Notice at Collection

PRIVACY NOTICE AT COLLECTION TO CALIFORNIA EMPLOYEES

GDH Consulting, Inc. and/or any affiliated entities (collectively, the “Company” or “we”) provide this California Privacy Notice (“Notice”) to describe our privacy practices with respect to our collection of Personal Information as required under the California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act (“CPRA”). This Notice applies only to employees who are residents of the State of California (“Consumers”) and from whom we collect “Personal Information” as defined in the CCPA/CPRA. We provide you this Notice because under the CCPA/CPRA, California residents who are employees qualify as Consumers. For purposes of this Notice, when we refer to Consumers, we mean you only to the extent you are an employee of the Company who has employees in California.

  1. Information We Collect from/or About Employees
CategoryExamplesDisclosed in Last 12 Months ToRetention Period
Personal IdentifiersName, alias, social security number, government authorized identification number, date of birth, driver’s license or state identification card number, passport number.A, B, C, D, E, F, G, H, I, J, K, L, MDuration of our relationship with you plus 4 years
Contact InformationHome, postal or mailing address, email address, home phone number, cell phone number.A, B, C, D, E, F, G, H, I, J, K, L, MDuration of our relationship with you plus 4 years
Account InformationUsername and password for Company accounts and systems, and any required security or access code, password, security questions, or credentials allowing access to your Company accounts.C, D, F, LUsername: permanent; Password or security code: while in use + 1 year
Protected ClassificationsRace, ethnicity, national origin, sex, gender, sexual orientation, gender identity, religious or philosophical beliefs, age, disability, medical or mental condition, military status, familial status, union membership.B, C, FDuration of our relationship with you plus 4 years
Physical Characteristics or DescriptionInformation on your Driver’s License (such as eye color, hair color, height, weight), as well as information collected to the extent relevant for workplace investigations or for enforcement of Company policies on appearance and grooming (such as tattoos, piercings)B, C, FDuration of employment plus 6 years
Biometric DataFingerprints, retina scans, facial recognition, handprint.Not Disclosed other than to the vendor we engaged to process this dataWhile in use for identity verification, plus 1 year
Financial InformationInformation collected including bank account number for direct deposit, account payments, or other financial information.A, F, K4 years; if related to payroll records, payment and other earning history 10 years from date of record
Pre-Hire InformationInformation gathered as part of background screening and reference checks, pre-hire drug test results, information recorded in job interview notes by persons conducting job interviews for the Company, information contained in candidate evaluation records and assessments, information in work product samples you provided, and voluntary disclosures by you.B, D, E, F, I, J, KIf hired, this data will be retained for duration of employment plus 6 years. If not hired, it will be retained for 4 years from when position is filled or the date we receive your information, whichever is longer.
Employment HistoryInformation contained in your resume regarding prior job experience, positions held, and when permitted by applicable law your salary history or expectations.B, D, E, F, I, J, KIf hired, this data will be retained for duration of employment plus 6 years. If not hired, it will be retained for 4 years from when position is filled or the date we receive your information, whichever is longer.
Education InformationInformation from resumes regarding educational history, information in transcripts or records of degrees, vocational certifications obtained, and informationB, D, E, F, I, J, KIf hired, this data will be retained for duration of employment plus 6 years. If not hired, it will be retained for 4 years from when position is filled or the date we receive your information, whichever is longer.
Professional or Employment Related InformationInformation contained in your personnel file and in other employment documents and records, including information contained in the following types of records: new hire or onboarding records, I-9 forms, tax forms, time and attendance records, non-medical leave of absence records, workplace injury records, safety records, performance evaluations and records, disciplinary records, investigatory records, training records, licensing and certification records, compensation and health benefits records, COBRA notifications, business expense records, and payroll records.A, B, C, D, F, KDuration of our relationship with Duration of our relationship with you plus 6 years; if related to payroll records, payment and other earning history information 10 years from date of record; benefits records including COBRA effective period + 6 years; workers compensation 18 years from date of record
Travel InformationInformation regarding business travel, vacation, and personal travel plans, and for infectious disease contact tracing purposes the locations travelled to within the applicable infectious period prior to coming to the workplace and the dates spent in those locations.B, C, F, KDuration of employment + 6 years; medical information related to benefits effective period + 6 years
