California Candidate Privacy Policy

Recruiting Privacy Policy Effective Date: January 25, 2023

Scope: This policy applies to all employees of HealthDrive and affiliated entities and should be furnished to all prospective employees during the recruitment process.

Purpose: This Recruiting Privacy Policy describes the privacy and security practices that HealthDrive Corporation and its affiliates employ when collecting, using and handling personal information about you in connection with our online and offline recruitment activities, including on our recruiting website made available at www.healthdrive.com. It also explains the choices you have in relation to these processing activities.

Policy: It is the policy of HealthDrive to disclose the information that we collect and process during the recruitment and hiring process. The categories of personal information we have collected about you in the last 12 months include the following:

  • Personal information means all information that relates to an identified individual or to an identifiable individual. For example, your name, address, email address, educational and employment background, CV and job qualifications. Personal information is also referred to as information about you.
  • Usage data is information that we automatically collect about your use of our Website and includes the sort that Web browsers and servers typically make available, through Web server logs, Web beacons, cookies and other similar tracking technologies, about the devices you use to access our Website, as well as information on how you interact with our Website. Usage Data may include the IP address of a device or internet service used to connect your device to the Internet and may provide information about your location; computer and connection information such as your browser type and version; operating system and platform; and the URLs which lead you to and around the Website including the date and time of access. Usage Data generally does not directly identify an individual, but may constitute Personal Information in some instances.

We may also collect the following information you provide during the application process:

  • Optional demographic information, such as gender, race/ethnicity, disability, and sexual orientation;
  • Information needed to provide you with an offer (e.g., rate of pay, start date, job title);
  • Professional certifications, relevant prior trainings and courses, letters of recommendation and references, the source from which you heard about job opportunities, and your availability to schedule interviews;
  • Military and/or veteran status, your ability to perform expected physical requirements for the position which you are applying, and physical limitations or other medical or health-related workplace accommodations;
  • The results of background screening searches including credit and criminal background checks, drug and alcohol testing and other pre-employment screenings, if applicable; and
  • Your right to work in the United States, and any limitations on your right to work associated with employment sponsorship, if applicable.

How We Collect Your Personal Information

We collect and process personal information you provide directly to us in connection with the below purposes, such as when you register for a recruiting event, submit a job application, or interview with us. We also receive personal information from other sources, such as during reference, background, or employment checks, and from third party recruitment sources and assessment sites.

We may also collect and process personal information and usage data automatically when you use the Website. We may use this data to analyze trends and statistics to improve your experience.

How We Use Your Personal Information

We use personal information to assess your qualifications for employment and other related services during the application and recruitment stage. This may include contacting you after you have applied, contacting your references, and potentially conducting background checks and other pre-employment screenings. We also use such information to respond to your requests or application, for recruitment and hiring purposes, to enable your use of, and to develop and improve our recruiting activities,; and to comply with applicable laws. For example, we may use applicant information for benchmarking, analyzing and reporting on the diversity of candidate pools. We may also contact you about any other jobs we think may be of interest to you.

How We Disclose Your Personal Information

Your personal information may be disclosed throughout HealthDrive’s organization. Your personal information may also be shared with various service providers that assist us in the recruitment process, such as service providers that carry out background checks and pre-employment screenings. We may also share personal information with third parties when we believe that the disclosure is required to comply with a court order, subpoena, warrant or other legal process, and with related companies in the event of a merger, acquisition, asset sale or other related transaction, or when we believe that the disclosure is required by law or to protect the safety of our employees, the public or HealthDrive’s property.

Retention

HealthDrive will retain the personal information that we process pursuant to this Privacy Policy for the duration of time necessary to assess your qualifications for employment, and for the period of time thereafter as provided in our retention policies. If you are hired by HealthDrive, your personal information will be subject to a separate employee privacy policy.

Security

HealthDrive has reasonable and appropriate safeguards in place to help protect the personal information HealthDrive collects from loss, misuse, and unauthorized access, disclosure, alteration, and destruction. Although HealthDrive attempts to protect the personal information in our possession, no security system is perfect, and HealthDrive cannot promise that your personal information will remain absolutely secure in all circumstances.

Cookies and other Tracking Technologies

We and our service providers may use various tracking technologies, including cookies and web beacons, to collect information about you when you interact with our Website. Cookies are small data files stored on your hard drive or in device memory that help us improve the Website and your experience, see which areas and features of the Website are popular, and count visits. Web beacons are electronic images that may be used on the Website or emails and help deliver cookies, count visits and understand usage and campaign effectiveness. You may set your browser to decline cookies. If you do so, however, you may not be able to fully experience some interactive features of the Website.

Notice concerning Do Not Track. Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. We are committed to providing you with meaningful choices about the information collected on our websites for third-party purposes, and that is why we provide the variety of opt-out mechanisms listed above. Some web browsers offer users a “Do Not Track” privacy preference setting in the web browser. We do not currently recognize or respond to browser-initiated Do Not Track signals. Please note that “Do Not Track” is a distinct privacy mechanism from the browser-based opt out signals referenced above, which HealthDrive does honor in accordance with applicable law.

Links to Third Party Websites

Our Website may contain certain links to third party websites. HealthDrive is not responsible or liable for the privacy practices or content found on these websites. You should check the privacy notice and policies of each website you visit. Links to third party websites are provided solely for your convenience and any use or submission of data to such websites shall be at your sole risk.

