Table of Contents:
SCOPE AND APPLICATION : What and who this Policy coversCOLLECTION OF INFORMATION : The sources of and methods by which we, our service providers, and our advertisers collect information from and about you, including information about your interaction with the Attain ServicesUSE AND DISCLOSURE : How we use the information we collect from and about you, and who we might share it with and whySECURITY AND COMPLIANCE : How we protect your information from loss or misuseUSER ACCESS AND CONTROL : How you can access and control the information we maintain about youCHILDREN'S PRIVACY : How Attain handles the personal information of users under 18 years of age.OTHER IMPORTANT INFORMATION : Other things you should know about this Policy and how we handle your informationCALIFORNIA PRIVACY RIGHTS ACT (CPRA) NOTICE : Other things you should know if you reside in CaliforniaADDITIONAL U.S. STATE PRIVACY RIGHTS : Other things you should know if you are a user residing in Virginia or other states with similar privacy laws.EMPLOYEE AND JOB APPLICANT PRIVACY NOTICE : How we collect and use data of current and prospective Attain employees and job applicants CONTACT US : How to contact Attain about this Policy1. SCOPE AND APPLICATION At Attain (“Attain” or “we”), we take your privacy seriously. This privacy policy governs and details the main privacy principles we apply to the data we collect through our website, www.attainoutcomes.com, and through business to business interactions conducted through the Attain website, products and services (“Attain Platform").
Attain would like you to be familiar with how we collect, use and disclose information from and about you. This Privacy Policy describes our practices in connection with this business-to-business website and content partner-related Site, and other Attain Services as further described in our Terms of Service (the “Attain Services”). California residents, please see the California Privacy Rights Act (CPRA) Notice in Section 8 below. By using or accessing our Services in any manner, you acknowledge that you accept the practices and policies outlined below, and you hereby consent to our collection, use and share your information as described in this Privacy Policy.
Remember that your use of Attain’s Services is at all times subject to our Terms of Service , which incorporates this Privacy Policy. Any terms we use in this Policy without defining them have the definitions given to them in our Terms of Service .
The Attain Services are not targeted to children, and Attain does not knowingly collect personal information from children under 18 years of age.
This Privacy Policy applies to Attain’s collection and use of its Business to Business partners’ personal information (i.e., information that identifies a specific person, such as full name or e-mail address). It also describes generally Attain’s practices for handling non-personal information (for example, demographics and services usage). If you are a consumer and would like more information regarding Attain’s use of your data, please see the Attain Consumer Privacy Policy .
2. COLLECTION OF INFORMATION Collection : We collect personally identifiable information, such as your name, phone number, company name and email address, directly from you when you choose to enter it on our website, for instance when you complete the “Contact Us” form or when you submit your information to register to learn more about the Attain Services, for example, to create an account, register for, or participate in an event, such as a webinar, conference or seminar, or receive a newsletter.
Attain may additionally collect data about you if you download our mobile application or use a location-enabled browser. If you download and install certain applications and software that we make available, we may receive and collect information transmitted from your device for the purpose of providing you the relevant Attain Services, such as information regarding when you are logged on and available to receive updates or alert notices.
Passive Collection : As is true of most websites, we gather certain information automatically. This information may include Internet protocol (IP) addresses, browser type, Internet service provider (ISP), referring/exit pages, the files viewed on our site (e.g., HTML pages, graphics, etc.), operating system, date/time stamp, and/or clickstream data to analyze trends in the aggregate and administer the site.
Tracking Technologies : Attain and our partners use cookies and similar technologies to analyze trends, administer the website, and track users’ movements around the website. We use cookies which are small text files stored on a user’s computer. The cookies store non-personally identifiable information related to your navigation on our website. Please consult the "Help" section of your browser for more information, including on how to clear data from local storage and, depending on your browser, how to turn off other data collection by the browser. Please note that by blocking any or all cookies, you may not have access to certain features, content or personalization available through the Attain Services.
