Updated September 13, 2024

Platform Privacy Policy

Effective September 13, 2024

This Platform Privacy Policy describes how Justworks, Inc., and its subsidiaries (“we”, “us,” “our,” or “Justworks”) collects, uses and discloses information about individuals who use our platform and solutions that we provide to our business/enterprise customers (“Customers”), including, applications (including mobile applications), services, tools, features, and customer service interactions (collectively, the “Platform”).

This Privacy Policy explains the types of information we collect about you when you:

  • Set up and / or operate a business account to use the Platform on behalf of one of our Customers (“Administrators”).

  • Are invited by our Customer (or their Administrator) to use the Platform as an end user (e.g., an existing or prospective employee or contractor of a Customer) (together with Administrators,“Customer Users”).

Policy Exclusions. This Privacy Policy does not apply to:

  • Visitors to our public-facing websites (“Website Visitors”); or

  • Individuals who use the Platform in connection with a trial account (“Trial Account Users”).

Our processing of information about Website Visitors and Trial Account Users is covered by our Website Privacy Policy.

Please read this Privacy Policy carefully. By using, accessing, or downloading any components of the Platform, you agree to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree to this Privacy Policy, please do not use, access or download any component of the Platform.

Contents

1. Changes

2. How We Collect Information

3. How We Use the Information We Collect

4. How We Disclose the Information We Collect

5. Cookie Technologies

6. User Generated Content

7. Third-Party Websites and Links

8. Your Privacy Rights and Choices

9. Children's Privacy

10. Security and Retention of Your Information

11. Additional Information for California Residents

12. Information for International Users

13. Contact Us

1. Changes

We may modify this Privacy Policy from time to time due to changes in applicable law or the Platform in which case we will include the “Last Updated” date at the top of this Privacy Policy. If we make material changes to the way in which we use information we collect, we will use reasonable efforts to notify you (such as by emailing you at the last email address you provided us, by posting notice of such changes in the Platform, or by other means consistent with applicable law) and will take additional steps as required by applicable law. If you do not agree to any updates to this Privacy Policy, please do not access or continue to use the Platform.

2. How We Collect Information

When you access or use the Platform, we collect certain categories of information about you from a variety of sources, depending on the type of user you are and the specific Platform services you are using, as detailed in this section.

A. Information We Collect About Customer Users

In order to provide the Platform to our Customers, we collect and process certain information (which may include “personal information” and “sensitive personal information” and the equivalent terms (as defined under applicable laws) about Customer Users (either directly from Customer Users or from Administrators), including (as applicable):

  • Contact information (e.g., name, address, phone number, email).

  • Account information (e.g., username, password, security questions, other credentials). If you choose to use the Platform and register an account, you are responsible for keeping your account credentials safe. We highly recommend that you do not share your username, password, or other access details with anyone else. If you believe your account has been compromised, please contact us immediately.

  • Financial information (e.g, bank account number to route payments to you, credit check information).

  • Government identifiers and related information (e.g., government identification and for ID verification purposes, social security numbers, tax documentation).

  • Employment-/work-related information (e.g., your title, role, photo, employer, time off requests, salary, emergency contacts, and any information our Customer has requested that you upload to the Platform, provide to us, or that our Customers input into the Platform related to your employment with the Customer).

  • Demographic and status information (e.g., date of birth, gender, military/veteran status, race/ethnicity, citizenship, number of children).

  • Information in communications with us, for example, when sending a message through the Platform or contacting customer support.

If you use our timekeeping services, we also collect GPS location information at the point of clock in and clock out, as well as a selfie photo of you. Note, however, that we use third-party identity verification service providers to perform the identity verification check; we do not collect, process, or store any biometric information generated in connection with these services.

We collect and process Customer User information for the purposes of providing our Platform to our Customers, and process such data as instructed by our Customer as their “data processor” or “service provider” (as defined under applicable laws). The Customer, and not us, is the “data controller” or “business” (as defined under applicable laws) of your information, and our processing activities may also be subject to a separate data processing agreement or similar agreement with the Customer. In the event of a conflict between the terms of the specific agreements with the Customer and this Privacy Policy, the agreement with the Customer controls.

B. Information We Collect About Administrators

In the course of using the Platform, there is certain information that we collect from and about Administrators in addition to the information we collect about Customer Users, as described above. Information we collect from and about Administrators includes:

Company-related information (e.g., the specific Platform services or features purchased, tax information, insurance policies and claims (if any), number of employees, ownership structure, business metrics, employee metrics, previous PEOs used).

Company-related payment information (e.g., bank account, billing address).

Any other information you choose to provide us with, which includes information completed viaa survey.

