Privacy Policy
Privacy Statement Effective as on September 28th, 2023
Note: This policy was last reviewed and updated on January 23rd, 2026, Ver 10.0
EMP Trust Solutions, LLC (“EMPTrust” or the” Company “) is committed to protecting the privacy of your information. This Privacy Statement describes EMPTrust’s Data Privacy information practices while on the company’s website or on the company’s application service website for customers.
If you have any questions about this Privacy Statement, please contact EMP Trust Solutions by mail.
Attention: Sr. Director – Privacy & Compliance Office,
101 Lakeforest Blvd, Suite 230, Gaithersburg, MD 20877, USA
Scope
This Privacy Policy applies to all Personally Identifiable Information (PII) received by EMPTrust from its customers, employees, website visitors, and job applicants
(each of which may be individually referred to herein as “you” or “your”) in any format, including electronic, paper, or verbal. For purposes of this Policy, “PII” or “Personal Identifiable Information” means any information collected by EMPTrust that identifies or could be used by EMPTrust to identify an individual. As a subset of the larger group listed above, EMPTrust processes information of employees of its customers under the direction of its customers and has no direct relationship with such customers’ employees, whose personal data it may process on the customer’s behalf.
Privacy Policy
EMPTrust respects the privacy of our customers, employees, website visitors, and job applicants. We believe it is important for you to understand the type of information we collect about you and how that information is used. We recognize the need for appropriate safeguards and management of Personally Identifiable Information (PII) you provide to us. This Privacy Policy sets forth the privacy principles EMPTrust follows with respect to your Personal Information.
1. Websites covered: –
This Privacy Statement covers the information practices of websites that link to this Privacy Statement: Company Website: https://www.emptrust.com.
Application service website www.empforce.com (collectively referred to as
“EMP Trust’s Websites” or “the Company’s Websites”). Applications may be posted by EMP Trust and third parties on the company website www.emptrust.com.
When applications are posted by EMPTrust, this Privacy Statement applies. When applications are posted by third parties, and visitors wish to avail themselves of services from 3rd party partners, the privacy statement of the third party applies, and this Privacy Statement does not apply.
When sites are posted by EMPTrust, the site will link to this Privacy Statement, and this Privacy Statement applies. When sites are posted by third parties, the privacy statement of the third party applies, and this Privacy Statement does not apply.
EMP Trust’s websites may contain links to other websites on the company website www.emptrust.com. EMPTrust is not responsible for the information practices or the content of such other websites. The Company encourages you to review the privacy statements of other websites to understand their information practices.
2. Personal Information Collected: –
EMPTrust offers a variety of services that are collectively referred to as the “Service.” EMPTrust collects information from individuals who visit the Company’s websites (“Visitors”), individuals acting on behalf of an organization who register to use the Service (“Customers”), job applicants, and employees.
Job Applicants and Employees:
EMPTrust collects PII from job applicants and employees of EMPTrust for, among other things, legitimate human resource business reasons such as Human Resource administration, filling employment positions, maintaining accurate employee records, meeting governmental reporting requirements, security, health and safety management, performance management, company network access, and authentication.
Customers:
EMPTrust collects PII from customers of EMPTrust who use our solution. The information may be collected through our SaaS solution or by members of our customer service and support teams who provide support to customers. The type of PII collected is like the information collected under the “Job Applicants and Employees” paragraph, above.
EMPTrust collects information under the direction of its customers and has no direct relationship with the individuals whose personal data it processes. If you are an individual of one of our customers and would no longer like to be contacted by one of our customers who uses our service, please contact the customer that you interact with directly. We may transfer personal information to companies that help us provide our services under specific requests from our customers. Transfers to subsequent third parties are covered by the service agreements with our customers. The use of information collected through our SaaS solution shall be limited to the purpose of providing the service for which the customer has engaged EMPTrust.
Visitors on Company Websites:
When expressing an interest in obtaining additional information about the Service or registering to use the Service, EMPTrust requires you to provide the company with contact information, such as name, company name, address, phone number, and email address (“Required Contact Information”).
