Namely Privacy Policy
Overview
This Privacy Policy describes Namely, and our subsidiaries and affiliates collect, use, share, and protect business, financial, and personal information. This Policy applies to all information collected or submitted on this website and mobile applications (“Site”). This policy is available on the homepage of this Site and at every login page where personally identifiable information may be requested.
Purpose
Your privacy, and the privacy of the information provided, is important to us. We responsibly protect your data from loss, misuse, unauthorized access, disclosure, alteration, and untimely destruction. We do not grant access to your personal information except as otherwise set forth herein. We do not share or sell personal information collected on the Site with any third parties for their marketing purposes. At times, we will provide you with links to other websites. We encourage our users to be aware when they leave our Site, and to read the privacy statements of every website that collects personally identifiable information.
Information Collection and Use
WHAT INFORMATION IS COLLECTED
We limit the collection of personal information to the information that we need to administer and improve the Site, to provide our products and services (“Services”) to our customers, and to fulfill any legal and regulatory requirements.
THE CATEGORIES OF PERSONAL INFORMATION THAT WE COLLECT MAY INCLUDE, BUT ARE NOT LIMITED TO:
- Contact information to allow us to communicate with you.
- Company name, address, and business information to provide Services.
- If a quotation is requested, employee information, including Social Security number, date of birth, financial, bank account, biometric, geolocation, medical, and beneficiary information, to provide Services.
- Credit, debit, or cash/payment card information if used, such as for billing.
- Credit or debt history regarding your creditworthiness or credit history.
- Employment history and application information can be used to determine eligibility for a job opening via our recruiting page.
HOW PERSONAL INFORMATION IS COLLECTED
We do not require you to provide any personal information in order to have general access to the Site. However, to access or use certain information, features, or services at the site, you may be required to provide personal information.
PERSONAL INFORMATION IS PRIMARILY COLLECTED:
- When you utilize the services, we obtain the information we need to provide the services.
- From applications, forms, and other information you provide us on the site.
- When you establish an account or an account is established for you at the direction of your employer, to receive services.
- From survey information and/or Site registration.
- If you provide us with comments or suggestions, request information about our services, or contact our Customer Service Department via phone, email, or other forms of communication.
- From consumer and business reporting agencies regarding your creditworthiness or credit history.
- From third parties to verify information given to us.
- From information you may provide via social media.
SMS Terms and Conditions
By providing your mobile number and opting in to receive SMS (Short Message Service) messages from Namely, you consent to receive event-based text messages related to your account, services, customer support, alerts, and other information relevant to your relationship with Namely.
- Message Type: Event-based (messages are only sent in response to specific actions, triggers, or events).
- Message Frequency: Varies depending on your interaction with our services. You will only receive messages relevant to events such as account changes, service updates, appointment reminders, or transactional notices.
- Message & Data Rates: Standard message and data rates may apply.
- Opt-Out Instructions: You can opt out of SMS messages at any time by replying STOP to any message you receive. For help, reply HELP or contact us using the methods below.
- Help: Reply HELP for more information. You may also contact Namely at 800.941.8731 or privacy@namely.com
- Use of Phone Numbers: Your mobile number will be used solely for the purposes described in this policy. We will not sell your number or use it for unrelated marketing without additional consent.
Your consent to receive SMS messages is not a condition of purchasing any goods or services. See additional information on SMS messaging below. Carriers are not liable for delayed or undelivered messages.
HOW PERSONAL INFORMATION IS USED
We use the information provided on the site to perform the services you request.
WE LIMIT THE COLLECTION OF PERSONAL CUSTOMER INFORMATION USED TO:
- Facilitate customer requested services, transactions, investments, distributions, and benefits.
- Provide superior service to our customers.
- Comply with legal, reporting, and regulatory requirements.
- Administer and improve our sites.
- Detect fraud or theft to protect our business and client information.
- Contact you with information on services, new services or products, or upcoming events.
- Facilitate applicant tracking and recruitment.
HOW AGGREGATED, NON-PERSONAL INFORMATION IS USED
We may collect general, non-personal, statistical information about the users of the site and our services in order to determine information regarding the use of our site and general information about our customers. We may also group this information to provide general aggregated data. The aggregated data will not personally identify any customers or visitors to the site.
HOW COOKIES ARE USED
A “cookie” is a piece of data that our site may provide to your browser while you are at our site. The information stored in a cookie is used for user convenience purposes, such as reducing repetitive messages, tracking helper tool versions, and retaining user display preferences. If a user rejects the cookie, they will be able to browse the site but will be unable to use our online application.
Namely may use third-party service providers to use cookies, web beacons, and similar technologies to collect or receive information from our site and elsewhere on the Internet and use that information to provide measurement services and target ads. You can opt-out of this information tracking using a web browser that supports a “Do Not Track” functionality.
