Consumer Privacy Notice
This Privacy Notice provides you with necessary information about the personal information we collect, how this information may be used by the Redwood Empire Schools Insurance Group (“RESIG”), your privacy rights and RESIG’s obligations in accordance with the California Consumer Privacy Act of 2018 ("CCPA") and the California Privacy Rights Act of 2020 ("CPRA").
This Privacy Notice applies solely to natural persons residing in California ("Consumers"), and does not apply to individuals living elsewhere, businesses or other corporate entities.
RESIG’s Executive Director is responsible for maintaining, reviewing, and updating this Privacy Notice, in consultation with RESIG’s legal counsel.
As defined by the CCPA and CPRA, a consumer is a natural person who is a California resident, living in California for other than a temporary or transitory purpose, or individual domiciled in California.
Commonly referred to as Personally Identifiable Information (“PII”), Personal Information (“PI”) may be defined under various privacy laws, but, generally, is a fact about an individual which, if combined with one or more other facts about that individual, would enable others to determine the specific person to whom the facts apply.
Sensitive Personal Information:
Sensitive Personal Information (“SPI”) is a subset of PI that requires greater security protections and standards of care in handling. SPI, also known as "special categories of information", is defined as information that if lost, compromised, or disclosed could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual.
For the purposes of this Notice, we will refer to the Redwood Empire Schools Insurance Group and our members as “RESIG”, and collectively as “we”, “our”, or “us”.
1. CONSUMER RIGHTS
1.1. RIGHT TO ACCESS
You have the right to access PI which we may collect or retain about you. If requested, we shall provide you with a copy of your PI which we collect as permitted by the CCPA/CPRA. You also have the right to receive your PI in a structured and commonly used format so that it can be transferred to another entity (“data portability”).
1.2. RIGHT TO KNOW
You have the right to request that we disclose the following about your PI, as defined by the CCPA/CPRA:
- The specific PI we may collect;
- The categories of PI we may collect;
- The categories of sources from which we may collect your PI;
- The business purpose(s) for collecting or sharing your PI;
- The categories of PI we may disclose for business purposes; and
- The categories of third parties to whom we may share your PI.
1.3. RIGHT TO OPT-OUT / DO NOT SELL MY PERSONAL INFORMATION
RESIG does not sell PI within the meaning of the CCPA/CPRA.
1.4. DO NOT SHARE OR DISCLOSE MY SENSITIVE PERSONAL INFORMATION
You have the right to limit how your SPI is disclosed or shared with third parties, as defined in the CCPA/CPRA.
1.5. RIGHT TO DELETION
In certain circumstances, you have the right to request the erasure of your PI. Upon verifying the validity of a deletion request, we will delete your PI from our records, and instruct any service providers or third parties to delete your information, when applicable.
1.6. RIGHT TO CORRECT/RIGHT TO RECTIFICATION
In certain circumstances, you have the right to request correction of any inaccurate PI. Upon verifying the validity of a verifiable consumer correction request, we will use commercially reasonable efforts to correct your PI as directed, taking into account the nature of the PI and the purposes of maintaining your PI.
1.7. Please note that the above rights are not absolute, and we may be entitled to refuse requests, wholly or partly, where exceptions under applicable law apply.
2. EXERCISING YOUR RIGHTS
If you are a California resident, you can exercise any of your rights as described in this Notice and under applicable privacy laws by using the contact information provided in this Notice. We will not discriminate against you for exercising such rights.
Except as described in this Notice or provided for under applicable privacy laws, there is no charge to exercise of your legal rights. However, if your requests are manifestly unfounded or excessive, in particular because of their repetitive character, we may:
- Charge a reasonable fee taking in account the administrative costs of providing the information or taking the action requested; or
- Refuse to act on the request and notify you of the reason for refusing the request.
3. VERIFYING CONSUMER REQUESTS
When you make a request to us, indicate the name of the RESIG employee with whom you worked. We will verify by consultation with the identified employee. If you have not worked with a RESIG employee, we will require your name, e-mail, phone number, and address. We will attempt to match our records based on that information. Where we have reasonable doubts concerning the identity of the person making the request, we may request additional information necessary to confirm their identity.
4. PERSONAL INFORMATION (PI) WE COLLECT
We collect personal information about consumers when it is necessary to conduct the business of insurance. In general, we have collected the following categories of personal information from consumers in the preceding twelve months:
- Identifiers such as your real name, alias, postal address, telephone number, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number, state identification card number, passport number, or other similar identifiers.
- Signature, physical characteristics, or description.
- Insurance policy number, bank account number, credit card number, debit card number, or any other financial information.
- Medical information and health insurance information.
- Age, race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, gender, pregnancy or childbirth and related medical conditions), and veteran or military status.
- Audio, electronic, visual, or similar information.
- Current or past education, employment history, performance evaluations, income and salary details, credentialing information.
- Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
We collect personal information from applications, claim forms and other documents that we receive from you and from your transactions with us. We also collect personal information from other sources, such as claims investigators, attorneys, medical providers, credit reports, public records, the Internet, and social media.
