US Workforce Privacy Notice
Effective date: October 2, 2023
This notice (Notice) sets out how Vestis collects, uses, stores, and shares personal information about our staff, including our current and former employees, temporary staff, consultants, contingent workers, and interns (staff or you or your). This Notice also applies to applicants of Vestis.
For purposes of this Notice, Vestis refers collectively to the Vestis group company that employs or engages you or any of its affiliate entities (“Vestis” or “we” or “our”). These companies can be reached using the relevant contact details set out in the “Your contact for any queries” Section below.
- Information we collect about you
- For purposes of this Notice, personal information means information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Personal information excludes deidentified information that cannot reasonably identify, relate to, describe, be capable of being associated with, or be linked, directly or indirectly, to a particular consumer. You are the sole source of this personal information unless an additional source is indicated below. We will collect and use some or all of the following personal information before, during, and after your employment (or similar engagement):
- Identifiers, such as name, date and place of birth, email, current and prior postal addresses, phone numbers;
- Professional or employment information, such as department, work location, job title information, absences from work, performance information, criminal history, performance evaluations, training records, job referral and references information, licenses, certifications, and professional organization membership (if applicable);
- Additional Sources of Personal Information: Third-party references, credit agencies, third-party entities conducting or reporting on such training, courses, or assessments, or entities verifying work authorization or membership;
- Compensation and benefits information: such as compensation details, bonus payments, pension details, and medical and other insurance;
- Additional Sources of Personal Information: Third-party entities required to verify such information, where necessary;
- Disciplinary, capability, and conduct records, details or of warnings and other records relating to conduct;
- Additional Sources of Personal Information: Third-party entities that collect and report on such information, where necessary;
- Age and benefits information, including your date of birth, national insurance numbers, information about your pension and other welfare or benefits, and information regarding your use of statutorily-protected or company-protected leaves, such as bereavement leave, domestic violence survivor leave, crime victim leave, military service leave, and marital status;
- Additional Sources of Personal Information: Third-party entities providing information to verify the information you provided, where necessary;
- Beneficiaries, dependents, and emergency contact information, such as information about any beneficiaries, dependents, emergency contacts, and next of kin;
- Internet or electronic network activity or other monitoring information, such as details of your use of and communications sent through Vestis systems and general geolocation information, and recordings from surveillance cameras on our business premises;
- Additional Sources of Personal Information: Information we may collect from your device or from Vestis surveillance cameras;
- Commercial information, such as details of travel that you undertake, or expenses you incur, in connection with your employment or engagement;
- Protected classifications, such as your, gender, age, marital status, or military or veteran status, and disability status;
- Vehicle usage information, such as dashboard camera footage;
- Education information, such as your prior training;
- Additional Sources of Personal Information: Third-party entities providing information to verify the information you provided, where necessary;
- National identification information, such as your country of birth or the country where you are a registered national citizen, and any visa or other right to work documentation;
- Additional Sources of Personal Information: Third-party entities verifying work authorization;
- Financial information, such as your bank account information and wage garnishment records (such as for child support obligations);
- Additional Sources of Personal Information: Third-party entities providing payment services and/or wage garnishment information;
- Driving history, drug testing and criminal history;
- Additional Sources of Personal Information: Third-party entities that conduct and report on background checks and screening.
- Any other information that you store on our equipment and computer systems, such as electronic communications or documents that you create or upload to our systems;
- Additional Sources of Personal Information: Information we may collect from monitoring your company device;
- Sensitive personal information, insofar as necessary and legally permitted, such as: (1) Social Security, driver’s license, state identification, or passport number, (2) account login, financial account, debit card or credit card number, in combination with any required security or access code, password, or credentials allowing access to an account, (3) precise geolocation, (4) racial or ethnic origin, religious or philosophical beliefs, or union membership, (5) the contents of your mail, email or text messages, unless we are the intended recipient of the communication, (6) biometric information for the purpose of uniquely identifying you, (7) information regarding your health, such as information relating to health and safety in the workplace, accidents and near misses, and vaccination records and vaccination status information, (8) information regarding your sexual orientation; and
- Additional Sources of Personal Information: Third-party references, credit agencies, entities verifying work authorization, third-party entities that verify memberships, or information that may be collected from monitoring your device.
