California Residents – For Candidates and Participants
ghSMART California Consumer Privacy Act (“CCPA”)
June 15, 2023
This ghSMART CCPA Privacy Policy (“privacy notice”, “privacy statement”, or “notice”) describes how G. H. Smart & Company, LLC and its affiliates and subsidiaries (collectively “ghSMART”) collect and use personal information about California residents (“Data Subjects”). Our mailing addresses are included at the end of this notice.
Scope
This Notice applies only to the personal information that ghSMART collects related to Data Subjects, including personal information collected in the context of conducting, reviewing, assessing, managing and storing personal information in relation to our proprietary candidate assessments. This Notice is intended to satisfy ghSMART’s applicable notice obligations under the CCPA.
The categories of personal information that we collect, and our use of personal information, may vary depending upon the position(s) a Data Subject is being considered for, as well as the associated qualifications and responsibilities. For example, ghSMART conducts in-depth verbal interviews or discussions as part of our services (including leadership selection, leadership coaching and development, talent and organizational strategy, team effectiveness, board effectiveness, executive learning, and/or any related services or products). The information in this Notice is intended to provide an overall description of our collection and use of personal information about Data Subjects. Also, in some cases (such as where required by law), we ask for your consent or give you certain choices prior to collecting or using certain personal information.
It is important that you read this notice, together with any other privacy notice we may provide on specific occasions when we are collecting or processing personal information about you, so that you are aware of how and why we are using such information.
For the purposes of the CCPA, ghSMART is a “business”. This means that we are responsible for deciding how we hold and use personal information about you. As a business we are required under CCPA to notify you of the information contained in this privacy notice.
What isn’t covered by this Notice? This Notice does not address or apply to our collection of personal information that is not subject to the CCPA, such as (i) consumer reports (such as credit reports and background checks), publicly available data lawfully made available from state or federal government records, or other information that is exempt under the CCPA; or (ii) the personal information that we collect about residents of states other than California. In addition, the personal information we collect from clients who are not residents of California is subject to other notices and not this one.
Your data
Categories of Personal Information Collected and Disclosed. The section below generally identifies the categories of personal information we have collected about California Applicants, as well as the categories of third parties to whom we may disclose this information for a business or commercial purpose:
- Identifiers: such as a real name, alias, postal address, phone number, unique personal identifier, online identifier, Internet Protocol address, email address
- Third Party Disclosures for Business or Commercial Purposes: ghSMART client that requested the services, service providers, affiliates and subsidiaries, regulators, government entities and law enforcement, internet service providers required for cloud data storage, email, antivirus protection and standard technology operations, operating systems, and platforms, and others as required by law
- Protected Classification Information: Candidate gender. We will not ask Candidates to identify their gender and we do not ask others about a Candidate’s gender. Rather, our professionals will note gender based on a Candidate’s outward manifestations and on any statements a Candidate makes during the assessment that clearly indicates gender identity. We are cognizant of the fact that certain individuals identify as non-binary or transgender.
- Business Purposes: ghSMART uses gender information to conduct and publish research. Examples of research topics could include: (a) the manner in which females perform as compared to males in given scenarios, or; (b) the performance of categories of data subjects in varying industries and/or private vs. public companies. When using gender data for research, ghSMART deidentifies and/or aggregates the data. ghSMART does not disclose the gender of any specific Candidate through such research.
