CALIFORNIA CANDIDATE PRIVACY NOTICE
Last Updated: January 1, 2023
This Privacy Notice describes how Legend Pictures, LLC (“Legend,” “we,” “us,” or “our”) collects, processes, shares, retains, and protects Personal Information of its job applicants who are California residents (“you” or “your”). This Privacy Notice covers our data practices both online and offline. If you have questions about this Privacy Notice please contact us at HR@legendary.com.
Additionally, please note that Section I of this Privacy Notice, which describes our collection and use of information from and about our job applicants, also serves as our Notice At Collection for California residents for purposes of the California Consumer Privacy Act (CCPA).
This Privacy Notice does not form part of any contract of employment or other contract to provide services.
This Privacy Notice is limited to the collection and use of personal information collected in the context of your job application with us, and if you interact with a website owned and operated by Legend as a consumer, the privacy policy for that website applies.
The entire Privacy Notice has been designed to be accessible to people with disabilities. If you experience any difficulties accessing the information in the Privacy Notice, please email us at HR@legendary.com.
TABLE OF CONTENTS
I. NOTICE AT COLLECTION; COLLECTION AND USE OF PERSONAL INFORMATION
II. SOURCES OF PERSONAL INFORMATION
III. DISCLOSURES OF PERSONAL INFORMATION TO OTHER ENTITIES
IV. CALIFORNIA RESIDENTS ONLY: YOUR CHOICES REGARDING YOUR PERSONAL INFORMATION
V. SECURITY OF PERSONAL INFORMATION
VI. OTHER IMPORTANT INFORMATION
VII. MINOR CHILDREN
VIII. CONTACT US
I. NOTICE AT COLLECTION; COLLECTION AND USE OF PERSONAL INFORMATION
We collect two types of information: Personal Information and Other Information.
Personal Information is any information:
Sale and Sharing. We do not sell or share your personal information.
We do not collect inferences to create profiles of you.
The list below and additional paragraphs immediately following the list are a summary of the categories of Personal Information we have collected over at least the last 12 months, the purposes for collection and use of that Personal Information, and how long we keep each category of Personal Information.
Categories of Personal Information and Business Purpose for Collecting and Using Personal Information
1. Personal Identifiers, such as your name, addresses, phone number, e-mail, alias, as well as Social Security number, and information that appears on your Driver's license, Green card, National ID, State ID, or Passport/Visa, which are considered Sensitive Personal Information.
Purpose:
2. Demographic Information, including gender, race, age, and your citizenship and military status, some of which are considered Sensitive Personal Information.
Purpose:
3. Financial Information, including payment card number, bank account number and account details, direct deposit information, income, pay history, and other financial information.
Purpose:
4. Professional, Employment, and Educational Information, including information about your education, employment and employment history, collected during the application, recruiting, interview, or hiring stages with Legend, including information you provide to us in your application, resume, curriculum vitae, survey or test results, or cover letter.
Purpose:
5. Audio and Visual Information, including your photo (when provided), image documentation, CCTV cameras, video and/or audio security footage of you on our premises, and your voice recordings (when provided).
Purpose:
6. Device, Internet and Network Activity Information, IP Address, cookie IDs and Device ID. This includes usage data of the Legend services (e.g. the date and time your device accesses our servers and what information and files have been downloaded to or presented through the services), information collected through cookies, web beacons and other technologies, and aggregated information about your visits to, or use of operations, as well as across other sites, and various attributes associated with your device (e.g. IP address, installed fonts, language and browser settings, and time zone in order to create a device fingerprint or identifier so that we can recognize your device). While that information alone may not reveal your specific individual identity, we may associate this usage and Other Information we collect with Personal Information about you.
Purpose:
7. General location information (e.g. zip code and IP address)
Purpose:
Additional Uses. We may also use all of the Personal Information noted above as we believe necessary:
(1) to assess and monitor your compliance with our policies and procedures;
(2) to comply with applicable legal or regulatory obligations with regard to your application, including to ensure meaningful equal opportunity monitoring and reporting, preventing corruption and crimes, and confirming your legal work status;
(3) for security, safety, and due diligence purposes, including measures to protect and prevent unauthorized access to our systems and networks;
(4) if we determine a policy violation has occurred, to enforce our rights, or to enforce agreements;
(5) to identify, contact, or bring legal action regarding the rights and property of Legend or its affiliates;
(6) to perform audits;
(7) to identify usage trends in the context of your use of the application site and services for the purpose of improvements and changes; and
(8) to communicate with you about your application, including responding to your inquires and notifying you of Site or policy updates, all on the basis of our legitimate interest related to a potential employment relationship with you and the protection of our rights.