GLOBAL PRIVACY CONTROL (GPC)
We recognize and honor opt-out preference signals sent via Global Privacy Control (GPC). If your browser or extension supports GPC and it is enabled, we will treat it as a valid request to opt out of the sharing of your personal information. We process GPC signals in a frictionless manner, meaning you do not need to take additional steps for your opt-out to be honored. We provide a means for you to confirm whether an opt-out request, including a GPC signal, has been honored.
CHILDREN AND KNOWN MINORS
The Site is not directed to children under thirteen, and we do not knowingly collect personal information directly from children under thirteen through the Site. Information about dependents that is needed to provide benefits or related services may be provided by an employee, parent, guardian, client, or other authorized person and is handled in accordance with this Policy and applicable law.
When Namely has actual knowledge that a consumer is a minor and applicable law requires consent before selling the minor’s personal data or processing it for targeted advertising, Namely will not engage in that processing without the required consent. This includes personal data of a Delaware consumer known to be between thirteen and seventeen years of age and personal data of a New Hampshire consumer known to be at least thirteen and under sixteen years of age. Where required, Namely will provide a mechanism to revoke consent and will stop the covered processing within the period required by applicable law.
Privacy Notice for California Consumers
This Privacy Notice for California Consumers supplements the information contained in the Privacy Statement of the Namely Privacy Policy and applies solely to California residents whose personal information is subject to comply with the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (collectively, the “CCPA”). It describes our collection, use, disclosure, sale, and sharing practices; retention practices; and California privacy rights. Terms defined in the CCPA have the same meaning when used in this Notice.
CALIFORNIA PRIVACY RIGHTS
Under California Civil Code 1798, California residents with an established business relationship can request information about sharing their personal information with third parties for the third parties’ direct marketing purposes. If you are a California resident and would like more information, please contact your service provider.
PARTIES WITH WHOM INFORMATION MAY BE SHARED
Information is shared to facilitate the Services needed in order to properly and efficiently handle duties related to your account.
WE MAY SHARE INFORMATION WITH:
- Government agencies to fulfill legal, reporting, and regulatory requirements.
- Attorneys, accountants, and auditors.
- Credit reporting agencies to supply vendor references on client’s behalf.
- Our employees, affiliated companies, subsidiaries, agents, and third-party service vendors to perform Services related to your account, to offer additional Services, perform analysis to determine qualification to receive future services, or collect amounts due.
- Banking and brokerage firms to complete payroll processing and securities transactions.
- Credit bureaus and similar organizations, law enforcement, or government officials. We reserve the right to release information if we are required to do so by law or if, in our business judgment, such disclosure is reasonably necessary to comply with legal process, in a fraud investigation, an audit, or examination.
- Affiliated companies that you select on our site for the purposes of obtaining more information or a proposal for services.
HOW TO ACCESS AND CORRECT YOUR INFORMATION
Keeping your information accurate and up to date is very important. You can review or correct your account information by contacting a customer service representative. If you have an account at the site, you can make changes to your account information after you log in to the Site from your PC or wireless device and use the online tools. Note that some information changes may be made by or have to be done through your employer.
CHANGES TO THIS PRIVACY STATEMENT
This Policy may be revised from time to time due to legislative changes, changes in technology or our privacy practices, or new uses of personal information. We will post revisions on this page with an updated revision date. Where applicable law requires notice or consent before a change takes effect, we will provide that notice or obtain that consent.
Information We Collect
We collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer (“personal information”).
WE COLLECT THE FOLLOWING CATEGORIES OF PERSONAL INFORMATION AS INDICATED BELOW:
PERSONAL INFORMATION DOES NOT INCLUDE:
- Publicly available information from government records
- De-identified or aggregated consumer information
- Information excluded from the CCPA’s scope, like:
- health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data.
- personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver’s Privacy Protection Act of 1994.
WE OBTAIN THE CATEGORIES OF PERSONAL INFORMATION LISTED ABOVE FROM THE FOLLOWING CATEGORIES OF SOURCES:
- Directly from our clients, prospects, or employees. For example, from documents that our clients provide to us related to the services for which they engage us.
- Indirectly from our clients, prospects, or their employees. For example, through information we collect from our clients in the course of providing services to them.
- Directly and indirectly from activity on our website (www.namely.com) or other portals. For example, from submissions through our website or website usage details collected automatically.
- From third parties that interact with us in connection with the services we provide. For example, from government agencies when we verify data associated with payroll processing and withholding tax payments.
We may also collect personal information about you from other categories of sources, such as our affiliates; our other clients; public and publicly available sources; our third-party referral partners, vendors, data suppliers, and service providers; partners with which we offer co-branded services or engage in joint event or marketing activities; social networks; news outlets and related media; and organizations with which you are employed or affiliated.
Use Of Personal Information
WE MAY USE OR DISCLOSE THE PERSONAL INFORMATION WE COLLECT FOR ONE OR MORE OF THE FOLLOWING BUSINESS PURPOSES:
- To fulfill or meet the reason for which the information is provided. For example, if you provide us with personal information in order for us to prepare a proposal for services, we will use that information to prepare the proposal.
- To provide you with information, products, or services that you request from us.