- Audio, visual, and other electronic data: interview recordings, transcriptions and other audio recordings (e.g., recorded interview sessions)
- Third Party Disclosures for Business or Commercial Purposes: ghSMART client that requested the services, service providers, affiliates and subsidiaries, regulators, government entities and law enforcement, internet service providers required for cloud data storage, email, antivirus protection and standard technology operations, operating systems, and platforms, and others as required by law
- Professional or Employment-Related Information: such as your application responses and cv/Resume, information related to your employment history provided during the recruitment process, including employment verification and references from former employers or colleagues; training; professional experience; contact details of employer; employment appraisal/assessment; details of qualifications; job description tasks and responsibilities; linguistic and job related skills and competencies; details of past and current organizational projects and initiatives; assessment of individual strengths and weaknesses; organizational structure; expressions of opinion or future intentions; reason for leaving prior roles; standardized test scores; volunteer or professional organization memberships
- Third Party Disclosures for Business or Commercial Purposes: ghSMART client that requested the services, service providers, affiliates and subsidiaries, regulators, government entities and law enforcement, internet service providers required for cloud data storage, email, antivirus protection and standard technology operations, operating systems, and platforms, and others as required by law
- Education information: such as information about education history or background that is not publicly available personally identifiable information as defined in the federal Family Educational Rights and Privacy Act (20 U.S.C. section 1232g, 34 C.F.R. Part 99)
- Third Party Disclosures for Business or Commercial Purposes: ghSMART client that requested the services, service providers, affiliates and subsidiaries, regulators, government entities and law enforcement, internet service providers required for cloud data storage, email, antivirus protection and standard technology operations, operating systems, and platforms, and others as required by law
- Inferences. Inferences drawn from any of the information identified above about California Personnel reflecting their experiences, preferences, characteristics, behavior and abilities
- Third Party Disclosures for Business or Commercial Purposes: ghSMART client that requested the services, service providers, affiliates and subsidiaries, regulators, government entities and law enforcement, internet service providers required for cloud data storage, email, antivirus protection and standard technology operations, operating systems, and platforms, and others as required by law
Sales and Sharing of Personal Information. California privacy laws define a “sale” as disclosing or making available to a third-party personal information in exchange for monetary or other valuable consideration, and “sharing” broadly includes disclosing or making available personal information to a third party for purposes of cross-context behavioral advertising. We do not sell or share personal information or sensitive personal information about California Applicants as defined by CCPA, nor do we sell or share any personal information about individuals who we know are under sixteen (16) years old.
Sources of Personal information. In general, we may collect personal information from the following categories of sources:
- Directly from the individual
- ghSMART client that requested the services
- Individual participants necessary for the completion of our Statement of Work
- Publicly available information and sources
Purposes of Collection, Use and Disclosure.
In this section we outline the purposes for which we may process your data.
I. For the Purpose of Employment Assessment, Leadership Development or Consulting Services
More specifically, we use your personal data described above for the following purposes:
To carry out the instructions of the Client Company to which we have contractual obligations
- Acknowledging your application;
- Determining and providing statements of opinion about your suitability for roles; Checking the validity of your qualifications and previous employment history;
- Fulfilling the deliverables of our client agreements as part of our consulting services which may include assessments, leadership development, coaching, training and any related services or products.
To comply with record keeping obligations
- To comply with record keeping obligations for external financial statement audits to substantiate our business transactions;
- To comply with record keeping obligations for tax records to support our tax returns.
To enable effective management and financial reporting
- Managing and reporting on our performance of consulting services which may include assessments, leadership development, coaching, training and any related services or products.
To comply with non-CA laws
- To comply with record keeping obligations for external financial statement audits to substantiate our business transactions;
- To comply with record keeping obligations for tax records to support our tax returns.
II. For the Purpose of General Administration
More specifically, we use your personal data described above for the following purposes:
To carry out the instructions of the Client Company to which we have contractual obligations
- Administering the contract we have with the Client mentioned above;
- Meeting arrangement/travel/scheduling;
- Facilitating other administrative purposes for normal business practices, such as internal reporting, and complying with policies and procedures.
To comply with record keeping obligations
- Facilitating other administrative tasks, such as accounting, audit, tax.
To enable effective management and financial reporting
- Administering the contract we have with the Client mentioned above;
- Business management and planning;
- Overseeing compliance with legal and regulatory requirements, including monitoring compliance with CCPA;
- Facilitating other administrative purposes for normal business practices, such as internal reporting, and complying with policies and procedures.