Aggregate or De-identified Information. We may collect, use and disclose information that does not identify you (including information that has been aggregated or de-identified) except as prohibited by applicable law. We will maintain and use de-identified information in de-identified form and will not attempt to re-identify the information, except to make sure the information is truly de-identified.
Retention. We will retain your Personal Information for as long as is needed to carry out the purposes we’ve described, or as otherwise required by law. The criteria used to determine the applicable retention period for your Personal Information includes the length of time we have an ongoing relationship with you as a current employer and whether there is a legal obligation to which we are subject that requires us to retain your Personal Information. Generally, this means we will keep your Personal Information until the end of the application process with us, plus a reasonable period of time as necessary to respond to any inquiries, deal with legal, tax, accounting or administrative matters, or to provide you with ongoing pensions or other benefits.
Where we have no continuing purpose to process your Personal Information, we will either delete or anonymize it or, if this is not possible (for example, because your Personal Information has been stored in backup archives), then we will securely store your Personal Information and isolate it from any further processing until deletion is possible.
II. SOURCES OF PERSONAL INFORMATION
We collect and obtain information from:
You. We collect your information when you provide it to us directly offline or online. We may collect additional Personal Information in the course of job-related activities throughout the period you work for us. This can be in the form of information you provide directly to us or information which we collect automatically about you, such as monitoring computer access and usage.
Service Providers and Contractors. We work with service providers and contractors who collect information on our behalf in order to provide services to us. We only allow our service providers and contractors to collect and use your personal information in connection with the services they provide us. Our service providers who provide software as a service collect cookies and provide us with reporting which include the IP address, activity, network, web browser used and in some cases, a device identifier so that we can understand how our systems are being used.
III. DISCLOSURES OF PERSONAL INFORMATION TO OTHER ENTITIES
During at least the past 12 months, we have disclosed the categories of Personal Information outlined in the table above to the following categories of entities:
Third Parties. We may disclose all of the categories of Personal Information outlined above with the following categories of third parties: government agencies to comply with mandatory reporting and other legally required disclosures, third-party identity verification services to verify the identity of employees, financial institutions for reviewing and processing your employment application, and fraud prevention agencies to prevent fraudulent or unauthorized actions related to our systems, network and premises.
Facilitating Requests. We disclose all of the categories of Personal Information listed above at your request or direction.
Consent. We disclose all of the categories of Personal Information listed above if we have let you know what information will be shared, with whom, and obtained your consent.
IV. CALIFORNIA RESIDENTS ONLY: YOUR CHOICES REGARDING YOUR PERSONAL INFORMATION
A. Your California Privacy Rights
If you are a California resident, you have certain rights with respect to Personal Information provided to us in the context of applying for a job with Legend. For purposes of this subsection, the terms “consumer”, “categories of personal information”, “business purpose”, “third party”, “sell”, and “share” have the meanings ascribed to them respectively in the applicable state specific privacy laws. Terms defined under the applicable state specific privacy laws may differ in meaning from the common usage of the same terms used elsewhere in this Privacy Notice. To the extent provided for under the applicable laws, you may have the right to:
1. Access and Disclosure – You can request, up to two times every 12 months, that we disclose to you (i) the categories of Personal Information we collected about you, (ii) the categories of sources from which we collected the Personal Information, (iii) the business or purpose for collecting , selling, or sharing your Personal Information (iv) the categories of third parties with whom we shared the Personal Information, and (v) the specific pieces of Personal Information we collected about you. You also have the right to request a portable copy of your Personal Information.
2. Correction and Deletion – You can request that we correct or delete Personal Information that we have about you, subject to certain exceptions allowed under applicable law. You can also delete your profile by simply deleting all the data fields, which will cause our server to delete the information from its online form.
3. Opt Out of Sale and Sharing of Your Personal Information – We do not sell or share your Personal Information as the terms “sell” and “share” are defined under California law.
4. Opt-out Preference Signals; Global Privacy Control - We do not sell or share your Personal Information. As a result, we do not respond to browser-based opt-outs such as the “Global Privacy Control.” Some browsers allow you to send a Do Not Track signal, an older request to block tracking of users by third parties. We may not honor these older signals, either.
5. Sensitive Personal Information – You may also have the right to limit the use of your Sensitive Personal Information under California law to those uses that are necessary to perform the services reasonably expected by an average person and to certain other permitted business purposes. These business purposes include helping to perform services reasonably expected by users of our services and who have requested such services, ensure security and integrity (to the extent the use of the information is reasonably necessary and proportionate for these purposes), ensure physical safety of natural persons (to the extent the use of the information is reasonably necessary and proportionate for these purposes), short-term, transient use (subject to certain conditions), performing certain services, and engaging in certain activities related to quality or safety of our services or products. We do not use or disclose your Sensitive Personal Information for any purpose other than permitted business purposes.
