California Consumer Privacy Act Privacy Notice For Personnel
Effective Date: September 6, 2024
The California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its implementing regulations (collectively, the “CCPA”), gives California residents certain rights and requires businesses to make certain disclosures regarding their Collection, use, and disclosure of Personal Information. This CCPA Privacy Notice for Personnel (the “Notice”) provides such notice to Septerna Inc.’s (collectively “Septerna,” “We,” “Us,” “Our”) job applicants (“Applicants”) and employees, independent contractors, and other individuals who interact with Septerna in an employment-related capacity (collectively, “Employees”) who are residents of California.
This Notice only addresses Septerna’s Collection (defined below), use, and disclosure of employment-related Personal Information and only applies to residents of California. This Notice does not apply to individuals who are residents of other US states or other countries and/or who do not interact with Septerna in an employment-related capacity. For further details about our privacy practices pertaining to non-Applicant/Employee Personal Information, please see our Privacy Notice.
As an Applicant or Employee, you have the right to know what categories of Personal Information Septerna Collects, uses, discloses, Sells, and Shares about you. This Notice provides that information and other disclosures required by California law.
A. DEFINITIONS
- Personal Information: As used in this Notice, “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Consumer or Personal Information includes Sensitive Personal Information, but does not include protected health information covered by the Health Information Portability and Accountability Act (“HIPAA”), nonpublic personal information under the Gramm-Leach-Bliley Act (“GLBA”), or any other information which is exempt from the CCPA.
- Sensitive Personal Information: As used in this Notice, “Sensitive Personal Information” includes Personal Information that reveals, among other things, social security number, driver’s license number, state identification card number, passport number, racial or ethnic origin, union membership, or the contents of a Consumer’s mail, email, and text messages, unless Septerna is the intended recipient of the communication.
- Other CCPA Definitions: As used in this Notice, the terms “Collect,” “Processing,” “Service Provider,” “Third Party,” “Sale,” “Share,” “Consumer,” and other terms defined in the CCPA and their conjugates, have the meanings afforded to them in the CCPA, whether or not such terms are capitalized herein, unless contrary to the meaning
B. APPLICANTS
- Collection & Processing of Personal Information
We, and Our Service Providers, may have Collected and Processed the following categories of Personal Information from Applicants in the preceding 12 months:
- Identifiers, such as name, alias, online identifiers, account name, physical characteristics or description;
- Contact information, including phone number, address, email address;
- Characteristics of protected classifications under state or federal law, such as age, gender, race, physical or mental health conditions, and marital status;
- Internet or other electronic network activity information, such as browsing history and interactions with Our websites or advertisements;
- Audio, electronic, visual, and similar information;
- Professional or employment-related information, such as work history and prior employer;
- Education information, as defined in the federal Family Educational Rights and Privacy Act, such as student records and directory information; and
- Sensitive Personal Information, including:
- Personal Information that reveals:
- Social security, driver’s license, state identification card, or passport number;
- Contents of a Consumer’s email and text messages, unless the business is the intended recipient thereof.
- Personal Information that reveals:
- Categories of Applicant Personal Information We Disclose to Service Providers & Third Parties
We disclose the following categories of Applicant Personal Information to Service Providers and Third Parties:
- Identifiers, such as name, alias, online identifiers, account name, physical characteristics or description;
- Contact and financial information, including phone number, address, email address;
- Characteristics of protected classifications under state or federal law, such as age, gender, race, physical or mental health conditions, and marital status;
- Internet or other electronic network activity information, such as browsing history and interactions with Our websites or advertisements;
- Audio, electronic, visual, and similar information;
- Professional or employment-related information, such as work history and prior employer;
- Education information, as defined in the federal Family Educational Rights and Privacy Act, such as student records and directory information; and
- Sensitive Personal Information, including:
- Personal Information that reveals:
- Social security, driver’s license, state identification card, or passport number;
- Contents of a Consumer’s email and text messages, unless the business is the intended recipient thereof.