Family InformationContact information for family members listed as emergency contacts, contact information for dependents and other dependent information, medical and health information for family members related to infectious diseases symptoms, exposure, diagnosis, testing, as well as information related to their travel and whom they have been in close contact with during the applicable infectious diseases infectious period.B, FMedical information related to infectious diseases is  end of the calendar year + 5 years;  Duration of employment + 6 years; medical information related to benefits effective period + 6 years
Medical and Health InformationMedical and health information provided to the Company for an employee’s friends, co-workers, and other associates related to infectious disease symptoms, exposure, diagnosis, testing, or vaccination, as well as information related to their travel and whom they have been in close contact with during the applicable infectious disease infectious period.B, C, D, F, JMedical information related to infectious disease is  end of the calendar year + 5 years;  Duration of employment + 6 years; medical information related to benefits effective period + 6 years
Internet Network and Computer ActivityDate and time of your visit to this website; webpages visited; links clicked on the website; browser ID; browser type; device ID; operating system; form information downloaded; domain name from which our site was accessed; search history; and cookies; internet or other electronic network activity information related to usage of Company networks, servers, intranet, or shared drives, including system and file access logs, security clearance level, browsing history, search history, and usage history.B, F, G, NDuration of our relationship with you plus 6 years
Mobile Device Security InformationInformation collected when you navigate, access or use any of our websites via mobile device, including device type, software type; data identifying your device if you access our business networks and systems, including cell phone make, model, and serial number, cell phone number, and cell phone provider.B, D, F, GDuration of our relationship with you plus 6 years
Online Portal and Mobile App Access and Usage InformationUsername and password, account history, usage history, file access logs, and security clearance level.B, D, F, GDuration of our relationship with you plus 6 years
Geolocation DataIP address and/or GPS location (latitude & longitude) recorded on Company-issued computers, electronic devices, and vehicles, as well as timekeeping applications on cell phones that employees use to clock in and out and that log the geographic location at which each time entry was made.B, D, F, G, NDuration of our relationship with you plus 6 years
Visual, Audio or Video RecordingsYour image when recorded or captured in surveillance camera footage or pictures of you taken on our premises or at our events or that you share with us, or in pictures or video of employees posted on social media to which the Company or its managers have access or that are submitted to the Company by another employee or third party.F, H, KSurveillance video – 90 days; duration of our relationship with you plus 6 years
Facility & Systems Access InformationInformation identifying you, if you accessed our secure company facilities, systems, networks, computers, and equipment, and at what times, using keys, badges, fobs, login credentials, or other security access method.BDuration of our relationship with you plus 6 years
InferencesBased on analysis of your activity on the website, we may develop inferences regarding strengths, aptitudes, characteristics, and responsibilities for career development.F, IDuration of our relationship with you plus 6 years
Contents of Personal Communications where the Company is not the intended recipientIf you use Company email, phones, computers, online chat applications (Slack, Teams, Zoom, etc.) or other Company systems for personal communications where the Company is not the intended recipient of the communication, the Company retains these communications in the ordinary course of managing its communication and computer systems and pursuant to the Company’s data retention policy. Employees have no expectation of privacy with respect to any communications or data they send, receive, access or store on any company computer or system, including any personal communications. The Company may monitor, access, review and use all such communications and data for lawful business purposes detailed below, including to manage and evaluate employee performance and make employment decisions.Not DisclosedUp to 3 years from date of email; chat messages 1 day from date of record

Of the above categories of Personal Information, the following are categories of Sensitive Personal Information the Company may collect from or about consumers, contractors, or applicants:

  1. Account Information (your Company account log-in, in combination with any required security or access code, password, or credentials allowing access to the account)
  2. Protected Classifications (racial or ethnic origin, religious or philosophical beliefs, union membership, or sexual orientation)
  3. Biometric Information (used for the purpose of uniquely identifying you)
  4. Medical and Health Information
  5. Geolocation Data (IP address and/or GPS location, latitude & longitude)

Personal information does not include:

  • Publicly available information from government records.
  • Information that a business has a reasonable basis to believe is lawfully made available to the general public by the employee or from widely distributed media.
  • Information made available by a person to whom the employee has disclosed the information if the employee has not restricted the information to a specific audience.
  • De-identified or aggregated information.

