Privacy Policy

Welcome to the Empyrean Benefit Solutions, Inc. (“Empyrean”). Empyrean performs third party administration services related to the employee benefit programs of your employer, former employer or plan sponsor as the case may be (collectively, the “Employer”). We appreciate the opportunity to serve you.

At Empyrean we respect your privacy and this Privacy Policy (“Policy”) explains how Empyrean collects, uses and discloses information about you when you visit the Empyrean website(s) (the “Site”), use Empyrean’s mobile application(s) and other online products and services that link to this Privacy Policy (the “Policy”) (collectively, the “Services”) or when you participate in any interactive features of the Services or otherwise interact with us (e.g., contact us via telephone or web chat or communicate with us through email). This Policy is incorporated by reference into the Empyrean Site Terms of Service (“Terms of Service”). In addition, in the event we offer a Service that does not reference a privacy policy, this Privacy Policy will apply to such offering unless a separate privacy policy explicitly states that it is applicable to such offering in lieu of this Empyrean Privacy Policy.

If you do not agree to the terms in this Privacy Policy or in the Terms of Service, you should not use the Site, the Services or contact us via the other methods listed in this Policy.

Please keep in mind that we may revise this Privacy Policy at any time and from time to time. If we revise our Privacy Policy, we will notify you by revising the date at the bottom of this Policy and post the revised policy on the Site. We may also elect to provide additional notice by adding a statement to our Site. We suggest that you review this Privacy Policy whenever you access the Services or otherwise interact with us to stay informed about Empyrean’s information practices and your options.

 

Definition of Personal Information

We define “Personal Information” as any data or information that can be used to identify you or your dependents or beneficiaries. This information includes but is not limited to name, address, age, date of birth, Social Security Number (or other identifier, such as driver’s license or state identification number or employee identification number), bank account information, e-mail address, telephone number or information related to your access of the Site and/or use of the Services which may include but not be limited to browser agent, IP address, internet domain, or date/times you access the Site. We may request Personal Information from you in order to deliver requested materials to you, respond to your questions, or deliver a product or Service(s) to you.

 

Collecting Personal Information

We collect, store and use Personal Information (defined below) so that we can perform the Service(s) for which we have been contracted by your Employer relating to your Employer’s employee benefit programs under which you may be participating or become eligible to participate.

We obtain Personal Information in several ways. Firstly, we obtain Personal Information about you, your dependents and/or your beneficiaries that has been provided to us directly from your Employer. We also collect Personal Information that you voluntarily submit to us whether directly on the Site or via Site interaction (e.g., web chat), or when you otherwise contact us (e.g., by phone or email). For example, when you call us, we record all calls and those calls may be shared with your Employer. Finally, we will automatically collect your Personal Information when you visit and navigate our Site, use the Services, or otherwise interact with us. Examples include: (i) log information (e.g., browser type, IP address, pages viewed); (ii) location information (e.g., precise location of your device in accordance with device permissions); (iii) device information (e.g., information about the computer or mobile device being used to access the Site or Services, operating system information, unique device identifiers); and (iv) cookies and other tracking mechanisms (further discussed below in ‘Other Information Collected’). When you voluntarily submit your Personal Information on the Site or through any Site interactive features, over the phone or via email, you are giving your consent to the collection, use and disclosure of your Personal Information in accordance with this Privacy Policy.

 

Other Information Collected

When you visit our Site, we collect information that does not identify you personally but does provide us with usage data, such as the number of visitors we receive and which pages they visited most often. This data helps us analyze and improve the Service(s) we provide.

Our Site may write and read “cookies” to your web browser. A cookie is an element of data that is stored temporarily or permanently on your computer and can be communicated between the Sites and your browser. We use cookies as unique identifiers to track each user, and use is required for the proper operation of the Site. A cookie is not a computer program and has no ability to read data residing on your computer or instruct it to perform any function. We do not use cookies to store Personal Information about you.