- To provide you with email alerts, event registrations, and other notices concerning our products or services, or events or news, that may be of interest to you.
- To operate, manage, and maintain our business.
- To accomplish our business purposes and objectives.
- To communicate with you.
- To carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collections.
- To improve our website and present its contents to you.
- For testing, research, analysis, and service offering development.
- For vendor management purposes.
- As necessary or appropriate to protect the rights, property, or safety of us, our clients, or others.
- To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
- As described to you when collecting your personal information or as otherwise set forth in the CCPA.
- To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by us is among the assets transferred.
We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.
Sharing Personal Information
SALE AND SHARING OF PERSONAL INFORMATION
Namely does not sell personal information for money. Some disclosures to advertising or analytics providers may constitute “sharing” for cross-context behavioral advertising under the CCPA, even when no money is exchanged. The categories of personal information shared, the purposes for sharing, and the categories of recipients must correspond to Namely’s actual practices and the disclosures in this Notice and the Notice at Collection.
We may disclose your personal information to a third party for a business purpose. When we disclose personal information for a business purpose, we require the recipient to keep that personal information confidential and secure, to not disclose that personal information to others, and to not use it for any purpose except performing the services related to the business purpose.
IN THE PRECEDING TWELVE MONTHS, WE HAVE DISCLOSED THE FOLLOWING CATEGORIES OF PERSONAL INFORMATION FOR BUSINESS PURPOSES:
- Category A: Identifiers
- Category B: California Customer Records Personal Information Categories
- Category C: Protected Classification Characteristics Under California or Federal Law
- Category D: Commercial Information
- Category E: Biometric Information
- Category F: Internet or Other Electronic Network Activity Information
- Category G: Geolocation Data
- Category I: Professional or Employment-Related Information
- Category K: Inferences Drawn from Other Personal Information
WE DISCLOSE YOUR PERSONAL INFORMATION FOR A BUSINESS PURPOSE TO OUR AFFILIATES AND/OR TO ONE OR MORE OF THE FOLLOWING CATEGORIES OF THIRD PARTIES:
- Third-party service providers.
- Administrators authorized by your organization.
- Licensors or third-party applications (if you access a third-party application on our services through a license agreement with a licensor).
- Other parties where required by law or to protect our rights.
- Third parties to whom you or your agents authorize us to disclose your personal information in connection with products or services we provide to you.
In the preceding twelve (12) months, we have not sold any personal information to third parties within the scope of the application of the CCPA.
Your Rights and Choices
The CCPA provides California consumers with specific rights regarding their personal information. This section describes your CCPA rights and explains how to exercise those rights.
ACCESS TO SPECIFIC INFORMATION AND DATA PORTABILITY RIGHTS
You have the right to request that we disclose certain information about our collection, use, disclosure, sale, and sharing of your personal information, subject to the CCPA and applicable exceptions.
ONCE WE RECEIVE AND CONFIRM YOUR VERIFIABLE CONSUMER REQUEST, WE WILL DISCLOSE TO YOU:
- The categories of personal information we collected about you.
- The categories of sources for the personal information we collected about you.
- Our business or commercial purpose for collecting or sharing that personal information.
- The affiliates with whom we shared your personal information.
- The categories of third parties with whom we share that personal information.
- The specific pieces of personal information we collected about you (also called a data portability request).
- If we disclosed your personal information to a third party for a business purpose, separate lists identifying the personal information categories that each category of recipient obtained.
DELETION REQUEST RIGHTS
You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies.
WE MAY DENY YOUR DELETION REQUEST IF RETAINING THE INFORMATION IS NECESSARY FOR US OR OUR SERVICE PROVIDERS TO:
- Complete the transaction for which we collected the personal information, provide a product or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
- Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 seq.).
- Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
- Comply with a legal obligation.
- Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
California Privacy Addendum – Third-Party Integrations
This California Privacy Addendum – Third-Party Integrations supplements our Privacy Policy and applies only to California residents. It is intended to address the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CCPA”), and the California Invasion of Privacy Act, Cal. Penal Code §§ 630–638.55. It describes certain third-party integrations and tracking technologies that may collect, record, intercept, or transmit personal information through our Site and the choices available to California residents.
1. Third-Party Features and Tracking Technologies
Our Site may use social media integrations, advertising tools, analytics services, cookies, pixels, web beacons, software development kits, session-replay technologies, chat or support tools, and similar technologies provided by third parties. Depending on the technology and your interaction with the Site, these technologies may collect, record, or transmit identifiers, device and browser information, Internet or other electronic network activity, approximate geolocation, page interactions, clicks, scrolling, search terms, form-field interactions, chat content, or other communications submitted through the Site. Passwords, Social Security numbers, financial account information, health information, and other sensitive data should not be entered into non-secure chat, search, or free-form website fields unless the field is specifically designed and authorized for that information.
Third parties may receive this information contemporaneously with your interaction and may process it under their own privacy notices when they act independently. When a recipient processes personal information on our behalf as a service provider or contractor, we contractually restrict its use of the information as required by applicable law.