- Personal Information that reveals:
- Purposes for Processing Applicant Personal Information
We, and Our Service Providers, Collect and Process Applicant Personal Information (excluding Sensitive Personal Information) described in this Notice to:
- Evaluate a potential Employee relationship with you;
- Perform background checks and verify past employment, educational history, professional standing, and other qualifications;
- Evaluate, determine, and arrange compensation, payroll, and benefits;
- Assess your fitness and physical capacity for work; and
- Contact you regarding your application and potential Employee relationship with
In addition to the purposes identified above, Septerna may use and disclose any and all Applicant Personal Information that We Collect as necessary or appropriate to:
- Comply with laws and regulations, including, without limitation, applicable tax, health and safety, anti- discrimination, immigration, labor and employment, and social welfare laws;
- Monitor, investigate, and enforce compliance with and potential breaches of Septerna policies and procedures and legal and regulatory requirements;
- Comply with civil, criminal, judicial, or regulatory inquiries, investigations, subpoenas, or summons; and
- Exercise or defend the legal rights of Septerna and its employees, affiliates, customers, contractors, and
C. EMPLOYEES
- Collection and Processing of Personal Information
We, and Our Service Providers, may have Collected and Processed the following categories of Personal Information from Employees in the preceding twelve (12) months:
- Identifiers, such as name, alias, online identifiers, account name, physical characteristics or description;
- Contact and financial information, including phone number, address, email address, financial information, medical information, health insurance information;
- Characteristics of protected classifications under state or federal law, such as age, gender, race, physical or mental health conditions, and marital status;
- Commercial information, such as transaction information and purchase history;
- Biometric information;
- Internet or other electronic network activity information, such as browsing history and interactions with Our websites or advertisements;
- Geolocation data, such as device location;
- Audio, electronic, visual, and similar information, such as call and video recordings;
- Professional or employment-related information, such as work history and prior employer;
- Education information, as defined in the federal Family Educational Rights and Privacy Act, such as student records and directory information; and
- Sensitive Personal Information, including:
- Personal Information that reveals:
- Social security, driver’s license, state identification card, or passport number;
- Financial account number or credit card number in combination with any credentials for allowing access to an account;
- Precise geolocation;
- Racial or ethnic origin, or religious beliefs;
- Contents of a Consumer’s email and text messages, unless the business is the intended recipient thereof.
- Biometric data processed for the purpose of uniquely identifying a Consumer; and
- Personal Information Collected and analyzed concerning a Consumer’s
- Personal Information that reveals:
- Categories of Employee Personal Information We Disclose to Service Providers & Third Parties
We disclose the following categories of Employee Personal Information to Service Providers and Third Parties:
- Identifiers, such as name, alias, online identifiers, account name, physical characteristics or description;
- Contact and financial information, including phone number, address, email address, financial information, medical information, health insurance information;
- Characteristics of protected classifications under state or federal law, such as age, gender, race, physical or mental health conditions, and marital status;
- Commercial information, such as transaction information and purchase history;
- Biometric information;
- Internet or other electronic network activity information, such as browsing history and interactions with Our websites or advertisements;
- Geolocation data, such as device location;
- Audio, electronic, visual, and similar information, such as call and video recordings;
- Professional or employment-related information, such as work history and prior employer;
- Education information, as defined in the federal Family Educational Rights and Privacy Act, such as student records and directory information; and
- Sensitive Personal Information, including:
- Personal Information that reveals:
- Social security, driver’s license, state identification card, or passport number;
- Financial account number or credit card number in combination with any credentials for allowing access to an account;
- Precise geolocation;
- Racial or ethnic origin, or religious beliefs;
- Contents of a Consumer’s email and text messages, unless the business is the intended recipient thereof.
- Biometric data processed for the purpose of uniquely identifying a Consumer; and
- Personal Information Collected and analyzed concerning a Consumer’s
- Personal Information that reveals:
- Purposes for Processing Employee Personal Information
We, and Our Service Providers, Collect and Process Employee Personal Information (excluding Sensitive Personal Information) described in this Notice to:
- Manage your Employee relationship with Us;
- Manage and provide compensation, payroll, tax, expense reimbursement, and benefits planning, enrollment, and administration;
- Provide you access to Septerna systems, networks, databases, equipment, and facilities;
- Manage Our workforce and its performance, including personnel planning, productivity monitoring, and evaluation;
- Manage workforce development, education, training, and certification;
- Monitor, maintain, and secure Septerna systems, networks, databases, equipment, and facilities;
- Authenticate your identity and verify your access permissions;
- Arrange, confirm, and monitor work-related travel, events, meetings, and other activities;
- Assess your working capacity or the diagnosis, treatment, or care of a condition impacting your fitness for work, and other preventative or occupational medicine purposes (including work-related injury and illness reporting);
- Contact and communicate with you regarding your employment, job performance, compensation, and benefits, or in the event of a natural disaster or other emergency;
- Contact and communicate with your designated emergency contact(s) in the event of an emergency, illness, or absence; and
- Contact and communicate with your dependents and designated beneficiaries in the event of an emergency or in connection with your benefits.
