Privacy Notice

LAST UPDATED: July 2021

THIS NOTICE DESCRIBES HOW PERSONAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

WHO WE ARE

Willis Towers Watson, our affiliated entities, and successors in interest ("Willis Towers Watson," "we," "our," or "us") provide benefits enrollment, benefits administration, and pension administration services, including the creation and hosting of websites (collectively, "Services"), on behalf of employers who offer healthcare, retirement, or similar employee benefit plans. Our clients who provide health, retirement, or similar plans for the benefit of their employees are referred to as "Plan Sponsors."

The Plan Sponsor of your benefit plan(s) has hired Willis Towers Watson to provide these Services (including this website) to you. For most participants, the Plan Sponsor is your current or former employer. The Services provide benefits enrollment, eligibility, administration, and other support related to the benefits programs made available to you by the Plan Sponsor.

SCOPE AND PURPOSE OF THIS NOTICE

Willis Towers Watson is committed to privacy and transparency in our information practices. This Privacy Notice describes how we receive, collect, process, and share your personal information when providing the Services, which include, but are not limited to, this website, our telephone service centers, data import files that we receive from the Plan Sponsor, other third-party import files approved by the Plan Sponsor, and electronic communications such as HTML-formatted email messages that may be sent to you.

This Privacy Notice describes our overall privacy and data protection practices related to the Services. Our exact practices will depend on and will always be limited by the terms of our contract with the Plan Sponsor. By utilizing the Services, you are agreeing to the terms in this Privacy Notice. If you do not agree to the terms in this Privacy Notice, please do not utilize the Services.

Please note that our collection, use, disclosure, and processing of personal information about individuals will vary depending upon the circumstances. As a result, in some cases, different or additional notices about our data collection and processing practices may be provided and/or may apply to our processing of certain personal information.

OUR ROLE

When providing the Services, Willis Towers Watson acts as a "data processor" or "service provider" under applicable privacy and data protection laws. This means that we will only process the personal information we collect about you through the Services on behalf of and subject to the limitations and instructions that we receive from the Plan Sponsor. If our contract with our client is more restrictive than the terms of this Privacy Notice, the more restrictive contract terms will apply.

The Plan Sponsor is the responsible "controller" or "business" under applicable privacy laws with respect to your personal information. The Plan Sponsor's privacy notices (and not this one) will apply to and control the processing of personal information, except as set forth below. Please contact the Plan Sponsor for more information regarding its data protection practices and/or review their privacy notice for more information.

HOW WE COLLECT, USE AND DISCLOSE PERSONAL INFORMATION

"Personal information" includes other similar terms under applicable privacy laws such as "personal data" or "personally identifiable information." In general, personal information is information that identifies, relates to, describes, or is reasonably capable of being associated with, or could be linked (directly or indirectly) with a particular individual or identifiable person. The types of personal information we may collect include, but are not limited to:

  • Name, contact information, and related identifiers (such as name, postal address, email address, unique personal identifier, online identifier, Internet Protocol address, account name, social security number, social insurance number, driver's license or state identification number);
  • Customer records (such as paper and electronic customer records containing personal information, such as name, signature, telephone number, insurance policy number, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, and health insurance information);
  • Characteristics of protected classifications (such as gender, age, disability, and citizenship status);
  • Biometric information (such as voice recordings, and sleep, health, or exercise data that are disclosed by you through the enrollment process);
  • Usage data (such as internet or other electronic network activity information, including information regarding your interaction with our websites and applications);
  • Geolocation data (such as precise geographic location information about a device used to access our website);
  • Audio/visual data (such as photographs, audio recordings, and other audio, electronic, visual, or similar information);
  • Professional or employment-related information (such as worksite, job responsibilities, salary history, and job end or termination date);
  • Information about education-related history or background (such as student status);
  • Profiles (such as a participant profile reflecting data from multiple sources).

Some of the information we collect is provided by the Plan Sponsor to confirm whether you, your spouse or partner, and/or dependents are eligible for benefits. You may be asked to provide additional information or to update or correct information about yourself, your spouse or partner, your dependents, and beneficiary designations.

If you submit any personal information relating to other people to us or to our service providers in connection with the Services, you represent that you have the authority to do so and to permit us to use the information in accordance with this Privacy Notice and applicable laws.