- Other information provided by you, including internal survey responses.
- For purposes of this Notice, personal information means information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Personal information excludes deidentified information that cannot reasonably identify, relate to, describe, be capable of being associated with, or be linked, directly or indirectly, to a particular consumer. You are the sole source of this personal information unless an additional source is indicated below. We will collect and use some or all of the following personal information before, during, and after your employment (or similar engagement):
- How we use personal information
The purposes for which we use your personal information are as follows:
-
- Recruiting and Hiring, such as determining your eligibility for work and suitability for certain job roles (to the extent permitted or required by law), checking references, and performing background checks.
- For recruiting purposes and to help us determine your ability to perform the job, we process your identifiers, professional or employment information, national identification information, and education information.
- Conducting checks, such as background checks, credit checks, anti-fraud checks, checks to prevent fraud and money laundering and drug tests, to the extent allowed under applicable employment laws.
- For purposes of conducting checks, we process your identifiers, protected classifications, professional or employment information, national identification information, and driving history and drug history.
- General HR administration, such as staff communications, on-boarding and off-boarding, succession planning, managing your career development, performing our legal obligations in relation to your professional or trade membership, assessing your suitability for a particular role, assessing your salary and other compensation, and performance, and assessing and taking action in relation to disciplinary, capability, grievance, and other conduct issues, and maintaining your employee records.
- For our general HR administration, we process your identifiers, professional or employment related information, beneficiaries, dependents, and emergency contact information, education information, disciplinary, capability, and conduct records, protected classifications, and financial information.
- Administering salary, expenses, and staff benefits, including administering insurance, payroll, retirement plans, and other employee benefits and tax, and in order to administer corporate expenses and reimbursements (including viewing details of transactions made using corporate credit cards and corporate travel undertaken).
- To administer salary, expenses, and benefits, we process your professional or employment information, compensation and benefits information, beneficiaries, dependents, and emergency contact information, commercial information, and financial information.
- Managing absences and occupational health requirements, including to keep a record of absences and to contact dependents or other family members in the event of an emergency.
- To manage absences and occupational health requirements, we process your identifiers, professional or employment information and protected classifications.
- Monitoring, such as monitoring for compliance with applicable state or federal laws and regulations, any Vestis policies provided to you, and limited monitoring of information technology systems (including communications transmitted through these systems) solely to the extent permitted by applicable law, including to prevent, detect and fight fraud or other illegal or unauthorized activities.
- For monitoring, compliance, and security purposes, we process your identifiers, vehicle usage information, internet or electronic network activity information, and employment or professional information.
- Such monitoring may be of dashboard camera footage, telephone conversations or transmissions, electronic mail or transmissions, or internet access or usage of or by an employee by any electronic device or system, including but not limited to the use of a computer, telephone, mobile device, wire, radio, or electromagnetic, photoelectronic or photo-optical systems, at any and all times and by any lawful means.
- Information Technology (IT) purposes, such as providing IT support for Vestis Information Systems and user authentication.
- For IT purposes, we process your identifiers, professional or employment information, and internet or electronic activity information.
- Storing staff communications, records, and work product, including as required in order to operate the Vestis business. These communications and records may contain personal information both related to work and private matters.
- For storing staff communications, records, and work product, we process your identifiers, professional or employment information, and internet electronic activity information.
- Complying with our legal obligations, like monitoring equal opportunities, complying with audits, ensuring an effective compliance program, or where necessary, for exercising, establishing, or defending legal claims, including the disclosure of your personal information to third parties in connection with proceedings or investigations anywhere in the world, such as public authorities, law enforcement agencies, regulators, and third-party litigants.
- For these purposes, we collect your identifiers, vehicle usage information, protected classifications, employment and professional information, age and benefits information, and internet or electronic network information.
- Uses of your sensitive personal information include:
- Health and disability records: We will use this information to address our legal obligations to you in relation to health and safety in the workplace, for any required reporting purposes (e.g., our workers’ compensation carrier), and to address our legal obligations to you, make any accommodations required to assist you in the performance of your role and determine whether you are fit to undertake tasks required by your job role.
- Equal opportunities monitoring information: We will use this information, such as your ethnicity, religion, gender, and sexual orientation, which you would provide only on a voluntary basis, to conduct equal opportunity and diversity monitoring where permitted or required by law.