Your Privacy Rights

If you reside in California, Colorado, Connecticut, Utah or Virginia, you may have legal rights with respect to your personal information. You may have the right to: (i) request additional disclosures about the personal information we collect, use, and share; (ii) request access to and deletion of your personal information, subject to certain exceptions; (iii) opt out of the sale and sharing of your personal information; (iv) correct inaccurate personal information that we maintain about you; (v) limit the use and disclosure of sensitive personal information; and (vi) obtain a copy of your personal information. We will not discriminate against you for exercising any of these rights.

Methods for submitting requests. If you wish to exercise any of these rights, please email RADept@healthdrive.com with the phrase “Privacy Rights” in the subject line. You may also send a request to us via mail at 100 Crossing Blvd., Suite 300, Framingham, MA 01702. Please mark the envelope ‘Data Protection Officer’ or call us toll-free at (888) 964-6681. We will process your request within the timeframe provided by applicable law. The rights described herein are not absolute and we reserve all of our rights available to us at law in this regard. Additionally, if we retain your personal information only in de-identified form, we will not attempt to re-identify your data in response to a privacy rights request.

If you make a request related to personal information about you, you will be required to supply a valid means of identification as a security precaution. We will verify your identity with a reasonably high degree of certainty using the following procedure where feasible: we will match identifying information you provide when making the request to the personal information maintained by us, or use a third-party

identity verification service. If it is necessary to collect additional information, we will use the information only for verification purposes and will delete it as soon as practicable after complying with your request. For requests related to particularly sensitive information, we may require additional proof of your identity.

Authorized Agents. You may use an authorized agent to submit a right to know or right to deletion request. When we verify your agent’s request, we may verify both your and your agent’s identity and request a signed document from you that authorizes your agent to make the request for you. To protect your personal information, we reserve the right to deny a request from an agent that does not submit adequate proof that you authorized them to act for you.

Sale of Personal Information. We do not generally sell personal information as the term “sell” is traditionally understood. We do not sell personal information to third parties for money. During the past 12 months, we may have engaged in delivering online advertising that was tailored to your interests, but we did not disclose data that would identify you by name, address or phone number. To the extent “sale” under the CCPA or other applicable law is interpreted to include advertising technology activities such as those disclosed here and in our Privacy Policy as a “sale,” we will comply with applicable law, including the CCPA, as to such activity. As described below, you have the right to opt out of the “sale” of your personal information. Additionally, you should know that the CCPA prohibits third parties to whom we “sell” personal information from reselling it unless you have received explicit notice and an opportunity to opt-out of further sales.

Verification. When you exercise your right to know or right to delete, we will take steps to verify your identity with a reasonably high degree of certainty before processing your request. We may ask for additional information so that we can verify your identity. If it is necessary to collect additional information, we will use the information only for verification purposes and will delete it as soon as practicable after complying with your request. We will only use the personal information you provide to us in response to this request to verify your identity and to process your request, unless you initially provided the information for another purpose. We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you.

Shine the Light: Individuals who are California residents may request (i) a list of categories of personal information disclosed to third parties during the immediately preceding calendar year for those third parties’ own direct marketing purposes; and (ii) a list of the categories of third parties to whom we disclosed such information. To exercise a request, please send us an email or a letter to the addresses in the section entitled “Contact Us” above and specify you are making a “California Shine the Light” request. We may require additional information from you to allow us to verify your identity and are only required to respond to requests once during any calendar year.

What Are Your Responsibilities?

You are responsible for the personal information that you provide or make available to HealthDrive, and must ensure it is truthful, accurate, and up-to-date in all respects. You must ensure that the information provided does not contain material that is obscene, defamatory, or infringes on any rights of any third party; does not contain malicious code; and is not otherwise legally actionable. Further, if you provide any personal information concerning any other person, such as individuals you provide as references, you are responsible for providing any notices and obtaining any consents necessary for HealthDrive to collect and use that information as described in this Privacy Policy. If you provide misleading, inaccurate, or

incomplete information, HealthDrive may determine you are ineligible for employment. You understand that this Privacy Policy does not form part of any employment contract you may be offered in connection with your employment at HealthDrive.

United States Only

The Website is intended for use only in the United States of America. If you use the Website or contact us from outside of the United States of America, please be advised that (i) any information you provide to us or that we automatically collect will be transferred to the United States of America; and (ii) by using the Website or submitting information, you explicitly authorize its transfer to and subsequent processing in the United States of America in accordance with this Privacy Policy.

Changes to the Privacy Policy

HealthDrive may change this Privacy Policy at any time. Unless we say otherwise, changes will be effective upon the last updated date at the top of this Privacy Policy. Please check this Privacy Policy regularly to ensure that you are aware of any changes. We may try to notify you of material changes to this Privacy Policy, which if we do so may be by means such as by posting a notice directly on the Website, by sending an e-mail notification (if you have provided your e-mail address to us), or by other reasonable methods. In any event, if you use the Website after changes to this Privacy Policy, you have accepted the changes. If you do not agree with the changes, please stop using the Website.

Contact Information

If you have any questions or concerns related to this Privacy Policy, please contact us at: (888) 964-6681.

Are you interested in a rewarding postion with HealthDrive?