CIPA Notice and Consent
Where a technology may intercept, record, or receive the contents of a confidential communication or electronic communication, or may function as a pen register or trap-and-trace process under applicable law, we provide notice and obtain any consent required by law before activating the technology. Consent is not inferred from silence, continued browsing, or failure to change browser settings. If consent is declined or withdrawn, technologies requiring consent will remain disabled or will be disabled, except technologies that may lawfully operate without consent.
2. Purposes and CCPA Disclosures
We may use these technologies to enable Site functionality, measure and improve performance, provide analytics, prevent fraud, support social-media features, and deliver or measure advertising. Some disclosures to advertising or analytics providers may constitute “sharing” for cross-context behavioral advertising under the CCPA, even when no money is exchanged.
3. Right to Opt Out of Sale or Sharing
California residents have the right to direct us not to sell or share their personal information. You may exercise this right through the “Do Not Sell or Share My Personal Information” control available on our Site or by using a browser or extension that sends a recognized opt-out preference signal, such as Global Privacy Control. We treat a recognized opt-out preference signal as a valid request to opt out for the browser or device that sends it. We will not require you to create an account or provide additional information solely to exercise this right. You may change a prior privacy choice through the same privacy controls.
4. California Privacy Rights
Subject to the CCPA and applicable exceptions, California residents may have the right to:
- Know the categories and specific pieces of personal information we collect, use, disclose, sell, or share, as applicable.
- Opt out of the sale or sharing of personal information.
- Request deletion of personal information and correction of inaccurate personal information, subject to applicable exceptions.
- Limit the use and disclosure of sensitive personal information when the CCPA provides that right.
- Receive equal service and pricing and not be retaliated against for exercising CCPA rights.
To exercise access, correction, deletion, portability, or other applicable CCPA rights, please use the methods described in “Exercising Access, Data Portability, And Deletion Rights” below. Requests to opt out of sale or sharing may be submitted through the Site control or a recognized opt-out preference signal as described above.
Exercising Access, Data Portability, And Deletion Rights
TO EXERCISE THE ACCESS, DATA PORTABILITY, AND DELETION RIGHTS DESCRIBED ABOVE, PLEASE SUBMIT A VERIFIABLE CONSUMER REQUEST TO US BY EITHER:
Only you or a person registered with the California Secretary of State that you authorize to act on your behalf may make a verifiable consumer request related to your personal information.
YOU MAY ONLY MAKE A VERIFIABLE CONSUMER REQUEST FOR ACCESS OR DATA PORTABILITY TWICE WITHIN A TWELVE-MONTH PERIOD. THE VERIFIABLE CONSUMER REQUEST MUST:
- Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or that you are an authorized representative of a person about whom we collected personal information.
- Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. Making a verifiable consumer request does not require you to create an account with us. We will only use personal information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.
Response Timing
We will respond within forty-five days after receiving a request. When reasonably necessary and permitted by applicable law, we may extend the response period once by an additional forty-five days, provided that we notify you of the extension and the reason within the initial forty-five-day period.
We do not charge a fee to process or respond to your request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why and provide a cost estimate before completing the request.
NONDISCRIMINATION
We will not discriminate against you for exercising any of your CCPA rights.
UNLESS PERMITTED BY THE CCPA, WE WILL NOT:
- Deny you products or services.
- Charge you different prices or rates for products or services, including through granting discounts or other benefits, or imposing penalties.
- Provide you a different level or quality of products or services.
- Suggest that you may receive a different price or rate for products or services or a different level or quality of products or services.
Data Retention
We will retain your personal data only as long as necessary to fulfill the purposes for which it was collected, comply with our legal obligations, resolve disputes, and enforce our agreements.
Changes To Our Privacy Notice
At a minimum, this notice will be reviewed and updated on an annual basis. We reserve the right to amend this notice at our discretion and at any time. Any changes will be posted on this page with an updated revision date.
Contact Information
If you have any questions or comments about this notice, our Privacy Statement, the ways in which we collect and use your personal information, your choices and rights regarding such use, or wish to exercise your rights under California law, please do not hesitate to contact us.
First Class Mail, Return Receipt:
Namely
ATTN: HR Compliance Team
1475 S Price Rd
Chandler, AZ 85286
General Data Protection Regulation (GDPR) and UK GDPR
This section applies to the processing of personal data covered by the European Union General Data Protection Regulation (EU GDPR) and the United Kingdom General Data Protection Regulation (UK GDPR). It covers personal data relating to individuals in the European Union or United Kingdom in the following contexts: website visitors, prospects, client contacts, client employees, applicants, and workers. Rights and obligations apply according to the territorial scope and other requirements of the applicable law.
LEGAL BASIS FOR PROCESSING – GDPR
- We process your personal data only when we have a legal basis, including providing the services or information that you have requested.
- Consent: When you have given us permission to process your personal data for a specific purpose.
- Contract: When processing is necessary to perform a contract with you or to take steps at your request before entering into such a contract.
- Legal Obligation: When we are required by law to process your personal data.