Our cookies are placed for the following purposes:
Personalization of your navigation. These cookies enable us to recognize you and remember any information you have entered during your navigation on our website (such as language choice, country you are browsing from, or browser type). This makes your visit on our website easier as we don’t ask you the same information several times during your navigation. For example, Google LLC (“Google”) uses cookies in connection with its Google Analytics services. Google’s ability to use and disclose information collected by Google Analytics about your visits to the Services is subject to the Google Analytics Terms of Use and the Google Privacy Policy. You have the option to opt-out of Google’s use of Cookies by visiting the Google Analytics Opt-out Browser Add-on at https://tools.google.com/dlpage/gaoptout/ . Demonstration page. These cookies are used for our advertising service, but on our website, we do not use these cookies to serve personalized advertisements. These cookies enable us to deliver our demonstration page that illustrates how our advertising service is running. Your browser may be initially set to accept cookies, but you can change your settings to notify you when a cookie is being set or updated, and to block cookies altogether. Please consult the "Help" section of your browser for more information, including on how to clear data from local storage and, depending on your browser, how to turn off other data collection by the browser. Please note that by blocking any or all cookies, you may not have access to certain features, content or personalization available through the Attain Services.
You can always find information and update your cookies settings to accept or reject them by visiting the Cookie Policy page at the bottom of each page of the site. To explore what Cookie settings are available to you or to modify your preferences with respect to Cookies, you can access your Cookie management setting by clicking the Cookie icon in the bottom left-hand corner of this screen. To find out more information about Cookies, including information about how to manage and delete Cookies, please visit http://www.allaboutcookies.org/ .
Third Parties : We may use analytics providers to analyze how you interact and engage with the Services, or third parties to help us provide you with a better experience.
Search Engine Marketing : We use Google AdWords service to advertise on the Google search result page. Google uses cookies to serve ads based on your past visits on our website. For more information on Google AdWords services and how to opt-out, please refer to Google specific privacy policy and settings for Google ads .
Data that is Not Personal Information: We may create aggregated, de-identified or anonymized data from the Personal Information we collect, including by removing information that makes the data personally identifiable to a particular user. We may use such aggregated, de-identified or anonymized data and disclose it to third parties for our lawful business purposes, including to analyze, build and improve the Services and promote our business, provided that we will not disclose such data in a manner that could identify you.
3. USE AND DISCLOSURE We may use the information we collect from and about you to provide the Attain Services and features to you, including: to measure and improve those Attain Services and features and to develop new products and services, to provide you with customer support and to respond to inquiries. When the information collected from or about you does not identify you as a specific person, we may use that information for any purpose or share it with other parties, to the extent permitted by applicable law.
We use the information we collect from and about you for these additional purposes:
To respond to you: We may use this information to respond to the request or inquiry you have submitted to us through the contact form or other entry field.
To allow service providers to assist us in providing and managing the Attain Services: The information we collect from and about you may be made available to certain service providers, such as contractors, analytics and other measurement companies, and agents or sponsors, who help us analyze and understand your use of the Attain Services and manage and/or provide the Attain Services.
To contact you: Attain may periodically send promotional emails or notifications related to the Attain Services. If you want to stop receiving emails, you can follow unsubscribe links at the bottom of promotional emails or contact Attain as set forth in Section 11 . There are certain service notification and other emails that you may not opt-out of, such as notifications of changes to the Attain Services or policies.
To protect the rights of Attain and others: There may be instances when Attain may use or disclose your information, including situations where Attain has a good faith belief that such use or disclosure is necessary in order to: (i) protect, enforce, or defend the legal rights, privacy, safety, or property of Attain, our Attain Affiliates or their employees, agents and contractors (including enforcement of our agreements and our Terms of Service ; (ii) protect the safety, privacy, and security of users of the Attain Services or members of the public; (iii) protect against fraud or for risk management purposes; (iv) comply with the law or legal process; or (v) respond to requests from public and government authorities.
To complete a merger or sale of assets or other corporate transaction: If Attain sells all or part of its business or makes a sale or transfer of its assets or is otherwise involved in a reorganization, merger or transfer of all or a material part of its business (including in connection with a bankruptcy or similar proceedings), Attain may transfer or disclose your information to the party or parties involved in the transaction as part of that transaction.
Links to Partner Websites : Our site includes links to other websites whose privacy practices may differ from ours. If you submit personal information to any of those sites, your information is governed by their privacy statements. We encourage you to carefully read the privacy statement of any website you visit.