In addition to the purposes identified above, Septerna may use and disclose any and all Employee Personal Information that We Collect as necessary or appropriate to:
- Comply with laws and regulations, including (without limitation) applicable tax, health and safety, anti- discrimination, immigration, labor and employment, and social welfare laws;
- Monitor, investigate, and enforce compliance with and potential breaches of Septerna policies and procedures and legal and regulatory requirements;
- Comply with civil, criminal, judicial, or regulatory inquiries, investigations, subpoenas, or summons; and
- Exercise or defend the legal rights of Septerna and its employees, affiliates, customers, contractors, and
D. PROCESSING SENSITIVE PERSONAL INFORMATION
We, and Our Service Providers, Collect and Process the Sensitive Personal Information described in this Notice only for:
- Performing the services or providing the goods reasonably expected by an average Consumer who requests those goods or services (including offering benefits to employees and their beneficiaries);
- Ensuring security and integrity to the extent the use of the Consumer’s Personal Information is reasonably necessary and proportionate for these purposes;
- Performing services on Our behalf, including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on Our behalf;
- Undertaking activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by Us, and to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by Us.
E. SOURCES FROM WHICH WE COLLECT APPLICANT AND EMPLOYEE PERSONAL INFORMATION
We Collect Personal Information directly from all Applicants and Employees, including Personal Information about Employees’ beneficiaries or dependents. We may also Collect Personal Information from joint marketing partners, public databases, providers of demographic data, publications, professional organizations, educational institutions, social media platforms, Service Providers and Third Parties that help Us screen and onboard individuals for hiring purposes, and Service Providers and Third Parties when they disclose information to Us.
F. CATEGORIES OF ENTITIES TO WHOM WE DISCLOSE APPLICANT AND EMPLOYEE PERSONAL INFORMATION
- Affiliates & Service Providers. We may disclose Applicant and Employee Personal Information to Our affiliates and Service Providers for the purposes described in Sections B and C, respectively, of this Notice. Our Service Providers provide Us with Applicant selection and related hiring services, benefits and wellness services, website services, as well as other products and services, such as web hosting, data analysis, customer service, infrastructure services, technology services, email delivery services, legal services, and other similar services. We grant Our Service Providers access to Personal Information only to the extent needed for them to perform their functions, and require them to protect the confidentiality and security of such information.
- Third Parties. We may disclose your Personal Information to the following categories of Third Parties:
- At Your Direction. We may disclose your Personal Information to any Third Party with your consent or at your direction.
- Business Transfers or Assignments. We may disclose your Personal Information to other entities as reasonably necessary to facilitate a merger, sale, joint venture or collaboration, assignment, transfer, or other disposition of all or any portion of Our business, assets, or stock (including in connection with any bankruptcy or similar proceedings).
- Legal and Regulatory. We may disclose your Personal Information to government authorities, including regulatory agencies and courts, as reasonably necessary for Our business operational purposes, to assert and defend legal claims, and otherwise as permitted or required by law.
G. DATA SUBJECT RIGHTS
- Data Subject Rights Available to You. As an Applicant or Employee, you have the following rights regarding Our Collection and use of your Personal Information, subject to certain exceptions:
- Right to Receive Information on Privacy Practices: You have the right to receive the following information at or before the point of Collection:
- The categories of Personal Information to be Collected;
- The purposes for which the categories of Personal Information are Collected or used;
- Whether or not that Personal Information is Sold or Shared;
- If the business Collects Sensitive Personal Information, the categories of Sensitive Personal Information to be Collected, the purposes for which it is Collected or used, and whether that information is Sold or Shared; and
- The length of time the business intends to retain each category of Personal Information, or if that is not possible, the criteria used to determine that period.We have provided such information in this Notice, and you may request further information about Our privacy practices by contacting Us at the contact information provided below.
- Right to Request Deletion: You may request that We delete any Personal Information about you that We Collected from you.
- Right to Request Correction: You may request that We correct any inaccurate Personal Information We maintain about you.