As you navigate the company’s websites, EMPTrust may also collect information using commonly used information-gathering tools, such as cookies and web beacons (“Web Site Navigational Information”). Web Site Navigational Information includes standard information from your web browser (such as browser type and browser language), your Internet Protocol (“IP”) address, and the actions you take on the company’s web sites (such as the web pages viewed, and the links clicked).
When purchasing the Service, EMPTrust requires you to provide the company with financial qualification and billing information, such as billing name and address, credit card number, and the number of employees within the organization that will be using the service (“Billing Information”). EMPTrust may also ask you to provide additional information, such as company annual revenues, work locations, number of employees, or industry (“Optional Information”). Required Contact Information, Billing Information, and Optional Information are referred to collectively as “Data about EMPTrust Customers.” Financial data about customers is not stored on the company website, application, or service.
3. Use of Information Collected: –
The company uses data about EMPTrust visitors and customers to perform the services requested. For example, if you fill out a “Contact Me” web form, the company will use the information provided to contact you about your interest in the service.
The company may also use data about EMPTrust visitors for marketing purposes. For example, the company may use information you provide to contact you to further discuss your interest in EMPTrust, the service, and to send you information regarding the Company and its partners, such as information about promotions or events.
EMPTrust uses credit card information solely to check the financial qualifications of prospective customers and to collect payment for the service. EMPTrust does not store credit card information within its application, service, or websites.
EMPTrust uses Website Navigational Information to operate and improve the company’s websites. The company may also use Website Navigational Information in combination with data about EMPTrust visitors to provide personalized information about the company.
4. Website Navigational Information: –
EMPTrust uses commonly used information-gathering tools, such as cookies and web beacons, to collect information as you navigate the company’s websites (“Web Site Navigational Information”). This section describes the types of Website Navigational Information the company may collect and how the company may use this information.
Cookies:
EMPTrust uses cookies to make interactions with the company’s websites easy and meaningful. When you visit one of the company’s websites, EMPTrust’s servers send a cookie to your computer. Standing alone, cookies do not personally identify you. They merely recognize your web browser. Unless you choose to identify yourself to EMPTrust, either by responding to a promotional offer, opening an account, or filling out a web form (such as a “Contact Me” or a “30 Day Free Trial” web form),you remain anonymous to the company. There are two types of cookies: session-based and persistent-based. Session cookies exist only during one session. They disappear from your computer when you close your browser software or turn off your computer. Persistent cookies remain on your computer after you close your browser or turn off your computer.
If you have chosen to identify yourself to EMPTrust, the company uses session cookies containing encrypted information to allow the company to uniquely identify you. Each time you log into the Service, a session cookie containing an encrypted, unique identifier that is tied to your account is placed in your browser. These session cookies allow the Company to uniquely identify you when you are logged into the service and to process your online transactions and requests. Session cookies are required to use the service.
EMPTrust uses persistent cookies that only the company can read and use to identify browsers that have previously visited the company’s websites. When you purchase the service or provide the company with personal information, a unique identifier is assigned to you. This unique identifier is associated with a persistent cookie that the company places on your web browser. The company is especially careful about the security and confidentiality of the information stored in persistent cookies. For example, the company does not store account numbers or passwords in persistent cookies. If you disable your web browser’s ability to accept cookies, you will be able to navigate the company’s websites, but you will not be able to successfully use the service.
EMPTrust may use information from session and persistent cookies in combination with data about EMPTrust customers to provide you with information about the company and the service.
Web Beacons:
EMPTrust uses Web beacons alone or in conjunction with cookies to compile information about visitors’ usage of the company’s websites and interaction with emails from the company. Web beacons are clear electronic images that can recognize certain types of information on your computer, such as cookies, when you view a particular website tied to the web beacon, and a description of a website tied to the web beacon. For example, EMPTrust may place web beacons in marketing emails that notify the Company when you click on a link in the email that directs you to one of the company’s websites. EMPTrust uses web beacons to operate and improve the company’s websites and email communications. EMPTrust may use information from web beacons in combination with data about EMPTrust visitors to provide you with information about the company and the Service.
IP Addresses:
When you visit EMPTrust’s websites, the company collects your Internet Protocol (“IP”) addresses to track and aggregate non-personally identifiable information. For example, EMPTrust uses IP addresses to monitor the regions from which customers and visitors navigate the company’s websites or to block undesirable regions or locations.