4. Security and Compliance The security of your information is fundamental to Attain. We have implemented industry standard security measures, which include the use of firewalls and encryption to protect your personal information. Attain is SOC 2 Type II certified. This certification reflects our commitment to the highest standards of data security, availability, and confidentiality. We maintain rigorous internal controls and undergo independent audits to ensure the trust and protection of our clients’ data.
However, no method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, we cannot guarantee its absolute security. If you have questions about the security of your personal information, you may contact us at support@attainoutcomes.com.
We will retain your profile information and credentials for as long as your account is active or as needed to provide you services. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
5. USER ACCESS AND CONTROL If you would like to access personal information we hold about you, or delete or correct, personal information you have previously provided directly to us, you may contact us as outlined in Section 11 . In your request, please include your email address, name, and telephone number and specify clearly what information you would like to suppress. We will try to comply with your request as soon as reasonably practicable and consistent with applicable law. Please note that subject to applicable law, in some cases we may not comply with your request where we may require your information in order to comply with applicable law, or to protect, enforce or defend our rights or employee rights, or those of an Attain Affiliate.
If you are a resident of California, please see the section entitled “California Privacy Rights Act (CPRA) Notice,” below, for more information about the rights you have under California law.
If you are a California resident, you may request that we not share your personal information on a going-forward basis with Attain Affiliates or unaffiliated third parties for their direct marketing purposes by sending an email as outlined in Section 8 with "Disclosure Opt-out" in the subject line and your full name, email address, postal address and the specific Attain Service you have subscribed to in the body of the email. We will try to comply with your request(s) as soon as reasonably practicable and consistent with applicable law. In the event that we are unable to fulfill your request, we will respond accordingly.
6. CHILDREN'S PRIVACY We do not knowingly collect or solicit Personal Information about children under 18 years of age; if you are a child under the age of 18, please do not attempt to register for or otherwise use the Services or send us any Personal Information. If we learn we have collected Personal Information from a child under 18 years of age, we will delete that information as quickly as possible. If you believe that a child under 18 years of age may have provided Personal Information to us, please contact us at support@attainoutcomes.com.
7. OTHER IMPORTANT INFORMATION Updates to Privacy Policy. Attain may modify this Privacy Policy. Please look at the Effective Date at the top of this Privacy Policy to see when this Privacy Policy was last revised. Any changes to this Privacy Policy will become effective when we post the revised Privacy Policy on the Attain Services. We’re constantly trying to improve our Services, so we may need to change this Privacy Policy from time to time. We reserve the right to modify this Privacy Policy at any time. If we make material changes to this Privacy Policy, we will notify you by placing a notice on the attainoutcomes.com website, by sending you an email and/or by some other means. Any modifications to this Privacy Policy will be effective upon our posting the new terms and/or upon implementation of the new changes on the Service (or as otherwise indicated at the time of posting). If you use the Services after any changes to the Privacy Policy have been posted, that means you agree to all of the changes.
Location of Data. The Attain Services are hosted in and managed from the United States. If you are a user located outside the United States, you understand and consent to having any personal information processed in the United States or in any other country in which we have facilities or in which we engage service providers. The United States and other countries’ data protection laws may not be the same as those in your jurisdiction. In certain circumstances, courts, law enforcement agencies, regulatory agencies or security authorities in the United States may be entitled to access your personal information.
Linked Services. The Attain Services may be linked to sites operated by unaffiliated companies, and may carry advertisements or offer content, functionality, games, newsletters, contests or sweepstakes, or applications developed and maintained by unaffiliated companies. Attain is not responsible for the privacy practices of unaffiliated companies, and once you leave the Attain Services or click an advertisement, you should check the applicable privacy policy of the other service.
In addition, Attain is not responsible for the privacy or data security practices of other organizations, any other app developer, app provider, social media platform provider, operating system provider, wireless service provider, or device manufacturer, including in connection with any information you disclose to other organizations through or in connection with the Attain Services.
Data Retention. We will retain your information for the period necessary to fulfill the purposes outlined in this Privacy Policy unless a longer retention period is required or allowed by law.