How We May Collect Personal Information

We may collect personal information in a variety of ways, including, but not limited to:

  • Through the Plan Sponsor: such as through data files from the Plan Sponsor.
  • Through the Services: such as when you model your benefits or provide or change your personal information through the website.
  • Offline: such as through mail or when you contact our telephone service center, if applicable.
  • From Other Sources: from third parties engaged by the Plan Sponsor to provide benefits-related services.

How We May Use Personal Information

Our uses of personal information will be subject to and consistent with our contractual agreements with the Plan Sponsor. The purposes for which we may process personal information will vary depending upon the circumstances in which we interact with you. In general, we use personal information that we collect about you to provide the Services (for example, to determine your benefit eligibility, validate election information, and otherwise facilitate your enrollment) and to comply with legal obligations. In addition, to the extent permitted by our contract with the Plan Sponsor, we may utilize personal information the following ways:

  • To respond to your inquiries and fulfill your requests, such as to send you plan disclosures or benefit information. Your personal information may be shared with third-parties (a printer or other service provider, for instance) involved in fulfilling the order or request.
  • To send administrative information to you such as information regarding the Services and changes to our terms, conditions, and policies.
  • To personalize the content and information provided to you.
  • For our internal use to build or improve the quality of our Services.
  • For fraud monitoring and prevention and security purposes.
  • To audit and improve our Services, including in support of training and quality control efforts.
  • As we believe to be necessary: (a) to comply with the law or a legal obligation; (b) to comply with legal process (such as a subpoena or court order); and (c) to protect the rights, privacy, safety, and property of ourselves and others.
  • To contact you regarding the Services by using an automated telephone dialing system and/or artificial or prerecorded voice.

Aggregated and de-identified information.

Subject to any contractual agreement with the Plan Sponsor, we may use de-identified and/or aggregated information and reports related to the Services in order to assess, improve, and develop our business, products, and services, prepare benchmarking reports on our industry, and for other research, marketing, and analytics purposes. Any information contained in such reports is not relatable or identifiable to a particular individual or Plan Sponsor. We do not share any personal information with third parties in such cases.

How Personal Information May Be Disclosed

Your personal information may be disclosed or transferred, in accordance with our contract with the Plan Sponsor, as follows:

  • To the Plan Sponsor.
  • To our affiliated companies, vendors, and service providers who perform functions in support of the Services, such as website hosting, data analysis, payment processing, order fulfillment, information technology and related infrastructure provision, customer service, email delivery, and auditing.
  • To vendors and third parties selected by the Plan Sponsor to provide you with services associated with your benefits and/or provide professional services to the Plan. Use of your personal information by the Plan Sponsor or such vendors and third parties is governed by the privacy policies of the Plan Sponsor or the vendors and third parties, not this Privacy Notice.
  • To other individuals and third parties as directed by the Plan Sponsor or by you.
  • To a third party in the event of any reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of our business, assets, or stock (including in connection with any bankruptcy or similar proceedings).
  • As we believe to be necessary: (a) to comply with the law or a legal obligation; (b) to comply with legal process (such as a subpoena or court order); or (c) to protect the rights, privacy, safety, and property of us and others.

COOKIES

Our website may use first-party and third-party cookies and similar technology to gather device and usage information when users visit the website. We use the information for security purposes, to facilitate navigation, to display information more effectively, to personalize your experience while using the website, and to recognize your computer to assist your use of the website. We also gather statistical information about use of the website to improve design and functionality and understand how the website is used. We do not use advertising cookies on the website.

There are different types of cookies, for example:

  • Cookies transferred directly by Willis Towers Watson or the website vendor ('first party cookies') and cookies transferred on our behalf, for example by our data analytics companies ('third party cookies')
  • Cookies which endure for different periods of time, including those that only last only as long as your browser is open ('session cookies'). Session cookies are deleted automatically from your device once you close your browser. Other cookies are 'permanent cookies', meaning that they remain on your device after your browser is closed. For example, permanent cookies recognize your device when you open your browser and browse the internet again.

Below we explain the different types of cookies and similar technologies that may be used on the Sites. Where we use third party cookies, we provide a link to the third party's cookie policy.

Strictly Necessary Cookies. Strictly necessary cookies enable you to navigate the Sites and to use their services and features. Without these necessary cookies, the Sites will not perform as smoothly for you as we would like them to and we may not be able to provide the Sites or certain services or features.

Functional Cookies. Functional cookies enable the website to provide enhanced functionality and personalization. They allow us to see the overall patterns of usage on the Sites. We use the information to analyze traffic on and improve the Sites. They may be set by us or by third party providers whose services we have added to our pages. Without these cookies, some or all of these services may not function properly.