6. Disclosure for Direct Marketing – We do not directly market to you as an employee or contractor.
7. No Discrimination – You will not be discriminated against for exercising any of the above rights, as an employee or contractor.
8. No Financial Incentive. We do not offer any programs to you as an employee or contractor that would be considered a “financial incentive” for sharing your Personal Information under California law. Any employee or contractor perks/benefits are unrelated to your personal information.
9. Submission of Requests - You may exercise the above rights by emailing us at HR@legendary.com. Note that we may deny certain requests, or fulfill a request only in part, based on our legal rights and obligations. For example, we may retain Personal Information as permitted by law, such as for tax or other record keeping purposes, to maintain an active account, and to process transactions and facilitate customer requests.
10. Authorized Agent – State specific privacy laws may permit consumers to designate authorized agents to submit requests on their behalf. Under certain state specific privacy law, an authorized agent is a natural person or a business entity in the applicable state that a person has authorized to act on their behalf subject to the requirements. If you would like to designate an authorized agent to submit a request to know, a request to delete, or a request to correct Personal Information on your behalf, please email us at HR@legendary.com. When submitting the request, please ensure the authorized agent identifies himself/herself/themselves as an authorized agent.
In addition, we may also require you to do the following directly with us:
Once verified, your authorized agent may act on your behalf.
11. Verification – Whether you submit a request directly on your own behalf, or through an authorized agent, we will take reasonable steps to verify your identity prior to responding to your requests under applicable state law.
In response to verified requests for access and disclosure or a portable copy of your Personal Information, we will confirm receipt of the request within 10 business days of receipt of the request, and disclose and deliver the required information to you free of charge within 45 days of receiving a verifiable consumer request. We may extend this time period to deliver information once by an additional 45 days when reasonably necessary. We will provide notice of the extension within the first 45-day period
In response to verified requests to correct or delete, we will confirm receipt of the request within 10 business days of receipt of the request.
Following verification of your request to delete, we may require you to separately confirm that you want your Personal Information to be deleted. We will delete the information within 45 days of receiving a verifiable consumer request (subject to certain exceptions). We may extend this time period once by an additional 45 days when reasonably necessary. We will provide notice of the extension within the first 45-day period.
Following verification of your request to correct, we may require you to provide documentation if necessary to rebut our own documentation that the Personal Information is accurate. If we determine, based on the totality of the circumstances, that the information is not accurate, we will respond to the request by correcting the information, deleting the information (if deletion of the information does not negatively impact you), or providing you with the name of the source from which we have received the alleged inaccurate information (if we are not the source). We will correct within 45 days of receiving a verifiable consumer request. We may extend this time period once by an additional 45 days when reasonably necessary. We will provide notice of the extension within the first 45-day period. You have the option to submit a 250-word written statement per alleged inaccurate piece of Personal Information if it is considered health information or is concerning your health and if you request, this statement will be made a part of your consumer record with us.
V. SECURITY OF PERSONAL INFORMATION
The security of your Personal Information is a priority. We make reasonable efforts to use standard security technologies designed to help ensure that the information we collect about our users is secure. However, we would like to remind you that the Internet is not 100% secure, and technology is no substitute for common sense. We strongly encourage users to keep their login names and passwords secret and to change their password when they think they have become compromised. Furthermore, we recommend that our users communicate over secure channels wherever possible, disable the automatic login features found in some browsers, and empty their browser caches regularly. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of any account you might have with us has been compromised), please immediately email us at HR@legendary.com.
VI. OTHER IMPORTANT INFORMATION
A. Notice of Changes
From time to time, we may update this Privacy Notice. If we make any material changes we will notify you as required by law, which may include a notice on this Site prior to the change becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices.
B. Third-Party Sites and Services
This Privacy Notice does not address, and we are not responsible for, the privacy, security, or other practices of any third parties operating any site or service to which this Site links. The inclusion of a link on our services does not imply endorsement of the linked site or service by us or by our affiliates. In addition, we are not responsible for the information collection, usage, disclosure, or security policies or practices of other organizations.
C. Jurisdictional Issues
Our services are controlled and operated by us from the United States and are not intended to subject us to the laws or jurisdiction of any state, country, or territory other than those of the United States. Information about you may be stored and processed in any country where we have facilities or in which we engage service providers and contractors, and, by using our services, you consent to the transfer of information to countries outside of your country of residence, including the United States, which may have data protection rules that are different from those of your country. In certain circumstances, courts, law enforcement agencies, regulatory agencies, or security authorities in those other countries may be entitled to access your Personal Information.
VII. MINOR CHILDREN
We do not hire individuals under the age of 18. We do not knowingly collect information from individuals under the age of 18.
VIII. CONTACT US
If you would like any more information about our Privacy Notice, please email us at HR@legendary.com