Remember that even after you cancel your registration, or if you ask us to delete your personal information, copies of some information from your account may remain viewable in some circumstances where, for example, you have shared information with social media or other services. Because of the nature of caching technology, your account may not be instantly inaccessible to others. We may also retain backup information related to your account on our servers for some time after cancellation or your request for deletion, for fraud detection or to comply with applicable law or our internal security or recordkeeping policies. It may not always be possible to completely remove or delete all of your information due to technical constraints or contractual, financial or legal requirements.
8. CALIFORNIA PRIVACY RIGHTS ACT (CPRA) NOTICE If you are a California resident, you have the rights set forth in this section. Except as otherwise specified below, please see the "Exercising Your Rights" section below for instructions regarding how to exercise these rights. Please note that we may process Personal Information of our customers’ end users or employees in connection with our provision of certain services to our customers. If we are processing your Personal Information as a service provider, you should contact the entity that collected your Personal Information in the first instance to address your rights with respect to such data.
If there are any conflicts between this section and any other provision of this Privacy Policy and you are a California resident, the portion that is more protective of Personal Information shall control to the extent of such conflict. If you have any questions about this section or whether any of the following rights apply to you, please contact us at support@attainoutcomes.com.
Categories of Personal Information Collected and/or Disclosed: The categories of Personal Information that we collected, disclosed, and/or “sold” or “shared” are below, along with the categories of third parties to whom each category of Personal Information was disclosed, and/or “sold” or “shared.” Please note that we disclose some categories of Personal Information in connection with certain types of advertisements, which could be considered a “sale” or “sharing” under the CCPA. Also, depending on the California resident’s interactions with us, Attain may not have collected or disclosed each of these categories about each individual.
Category of Personal Information Collected
Examples of Personal Information We Collect
Categories of Third Parties to Whom Personal Information Is Disclosed
Identifiers
First and last name
Email
Phone number
Unique identifiers such as passwords or device identifiers
IP address
Domain server
Type of device/operating system/browser used to accept the Services
Connection type
Service Providers
Advertising Partners
Analytics Partners
Business Partners
Parties You Authorize, Access or Authenticate
Payment Data
Payment card type
Credit or debit card number
Bank account information
Billing information
Payment processors
Service Providers
Business Partners
Web Analytics
Browsing or search history
Web page interactions
Referring webpage/source through which you accessed the Attain webpage
Non-identifiable request IDs
Statistics associated with the interaction between device or browser and the Services
Service Providers
Advertising Partners
Analytics Partners
Business Partners
Social Network Data
Service Providers
Advertising Partners
Analytics Partners
Business Partners
Professional or Employment-Related Data
Job title
Company where employed
Service Providers
Advertising Partners
Analytics Partners
Business Partners
Categories of Data that may be Considered “Sensitive under the California Privacy Rights Act and the Virginia Privacy Rights Act
Account log-in, debit or credit card number in combination with any required security or access code, password, or credentials allowing access to an account
Service Providers
Advertising Partners
Analytics Partners
Business Partners
Parties You Authorize for Access or Authentication
Geolocation Data
Non-precise location data
IP address
Service Providers
Advertising Partners
Analytics Partners
Business Partners
Inferences Drawn from any of the Personal Information Above
Profiles reflecting user attributes, behavior, preferences or abilities/aptitudes
Service Providers
Advertising Partners
Analytics Partners
Business Partners
Please note that the CPRA definitions of “sale” and “share” do not include, for example, the transfer of Personal Information as an asset that is part of a merger, bankruptcy, or other similar transaction involving all or any portion of our business.
Sensitive Personal Information. We do not process “sensitive” Personal Information of Contacts for purposes other than those specified in the Regulations section 7027(m) (such as to provide our products and services and for security purposes).
California Rights. If you reside in California, you have the following rights:
Right to Know
You have the right to request that we disclose what personal information we collect, use, disclose, and “sell”.
Attain collects the following categories of personal information for the purpose of providing the Attain Services:
Categories personal information we may collect:
Identifiers (e.g. Cookie IDs, Mobile Advertising IDs, hashed email addresses, IP addresses, User Agent, etc.) Internet or other electronic network activity information: (i) Browsing history (e.g. URL of the websites browsed, name of the apps opened); (ii) Interactions with an Internet Web site, mobile application or advertisement (e.g. ads seen, clicked, etc.) Commercial information, including records of products or services purchased, obtained, or considered (e.g. products seen, put in basket, bought) To learn more about the categories of personal information we collect, the categories of sources from which the personal information is collected and the categories of third parties with whom we may share personal information, please refer to Section 2 and Section 3 above.