We may also use what is known as “client-side page tagging”, which uses code on each page of the Site to write certain information about the page and the visitor to a log when a page is rendered to your browser. This technique is commonly used on commercial websites. “Tagging” does result in JavaScript or other client-side code to be run on your computer, but it is limited to providing information about the page from our Site that you are requesting and the configuration of your browser. It will not read any of the data files on your computer or execute other functions. It does not extract any personal information about you. You can prevent tagging by disabling JavaScript in your browser, but that may prevent you from using some or all of our Site’s features.

 

Information Collected from Other Sources

Empyrean may also obtain your Personal Information from other sources. For example, we may collect information about you from publicly available sources or from third parties as directed by your Employer in support of our delivery of the Services. In addition, if you log into the Site through a social media site we may have access to information from that site such as your name, account information and other information pursuant to the authorization procedures determined by such social media site.

 

Use of Personal Information

We may use the Personal Information we collect in accordance with this Policy to deliver, provide, maintain and improve our Service(s). We may use the Personal Information we collect to: (i) provide you with customer support services; (ii) provide you with technical support services; (iii) perform updates and provide security alerts; (iv) perform analytics related to the Service(s); (v) improve and update the Service(s); (vi) personalize your access to and use of the Service(s); (vii) prevent illegal or fraudulent activities including without limitation fraud detection, security enhancements, investigate security incidents or other unauthorized access attempts; (viii) provide you with information about Empyrean and its offerings, products, services and events; (ix) provide reports to your Employer; and (x) other legally permissible activities. We may also use information about you in aggregated format that has been otherwise de-identified so that such information cannot be reasonably used to identify you for any legally permissible purposes. Empyrean also may grant third parties with similar use rights in connection with the services they provide to Empyrean in connection with our delivery and performance of the Service(s).

 

Sharing or Disclosing of Personal Information

Empyrean may share or disclose your Personal Information as follows or as otherwise specified in this Policy (in accordance with applicable laws): (i) with Empyrean subcontractors, business associates and partners (see below for additional information); (ii) with third parties in connection with their communications about their services and products as authorized by you; (iii) with your Employer (to the extent legally permissible); (iv) pursuant to disclosures required by legal process (e.g., subpoena or court order), regulation, or as otherwise required by law; (v) in connection with any sale of Empyrean or its assets, financing arrangements, merger, or acquisition inclusive of any related negotiations; (vi) between Empyrean and its parent, subsidiary or affiliate companies; (vii) as necessary for our internal management and administration; and/or (viii) as expressly authorized by you. In addition to the above, we may also share information about you in aggregated format or that has been otherwise de-identified so that such information cannot reasonably be used to identify you for any legally permissible purpose. In all cases, we will share or disclose Personal Information consistent with applicable laws and regulations.

 

Subcontractors And Partners We May Use

We may retain other companies and individuals to perform services and functions on our behalf to support our delivery of the Service(s) consistent with this Privacy Policy. Examples include, without limitation, customer support specialists, web hosting companies, print fulfillment companies, data analysis firms, e-mail service providers, ancillary service providers such as COBRA or flexible spending accounts, and/or back office support providers. Such third parties may be provided with limited access to your Personal Information as needed to provide their services to Empyrean to be used in accordance with this Policy or pursuant to other written terms and conditions with Empyrean.

We may also partner with entities that are not our subcontractors but who provide benefit related products and services which, to the extent your Employer makes such products and services available to you, you may choose to enroll, if eligible. Examples of these partners include, but are not limited to, financial product providers such as SAVVI, health savings account bank providers such as Optum or HSA Bank, and/or various insurance carriers who offer voluntary products. These third parties will have a direct relationship with either you and/or your Employer and are also obligated to protect your data in accordance with that relationship. We encourage you to review their respective privacy policies if you choose to participate in their offerings as applicable.

