Worksite Employee Privacy Policy

Scope of this Policy
Sequoia One PEO, LLC (the “Company,” “our,” or “we”) has developed this Privacy Policy out of respect for the privacy of our worksite employees of our clients and their family members, dependents, and beneficiaries. Your employer (“Worksite Employer”) has entered into an agreement with the Company under which we provide Professional Employer Organization (“PEO”) services to the Worksite Employer. The PEO services provided by the Company typically include payroll processing, workers’ compensation coverage, and other services and/or benefits as may be selected by your Worksite Employer. As a worksite employee, you remain an employee of the Worksite Employer. The Company is not a joint employer with your Worksite Employer, and this Privacy Policy does not and cannot be interpreted to create an employment relationship between you and the Company.

This Policy describes the personal information we collect, both online and offline, for what purposes we use and disclose it, how long we retain it, and whether we sell it or share it for cross-context behavioral advertising purposes (we don’t by the way). We will collect some information from you, including information about your family members, dependents, and beneficiaries, for various purposes as detailed in this Privacy Policy during the course of the Company providing services to your Worksite Employer.

This Privacy Policy applies only to information collected, used, or disclosed by the Company in the course of providing services to your employer. It does not apply to other contexts, such as if you visit our public-facing website or engage in transactions with the Company in other capacities (as a client or customer); interactions outside of the Company providing services to your Worksite Employer are subject to the privacy policy on our website.

Collection of Personal Information and Sensitive Personal Information

In the last 12 months, we have collected the following categories of personal information from or about worksite employees and their family members, dependents, and beneficiaries. For each category of information, we identify below the categories of third parties, service providers, and contractors to whom we have disclosed the information in the last 12 months. The examples provided for each category are not intended to be an exhaustive list or an indication of all specific pieces of information we collect from or about you in each category, but rather the examples are to provide you a meaningful understanding of the types of information that may be collected within each category.

  • Identifiers, which may include a real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, social security number, or driver’s license number
  • Personal Records (listed in Cal. Civil Code § 1798.80(e)), which may include physical characteristics or description, signature, telephone number, education, employment, employment history, insurance policy number, bank account number, or any other financial information, medical information, or health insurance information.
  • Consumer Characteristics, which may include sex, marital status, religion, veteran status, familial status, ethnicity, disability, or citizenship or immigration status.
  • Customer Account Details/Commercial Information, which may include products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies
  • Internet Usage Information, which may include browsing history, search history, or information regarding your interaction with an Internet Web site, application, or advertisement.
  • General Location Data, a general location such as that inferred from an IP address.
  • Sensory Data, which may include audio recordings of customer calls, electronic, visual, or similar information.
  • Professional or Employment Information, which may include professional, educational, or employment-related information

What Sensitive Personal Information We Collect
Of the above categories of personal information, the following are categories of sensitive personal information we may collect from or about worksite employees:

  • Personal Identifiers (social security number, driver’s license or state identification card number, passport number)
  • Account Information (your Company account log-in, in combination with any required security or access code, password, or credentials allowing access to the account)
  • Protected Classifications (racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, union membership, or sexual orientation)
  • Medical and Health Information

Personal information does not include:

  • Publicly available information from government records.
  • Information that a business has a reasonable basis to believe is lawfully made available to the general public by the worksite employee or from widely distributed media.
  • Information made available by a person to whom the worksite employee has disclosed the information if the worksite employee has not restricted the information to a specific audience.
  • De-identified or aggregated information.

