Career Site Privacy Policy – California Residents (CCPA/CPRA Compliant)
 

HealthFlex for itself and on behalf of its affiliated entities and subsidiaries (“we,” “our,” or “us”) values your privacy and is committed to protecting the personal information you provide during the application process. This policy outlines how we collect, use, disclose, and protect personal information submitted through our career site, in accordance with the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). 


1. Categories of Information We Collect - We may collect the following categories of personal information from consumers:

  • Identifiers: name, email, phone number, address, account credentials, online identifiers, IP address, device identifier, alias/account name, and in limited circumstances, state ID number, business tax ID, and other identifiers for professional use.
  • Professional/Employment Information: information from your resume, employment history, certifications, references, background screening information, and professional licenses.
  • Education Information: educational records, transcripts, letters of recommendation or other information related to educational      history. 
  • Demographic Information: voluntarily disclosed data (e.g., gender, age, veteran status, etc.)
  • Internet/Technical Data: this may include but is not limited to information about your use of our sites, apps, or services,      information regarding your interaction with HealthFlex sites and mobile apps, and data regarding network connected hardware, browsing activity, IP address, and device identifiers.
  • Sensitive Personal Information: government-issued ID, SSN (used only as required for background checks or legal compliance), account login  credentials, and physical location or device location data.   

We collect this information from you directly or from third parties such as background check vendors or references.
 

2. Purpose of Collection and Use - We collect and use personal information to:

  • Evaluate your qualifications and process your application
  • Contact you regarding job opportunities
  • Conduct background checks and verify credentials
  • Comply with legal and regulatory obligations
  • Maintain records related to our recruitment activities
  • Improve our hiring processes

We do not use your information for automated decision-making or for cross-context behavioral advertising as defined under CPRA. We use sensitive personal information only as necessary to perform our services, verify credentials, comply with legal obligations, or ensure security and integrity.
 

3. Disclosure of Personal Information - We may disclose your information to:

  • Internal hiring personnel and managers
  • Third-party service providers assisting in recruitment (e.g., background checks, applicant tracking)
  • Government or regulatory bodies when legally required

We do not sell or share your personal information, including sensitive personal information.
 

4. Data Retention

  • We retain personal information for no longer than is reasonably necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required or permitted by law. 
  • You may request deletion at any time (subject to exceptions under law) by contacting our Privacy Officer at, privacyofficer@healthflex.com. 
  • Please note that even if you make a request to delete your personal information, applicable law may permit or require us to retain personal information that was collected to complete transactions and services you have requested or that are reasonably anticipated, for security purposes, for legitimate internal business purposes, including maintaining business records, to comply with law, to exercise or defend legal claims, and to cooperate with law enforcement.   

5. Your Rights Under CCPA/CPRA - As a California resident, you have the right to:

  • Know what personal information we collect, use, and disclose
  • Access your personal information
  • Request deletion of your personal data (with certain exceptions)
  • Correct inaccurate information
  • Limit use of your sensitive personal information
  • Non-discrimination for exercising your privacy rights

You have the right to obtain a copy of the specific pieces of personal information that we have collected about you. You may authorize an agent to submit a request on your behalf by providing the agent with written permission signed by you and verifying your identity directly with us. To exercise your rights or to request this policy in an alternative format due to a disability contact us at: privacyofficer@healthflex.com. We may need to verify your identity before fulfilling your request.
 

6. Prospective Opt-Out for CA Residents
 

Although as of the Effective Date of this revised Privacy Policy it is not our current practice to share your “personal information” as defined by California’s “Shine the Light” law (CA Civil Code Section § 1798.83) with third parties, other than our affiliated companies and subsidiaries, we reserve the right to do so in the future. Accordingly, we provide California residents with the option to prospectively opt-out of our sharing of such data for those purposes to third parties other than our affiliated companies and subsidiaries. 

To do so, contact HealthFlex at privacyofficer@healthflex.com or send a letter to us at: HealthFlex Privacy Inquiries; Attn: Privacy Officer, 7677 Oakport St Suite 930, Oakland, CA 94621
 

Requests must include “California Privacy Rights Request” in the first line of the description and include your name, street address, city, state, and ZIP code. Please note that, by law, HealthFlex is only required to respond to one request per customer each year, and we are not required to respond to requests made by means other than through the provided e-mail address or mail address.
 

7. Security

We maintain reasonable administrative, technical, and physical safeguards to protect your personal data from unauthorized access, loss, or misuse.
 

8. Children’s Privacy

We do not knowingly collect personally identifiable information from anyone under the age of 16. If You are a parent or guardian and you are aware that your child has provided us with personal data, please contact us. If we become aware that we have collected personal data from anyone under the age of 16 without verification of parental consent, we take steps to remove that information from our servers.  
 

9. Policy Updates

This policy may be updated periodically. The latest version will always be available on our career site with an updated effective date.
 

Effective Date: June, 2025