Information We Collect Automatically

As you use the Platform, whether you are a Customer User or an Administrator, we also automatically collect certain information about your interactions with the Platform (“Usage Data”). To do this, we may use cookies, web beacons/clear gifs, and similar online technologies, etc. (“Cookie Technologies”). Usage Data may include:

  • Device information (e.g., unique device identifier, device type, IP address, operating system)

  • Device event information such as crashes, system activity and hardware settings

  • Browser information (e.g., browser type and version)

  • Location information (e.g., geolocation)

  • Log data

  • Other information regarding your interaction with the Platform (e.g., log data, date and time stamps, clickstream data)

We use Usage Data to tailor the Platform to you, run analytics and better understand user interactions with the Platform. Please note that we do not process Customer User or Administrator information through Cookie Technologies for targeted online advertising purposes or in ways that would be considered a “sale” or “share” of information under applicable law.

For more information on how we use Cookie Technologies and your choices, see the section below, Cookies and Similar Technologies.

Information We Obtain from Third Parties

Finally, we may obtain information about you from third parties. Such information may include:

  • Information that you choose to disclose to us through third parties, such as:

    • When you set up two-factor authentication to receive unique verification codes from third-party sources to gain access to your account.

    • Information we receive when you choose to link to your personal or business email account in order to gain access to your Justworks account, for example, through the use of single-sign on applications.

    • If you are an Administrator and choose to integrate third-party tools/services for your use of the Platform for certain information may be disclosed to us from those tools and added to your Platform account.

In some instances, our Customers may also choose to integrate with third-party platforms that process additional information about Customer Users (e.g., recruiters who maintain your employment applications, providers of Office of Foreign Asset Control (OFAC) searches, background check results from third-party background check providers). When these integrations occur, the additional information from these third-party platforms will also be added to your account with us.

3. How We Use the Information We Collect

We use the information we collect for the following purposes:

  • Providing the Platform and related customer service

  • Maintaining your account

  • Communicating with you about the Platform

  • Securing your account, as well as the Platform as a whole, and detecting and preventing fraud

  • Analyzing use of the Platform to improve the Platform and develop new features and products

  • In accordance with applicable law, sending marketing communications

  • Addressing disputes involving Justworks and / or Customer Users, including with respect to bringing or ‎defending against claims or litigation‎

  • Complying with legal obligations and protecting Justworks and our users by enforcing our terms

The laws in some jurisdictions (e.g., the European Union, United Kingdom, and Brazil) require us to tell you about the legal grounds on which we rely to process your information. Our legal bases for processing your information as described in this Privacy Policy are as follows:

  • Where use of your information is necessary to perform our obligations under a contract or commitment to you. For example, to provide the services you’ve requested from us, or to comply with our legal terms with Customers.

  • Where use of your information furthers our legitimate interests or the legitimate interests of others. For example, to provide security for our Platform, operate our business and our Platform, make and receive payments, defend our legal rights, and prevent fraud.

  • Where we use your information to comply with applicable legal obligations. For example, keeping track of purchases for tax and auditing purposes.

  • Where you have consented to our processing of your information for a particular purpose.

Data combination. For the purposes discussed in this Privacy Policy, we may combine the information that we collect through the Platform with information that we receive from other sources, both online and offline, and use such combined information in accordance with this Privacy Policy.

De-Identified Information. We may de-identify information we collect so the information cannot reasonably identify you or your device, or we may collect information that is already in de-identified form. Our use and disclosure of de-identified information is not subject to any restrictions under this Privacy Policy, and we may use and disclose it to others for any purpose, without limitation.

4. How We Disclose the Information We Collect

In certain circumstances, we may disclose information about you to third parties for our business purposes subject to this Privacy Policy. Such circumstances may include:

  • With our affiliates and subsidiaries under common ownership and / or control.

  • With vendors/service providers (e.g., payment processors, data analytics vendors, cloud storage providers, IT service management vendors, identity verification providers, email services vendors, security vendors) that provide services on our behalf.

  • When you, our Customer, or an Administrator requests us to share certain information with third parties, such as through your use of integrations.

  • To the Customer that has invited you to use the Platform and its Administrator(s) and to other entities when instructed by such Customer / Administrator(s).

  • In connection with or anticipation of an asset sale, merger, bankruptcy, or other business transaction involving all or a portion of our business / assets.

  • To comply with applicable law or any obligations thereunder, including cooperation with law enforcement, judicial orders, and regulatory inquiries.

  • To enforce any applicable terms of service and ensure the safety and security of Justworks and / or its users.

  • With professional advisors, such as auditors, law firms, or accounting firms.