- Legitimate Interests: When we process your data to pursue our legitimate business interests and those interests are not overridden by your rights and interests.
RIGHTS UNDER THE GDPR
Individuals whose personal data is subject to the EU GDPR or UK GDPR may have the following rights, subject to the conditions and exceptions in the applicable law:
- Access their personal data
- Rectify inaccurate data
- Erase their data (“right to be forgotten”)
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
- Object at any time to processing for direct marketing, including related profiling.
- Request human intervention and contest a decision where applicable rights concerning solely automated decision-making apply.
- Seek a judicial remedy where available under applicable law.
EXERCISING EU GDPR AND UK GDPR RIGHTS
You may submit a request using the contact methods listed in this Policy. We will respond without undue delay and ordinarily within one month after receiving the request. Where permitted by applicable law, we may extend that period by up to two additional months because of the complexity or number of requests; if so, we will notify you within the initial one-month period and explain the reason. Requests are generally free of charge unless they are manifestly unfounded or excessive. We may request information reasonably necessary to confirm identity. If we do not act on a request, we will explain why and provide information about applicable complaint and judicial-remedy rights.
Rights Under the New York SHIELD Act
New York residents are entitled to reasonable administrative, technical, and physical safeguards to protect their private information.
Data Security
We implement reasonable organizational, technical, and physical security measures designed to protect your information in accordance with the SHIELD Act, GDPR, and CCPA. However, no electronic transmission or storage of information can be entirely secure, so we cannot guarantee absolute security.
Policy On Compliance with Telephone Consumer Protection Act 47 U.S.C. § 227 For Sending SMS Text Messages
INTRODUCTION
The Telephone Consumer Protection Act (TCPA), codified at 47 U.S.C. § 227, is a significant federal statute enacted to safeguard consumer privacy against unwanted telemarketing calls, faxes, and SMS (Short Message Service) text messages. This policy outlines Namely procedures and standards our organization will adhere to in order to ensure compliance with the TCPA when sending SMS text messages to consumers.
OBJECTIVE
The primary objective of this policy is to establish a framework that ensures all SMS text messages sent by our organization are in compliance with TCPA regulations, thereby protecting consumer rights and avoiding legal penalties.
SCOPE
This policy applies to all employees, contractors, and third-party vendors involved in the creation, approval, and dissemination of SMS text messages on behalf of our organization.
DEFINITIONS
- TCPA: The Telephone Consumer Protection Act, a federal law that restricts telemarketing calls, auto-dialed calls, prerecorded calls, text messages, and unsolicited faxes.
- SMS Text Message: A short message service text message, which can include marketing, informational, or transactional content.
- Consent: Prior express written consent from the consumer, which is required for sending marketing SMS text messages.
CONSENT REQUIREMENTS
To comply with TCPA regulations, our organization must obtain prior express written consent from consumers before sending any SMS text messages for marketing purposes. This consent should be:
- Explicit: Clearly stating that the consumer agrees to receive marketing messages via SMS.
- Written: Documented in written form, which can be electronic or physical.
- Voluntary: Given freely by the consumer without any coercion.
Transactional or informational SMS text messages may be sent without prior consent but must comply with applicable regulations.
OPT-OUT MECHANISM
Every SMS text message must include an opt-out mechanism, allowing consumers to easily and promptly unsubscribe from receiving future messages. This can be achieved by including instructions within the message, such as replying with “STOP” to opt-out.
DATA SHARING
No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
DOCUMENTATION AND RECORD KEEPING
Our organization will maintain comprehensive records of consumer consent and opt-out requests. These records will include:
- Date and time consent was obtained.
- Method used to obtain consent.
- Copies of consent forms or applicable logs.
- Details or log of opt-out requests and confirmations.
MESSAGE CONTENT AND FREQUENCY
SMS text messages should be concise, relevant, and respectful of consumer privacy. Our organization will:
- Limit the frequency of messages to avoid overwhelming consumers.
- Ensure messages do not contain inappropriate or misleading content.
- Provide accurate information regarding the identity of the sender.
THIRD-PARTY VENDORS
Any third-party vendors involved in sending SMS text messages on behalf of our organization must comply with TCPA regulations. Our organization will conduct due diligence and establish contractual agreements to ensure vendors adhere to these standards.
TRAINING AND AWARENESS
Employees and contractors involved in SMS text messaging activities must receive regular training on TCPA compliance. This training will cover:
- Overview of TCPA regulations and requirements.
- Procedures for obtaining and documenting consumer consent.
- Opt-out mechanisms and record-keeping practices.
MONITORING AND ENFORCEMENT
Our organization will implement monitoring systems to ensure ongoing compliance with this policy. Non-compliance may result in disciplinary action, including termination for employees and contract termination for vendors.
REVIEW AND AMENDMENTS
This policy will be reviewed annually and amended as necessary to reflect changes in TCPA regulations or organizational practices. All amendments will be communicated to relevant stakeholders.
