personal Information?
We take reasonable steps to prevent your Personal Information from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your Personal Information to those employees, agents, contractors and other third parties who have a business need to know. They will only process your Personal Information on our instructions and they are subject to a duty of confidentiality. Furthermore, all LifeWorks employees, agents and contractors receive regular training on LifeWorks policies, procedures and standards on data protection and privacy. 

We also maintain procedures to deal with any suspected Personal Information breaches and will notify you and any applicable regulator of a breach where we are legally required to do so.

Section 14. How Long Does LifeWorks Retain Your Personal Information?
LifeWorks retains your Personal Information for only as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting or reporting requirements.

  • In certain cases (such as for information relating to the provision of EAP & Wellness Services (including Sensitive Personal Information)), LifeWorks retains your Personal Information for up to seven (7) years.

  • As part of the Work & Perks service, LifeWorks retains your Personal Information for the duration of the contract with our Work & Perks Partner. At the end of the contract, LifeWorks retains your information for an additional ninety (90) days to ensure all claims have been satisfied. 

In general, to determine the appropriate retention period for Personal Information, we consider the amount, nature, and sensitivity of the Personal Information, the potential risk of harm from unauthorised use or disclosure of your Personal Information, the purposes for which we process your Personal Information and whether we can achieve those purposes through other means, as well as the applicable legal requirements.

At the end of the applicable retention period, LifeWorks will either physically or electronically erase the Personal Information from our systems or will anonymize the Personal Information in a non-recoverable manner.

Section 15. What Rights Do You Have In Connection With Your Personal Information?
Depending on where you are located, you may have the following rights in connection with your Personal Information:

  • Right to withdraw consent at any time: This applies where we are relying on consent to process your Personal Information and you can exercise this right by contacting us using this form. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide the LifeWorks Services to you. We will advise you if this is the case at the time you withdraw your consent.
  • Request access to your Personal Information: This enables you to receive a copy of the Personal Information we hold about you and to check that it is accurate and that we are processing it lawfully. Where Personal Information is not made directly available to you, please contact us using this form

  • Object to our processing of your Personal Information: This enables you to object to processing of your Personal Information where we are relying on a legitimate interest and there is an impact on your fundamental rights and freedoms. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override certain of your rights and freedoms.

You also have the right to object where we are processing your Personal Information for direct marketing purposes, but this may prevent you from further using certain of our Services, including Works & Perk. The marketing emails we send you will provide you with the opportunity to unsubscribe.

  • Request correction of your Personal Information: This enables you to have any incomplete or inaccurate Personal Information we hold about you corrected, though we may need to verify the accuracy of the new Personal Information you provide to us.

  • Request erasure of your Personal Information: This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.

  • Request transfer of your Personal Information: This enables you to request the transfer of your Personal Information to you or to a third party. We will provide to you, or a third party you have chosen, your Personal Information in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

  • Request restriction of processing: This enables you to ask us to suspend the processing of your Personal Information in the following scenarios: (a) if you want us to establish the information’s accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the Personal Information even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your Personal Information but we need to verify whether we have overriding legitimate grounds to use it. 

  • Right not to be subject to a decision based on automated profiling: This applies where the automated processing produces legal effects on you or similarly significantly affects you. Note, it does not apply if the decision (a) is necessary for the us to perform any contracts between you and us, (b) is authorized by applicable law, or (c) is based on your Explicit Consent. However, where (a) or (c) applies, you have the right to obtain human intervention. You also have the right to be informed of the logic involved in such processes.

  • Make a complaint: You have the right to make a complaint at any time to the relevant regulator or data protection authority in the country in which you reside. Please see Section 16.

Please note that with the exception of “make a complaint”, you cannot request to exercise any of the above rights where your Personal Information has been anonymized or de-identified.

You will not have to pay a fee to access your Personal Information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.

We may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Information (or to exercise any of your other rights). This is a security measure to ensure that Personal Information is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response. 

We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

Section 16. Who Supervises LifeWorks’ Activities And How Do You Contact Them?
In the United States, LifeWorks US Inc., is subject to the investigatory and enforcement powers of the US Federal Trade Commission (FTC).  The FTC can be contacted by calling the FTC’s Consumer Response Center at 1-877-FTC-HELP (1-877-382-4357) or at https://www.ftc.gov/news-events/media-resources/identity-theft-and-data-security/filing-complaint.

In Canada, LifeWorks Canada Ltd. is subject to the Privacy Commissioner of Canada or the Privacy Commissioner in the applicable province: Office of the Privacy Commissioner of Canada, 30 Victoria Street, Gatineau, Quebec, K1A 1H3, Phone: 1-800-282-1376.

In the EU, Work Angel Technology Ltd (trading as LifeWorks), is supervised by the UK Information Commissioner’s Office, Phone: +44 1625 545 700, Email: https://ico.org.uk/global/contact-us/email/.

To contact other European data protection authorities directly see http://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm.   

We commit to cooperate with EU data protection authorities and comply with the advice given by such authorities with regard to human resources data transferred from the EU in the context of the employment relationship.

In Switzerland, we are subject to the Swiss Federal Data Protection and Information Commissioner, Office of the Federal Data Protection and Information Commissioner FDPIC, CH - 3003 Berne, Telephone: +41 (0)58 462 43 95.

Version: 2018.05.08  Please Direct Questions and Comments to:  privacy@lifeworks.com

 

* * *