EMP Trust also collects IP addresses from customers when they log into the service,
as part of the company’s “Identity Confirmation” and “IP Range Restrictions” security
features.
Third Party Cookies:
From time-to-time, EMPTrust may engage third parties to track and analyze non-personally identifiable usage and volume statistical information from individuals who visit the company’s websites. EMPTrust may also use other third-party cookies to track the performance of company advertisements. The information provided to third parties does not include personal information, but this information may be re-associated with personal information after the company receives it. This Privacy Statement does not cover the use of third-party cookies.
5. Public Forums Refer a Friend, and Customer Testimonials: –
EMPTrust may provide bulletin boards, blogs, or chat rooms on the company’s websites. Any personally identifiable information you choose to submit in such a forum may be read, collected, or used by others who visit these forums, and may be used to send you unsolicited messages. EMPTrust is not responsible for the personally identifiable information you choose to submit in these forums.
Customers and visitors may elect to use the company’s referral service to inform friends about the company’s websites. When using the referral service, the company requests the friend’s name and email address. EMPTrust will automatically send the friend a one-time email inviting him or her to visit the company’s websites. EMPTrust does not store this information.
EMPTrust may post a list of customers and testimonials on the company’s websites that contain information such as customer names and titles. EMPTrust obtains the consent of each customer prior to posting any information on such a list or posting testimonials.
6. Sharing of Information Collected: –
EMPTrust may share data about EMPTrust customers within the EMPTrust customer service department so that customer service agents can contact customers and visitors who have provided contact information on our behalf. EMPTrust may also share data about EMPTrust customers with the company’s agents to ensure the quality of information provided, measure service level agreements, and monitor the agents’ performance.
EMPTrust does not share, sell, rent, or trade personally identifiable information with third parties for their promotional purposes.
EMPTrust uses a third-party intermediary to manage credit card processing. This intermediary is not permitted to store, retain, or use billing information except for the sole purpose of credit card processing on the company’s behalf. EMPTrust does not store or collect credit card information in internal databases for future use or require that credit information be entered into EMPTrust websites.
EMPTrust reserves the right to disclose personally identifiable information of the company’s customers or visitors if required by law or if the company reasonably believes that disclosure is necessary to protect the company’s rights and/or to comply with a judicial proceeding, court order, or legal process.
7. Communications Preferences: –
EMPTrust offers visitors who provide contact information a means to choose how the company uses the information provided. You may manage your receipt of marketing and non-transactional communications by clicking on the “Unsubscribe” link located at the bottom of the company’s marketing emails.
Customers cannot opt out of receiving transactional emails related to their account with EMPTrust or the service. The company does not send marketing or promotional emails to customers unless users sign up specifically for newsletters and promotional events. Customers who signed up for marketing and promotional emails may manage receipt of marketing and non-transactional communications by clicking on the “Unsubscribe” link located at the bottom of the company’s marketing emails.
8. Correcting and Updating your Information: –
Customers may update or change their registration information by editing their user or organization record. To update a user profile, please log in to your account with your EMPTrust username and password or Active Directory login and click “User Profile.”
To update an organization’s information, please contact your organization’s assigned application administrator with your EMPTrust username and password and select “Accounts”.
9. Customer Data: –
EMPTrust customers use the service to host data and information (“Customer Data”). EMPTrust will not review, share, distribute, or reference any such customer data except as provided under the customer software license agreement or EMPTrust Master Subscription Agreement, whichever applies, or as may be required by law. Individual records of Customer Data may be viewed or accessed only with specific permission from the customer by EMP Trust customer service agents for the purpose of resolving a problem or supporting a reported issue, or as may be required by law. Customers are responsible for maintaining the security and confidentiality of their EMPTrust usernames and passwords.
10. Security: –
EMPTrust uses robust security measures to protect customer data from unauthorized access or disclosure, maintain data accuracy, and allow only the appropriate use of your PII. We utilize physical, technical, and administrative controls and procedures to safeguard the information we collect.