CONCLUSION
Adhering to TCPA regulations is crucial for maintaining consumer trust and avoiding legal penalties. This policy serves as a comprehensive guide to ensure our organization’s SMS text messaging practices are compliant, respectful, and transparent.
Privacy Notice for Colorado, Connecticut, Delaware, Nevada, Rhode Island, Utah, and Virginia
This Notice forms part of our Privacy Policy and provides supplemental information for residents of Colorado, Connecticut, Delaware, Rhode Island, Utah, and Virginia regarding rights available under applicable state privacy laws. This Notice applies specifically to residents of those states. These include the Colorado Privacy Act, Connecticut Data Privacy Act, Delaware Personal Data Privacy Act, Rhode Island Data Transparency and Privacy Protection Act, Utah Consumer Privacy Act, and Virginia Consumer Data Protection Act. The separate Nevada Privacy Rights section below applies to Nevada residents. If you are a Consumer residing in Colorado, Connecticut, Utah, or Virginia, the following provisions may apply to our processing of information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, to a particular consumer’s (“personal information”) as defined under the Privacy Laws.
For purposes applicable to Privacy Laws in this Notice, “consumer” or “customer” generally means a resident acting in an individual or household context, as defined by the applicable law. The term generally does not include an individual acting in an employment context or, where excluded provided by applicable law, a commercial context. “Personal data” means information is linked or reasonably linkable to an identified or identifiable individual and does not include deidentified data or publicly available information, as defined by applicable law.
Rhode Island Information-Sharing and Consent Disclosures
For Rhode Island residents, the categories of personal data we collect are described in “Categories of Personal Data,” and the categories of third parties to which we disclose personal data are described in “Sharing Personal Information.” Rhode Island law also requires a commercial website or internet service provider that collects personal data to identify all third parties to whom it has sold or may sell customers’ personally identifiable information. Namely does not sell personal data as “sale” is defined by the Rhode Island Data Transparency and Privacy Protection Act. If that practice changes, this Notice will be updated to identify the third parties to whom Namely has sold or may sell such information before any such sale occurs.
We will not process sensitive data concerning a Rhode Island customer without obtaining consent required by Rhode Island law. We will provide a mechanism to grant and revoke that consent. After receiving a revocation, we will stop the processing covered by the consent as soon as practicable and no later than fifteen days after receipt.
Changes to This Privacy Statement
This policy statement may be revised from time to time due to legislative changes, changes in technology or our privacy practices, or new uses of customer information not previously disclosed in this policy. Revisions are effective upon posting and your continued use of this site will indicate your acceptance of those changes. Please refer to this policy regularly.
Categories of Personal Data
We collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer (“personal information”).
WE COLLECT THE FOLLOWING CATEGORIES OF PERSONAL INFORMATION AS INDICATED BELOW:
1. Identifiers
A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers.
2. Personal Information
Contact, name, employment information, financial, and educational information.
3. Protected Classifications
Race, religious creed, color, national origin, ancestry, physical disability, mental disability, medical condition, marital status, sex, gender expression, gender identity, age, sexual orientation, military and veteran status.
4. Commercial Information
Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
5. Biometric Information
Colorado: Fingerprint, Voiceprint, Scan or record of an eye retina or iris, facial map, facial geometry, facial template, or other unique biological, physical, or behavioral patterns or characteristics.
“Biometric Information” does not include the following unless the biometric data is used for identification purposes: (i) a digital or physical photograph; (ii) an audio or voice recording; or (iii) any data generated from a digital or physical photograph or an audio or video recording.
This section does not apply to Connecticut, Utah, or Virginia.
6. Internet or other similar network activity
Mobile device and online identifiers, Mac address, IP address, cookie IDs, browser activity, search history, social media information, and information regarding your interaction with our website or mobile application.
7. Geolocation data
Physical location or movements.
8. Demographic Information
Age, gender, race, citizenship, ethnicity, date of birth, family or marital status, household income, education, professional and employment information.
9. Profile information
Any form of automated process performed on personal data to evaluate, analyze, or predict personal aspects related to an identified or identifiable individual’s economic situation, health, personal preferences, interests, reliability, behavior, location or movements.
10. Sensitive Data
Data revealing racial or ethnic origin, religious beliefs, mental or physical health condition or diagnosis, sexual orientation or citizenship or immigration status; the processing of genetic or biometric data for the purpose of uniquely identifying an individual; personal data collected from a known child; or precise geolocation data.
WE OBTAIN THE CATEGORIES OF PERSONAL INFORMATION LISTED ABOVE FROM THE FOLLOWING CATEGORIES OF SOURCES:
- Directly from our clients, prospects, or employees. For example, from documents that our clients provide to us related to the services for which they engage us.
- Indirectly from our clients, prospects, or their employees. For example, through information we collect from our clients in the course of providing services to them.
- Directly and indirectly from activity on our website (www.namely.com) or other portals. For example, from submissions through our website or website usage details collected automatically.
- From third parties that interact with us in connection with the services we provide. For example, from government agencies when we verify data associated with payroll processing and withholding tax payments.