- Biometric information: We will use this information, such as facial recognition, fingerprint or hand punch/hand-geometry data collected by a biometric time clock to monitor and record your hours of work unless otherwise prohibited by law. We will also use this information, such as vehicle usage information, to investigate incidents, to monitor and encourage the safe operation of Vestis vehicles, to monitor, track and protect Vestis’s inventory of vehicles, and to monitor and manage compliance with Vestis’s policies or state or federal law.
- As required: We will also use sensitive personal information to ensure compliance with legal and regulatory requirements, and for any other purposes required by law or government authorities.
- When changing our business structure, such as in the event of a business sale or corporate restructuring, where we may disclose your personal information to any potential acquirer of, or investor in, any part of the Vestis business (and to their legal advisors and consultants) for the purpose of that acquisition or investment.
- For this purpose, we process your identifiers, employment or professional information, and protected classifications.
- Recruiting and Hiring, such as determining your eligibility for work and suitability for certain job roles (to the extent permitted or required by law), checking references, and performing background checks.
- How we share personal information
In connection with the purposes listed above and consistent with this Notice:
-
- The Vestis group company that employs or engages you shares your personal information with Vestis affiliates where required for Vestis’s internal administrative purposes. Vestis may grant other group entities access to such data where required for the purposes consistent with this Notice.
- In limited situations, Vestis may share your personal information with certain third parties for the purpose of managing Vestis’s relationship with its clients and related parties, such as unions.
- Subject to local legal requirements, we may use third parties to assist us with human resources and IT related services, including but not limited to payroll providers, healthcare providers, insurers, retirement administrators, information systems storage providers, IT managed service providers, accountants, and legal advisors, and other third-party vendors that need your personal information to provide their services. We require that such external service providers or third parties will ensure adequate protection for your personal information and will comply with local legal requirements and our privacy and data security standards.
- In addition, we may share your personal information with other third parties where disclosure is permitted or required by law to comply with legal obligations, protect our rights and property, or protect the safety of our staff or any third party.
- Sensitive Personal Information
Your sensitive personal information will not be used for any additional purposes that are incompatible with the purposes listed above unless we provide you with notice of those additional purposes.
- Storage of personal information
We will retain your personal information for as long as is necessary for the purposes for which it was collected and any other permitted or required purposes (such as to comply with regulatory requirements to retain such information). Our retention periods are based on business needs and relevant laws. Please note that these periods may be extended where reasonably necessary (for example where we are required to do so by law or by a regulator). We retain your personal information for up to 7 years following the end of your services or other business relationship in accordance with applicable law. We will either deidentify or securely destroy personal information that we no longer need. We reserve the right to use deidentified information for any legitimate business purpose without further notice to you or your consent.
- Your California Privacy Rights
- Vestis complies with laws and regulations that permit certain requests related to your data in our files, including, but not limited to, the California Consumer Privacy Act (the “CCPA”). The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides California residents with the following rights regarding their Personal Information.
- The right to know what personal information we have collected, used, disclosed, and sold about you, including the categories of personal information, the categories of sources from which the personal information is collected, the business or commercial purpose for collecting, selling, or sharing personal information, the categories of third parties to whom Vestis discloses personal information, and the specific pieces of personal information Vestis has collected about you.
- The right to correct inaccuracies in your personal information, taking into account the nature of the personal information and the purposes of the processing.
- The right to request deletion of personal information we have collected from you.
- The right to opt out of the selling or sharing of your personal information.
You may exercise these rights by contacting Vestis as described in the queries/concerns section below. You may also designate an authorized agent to make a request on your behalf by contacting us as described below. In order to protect your data from unauthorized access or alteration by third parties, all requests regarding your personal information will be subject to verification of the identity of the requesting individual. We endeavor to respond to a verifiable request within forty-five (45) days of its receipt. If we require more time (up to forty-five (45) days), we will inform you in writing.
- If you have any queries or concerns regarding personal information, please contact us at:
Privacy@vestis.com
Privacy Team Vestis
115 N. First Street
Burbank, CA 91502
- Changes to this Notice
This Notice was last updated on the effective date listed at the top of this Notice. We will notify you of any material changes to this Notice by posting information about the change.