Depending on whether certain of our partner’s products are made available to you by your Employer, additional terms and/or consents may be requested of you in order for Empyrean to share your Personal Information with them.

 

Residents of the European Economic Area

If you are a resident of the European Economic Area (“EEA”), you have certain rights and protections under the law regarding the processing of your personal data.

 

Legal Basis for Processing

If you are a resident of the EEA, when we process your personal data we will only do so in the following situations:

  • We need to use your personal data to perform our responsibilities under our contract with you or your Employer (e.g., providing the Services that have been requested on your behalf).
  • We have a legitimate interest in processing your personal data. For example, we may process your personal data to send you marketing communications, to communicate with you about changes to our Services, and to provide, secure, and improve our Services.
  • You have consented to the processing of your personal data for one or more specific purposes.

 

Data Subject Requests

If you are a resident of the EEA, you have the right to access personal data we hold about you and to ask that your personal data be corrected, erased, or transferred. You may also have the right to object to, or request that we restrict, certain processing. If you would like to exercise any of these rights, please contact Empyrean through the Contact Us process outlined below.

 

Questions or Complaints

If you are a resident of the EEA and have a concern about our processing of personal data that we are not able to resolve, you have the right to lodge a complaint with the data privacy authority where you reside.

For contact details of your local Data Protection Authority, please see:

http://ec.europa.eu/justice/data-protection/article-29/structure/data-protection-authorities/index_en.htm.

 

Residents of California

California Civil Code Section 1798.83 permits users of the Service(s) who are California residents to request certain information regarding disclosures of Personal Information to third parties for their direct marketing purposes. We do not share your Personal Information with third parties for such purposes.

If you are a California resident under the age of 18, and user of the Service(s), California Business and Professions Code Section 22581 permits you to request and obtain removal of content or information you have publicly posted. To make such a request, please send an email with a detailed description of the specific content or information to Empyrean at the Contact Us information provided below. Please be aware that such a request does not ensure complete or comprehensive removal of the content or information you have posted and that there may be circumstances in which the law does not require or allow removal even if requested.

 

Empyrean’s Decision Support Tool Pilot

Pilot℠ is Empyrean’s benefit plan decision support tool. If your Employer chooses to make the enhanced version of Pilot available to you, you will be prompted to review a Pilot℠ specific privacy policy and terms of use. If you are provided access to the standard version of Pilot℠ (i.e., not the enhanced version) this Privacy Policy applies to your use of the standard version of Pilot℠.

 

Data Storing and Transferring

All data that we collect, use, and/or may transfer to any subcontractor is processed and stored here in the United States where Empyrean is based and not transferred outside of the United States unless otherwise agreed with your Employer. Empyrean and its service providers may transfer your information to, or store or access it in, jurisdictions that may not provide equivalent levels of data protection as your home jurisdiction. We will take steps to ensure that your Personal Information receives an adequate level of protection in the jurisdictions in which we process it. For example, all stored data while at rest remains encrypted. Your data will be retained for a long as our agreement with your Employer requires us or the maximum time we are permitted to retain your records under applicable laws, whichever is longer. Any data that is not destroyed upon termination of our agreement with your Employer will be protected in accordance with applicable laws and consistent with our Privacy Policy.

 

Sale of Your Personal Information

Neither we nor our subcontractors sell your individually identifiable Personal Information to a third party.

 

Your E-Mails to Us

We welcome e-mails from you, and, within the Site, there may be e-mail boxes for your questions and comments. You may also send us email directly outside of the Site. We may share the information you send to us via email with our Service Center Representatives, other employees capable of addressing your questions and concerns, certain third parties, as necessary, or your employer when required, to assist you.

Please note that non-encrypted internet e-mail sent by you may be accessed and viewed by unintended third parties without your knowledge and permission while in transit to us. If you elect to use e-mail to communicate information to us that you consider confidential you do so at your own risk, acknowledgment and agreement that Empyrean is not responsible for unauthorized access, losses, security incidents, or data breaches to the extent arising out of or otherwise related to such e-mail communications.