Performance Cookies. Performance cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. Without these cookies, we will not know when users have visited our site and will not be able to monitor its performance.

We use the following cookies for our site:

Cookie Name: _RequestVerificationToken[UniqueIdentifier]
Cookie Type: Strictly Necessary
Description or Purpose: ASP.NET MVC anti-forgery token, used to prevent Cross-Site Request Forgery (CSRF) attempts
Persistent or Session: Session
1st or 3rd Party Cookie: 1st

Cookie Name: ESS_[Environment]_[ClientCode]_Application
Cookie Type: Strictly Necessary
Description or Purpose: Application claims/data
Persistent or Session: Session
1st or 3rd Party Cookie: 1st

Cookie Name: ESS_[Environment]_[ClientCode]_PreferredCulture
Cookie Type: Functional
Description or Purpose: User preferred language/culture
Persistent or Session: Persistent
1st or 3rd Party Cookie: 1st

Cookie Name: ESS_[Environment]_[ClientCode]_Tags
Cookie Type: Strictly Necessary
Description or Purpose: Application data to support application functionality
Persistent or Session: Session
1st or 3rd Party Cookie: 1st

Cookie Name: ESS_[Environment]_[ClientCode]_TRM_PendingChanges
Cookie Type: Strictly Necessary
Description or Purpose: Application data to support application functionality
Persistent or Session: Session
1st or 3rd Party Cookie: 1st

Cookie Name: ESS_[Environment]_[ClientCode]_TRM_ScenarioId
Cookie Type: Strictly Necessary
Description or Purpose: Application data to support application functionality
Persistent or Session: Session
1st or 3rd Party Cookie: 1st

Cookie Name: ESS_[Environment]_[ClientCode]_TRM_SelectedAge
Cookie Type: Strictly Necessary
Description or Purpose: Application data to support application functionality
Persistent or Session: Session
1st or 3rd Party Cookie: 1st

Cookie Name: ESS_[Environment]_[ClientCode]_TwoFactorCookie
Cookie Type: Strictly Necessary
Description or Purpose: Used during multi-factor authentication challenges
Persistent or Session: Session
1st or 3rd Party Cookie: 1st

Cookie Name: ESS_[Environment]_[ClientCode]_TwoFactorRememberBrowser
Cookie Type: Functional
Description or Purpose: Tracks the browser, allowing the user to bypass multi-factor authentication challenges for a period of time
Persistent or Session: Persistent
1st or 3rd Party Cookie: 1st

Cookie Name: ESS_[Environment]_[ClientCode]_User
Cookie Type: Strictly Necessary
Description or Purpose: User authentication claims/data
Persistent or Session: Session
1st or 3rd Party Cookie: 1st

Cookie Name: ESS_Session
Cookie Type: Strictly Necessary
Description or Purpose: Session identification/management
Persistent or Session: Session
1st or 3rd Party Cookie: 1st

Cookie Name: SWID
Cookie Type: Strictly Necessary
Description or Purpose: Routes users to specific servers/resources
Persistent or Session: Session
1st or 3rd Party Cookie: 1st

Cookie Name: SWT_[UniqueIdentifier]
Cookie Type: Strictly Necessary
Description or Purpose: Routes users to specific servers/resources
Persistent or Session: Session
1st or 3rd Party Cookie: 3rd — vimeo.com

Cookie Name: _ga
Cookie Type: Functional
Description or Purpose: Embedded Vimeo video player – Google Analytics cookie
Persistent or Session: Session
1st or 3rd Party Cookie: 3rd — vimeo.com

Cookie Name: continuous_play_v3
Cookie Type: Functional
Description or Purpose: Embedded Vimeo video player – used to keep track of whether continuous play is on or not for a user
Persistent or Session: Session
1st or 3rd Party Cookie: 3rd — vimeo.com

Cookie Name: player
Cookie Type: Functional
Description or Purpose: Embedded Vimeo video player
Persistent or Session: Session
1st or 3rd Party Cookie: 3rd — vimeo.com

Cookie Name: vuid
Cookie Type: Functional
Description or Purpose: Embedded Vimeo video player – analytics unique identifier
Persistent or Session: Session
1st or 3rd Party Cookie: 3rd — vimeo.com

You can control the way in which cookies are used by altering your browser settings. You may refuse to accept cookies by activating the setting on your browser that allows you to reject cookies. Information about the procedure to follow to enable or disable cookies can be found on your Internet browser provider's website via your help screen. To find out more about cookies, including how to see what cookies have been set and how to manage and delete them, visit www.aboutcookies.org, www.allaboutcookies.org, or www.youronlinechoices.eu.