2. How We Use Personal Information and Sensitive Personal Information

The Personal Information and Sensitive Personal Information we collect, and our use of Personal Information and Sensitive Personal Information, may vary depending on the circumstances. This Notice is intended to provide an overall description of our collection and use of Personal Information and Sensitive Personal Information. Generally, we may use or disclose Personal Information and Sensitive Personal Information we collect from you or about you for one or more of the following purposes:

  1. To fulfill or meet the purpose for which you provided the information. For example, if you share your name and contact information to become an employee, we will use that Personal Information in connection with your employment and for current and future job opportunities with us or with our customers, including determining your eligibility and suitability for such opportunities.
  2. To comply with local, state, and federal law and regulations requiring employers to maintain certain records (such as immigration compliance records, travel records, personnel files, wage and hour records, payroll records, accident or safety records, and tax records), as well as local, state, and federal law, regulations, ordinances, guidelines, and orders relating to COVID-19.
  3. To evaluate suitability for temporary assignments with clients; and to facilitate such assignments and address any issues that may arise therefrom.
  4. To manage and process payroll and/or Company travel and expenses.
  5. To validate an employee’s identity for payroll and timekeeping purposes.
  6. To maintain commercial insurance policies and coverages, including for workers’ compensation and other liability insurance.
  7. To manage workers’ compensation claims.
  8. To administer, manage, and maintain group health insurance benefits, 401K and/or retirement plans, and other Company benefits and perks.
  9. To manage employee performance of their job duties and/or employee conduct, including by engaging in lawful monitoring of employee activities and communications when they are on duty, on Company premises, or utilizing Company internet and WiFi connections, computers, networks, devices, software applications or systems.
  10. To conduct workplace investigations (such as investigations of workplace accidents or injuries, harassment, or other misconduct).
  11. To evaluate job applicants and candidates for employment or promotions.
  12. To obtain and verify background checks on job applicants and employees and to verify employment references.
  13. To evaluate, make, and communicate decisions regarding an employee’s employment, including decisions to hire, terminate, promote, demote, transfer, suspend or discipline.
  14. To communicate with employees regarding employment-related matters such as upcoming benefits enrollment deadlines, action items, availability of W2s, and other alerts and notifications.
  15. To grant employees access to secure Company facilities and maintain information on who accessed the facility.
  16. To track employee movement and activity throughout Company facilities and keep the facilities secure.
  17. To implement, monitor, and manage electronic security measures on Company internet and WiFi connections, computers, networks, devices, software applications or systems, as well as on employee devices that are used to access Company internet and WiFi connections, computers, networks, devices, software applications or systems.
  18. To engage in corporate transactions requiring review or disclosure of employee records subject to non-disclosure agreements, such as for evaluating potential mergers and acquisitions of the Company.
  19. To communicate with an employee’s family or other contacts in case of emergency or other necessary circumstance.
  20. To manage employee recognition programs.
  21. To promote and foster diversity, equity, and inclusion in the workplace.

3. Retention of Personal Information

We apply our data retention procedures on an annual basis to determine if the business purposes for collecting the personal information, and legal reasons for retaining the personal information, have both expired. If so, we will purge the information in a secure manner.

4. Sale/Sharing of Information to Third Parties

The Company does not and will not sell your Personal Information or Sensitive Personal Information for any monetary or other valuable consideration. The Company does not and will not share your Personal Information or Sensitive Personal Information for cross-context behavioral advertising.

5. Access to Privacy Policy

For more information, please review the Company’s Privacy Policy. If you are an employee, the policy can be found by navigating to your Paylocity Home. If you are not an employee, you may review the Company’s online Privacy Policy at Privacy Policy – GDH (gdhinc.com).  

6. Changes to this Notice and Effective Date

    If we change this Notice, we will post the revised Notice on our site with an updated revision date. Any new Notice will automatically be effective when it is published on the website. You should therefore return here regularly to review our most up-to-date Notice. The Effective Date of this Privacy Notice is October 15, 2025.