Cookie Technologies are small files or code placed on your browser or device; they are designed to store basic information and to help websites and apps recognize your browser. We may use both session cookies and persistent cookies. A session cookie disappears after you close your browser. A persistent cookie remains after you close your browser and may be accessed every time you use the Services.

Most browsers accept cookies automatically, but you may be able to control the way in which your devices permit the use of Cookie Technologies. If you so choose, you may block or delete our cookies from your browser; however, blocking or deleting cookies may cause parts of the Platform, including certain features and general functionality, to work incorrectly.

Do Not Track. Your browser settings may allow you to transmit a “do not track” signal “opt-out preference” signal, or other mechanism for exercising your choice regarding the collection of your information when you visit various online services. Like many services, our Platform is not designed to respond to such signals and we do not use or disclose information collected through the Platform in any way that would legally require us to recognize opt-out preference signals.

6. User Generated Content

  • The Platform also hosts tools, which you may elect to use, that enable you to submit information (e.g., messages, photos, recordings, etc.) (“User-Generated Content” or “UGC”). We or others may store, display, reproduce, publish, or otherwise use UGC, and may or may not attribute it to you. Others may also have access to UGC, such as other Platform users who work at your company, and may have the ability to disclose it to third parties. If you choose to submit UGC viewable by others, your UGC will be considered “public” and will be accessible by anyone, including Justworks.

  • Please note that we do not control who will have access to the information that you choose to make available to others, and cannot ensure that parties who have access to such information will respect your privacy, keep it secure, or not further disclose it to others. We are not responsible for the privacy or security of any information that you make non-private on the tools permitting creation of UGC or what others do with information you share with them on such platforms. We are not responsible for the accuracy, use or misuse of any UGC that you disclose or receive from third parties through the Platform.

We may provide links within the Platform to websites or other online platforms operated by third parties. If you follow links to sites not affiliated or controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of these sites, including the accuracy, completeness, or reliability of information found on these sites. Information you provide on public or semi-public venues, including information you share on third-party social networking platforms may also be viewable by other users of the Platform and/or users of those third-party platforms without limitation as to its use by us or by a third party. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators, except as disclosed on the Platform.

8. Your Privacy Rights and Choices

Information rights and choices. We provide you with the ability to exercise certain controls and choices regarding our collection, use, and disclosure of your information. Depending on the laws in your jurisdiction of residence (e.g., California, Colorado, United Kingdom, European Union), you may request:

  • General information about our processing activities

  • Confirmation that we are processing your information

  • Access to, or a copy of, your information in a structured, commonly used and machine-readable format

  • Correction or rectification of your information

  • Deletion of your information

  • Restriction or objection to certain processing of your information

  • To withdraw your consent to our use of your information for certain processing purposes, where the processing purpose was based on your consent

Please note that we do not make decisions based solely on the automated processing of your information.

We may ask you to provide us with information necessary to reasonably verify your identity before responding to your request. We will consider all requests and provide our response within the time period required by applicable law. Please note, however, that certain information may be exempt from such requests. If we deny your request in whole or in part, you may have the right to appeal the decision. In such circumstances, we will provide you with information regarding the appeals process.

To make a request, please contact us using the How to Contact Us information below.

Sale/Targeted advertising opt out rights. Under the laws in certain United States jurisdictions, you also have the right to opt out of our processing or sharing of your information for online targeted advertising purposes. Note that certain state laws also allow you to opt out of the “sale” of your information to third parties in exchange for valuable consideration. We do not “sell” or “share” (as defined under applicable laws) personal information regarding Customer Users or Administrators collected through the Platform, nor have we done so in the preceding 12 months.

Marketing choices. You can opt out of receiving marketing emails from us by following the instructions at the bottom of the email. Please note that your request will take some time to process, in accordance with applicable law. After you opt out, you will still receive transactional communications from us regarding your account or important legal information.

9. Children's Privacy

Children under the age of 16 are not permitted to use the Platform, and we do not seek or knowingly collect any personal information about children under 16 years of age. If we become aware that we have unknowingly collected information about a child under 16 years of age, we will make commercially reasonable efforts to delete such information. If you are the parent or guardian of a child under 13 years of age who has provided us with their personal information, you may contact us using the below information to request that it be deleted.

10. Security and Retention of Your Information

We maintain a variety of physical, administrative, technical, and organizational security controls. However, please be aware that, despite our efforts to protect your information, no security measures are perfect or impenetrable, and we cannot guarantee “perfect security.” Any information you send to us electronically, while using the Platform or otherwise interacting with us, may not be secure while in transit. We recommend that you do not use unsecure channels to communicate sensitive or confidential information to us.