To receive a copy of the personal information we may currently hold about you, please send us an email at support@attainoutcomes.com.
Right to Delete
You have the right to request that Attain deletes the personal information we currently hold about you.
To exercise this right, simply follow the instructions available by clicking here Your Privacy Choices .
Right to Correct
You have the right to request that Attain correct inaccurate personal information.
To exercise this right, please send us an email at support@attainoutcomes.com.
Right to Opt-Out of ‘Sales’ or ‘Sharing’ of Personal Information
If you are a California resident, the CPRA allows you to request that Attain no longer “sells” or “shares” your personal information.
To opt-out of these “sales” or “sharing,” simply follow the instructions available by clicking here Your Privacy Choices .
Right to Non-Discrimination for the Exercise of a Consumer’s Privacy Rights
You have the right not to receive discriminatory treatment for the exercise of the privacy rights conferred by the CCPA.
Please see Section 8 for information on how to contact us.
9. ADDITIONAL U.S. STATES PRIVACY RIGHTS If you live in certain U.S. states such as Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia you may have additional rights to your Personal Information, such as rights of access, deletion, correction, and portability. Pursuant to the laws of these states, Attain may “sell” your Personal Information as defined by each applicable state law or “share” your Personal Information for the basis of cross-context behavioral advertising subject to your right to opt out. Please see the “Exercising Your Rights” section below for instructions regarding how to exercise these rights.
Access : You may have the right to request confirmation of or access to the Personal Information that we process about you. You can also request access to a portable copy of your Personal Information. If you are an Oregon resident, you also have the right to request a list of specific third parties, other than natural persons, to which we have disclosed your Personal Information.Deletion : You may have the right to request that we delete the Personal Information that we have collected about you. Correction : You may have the right to request that we correct any inaccurate Personal Information we have collected about you. Portability : You may have the right to request a copy of your Personal Information in a machine-readable format, to the extent technically feasible.“Selling,” “Sharing,” or “Targeted Advertising”
Depending on your state of residence, you may have the right to opt out from the “sale,” “share,” or disclosure of your Personal Information for the purposes of targeted advertising. These or similar terms may be defined differently depending on the applicable U.S. state privacy law.
You have the right to opt-out of the sale or share of your Personal Information by following the instructions in the “Exercising Your Rights” section. Once you have submitted an opt-out request, we will not ask you to reauthorize the sale of your Personal Information for at least 12 months.
Processing of Sensitive Personal Information
You may choose to provide us with Personal Information that may be deemed “sensitive” under certain U.S. state privacy laws (“Sensitive Personal Information”). The categories of Sensitive Personal Information we collect, and our purposes for collecting such Sensitive Personal Information is described in the ‘Categories of Personal Information We Collect’ section above.
Depending on your state of residence, you may either have the right to opt-in, the right to opt-out, or if you are a California resident, the right to limit our use of your Sensitive Personal Information to permitted purposes as described above, by following the instructions in the “Exercising Your Rights” section.
Exercising Your Rights
To exercise the rights described in this Privacy Policy, you or, your Authorized Agent (defined below) must send us a request that (1) provides sufficient information to allow us to verify that you are the person about whom we have collected Personal Information including an email attachment, and (2) describes your request in sufficient detail to allow us to understand, evaluate and respond to it. Each request that meets both of these criteria will be considered a "Valid Request." We may not respond to requests that do not meet these criteria. We will only use Personal Information provided in a Valid Request to verify your identity and complete your request. You do not need an account to submit a Valid Request.
We will work to respond to your Valid Request within the time period required by applicable law.
We will not charge you a fee for making a Valid Request unless your Valid Request(s) is excessive, repetitive or manifestly unfounded. If we determine that your Valid Request warrants a fee, we will notify you of the fee and explain that decision before completing your request.