III. For the Purpose of Aggregated Analysis and Research
More specifically, we use your personal data described above for the following purposes:
To carry out the instructions of the Client Company to which we have contractual obligations
- To improve our consulting business practices and products related to the services we provide to the Client Company.
To provide training to our consultants and to improve our consulting business practices and products
- To improve our consulting business practices and products related to the services we provide to our clients generally;
- To provide training to our internal consultant team and evaluate the quality of our services and products.
Providing information about our products, services, and events to prospective clients or candidates for employment
- Findings that are aggregated and/or deidentified/anonymized may be used in publications, editorial content or communications related to our services and products.
To conduct and publish research: ghSMART conducts research to educate and inform the company, our clients, and society at large about historical trends and experiences of candidates and executives from a career performance perspective.
- Examples of research topics could include: (a) the manner in which females perform as compared to males in given scenarios, or; (b) the performance of categories of data subjects in varying industries and/or private vs. public companies. When using gender data for research, ghSMART deidentifies and/or aggregates the data. ghSMART does not disclose the gender of any specific Candidate through such research.
Change of purpose
We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal information for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. Please note that we may process your personal information without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
The period for which data is stored
The information we collect during the ghSMART service process will form part of our records and as such will be retained as required by legal, accounting, reporting standards as reflected in the ghSMART corporate records retention policy applicable to our business. ghSMART may also be required to retain this information based on statute of limitations for specific countries, as well as government record retention requirements for tax purposes. ghSMART reviews the data to determine that the policy for data storage is in line with our stated purposes for which we may process your data. In some circumstances, we may aggregate or deidentify your personal information so that it can no longer be associated with you, in which case we may continue to use such information without further notice to you.
Your rights
CCPA Rights. Under the CCPA, California residents have the following rights (subject to certain limitations):
- Opt out of sales and sharing: The right to opt-out of our sale and sharing of their personal information. As noted above, we do not sell or share (as such terms are defined in CCPA) California Applicants’ personal information.
- Limit uses and disclosure of sensitive personal information: the right to limit our use or disclosure of sensitive personal information to those authorized by the CCPA.
- Deletion: the right to the deletion of their personal information that we have collected, subject to certain exceptions.
- To know/access. The right to know what personal information we have collected about them, including the categories of personal information, the categories of sources from which the personal information is collected, the business or commercial purpose for collecting, selling, or sharing personal information, the categories of third parties to whom we disclose personal information, and the specific pieces of personal information we have collected about them.
- Correction. The right to correct inaccurate personal information that we maintain about them.
- Non-discrimination. The right not to be subject to discriminatory treatment for exercising their rights under the CCPA.
How to Exercise Available Rights. If you think we may have incorrect personal information, or would like a copy of the personal information we hold on you, or to exercise any other data protection right, please contact dataprotection@ghsmart.com or call +1 877 294 3368.
We will take steps to verify your request by matching the information provided by you with the information we have in our records. This may include your first and last name, email address, physical address, telephone number, and information about your relationship with us or other information needed to verify your identity. You must provide us with this information via the above phone number or email address to verify your request. We will process your request based upon the personal information in our records that is linked or reasonably linkable to the information provided in your request. We may need to request additional specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another security measure designed to ensure that personal information is not disclosed to any person who has no right to receive it. If we are unable to adequately verify a request, we will notify the requestor. Authorized agents may initiate a request on behalf of another individual; authorized agents will be required to provide proof of their authorization and we may also require that the relevant consumer directly verify their identity and the authority of the authorized agent.
No fee usually required
You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.
Changes to this privacy notice
Any changes we make to our privacy notice in the future will be posted on this page and, where appropriate, notified to you by e-mail. Please check back frequently to see any updates or changes to our privacy notice.
Contact details
If you have any questions about this privacy notice or how we handle your personal information, please contact: dataprotection@ghsmart.com or +1 877 294 3368.
Mail address:
G. H. Smart & Company, LLC
203 North LaSalle Street
Suite 2100
Chicago, IL 60601
The United States of America