We limit access to your PII and data to those persons who have a specific business purpose for maintaining and processing such information. EMPTrust’s employees who have been granted physical access to your PII are made aware of their responsibilities to protect the confidentiality, integrity, and availability of that information and have been provided training and instruction on how to do so.
To protect the confidentiality, integrity, and availability of your PII, EMPTrust utilizes a variety of physical and logical access controls, firewalls, intrusion detection/prevention systems, network and database monitoring, anti-virus, and backup systems. We use encrypted sessions when collecting or transferring sensitive data through our websites.
When the service is accessed using any internet browser such as Google Chrome, Firefox, Safari, Microsoft Edge, or Internet Explorer version 11.0 or later, Secure Socket Layer (“SSL”) technology protects customer data using both server authentication and data encryption. These technologies help ensure that customer data is safe, secure, and only available to the customer to whom the information belongs and those to whom the customer has granted access. EMPTrust also implements an advanced security method based on dynamic data and encoded session identifications, and the company hosts its websites in a secure server environment that uses firewalls, intrusion detection, log monitoring, and other advanced technology to prevent interference or access from outside intruders. All Personally Identifiable Information (PII) used in customer applications or service are encrypted at rest and within the database. EMPTrust also offers enhanced security features within the service that permit customers who have private cloud or dedicated servers to configure security settings to the level they deem necessary.
Because the company uses the service to maintain data about EMPTrust customers, this information is secured in the same manner as described above for customer data.
11. Data Integrity: –
As to its own employees and its own job applicants, EMPTrust will take reasonable steps to ensure that PII is accurate, complete, and current to its intended use. EMPTrust will only use PII in ways that are compatible with the purposes for which it was collected or subsequently authorized by the individual.
12. Enforcement &Verification: –
EMPTrust will conduct periodic assessments to validate its continued adherence to this Privacy Policy. Where EMPTrust has knowledge that one of EMPTrust’s employees or third parties is using or disclosing PII in a manner contrary to this Policy, EMPTrust will take reasonable steps to prevent or stop the use or disclosure. EMPTrust holds its employees and agents accountable for maintaining the trust that our customers place in our company.
13. Data Privacy Frameworks for Data Transferred to the United States from the EU/Switzerland: –
EMP Trust Solutions, LLC complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. EMP Trust Solutions, LLC has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. EMP Trust Solutions, LLC has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) Program, and to view our certification, please visit https://www.dataprivacyframework.gov/
With respect to personal information received or transferred pursuant to the Data Privacy Frameworks, EMPTrust is subject to the regulatory and enforcement powers of the U.S. Federal Trade Commission.
Pursuant to the Data Privacy Frameworks, EU, UK Individuals and Swiss individuals have the right to obtain our confirmation of whether we maintain personal information relating to you in the United States. Upon request, we will provide you with access to the personal information that we hold about you. You also may correct, amend, or delete the personal information we hold about you. An individual who seeks access, or who seeks to correct, amend, or delete inaccurate data transferred to the United States under Data Privacy, should direct their query to [email protected]. If requested to remove data, we will respond within a reasonable timeframe.
We will provide an individual opt-out choice, or opt-in for sensitive data, before we share your data with third parties other than our agents, or before we use it for a purpose other than which it was originally collected or subsequently authorized. To request to limit the use and disclosure of your personal information, please submit a written request to [email protected].
In certain situations, we may be required to disclose personal information in response to lawful requests by public authorities, including meeting national security or law enforcement requirements.
EMPTrust’s accountability for personal information that it receives in the United States under the Data Privacy and subsequently transfers to a third party is described in the Data Privacy Principles. EMPTrust remains responsible and liable under the Data Privacy Principles if third-party agents that it engages to process personal information on its behalf do so in a manner inconsistent with the principles, unless EMPTrust proves that it is not responsible for the event giving rise to the damage.
Our organization commits to cooperate with EU data protection authorities (DPAs) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) and comply with the advice given by such authorities about human resources data transferred from the EU and Switzerland in the context of the employment relationship.
In compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S.DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF), EMP Trust Solutions, LLC commits to resolving complaints about our collection or use of your personal information transferred to the U.S. pursuant to the EU-U.S. DPF and the Swiss-U.S. DPF. EU, UK Individuals and Swiss individuals with inquiries or complaints should first contact the EMP Trust Privacy Officer by email at [email protected], or via post at:
EMP Trust Solutions
Attention: Sr. Director – Privacy & Compliance Office
101 Lakeforest Blvd, Suite 230
Gaithersburg, MD 20877, USA.
EMP Trust Solutions, LLC has further committed to refer unresolved DPF Principles-related complaints to a U.S.-based independent dispute resolution mechanism, BBB NATIONAL PROGRAMS. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed please visit www.bbbprograms.org/dpf-complaints for more information and to file a complaint. This service is provided free of charge to you.
If your DPF complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms. See https://www.dataprivacyframework.gov/s/article/ANNEX-I- introduction-dpf
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, EMP Trust Solutions, LLC commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of human resources data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF in the context of the employment relationship.
If your complaint involves human resources data transferred to the United States from the European Union, the United Kingdom, or Switzerland in the context of the employment relationship, and EMP Trust Solutions, LLC does not address it satisfactorily, EMP Trust Solutions, LLC commits to cooperate with the panel established by the EU data protection authorities (DPA Panel), [the UK Information Commissioner’s Office, and the Swiss Federal Data Protection and Information Commissioner, as applicable] and to comply with the advice given by the DPA panel [ICO, or FDPIC, as applicable] with regard to such human resources data. To pursue an unresolved human resources complaint, you should contact the state or national data protection or labor authority in the appropriate jurisdiction. Contact details for the EU data protection authorities can be found at https://edpb.europa.eu/about-edpb/board/members_en. Complaints related to human resources data should not be addressed to the BBB NATIONAL PROGRAMS.
14. Onward Transfers: –
EMPTrust uses a limited number of third-party providers in the U.S. and in Europe to provide data hosting services and to help to perform customer support and technical operations.
EMPTrust shall remain responsible in case of onward transfers to third parties. EMPTrust shares the personal information with these third-party providers to support EMPTrust’s Services only. Any other use of the personal information by third-party providers is prohibited.
All third-party providers receiving personal information from the European Union and/or Switzerland agree to,
- process the personal data only to the extent required by EMPTrust’s services and in accordance with EMPTrust’s instructions
- comply with the data protection laws for the transfer and processing of personal data
- Provide adequate technical and organizational measures to protect the personal information.
To this end, we use the European Standard Contract clauses (https://ec.europa.eu/info/law/law-topic/data-protection_en) with our sub-processors in order to guarantee the privacy and the security of your personal information.
How can you access your personal information?
EMPTrust acknowledges that individuals have a right to access, correct, amend, and delete their personal information. Because EMPTrust is the data processor of the personal information and collects personal information under the instructions of its customers, EMPTrust shall follow its customers’ instructions. Therefore, EMPTrust encourages the individuals to contact these customers. This can be done by replying to the last email that was sent via the EMPTrust system. For instructions on contacting EMPTrust directly with your relevant privacy concern, please see our Data Privacy statement, section 13 above.
15. Changes to this Privacy Statement: –
The practices described in this policy are the current PII protection policies approved on February 2, 2021. EMPTrust reserves the right to change this privacy statement at any time consistent with the Data Privacy principles. EMPTrust will provide notification of the material changes to this privacy statement through the company’s websites at least thirty (30) business days prior to the change taking effect. We encourage you to periodically review this page for the latest information on our privacy practices.
16. Independent Recourse Mechanism: –
If you have not received a timely or satisfactory response from EMP Trust Solutions, LLC to your question or complaint, please contact the independent recourse mechanism listed below:
HR RECOURSE MECHANISM
Swiss Federal Data Protection and Information Commissioner (FDPIC) EU Data
NON-HR RECOURSE MECHANISM
17. Contacting US: –
Questions regarding this privacy statement or the information practices of the company’s websites should be directed to the EMPTrust’s privacy officer by email at [email protected] or by mail at our offices below:
EMP Trust Solutions Attention:
Sr. Director – Privacy & Compliance Office
101 Lakeforest Blvd, Suite 230
Gaithersburg, MD 20877, USA