This PI is required to enable us to provide our services to you. If you do not provide the PI we ask for, it may delay or prevent us from providing services to you. You confirm that you are authorized to provide to us the PI which we shall collect on your behalf. Where the PI relates to your employees, agents, associates, or family members, it is not reasonably practicable for us to provide to them the information set out in this Notice. Accordingly, where appropriate, you are responsible for providing this information to any such person.
5. SENSITIVE PERSONAL INFORMATION (SPI) WE COLLECT
We may also collect or process SPI as necessary to enable us to carry out your instructions, to manage and operate our business, and to comply with our legal and regulatory obligations. You may also supply us with, or we may receive, the following SPI:
- Username and password;
- Financial, account or billing information, including tax identification number, social security number, or credit/debit card information;
- Proof of identification, including driver's license number, or state/national government-issued identification;
- Diversity or demographic information, including race or ethnicity, gender, or gender identity, religious or philosophical beliefs, political affiliation, opinion or association, veteran or disability status, or sexual preference.
RESIG collects SPI on the basis of one or more of the following:
- You have given explicit consent to the collection for one or more specified purposes;
- Where the collection of SPI is manifestly made public by you; and/or
- Where the collection is necessary for the establishment, exercise, or defense of insurance claims.
Where the collection is necessary for reasons of substantial public interest, in accordance with applicable law, RESIG may collect SPI for the following reasons:
- For the purposes of the prevention or detection of an unlawful act or for preventing fraud; and
- For the provision of confidential advice.
6. HOW PERSONAL INFORMATION IS COLLECTED
We collect most PI directly from you. However, we may also collect PI from the following:
- Publicly accessible sources;
- Directly from a third party for background checks or due diligence providers;
- A third party, such as a bank, financial institution, or advisor, with your consent;
- Consultants and other professionals we may engage in relation to your matter, with your consent;
- Our Information Technology (IT) systems.
7. THE PURPOSE FOR WHICH PERSONAL INFORMATION IS COLLECTED
The purposes for which RESIG will collect or use your PI include:
- To underwrite and service our insurance policies.
- To investigate and process claims under our insurance policies.
- To provide you with support and respond to your inquiries, including investigating and addressing your concerns and monitoring and improving our responses.
- To create, maintain, customize, and secure your account with us, including detecting security incidents and debugging to identify and repair errors that impair existing functionality.
- To process your premium payments, transactions, and other payments to and from you, and prevent transactional fraud.
- To respond to law enforcement requests, regulatory agency requests and as required or allowed by applicable laws, court order, rules, or regulations.
- To conduct fraud investigations and report fraud pursuant to applicable laws, court order, rules, or regulations.
- To carry out our business operations and associated administration in connection with your matters or as your potential employer;
- To comply with our internal business processes and policies;
- To comply with our legal, regulatory, and professional obligations;
- For operational reasons, such as improving efficiency, training, and quality control;
8. DISCLOSURE OF PERSONAL INFORMATION
RESIG shall use a reasonable standard of care to store and protect from disclosure any PI collected using the principles of least-privileged access and by limiting access to PI and SPI to individuals with a 'need to know'. PI will be retained by us as set out in RESIG's policies. RESIG may share your PI under the following circumstances:
- In the event that we sell or purchase any business or assets, or if all or substantially all of the RESIG's assets are acquired by a third party, in which we may disclose your PI to the prospective seller or buyer of such business or assets, solely for the purpose of permitting the due diligence required to decide whether to proceed with a transaction;
- If reasonably necessary to protect the vital interests of a person or RESIG;
- If we are subject to disclose or share your information in order to comply with any legal or regulatory obligation; or
- To enforce or apply our terms and conditions or to establish, exercise or defend the rights of RESIG, RESIG Personnel, board members or others.
Our third-party service providers are subject to security and confidentiality obligations and are only permitted to process information for a specified, legitimate business purpose and in accordance with our instructions.
We only share your information with the following third parties:
- Service providers
- Claims administrators, investigators, and attorneys
- Premium audit firms
- Insurance advisory rate service organizations
- Governmental authorities and regulatory entities
- Law enforcement personnel
- As required by law or subpoena
9. DATA STORAGE AND SECURITY
RESIG shall use a reasonable standard of care to store and protect your PI. We use appropriate physical, technical and organizational security measures, and procedures to protect PI from unauthorized use, loss, alteration, destruction, or modification. RESIG shall retain your PI until the initial purpose for collecting and retaining such data has been satisfied. If you subsequently agree to a new or additional purpose, your PI may be retained for that.
10. CONTACT INFORMATION
RESIG is not required to appoint a Data Protection Officer. However, we have appointed the following contact in the event you have any questions regarding this Notice, or any questions about your rights with respect to your Personal Information.
5760 Skylane Blvd, Suite 100
Windsor, CA 95492
Privacy Notice Email Contact Form
Complete this form to send an email about your Privacy Notice questions, concerns, and requests.
11. MODIFICATIONS AND REVISIONS
We reserve the right to modify, revise, or otherwise amend this Privacy Notice at any time and in any manner. Any new version of this Notice will be posted on the RESIG website. This Notice will be reviewed annually and updated, as necessary.