 

Your Rights

You may have certain rights concerning your Personal Information in accordance with applicable law. These rights may include:

  • Right to access your Personal Information;
  • Right to amend your Personal Information;
  • Right to an accounting of your Personal Information;
  • Right to receive your Personal Information in a useable electronic format;
  • Right to data portability and transmittal of your Personal Information to a third party;
  • Right to request validation or other proof of prior authorizations or consents provided to us to perform the collection and processing of your Personal Information;
  • Right to correct or rectify your Personal Information maintained by Empyrean;
  • Right to erase your Personal Information;
  • Right to restrict our use or disclosure of your Personal Information;
  • Right to object our use or disclosure of your Personal Information;
  • Right to revoke the consent or authorization given by you for the processing of your Personal Information; or
  • Right to file a complaint with your local data protection authority or other applicable governmental regulatory authorities.

You understand and acknowledge that your decision to exercise any or all of such rights may impact our ability to deliver the Service(s) to your Employer that pertain to you, your dependents and/or your beneficiaries and that the law may not require our support of such right as relates to our Services.

If you have questions about such rights you may contact Empyrean at through the Contact Us process described below.

 

Children Under 13 and Parental/Guardian Access

The Site is designed and directed to adults; it is not directed to children under the age of 13. We do not knowingly collect Personal Information from children under the age of 13, although we use and disclose your dependent children’s Personal Information we have obtained voluntarily from you, your Employer, or other third parties in connection with the administration of your benefit programs. If you are under the age of 13, you are not permitted to submit information to this Site. If Empyrean is notified that we have collected personal information of a child under the age of 13, as defined under the Children’s Online Privacy Protection Act (“COPPA”), we will promptly delete such information.

Parents or guardians of children under the age of 13 may print out and mail or fax us a signed form that allows them to review any information collected about their child/children, have this information deleted, and/or request that there be no further collection or use of their child’s information. Such access and directives will be subject to authenticating the parental/guardian identity and status.

 

Links

The Site may contain links to or from other websites. Please be aware that we are not responsible for the privacy practices of other websites. This Privacy Policy applies only to the Personal Information we collect as described in this Policy. We encourage you to review the privacy policies of other third party websites you link to or from the Site or otherwise visit.

 

Security

We implement various reasonable security measures to protect your Personal Information from theft, misuse, unauthorized access, disclosure, loss, alteration and destruction.

 

Updating Your Information or Account Deactivation

If you wish to change any Personal Information that has come to us from your Employer, you will need to contract your Employer directly to support your request. However, you have the ability to review, change and/or correct the Personal Information you provide directly to us by contacting us. If you are a registered user, you can also review, change or correct your Personal Information at any time by using the features within the Site or submitting a written request through the Contact Us process described below. You may request that we deactivate your account by contacting us. Please note, however, that we may retain certain Personal Information as required by law or for legitimate business purposes. We may also retain cached or archived copies of your Personal Information for a certain period of time.

 

Mobile Push Notifications/Alerts

We may, with your consent, send promotional and non-promotional push notifications or alerts to your mobile device. You can deactivate these messages at any time by changing the notification settings on your mobile device.

 

Promotional Communications

You may opt out of receiving promotional communications from Empyrean by following the instructions in those communications or by emailing us at the Contact Us information provided below. If you opt out, we may still send non-promotional emails, such as those about your account or our ongoing business relations.

 

Contact us

If you have any questions about this Policy or how we collect, use, share or protect the security of your Personal Information, please see the Contact Us page on our Site or you can submit your questions or requests in writing to Empyrean at:

Data Privacy Official
Empyrean Benefit Solutions, Inc.
3010 Briarpark Drive, Suite 800
Houston, TX 77042
E-mail: Dataprivacy@goempyrean.com
Phone: 866- 915-4945

 

Last Updated: 01/01/2020