You may submit a Valid Request using the following methods:
If you are a resident of a state that allows authorized agents to submit requests on your behalf, you may also authorize an agent (an "Authorized Agent") to exercise your rights on your behalf. To do this, you must provide your Authorized Agent with written permission to exercise your rights on your behalf, and we may request a copy of this written permission from your Authorized Agent when they make a request on your behalf.
Appealing a Denial
If you are a Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, or Virginia resident and we refuse to take action on your request within a reasonable period of time after receiving your request in accordance with this section, you may appeal our decision. In such appeal, you must (1) provide sufficient information to allow us to verify that you are the person about whom the original request pertains and to identify the original request, and (2) provide a description of the basis of your appeal. Please note that your appeal will be subject to your rights and obligations afforded to you under the state privacy laws (as applicable). We will respond to your appeal within the time period required under the applicable law. You can submit a request to appeal by the following methods:
If we deny your appeal, you have the right to contact the Attorney General of your State, including by the following links: Colorado , Connecticut , Delaware , Iowa , Montana , Nebraska , New Hampshire , New Jersey , Oregon , Texas , Indiana , Kentucky , Maryland , Minnesota , Rhode Island , Tennessee , and Virginia .
California Shine the Light Law
Under California Civil Code Sections 1798.83-1798.84, the “Shine the Light” law, California residents are entitled to contact us to prevent disclosure of Personal Information to third parties for such third parties’ direct marketing purposes. In order to submit such a request, please contact us at support@attainoutcomes.com.
Your browser may offer you a “Do Not Track” option, which allows you to signal to operators of websites and web applications and services that you do not wish such operators to track certain of your online activities over time and across different websites. Our Services do not support Do Not Track requests at this time. To find out more about “Do Not Track,” you can visit www.allaboutdnt.com .
Nevada Resident Rights
If you are a resident of Nevada, you have the right to opt-out of the sale of certain Personal Information to third parties who intend to license or sell that Personal Information. You can exercise this right by contacting us at support@attainoutcomes.com with the subject line “Nevada Do Not Sell Request” and providing us with your name and the email address associated with your account.
10. EMPLOYEE AND JOB APPLICANT PRIVACY NOTICE This Section applies to current and former employees, job applicants, independent contractors, and other personnel of Attain (collectively, “Personnel”). It describes how Attain collects, uses, retains, and discloses Personal Information in the context of the employment relationship and the application and hiring process. This notice is provided in addition to, and consistent with, any separate Notice at Collection provided to Personnel at the time of data collection.
Categories of Personal Information We Collect from Personnel
Attain may collect the following categories of Personal Information from or about Personnel:
Identifiers: Name; home and work address; email address; phone number; Social Security number; driver’s license or state ID number; passport number; employee ID; username and password.Professional and Employment Information: Employment history; resume and application materials; job title; department; supervisor; performance evaluations; disciplinary records; professional licenses and certifications; education history.Financial Information: Bank account information for payroll; compensation details; tax withholding information (W-4); direct deposit instructions; expense reimbursement records.Health and Medical Information: Information provided in connection with benefits enrollment; disability accommodation requests; leave of absence requests; medical certifications (where required by law); workplace injury records.Background Check Information: Criminal background check results (where permitted by applicable law); credit history (where relevant to the position); reference check information; drug test results (where permitted by law). Geolocation Data: Location data in connection with work performed remotely or using company devices, where disclosed and permitted by applicable law. Communications and Electronic Activity: Electronic communications on company systems and devices, to the extent permitted by applicable law and disclosed in company policies; internet and network usage logs on company systems. Government and Immigration Records: Work authorization documentation; visa and immigration status information (as required for I-9 and E-Verify compliance). Demographic Information: As provided voluntarily for EEOC/EEO-1 reporting purposes (e.g., race, ethnicity, gender, veteran status, disability status). Emergency Contact Information: Name and contact information for designated emergency contacts.Sensitive Personal Information
Certain categories listed above constitute “Sensitive Personal Information” under applicable laws, including the CPRA. These include Social Security numbers and other government-issued identification numbers; financial account information (e.g., bank account numbers used for payroll); health and medical information; biometric data, if collected for timekeeping or access control; precise geolocation data; racial or ethnic origin, religious beliefs, and other protected characteristics collected for EEOC compliance; and information about immigration or citizenship status. We use Sensitive Personal Information only as necessary for employment administration, benefits, legal compliance, and the other purposes described below, and do not use it to infer characteristics beyond what is permitted by law.