- Right to Know: You may request that We provide you with the following information about how We have handled your Personal Information in the 12 months preceding your request
- The categories of Personal Information We Collected about you;
- The categories of sources from which We Collected such Personal Information;
- The business or commercial purpose for Collecting, Selling, or Sharing Personal Information about you;
- The categories of Third Parties with whom We disclosed such Personal Information; and
- The specific pieces of Personal Information We have Collected about
- Right to Receive Information About Onward Disclosures: You may request that We disclose to you:
- The categories of Personal Information that We have Collected about you;
- The categories of Personal Information that We have Sold or Shared about you and the categories of Third Parties to whom the Personal Information was Sold or Shared; and
- The categories of Personal Information We have disclosed about you for a business purpose and the categories of persons to whom it was disclosed for a business purpose.
- Right to Non-Discrimination: You have the right not to be discriminated against for exercising your data subject rights. We will not discriminate against you for exercising your data subject rights. For example, We will not make hiring, firing, promotion, or disciplinary decisions based on or in consideration of your exercise of your data subject rights. We also will not deny goods or services to you, charge you different prices or rates, or provide a different level of quality for products or services as a result of you exercising your data subject rights.
- Rights to Opt-Out of the Sale and Sharing of Your Personal Information and to Limit the Use of Your Sensitive Personal Information: You have the right to opt-out of the Sale and Sharing of your Personal Information. You also have the right to limit the use of your Sensitive Personal Information to the purposes authorized by the We do not Sell or Share Personal Information. Further, We do not use Sensitive Personal Information for purposes beyond those authorized by the CCPA. For purposes of the CCPA, a “Sale” is the disclosure of Personal Information to a Third Party for monetary or other valuable consideration, and a “Share” is the disclosure of Personal Information to a Third Party for cross-context behavioral advertising, whether or not for monetary or other valuable consideration.
- Exercising Data Subject Rights. Applicants and Employees may exercise your data subject rights by contacting dpo@septerna.com or by calling (650) 338-3533. You may also authorize an agent to make a data subject request on your behalf, and the authorized agent may do so via the above-listed submission methods.
- Verification of Data Subject Requests. We may ask you to provide information that will enable Us to verify your identity in order to comply with your data subject request. In particular, if you authorize an agent to make a request on your behalf, We may require the agent to provide proof of signed permission from you to submit the request, or We may require you to verify your own identity to Us or confirm with Us that you provided the agent with permission to submit the In some instances, We may decline to honor your request if an exception applies under the CCPA. We will respond to your request consistent with applicable law.
H. OTHER DISCLOSURES
- Protection & Retention of Personal Information: Septerna processes your Personal Information for the period necessary to fulfill the purposes outlined in this Notice and to preserve your Personal Information in accordance with the provisions of relevant laws and regulations. The Personal Information you provide to Us may be held and stored electronically and/or in hard copy. Septerna implements appropriate technical and organizational security measures, to protect against and detect accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to Personal Information.Septerna employees and Service Providers that have access to your Personal Information are bound by strict confidentiality obligations and are required to treat your Personal Information in accordance with legal requirements. In addition, depending on the information or purpose for Collection, only Septerna employees and Service Providers who have a “need to know” your information will be permitted to access it.The criteria for retention is followed and determined by:
- The purpose of the Personal Information Collected and the fulfillment of that purpose
- Mandatory retention periods provided by contractual and regulatory requirements
- Financial Incentives for Applicants/Employees. We do not provide financial incentives to Applicants or Employees who allow Us to Collect, retain, Sell, or Share their Personal Information. We will describe such programs to you if and when We offer them to you. Please note that for non-Applicant/Employee California Consumers, We do provide discounts and incentives to individuals who use Our products and services, which could be considered an offer of a “financial incentive” under the
- Changes to this Notice. We reserve the right to amend this Notice in Our discretion and at any time. When We make material changes to this Notice, We will notify you by posting an updated Notice on Our website and listing the effective date of such updates.
- Contact Us: If you have any questions regarding this Notice or Septerna’s Collection and use of your Personal Information, or would like to exercise your data subject rights, please contact dpo@septerna.com. If you are unable to review or access this notice due to a disability, you may contact Us at (650) 338-3533 to access this notice in an alternative format. For further details about our privacy practices pertaining to non-Applicant/Employee Personal Information, please see our Privacy Notice