Sources of Personal Information

We may collect your personal information from you, the worksite employee, when you voluntarily submit information, and other sources, including the following:

  • Company systems, networks, software applications, and databases you log into or use in the course of performing your job, including from vendors the Company engages to manage or host such systems, networks, applications or databases
  • Credit and consumer reporting agencies
  • HR support vendors, including administrators of benefits, workers’ compensation, unemployment claims, payroll, timekeeping, expense management, and training platforms
  • Social media platforms
  • Recruiters
  • Staffing agencies
  • Your Worksite Employer
  • Insurance carriers, retirement service providers, and other health and welfare providers
  • Personal references and former Worksite Employers
  • Other worksite employees, contractors, vendors, suppliers, and customers based on your interactions with them
  • Affiliated entities (subsidiaries, sister companies, or parent company)

To Whom We Disclose Personal Information:

We may disclose your personal information to the following categories of service providers, contractors or third parties:

  • Financial institutions
  • Government agencies
  • Benefits administrators and vendors, including third party administrators, 401K administrators, workers’ compensation and unemployment administrators, and wellness vendors
  • Insurance carriers, administrators, and brokers
  • Employee tracking and talent management systems
  • Payroll processors, timekeeping vendors, and vendors providing services for purposes of our human resources information system (HRIS)
  • Consulting and investigation firms, including human resources consultants, safety consultants, and workplace investigators
  • Communications providers/vendors (such as those that manage SMS text messaging or mailers)
  • Your Worksite Employer, including third parties that your Worksite Employer has provided access to
  • IT, cybersecurity, and privacy vendors and consultants
  • Artificial intelligence vendors
  • Other vendors
  • Affiliated entities (subsidiaries, sister companies, or parent company)
  • Other third parties (i) with your consent, (ii) at your direction, (iii) in connection with the consideration, negotiation, or completion of a corporate transaction in which we are acquired by or merged with another company or we sell, liquidate, or transfer all or a portion of our assets, (iv) as legally required, or (v) based on the good faith belief that such action is necessary or appropriate to: (a) protect and defend the rights or property of the Company, or (b) protect the rights, property, safety or security of the public, our agents and affiliates, our employees, or of users of the Company products and services

Reasons Why We Collect, Use, Retain, and Disclose Personal Information
We may collect and disclose your personal information for any of the following business purposes:

  1. To fulfill or meet the purpose for which you provided the information. For example, if you share your name and contact information to become a worksite employee, we will use that Personal Information in connection with your employment with your Worksite Employer or your relationship with us.
  2. To assist your Worksite Employer to comply with local, state, and federal law and regulations requiring maintenance of certain records (such as immigration compliance records, travel records, personnel files, wage and hour records, payroll records, accident or safety records, and tax records).
  3. To comply with local, state, and federal law and regulations that apply to the Company.
  4. To manage and process payroll.
  5. To validate a worksite employee’s identity for payroll and timekeeping purposes.
  6. To maintain commercial insurance policies and coverages, including for workers’ compensation and other liability insurance.
  7. To manage workers’ compensation claims.
  8. To administer, manage, and maintain group health insurance benefits, 401K and/or retirement plans, and other Company benefits and perks.
  9. To provide Human Resources best practices consulting services to the Worksite Employer, including the following topics:
    1. Worksite Employer’s management of worksite employees.
    2. Workplace investigations (such as investigations of workplace accidents or injuries, harassment, or other misconduct).
    3. Worksite Employer’s evaluation of job applicants and candidates for employment or promotions.
    4. Information gathered through background checks on job applicants and worksite employees and to verify worksite employment references.
    5. Worksite Employer’s decisions regarding a worksite employee’s employment, including decisions to hire, terminate, promote, demote, transfer, suspend or discipline.
  10. To communicate with worksite employees regarding employment-related administrative matters such as upcoming benefits enrollment deadlines, action items, availability of W2s, and other alerts and notifications.
  11. To implement, monitor, and manage electronic security measures on Company networks, software applications or systems, including managing and securing Company’s online portal, as well as on worksite employee devices that are used to access Company networks, software applications or systems.
  12. To engage in corporate transactions requiring review or disclosure of worksite employee records subject to non-disclosure agreements, such as for evaluating potential mergers and acquisitions of the Company.
  13. To assist in communications with a worksite employee’s family or other contacts in case of emergency or other necessary circumstance.
  14. To assist the Worksite Employer to promote and foster diversity, equity, and inclusion in the workplace.
  15. Infectious disease purposes (pandemic, outbreak, public health emergency, etc.).
  16. To evaluate, assess, and manage the Company’s business relationship with vendors, service providers, and contractors that provide services to the Company, including artificial intelligence (“AI”) technologies.
  17. To improve user experience on Company computers, networks, software applications or systems, and to debug, identify, and repair errors that impair existing intended functionality of our systems.
  18. To detect security incidents involving potentially unauthorized access to and/or disclosure of Personal Information or other confidential information, including proprietary or trade secret information and third-party information that the Company received under conditions of confidentiality or subject to privacy rights.
  19. To protect and defend the rights or property of the Company.
  20. To protect the rights, property, safety, or security of the public, our agents and affiliates, our employees, or of users of the Company products and services.
  21. To protect against malicious or illegal activity and prosecute those responsible.
  22. To prevent identity theft.
  23. To verify and respond to privacy requests under applicable privacy laws.
  24. To comply with applicable laws and regulations or as otherwise requested by any law enforcement officer or agency acting under color of law.
  25. To disclose your information to other parties based on your consent to do so.