We may also collect personal information about you from other categories of sources, such as our affiliates; our other clients; public and publicly available sources; our third-party referral partners, vendors, data suppliers, and service providers; partners with which we offer co-branded services or engage in joint event or marketing activities; social networks; news outlets and related media; and organizations with which you are employed or affiliated.
Use Of Personal Information
WE MAY USE OR DISCLOSE THE PERSONAL INFORMATION WE COLLECT FOR ONE OR MORE OF THE FOLLOWING BUSINESS PURPOSES:
- To fulfill or meet the reason for which the information is provided. For example, if you provide us with personal information in order for us to prepare a proposal for services, we will use that information to prepare the proposal.
- To provide you with information, products, or services that you request from us.
- To provide you with email alerts, event registrations, and other notices concerning our products or services, or events or news, that may be of interest to you.
- To operate, manage, and maintain our business.
- To accomplish our business purposes and objectives.
- To communicate with you.
- To carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collections.
- To improve our website and present its contents to you.
- For testing, research, analysis, and service offering development.
- For vendor management purposes.
- As necessary or appropriate to protect the rights, property, or safety of us, our clients, or others.
- To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
- As described to you when collecting your personal information.
- To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by us is among the assets transferred.
We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.
Sharing Personal Information
WE DO NOT, AND WILL NOT, SELL YOUR PERSONAL INFORMATION.
We may share your personal information within the Namely family of companies to provide services to you or in an effort to assess your needs and how we can help fulfill those needs.
We may disclose your personal information to a third party for a business purpose. When we disclose personal information for a business purpose, we require the recipient to keep that personal information confidential and secure, to not disclose that personal information to others, and to not use it for any purpose except performing the services related to the business purpose.
WE DISCLOSE YOUR PERSONAL INFORMATION FOR A BUSINESS PURPOSE TO OUR AFFILIATES AND/OR TO ONE OR MORE OF THE FOLLOWING CATEGORIES OF THIRD PARTIES:
- Third-party service providers.
- Administrators authorized by your organization.
- Licensors or third-party applications (if you access a third-party application on our services through a license agreement with a licensor).
- Other parties where required by law or to protect our rights.
- Third parties to whom you or your agents authorize us to disclose your personal information in connection with products or services we provide to you.
Rights Under the CPA, CTDPA, DPDPA, RIDTPPA, UCPA, and VCDPA
Subject to the applicable law and its exceptions, if you reside in Colorado, Connecticut, Delaware, Rhode Island, Utah, or Virginia, you may have the following rights provided by their applicable state law:
- Confirm whether we process your personal data and access that data.
- Correct inaccuracies in your personal data, taking into account the nature and purposes of the processing, where the applicable law provides a correction right.
- Delete personal data provided by or obtained about you, subject to applicable exceptions.
- Obtain a copy of personal data you previously provided to us in a portable and, where technically feasible, readily usable format, subject to the applicable law.
- Opt out of processing for targeted advertising.
- Opt out of the sale of your personal data.
- Opt out of profiling in furtherance of decisions that produce legal or similarly significant effects, where the applicable law provides that right.
- Receive equal treatment and not be discriminated against for exercising a privacy right.
- Use an authorized agent to submit an opt-out request where the applicable law provides that right.
- Appeal our refusal to act on your request where the applicable law provides an appeal right.
REQUEST FOR DATA
Once We Receive and Confirm Your Verifiable Consumer Request, We Will Disclose to You:
- The categories of personal information we collected about you.
- The categories of sources for the personal information we collected about you.
- Our business or commercial purpose for collecting or sharing that personal information.
- The affiliates with whom we shared your personal information.
- The categories of third parties with whom we share that personal information.
- The specific pieces of personal information we collected about you (also called a data portability request).
- If we disclosed your personal information to a third party for a business purpose, separate lists identifying the personal information categories that each category of recipient obtained.
Deletion Request Rights
You have the right to request that we delete any of your personal information that we collected from you and retained, unless otherwise permitted by law, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies.
WE MAY DENY YOUR DELETION REQUEST IF RETAINING THE INFORMATION IS NECESSARY FOR US OR OUR SERVICE PROVIDERS TO:
- Complete the transaction for which we collect the personal information, provide a product or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise fulfil our contract with you.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
- Exercise free speech, ensure the right of another consumer to exercise their free-speech rights, or exercise another right provided for by law.
- Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
- Comply with a legal obligation.
- Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
Submitting a Request
To submit an applicable access, correction, deletion, portability, opt-out, or appeal request, contact us by:
AUTHENTICATION AND AUTHORIZED AGENTS
We may authenticate a request when authentication is permitted or required by the applicable law. We will not require authentication of an opt-out request unless necessary to determine that the request is not fraudulent, and we will not require you to create an account solely to exercise a privacy right. An authorized agent may submit a request where permitted by applicable law, subject to legally permitted proof of authorization.