Purposes for Collection and Use
We collect and use Personnel’s Personal Information for the following purposes:
Evaluating and processing job applications, including conducting interviews and background checks; Making hiring decisions and extending offers of employment; Onboarding new employees and administering the employment relationship; Administering payroll, compensation, and benefits programs (including health insurance, retirement plans, and other employee benefits); Managing performance, conducting performance reviews, and supporting employee development and training; Complying with employment laws and regulations, including tax withholding, wage and hour laws, OSHA requirements, EEOC reporting, and leave management; Verifying work authorization and maintaining I-9 and E-Verify records; Conducting background checks in connection with employment decisions (see FCRA disclosures below); Maintaining workplace safety and security; Managing company property, systems, and network security; Investigating workplace incidents, complaints, and disciplinary matters; Operating and defending legal claims; and Complying with court orders, subpoenas, and other legal processes. Sharing of Personnel Personal Information
We may share Personnel’s Personal Information with:
Service providers who assist us in operating our HR, payroll, benefits, and recruiting systems; Background check companies and reference check services; Benefits administrators, insurance carriers, and retirement plan providers; Government agencies, including the IRS, Social Security Administration, EEOC, and Department of Labor, as required by law; Successor entities in the event of a merger, acquisition, reorganization, or similar corporate transaction; and Professional advisors such as attorneys and accountants, subject to applicable confidentiality obligations. Data Retention for Personnel
We retain Personal Information of Personnel for the period necessary to fulfill the purposes for which it was collected and to comply with applicable legal obligations. As a general matter:
Active employee records are maintained throughout the employment relationship. Post-termination records are generally retained for a minimum of 3 to 7 years, depending on the type of record, to comply with applicable federal and state recordkeeping requirements. Job applicant records for individuals not hired are retained for at least 1 year from the date of the employment decision, or as required by applicable law. Records subject to pending litigation, government investigation, or legal hold are retained until resolution of the matter plus applicable statutes of limitations. California Employee and Applicant Rights (CPRA)
California employees and job applicants have the same CPRA rights described in Section 8 with respect to their Personal Information: the right to know, the right to delete (subject to employment-related exceptions), the right to correct, the right to opt-out of sale or sharing, the right to limit use of Sensitive Personal Information, and the right to be free from discrimination for exercising these rights. To submit a CPRA request, please contact us as described in Section 11 .
Background Check Disclosures — Fair Credit Reporting Act (FCRA)
In connection with your application for employment, or as part of your ongoing employment with Attain, we may obtain one or more consumer reports (background checks) about you from a consumer reporting agency (“CRA”). Such reports may include information about your character, general reputation, personal characteristics, credit standing, criminal history, employment history, and educational background, to the extent permitted by applicable law.
Before obtaining a consumer report, we will provide you with a clear and conspicuous written disclosure in a document consisting solely of that disclosure, and obtain your written authorization, as required by the FCRA (15 U.S.C. § 1681b).
If we take an adverse employment action based in whole or in part on information in a consumer report, we will: (i) provide you with a pre-adverse action notice that includes a copy of the consumer report and a copy of “A Summary of Your Rights Under the Fair Credit Reporting Act”; (ii) give you a reasonable period of time (at least 5 business days) to review and dispute the accuracy of the report before taking final adverse action; and (iii) provide you with a final adverse action notice that identifies the CRA, states that the CRA did not make the adverse decision, and informs you of your right to obtain a free copy of the report within 60 days and to dispute the accuracy or completeness of any information in the report.
EEOC Recordkeeping
Attain retains personnel and employment records, including records relating to job applicants, in accordance with EEOC recordkeeping regulations (29 CFR Part 1602). For private employers, we retain such records for at least 1 year from the date of making the record or taking the personnel action, whichever is later. Records related to pending charges of discrimination or litigation are retained until final disposition of the charge or action, plus the applicable statute of limitations period.
If you have any questions or comments about this Privacy Policy, please contact us at support@attainoutcomes.com and please visit Your Privacy Rights if you wish to move forward on any of your DSAR requests.