We do NOT and will not sell your personal information in exchange for monetary or other valuable consideration. We do not share your personal information for cross-context behavioral advertising.

We do NOT and will not use or disclose your sensitive personal information for any purposes that give rise to a right to limit the use or disclosure of your sensitive personal information under the California Consumer Privacy Act (CCPA), if it applies and you are a California resident.

Retention of Personal Information

The personal information that we maintain about you will be stored and maintained by us until you instruct us otherwise, or, in our sole discretion, for the longer of: (a) for so long as is necessary or appropriate to carry out the purpose(s) for which such information was collected and (b) for so long as we are required or allowed to maintain such information by law or other applicable rules or regulations. Some of the retention periods are measured from a particular point in time that has not occurred yet, such as the end of worksite employment or end of a relationship (whether business, contractual, or transactional) plus a certain number of years.

In deciding how long to retain each category of personal information that we collect, we consider many criteria, including, but not limited to: the business purposes for which the Personal Information was collected; relevant federal, state and local recordkeeping laws; applicable statute of limitations for claims to which the information may be relevant; and legal preservation of evidence obligations.

Third-Party Vendors

We may use other companies and individuals to perform certain functions on our behalf. Examples include administering e-mail and payroll services. Such parties only have access to the personal information needed to perform these functions and may not use or store the information for any other purpose.

Artificial Intelligence

We may disclose personal information to AI technologies, including tools provided by third-party AI service providers, to enhance our services and provide a better user experience. Your information is processed in accordance with applicable privacy laws, and we maintain safeguards to ensure fairness, accuracy, and transparency. We do not use AI for decisions that produce legal or similarly significant effects without human oversight. You have the right to request information about how we use AI and to contest any decisions made through automated means.

Business Transfers

In the event we sell or transfer a particular portion of our business assets, worksite employee information may be one of the business assets transferred as part of the transaction. If substantially all of our assets are acquired, employee information may be transferred as part of the acquisition.

Compliance With Law and Safety

We may disclose specific personal and/or sensitive personal information based on a good faith belief that such disclosure is necessary to comply with or conform to the law or that such disclosure is necessary to protect worksite employees or the public.

Worksite Employees and Their Family Members, Dependents, and Beneficiaries Under the Age of 16

We do not knowingly sell or share the personal information of worksite employees or any of their family members, dependents or beneficiaries under 16 years of age.

How We Protect the Information That We Collect

To prevent unauthorized access or disclosure, maintain data accuracy and facilitate the appropriate use of information, we use physical, technological and administrative procedures to attempt to protect the personally identifiable information we collect. Nevertheless, Internet transmissions are never completely private or secure. You understand that any messages or information you send to us may be read or intercepted by others. If you have any questions about the security of personally identifiable information collected by us, please contact us at [email protected].