THIRD PARTY SERVICES

The Services may include links to websites for the Plan Sponsor and other third-parties such as insurance carriers, government agencies, and financial service providers. If you access these links, you will be leaving the Services. Your use of such third-party sites is governed by the privacy policies of those third parties, not by this Privacy Notice. This Privacy Notice does not address, and we are not responsible for, the privacy, information, or other practices of any third parties, including the Plan Sponsor or any third party operating any site or service to which the Services may link. The inclusion of a link on the Services does not imply endorsement of the linked site or service by us or by our affiliates.

SECURITY

We have implemented security measures to protect personal information we collect. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure (for example, if you believe that the security of your account has been compromised), please immediately notify us in accordance with the Contacting Us section below.

YOUR DATA PRIVACY RIGHTS

Certain individuals have a legal right to review, correct, update, or delete personal information pursuant to applicable privacy and data protection laws. As indicated above, Willis Towers Watson acts as a "data processor" or "service provider" under applicable privacy and data protection laws. For this reason, the Plan Sponsor, not Willis Towers Watson, is legally responsible for fulfilling any legal rights requests you might have.

Data may be accessed and, in some cases, corrected through our self-service website. You may also be able to access data and make data corrections through a toll-free telephone number established for the purpose of administering your benefits. If you do not want to, or you are unable to, self-serve through our website or the toll-free telephone number (if any) established for the purpose of administering benefits, you may exercise your rights by contacting the Plan Sponsor subject to applicable law.

If you reside in Canada, you have the right to request access to any additional information that we hold about you subject to limited exceptions under applicable law. If you believe that any information that is held about you is inaccurate, you may also request a correction.

Applicable privacy and data protection law may limit the fulfillment of a rights request. For example, the Plan Sponsor may limit a rights request so that it can retain certain information for recordkeeping purposes and/or to complete any transactions that began prior to the request for a change or deletion.

RETENTION PERIOD

We will retain your personal information as directed by the Plan Sponsor and otherwise for the period necessary to fulfill the purposes outlined in this Privacy Notice, or longer where required by law.

USE OF SERVICES BY MINORS

The Services are not directed to individuals under the age of sixteen (16), and we request that individuals under age 16 not provide personal information through the Services.

Because of the nature of our Services, we do not solicit or intentionally receive information from children under the age of 16, except that we do collect information regarding dependent children that pertains to their benefits coverage and to beneficiary designations.

CROSS-BORDER TRANSFER

To the extent allowed by our agreement with the Plan Sponsor, your personal information may be collected, stored, and processed in any country where we have facilities or in which we engage service providers. By using the Services, you acknowledge that we may transfer your personal information to countries outside of your country of residence, including the United States, which may have laws and data protection rules that are different from those of your country of residence. While your information is in another jurisdiction, it may be accessed by the local courts, law enforcement, and national security authorities. To receive information regarding our policies and procedures with respect to service providers in different countries, please email or write to us at the address in the Contacting Us section below.

SENSITIVE INFORMATION

We ask that you not send us, and not disclose, any sensitive personal information (for example, information related to racial or ethnic origin, political opinions, religion or other beliefs, or criminal background) on or through the Services or otherwise.

UPDATES TO THIS PRIVACY NOTICE

We may change this Privacy Notice from time to time. The "LAST UPDATED" legend at the top of this page indicates when this Privacy Notice was last revised. We encourage you to refer to this Privacy Notice often for the latest information about our personal information practices. By continuing to utilize the Services, you are agreeing to the terms contained in the last revised Privacy Notice.

INFORMATION FOR CALIFORNIA RESIDENTS

In providing the Services, we do not "sell" any personal information under the California Consumer Privacy Act (CCPA).

If you wish to submit a consumer rights request under the CCPA, please do so through the Plan Sponsor. We will cooperate with and facilitate these requests to the extent required by law.

CONTACTING US.

If you have any questions about this Privacy Notice or how your personal information may be used or disclosed, please contact us at privacy@willistowerswatson.com or toll-free at 888-471-4502. Because email communications are not always secure, please do not include credit card or other sensitive information in your emails to us.

For all other inquiries, please refer to the contact information on this website or the service center contact information provided by your Plan Sponsor.