RESPONSE TIMING
We will respond within forty-five days after receiving a request. When reasonably necessary and permitted by applicable law, we may extend the response period once by an additional forty-five days, provided that we notify you of the extension and the reason within the initial forty-five-day period. If we decline to act on a request, we will provide the reason and instructions for appealing the decision where an appeal right applies.
We do not charge a fee to process or respond to your request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why and provide a cost estimate before completing the request.
APPEAL PROCESS
If we decline to act on your request and the applicable law provides an appeal right, we will inform you of the justification for our decision and provide instructions for appealing it. You may submit an appeal by contacting us at
privacy@namely.com. We will respond to the appeal within the period required by applicable law. If a Delaware appeal is denied, you may submit a complaint to the Delaware Department of Justice at
privacy@delaware.gov NONDISCRIMINATION
We will not discriminate against you for exercising any of your privacy rights.
Unless Permitted by Applicable State Law, We Will Not:
- Deny you products or services.
- Charge you different prices or rates for products or services, including through granting discounts or other benefits, or imposing penalties.
- Provide you a different level or quality of products or services.
- Suggest that you may receive a different price or rate for products or services or a different level or quality of products or services.
Nevada Privacy Rights
Privacy rights for residents of Nevada are governed by NRS Chapter 603A, enacted in 2005, and Senate Bill 220, enacted in 2019, granting Nevada consumers the ability to restrict the sale of their “Covered Information.” This term refers to one or more types of personally identifiable information collected by an operator through a website or online service operated by that entity, including:
- First and last name
- A home or other physical address that includes the street name and city or town
- Email address
- Telephone number
- Social Security number
- Any identifier that enables a specific individual to be contacted either physically or online
- Any other information collected from the individual via the operator’s website or online service and maintained in combination with an identifier in a way that renders the data personally identifiable.
If you wish to submit an additional inquiry concerning the sale of your Covered Information, as defined by Nevada law, please contact us via email at
privacy@namely.com.
Namely Biometric Data Privacy Policy
1. Introduction
Namely (the “Company,” “we,” or “us”) has established this Biometric Data Privacy Policy for individuals whose biometric data is collected, obtained, possessed, stored, disclosed, or otherwise processed by Namely through client-selected or Namely-supported biometric systems. Depending on the applicable arrangement, those individuals may include client employees, worksite employees, internal employees, applicants, contractors, customer users, or other authorized users. Clients may determine whether and how a biometric system is used, and Namely may process biometric data on a client’s behalf.
Biometric systems may include timekeeping, attendance, access control, authentication, identity verification, security, fraud prevention, or similar workforce-management systems. “Biometric Data” means biometric identifiers and biometric information protected by applicable law, including a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry, and information based on such identifiers that is used to identify an individual.
2. Collection, Notice, Consent, and Use
Before Namely collects, captures, purchases, receives through trade, or otherwise obtains Biometric Data where Illinois law applies, Namely will:
- inform the individual or the individual’s legally authorized representative in writing that Biometric Data is being collected or stored;
- inform the individual or representative in writing of the specific purpose and length of term for which the Biometric Data is being collected, stored, and used; and
- obtain a written release executed by the individual or representative.
Biometric Data will be used only for the purpose disclosed in the applicable written notice and release, which may include timekeeping, attendance, workforce management, identity authentication, access control, fraud prevention, security, compliance, or client-requested services. In the event we begin collecting or using Biometric Data in connection with the Biometric System for any additional purpose, we will update this policy. Namely will not sell, lease, trade, or otherwise profit from a person’s or customer’s Biometric Data.
3. Disclosures
Namely will not disclose, redisclose, or otherwise disseminate a person’s or customer’s Biometric Data unless:
- the individual or legally authorized representative consents to the disclosure or redisclosure;
- the disclosure completes a financial transaction requested or authorized by the individual or representative;
- the disclosure is required by state or federal law or municipal ordinance; or
- the disclosure is required by a valid warrant or subpoena issued by a court of competent jurisdiction.
When a legally permitted disclosure is made to a service provider that operates, hosts, supports, maintains, secures, troubleshoots, audits, or provides a biometric system or related service, the disclosure will be limited to the authorized purpose.
4. Retention and Destruction
Namely will permanently destroy Biometric Data when the initial purpose for collecting or obtaining the data has been satisfied or within three years of the individual’s last interaction with Namely, whichever occurs first, unless a valid warrant or subpoena issued by a court of competent jurisdiction requires otherwise. Namely will comply with this publicly available retention schedule and destruction guideline.
Verified deletion requests and authorized client instructions will be handled subject to applicable law and cannot extend retention beyond an earlier statutory destruction deadline. Contractual terms or internal record-retention schedules will not extend retention beyond the deadline required by applicable biometric law.
5. Security
Namely will store, transmit, and protect Biometric Data using the reasonable standard of care within its industry and in a manner that is the same as or more protective than the manner in which Namely stores, transmits, and protects other confidential and sensitive information.
6. Contact Us
For more information, or if you have any questions about this Biometric Data Privacy Policy, you may contact us using the information below:
Last updated September 9, 2026