Rights Under the CCPA and CPRA

This section of the Privacy Policy applies only to California residents. If you are a California resident, you have the following rights pursuant to the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  1. Right to Know. The right to request, up to 2 times in a 12-month period, that we identify to you (1) the categories of personal information we have collected, shared or sold about you, (2) the categories of sources from which the personal information was collected, (3) the business purpose for which we use this information, and (4) the categories of third parties with whom we disclose or have disclosed your personal information;
  2. Right to Access. The right to request, up to 2 times in a 12-month period, that we provide you access to or disclose to you the specific pieces of personal information we have collected about you;
  3. Right to Delete. The right to request, up to 2 times in a 12-month period, that we delete personal information that we have collected from you, subject to certain exceptions;
  4. Right to Correct. The right to request that we correct inaccurate personal information (to the extent such an inaccuracy exists) that we maintain about you;
  5. The right to designate an authorized agent to submit one of the above requests on your behalf. See below for how you can designate an authorized agent; and
  6. The right to not be discriminated or retaliated against for exercising any of the above rights. 

You Can Submit Any of the Above Types of Requests by the Option Below:

Submit a request via email at [email protected].

How We Will Verify That it is Really You Submitting the Request:

If you are a California resident, when you submit a Right to Know, Right to Access, Right to Delete, or Right to Correct request through one of the methods provided above, we may ask you to provide some information in order to verify your identity and respond to your request. Specifically, we may ask you to verify information that can be used to link your identity to particular information in our possession, which depends on the nature of your relationship and interaction with us. To the extent permitted by law, we may deny your request where we are unable to reasonably verify you are the California resident about whom we collected personal information.

Responding to your Right to Know, Right to Access, Right to Delete, and Right to Correct Requests

Upon receiving a verifiable request from a California resident, we will confirm receipt of the request no later than 10 business days after receiving it. We endeavor to respond to a verifiable request within forty-five (45) calendar days of its receipt. If we require more time (up to an additional 45 calendar days, or 90 calendar days total from the date we receive your request), we will inform you of the reason and extension period in writing. We will deliver our written response electronically. The response we provide will also explain the reasons we cannot comply with a request, if applicable.

We do not charge a fee to process or respond to your verifiable request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.

For a request to correct inaccurate personal information, we will accept, review, and consider any documentation that you provide, and we may require that you provide documentation to rebut our own documentation that the personal information is accurate. You should make a good-faith effort to provide us with all necessarily information at the time that you make the request to correct. We may deny a request to correct if we have a good-faith, reasonable, and documented belief that a request to correct is fraudulent or abusive. If we deny your request to correct, we shall inform you of our decision not to comply and provide an explanation as to why we cannot comply with a request, if applicable.

If You Have an Authorized Agent:

If you are a California resident, you can authorize someone else as an authorized agent who can submit a request on your behalf. To do so, you must either (a) execute a valid, verifiable, and notarized power of attorney, or (b) provide other written, signed authorization that we can then verify. When we receive a request submitted on your behalf by an authorized agent who does not have a power of attorney, that person will be asked to provide written proof that they have your permission to act on your behalf. We will also contact you and ask you for information to verify your own identity directly and not through your authorized agent. We may deny a request from an authorized agent if the agent does not provide your signed permission demonstrating that they have been authorized by you to act on your behalf.

Consent to Terms and Conditions

By onboarding as a worksite employee of a Worksite Employer who has contracted with the Company, you consent to all terms and conditions expressed in this Privacy Policy.

Changes to Our Privacy Policy

As our services evolve and we perceive the need or desirability of using personal information collected in other ways, we may from time to time amend this Privacy Policy. We encourage you to check this Privacy Policy frequently to see the current Privacy Policy in effect and any changes that may have been made to them. If we make material changes to this Policy, we will post the revised Policy and the revised effective date. Please check back here periodically or contact us at the address listed at the end of this Policy.

Individuals With Disabilities

This Policy is in a form that is or will be made accessible to individuals with disabilities.

Questions About the Policy

If you have any questions about this Privacy Policy, please contact us at [email protected].

**This Policy was last updated April 29, 2026.