We retain your information for as long as is reasonably necessary for the purposes specified in this Privacy Policy. When determining the length of time to retain your information, we consider various criteria, including whether we need the information to continue to provide you the Platform, resolve a dispute, enforce our contractual agreements, prevent harm, promote safety, security and integrity, or protect ourselves, including our rights, property or products.

11. Additional Information for California Residents

This section applies to Administrators and Customer Users who are California residents (“residents”). For purposes of this section, references to “personal information” shall include “sensitive personal information,” as these terms are defined under the California Consumer Privacy Act (“CCPA”). The CCPA requires us to provide you with the following additional information about:

  • the purpose for which we use each category of personal information we collect; and

  • the categories of third parties to which we (a) disclose such personal information for a business purpose, (b) “share” personal information for “cross-context behavioral advertising,” and/or (c) “sell” such personal information.

We do not “sell” or “share” Administrator or Customer User personal or sensitive information collected through the Platform, and have not done so over the preceding 12 months. In the preceding 12 months, we collected and (where indicated below) disclosed for a business purpose the following categories of personal information and sensitive personal information about Administrator and/or Customer User residents:

Category

Categories of Recipients

Identifiers and records information such as name, e-mail address, IP address, government ID, social security number, financial account numbers

Affiliates; Vendors; Customers; Entities for legal purposes; Entities for business transactions; Professional advisors

Characteristics of protected classifications under California or Federal Law (e.g., gender, race/ethnicity, age)

Affiliates; Vendors; Customers; Entities for legal purposes; Entities for business transactions; Professional advisors

Internet or other similar network activity such as information regarding your interaction with the Platform

Affiliates; Vendors; Customers; Entities for legal purposes

Geolocation data such as IP address or precise geolocation information in connection with certain products (e.g., timekeeping)

Affiliates; Vendors; Customers; Entities for legal purposes;

Audio, electronic, visual, thermal, olfactory, or similar information, such as voice recordings when you call customer support or selfies in connection with identity verification

Vendors; Customers; Entities for legal purposes

Professional or employment-related information such as title of profession, employer, professional background

Affiliates; Vendors; Customers; Entities for legal purposes; Entities for business transactions; Professional advisors

Account access credentials such as account log-in, in combination with any required security or access code, password, or credentials allowing access to your account

Affiliates; Vendors; Customers; Entities for legal purposes

Administrators only: Commercial and financial information about your company such as records of products or services purchased and financial account information

Affiliates; Vendors; Entities for legal purposes; Entities for business transactions Professional advisors

Administrators only: Inferences drawn from other personal information such as profile reflecting your preferences

Affiliates; Vendors; Entities for business transactions

The specific business or commercial purposes for which we collect your personal and sensitive information, the categories of sources from which we collect your personal information, and more information about the entities to which we disclose your personal information are described in the sections above, How we Collect Your Information, How we Use Your Information, and How we Disclose Your Information.

Other CCPA rights.

Financial incentives. We do not offer any financial incentives for the collection, sale or sharing, or retention of personal information in connection with the Platform.

Right to Limit. The CCPA allows you to limit the use or disclosure of your “sensitive personal information” (as defined in the CCPA) if your sensitive personal information is used for certain purposes. Please note that we do not use or disclose sensitive personal information other than for business purposes for which you cannot opt out under the CCPA.

Personal Information rights. Please see the “Your Privacy Rights and Choices” section of our Privacy Policy above for information about the additional rights you have with respect to your personal information under California law and how to exercise them.

12. Information for International Users

We operate globally and may transfer, store, and / or process your information to or with other entities within the Justworks family of companies or other third parties such as trusted service providers and partners in locations around the world (including the United States) for the purposes described in this Privacy Policy. Wherever your information is transferred, stored or processed by us, we take reasonable steps to protect your information in accordance with this Privacy Policy and applicable laws. These measures may include implementing Standard Contractual Clauses to govern the transfer of your information, or other means recognized by applicable laws. By providing us with your information, you acknowledge any such transfer, storage, or processing.

If you have any concerns or complaints about our data processing activities, we urge you to first try to resolve such issues directly with us by contacting us using the information below. However, if applicable, you may make a complaint to the data protection supervisory authority in the country where you are based, or seek a remedy through local courts if you believe your rights have been breached.

13. Contact Us

The Platform is owned and operated by Justworks, Inc. If you have any questions about our privacy practices or this Privacy Policy, or if you wish to exercise any of the data rights discussed above, you can write to us at Justworks, Inc., P.O. Box 7119, Church Street Station, New York, NY 10008-7119, call (888) 534-1711, or you can simply click on Contact Us to send us an email.