CCPA Business Contact Notice at Collection (“Notice”)
Last updated May 2024
This Notice describes how Milliman, Inc. and its affiliates (“Milliman” or “we”) handle the Personal Information of California residents when they interact with Milliman as a business contact (“you”). This Notice is being provided in accordance with the California Consumer Privacy Act 2018 (Cal. Civ. Code § 1798.100 et seq.), as amended by the California Privacy Rights Act of 2020 (together, “CCPA”). For more complete information about Milliman’s California Consumer Privacy Policy, please visit our U.S. Data Privacy Policy.
This Notice applies to the Personal Information we collect, use, disclose, and process when you interact with Milliman in a business-to-business capacity. The term “Business Contacts” shall include representatives, officers, agents and employees, business partners, providers, parties to a contract, and any other person which contacts or interacts with Milliman in the context of establishing, developing, maintaining, servicing, or otherwise furthering a business relationship.
“Personal Information” means information that identifies, relates to, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a Business Contact. This Notice does not cover:
- Applicant, employee, or contractor Personal Information.
- People who interact with Milliman in a non-business context, such as browsing our website on their own time
- Milliman’s handling of Personal Information that is exempt under the CCPA, which includes, but is not limited to, publicly available information, information we receive from consumer reporting agencies that are subject to the Fair Credit Reporting Act, or de-identified or aggregated information.
How Milliman Collects Personal Information
We collect Personal Information about you in the following ways:
- Directly from you;
- From your employer;
- From our affiliates and subsidiaries;
- From our vendors and service providers;
- From operating systems and platforms;
- From interacting on and visiting our websites; and
- Publicly available information and sources.
Categories of Personal Information Milliman Collects
The following describes the categories of Personal Information Milliman may collect about you (and may have collected in the last twelve (12) months).
- Identifiers, such as a name, alias, postal address, telephone number, unique personal identifier, online identifier, IP address, email address, or other similar identifiers.
- Online Identifiers, such as IP addresses and cookie data.
- Characteristics of Protected Classifications, such as age, gender, or nationality.
- Client Records, such as name, account name, other characteristics, contact information, account credentials, communications preferences, billing and payment information, customer service and support tickets and records, and other information you provide.
- Commercial Information, including products or services purchased, obtained or considered.
For What Purposes Does Milliman Use Your Personal Information
Milliman may process the Personal Information described above for the following business purposes:
- Conduct Our Business. This includes the initiation, administration, performance, and execution of a contract; performing necessary due diligence; completing onboarding requirements; providing various professional services and products to our clients; providing access to systems; billing, collections, and payments.
- Marketing and Advertising. This includes providing information regarding the products and services we offer or develop; providing marketing materials about products, services, news, offers, promotions, and events which may be of interest to you.
- Customer Service Activities. This includes responding to queries; fulfilling requests; providing customer support.
- Communication. This includes general business communication between Milliman and Business Contacts; provision of deliverables.
- IT Security and Maintenance. This includes managing technology resources; IT maintenance and security practices; website management and security; vendor management; vendor risk management.
- Event Management and Planning. This includes event, webinar, and presentation planning; event management.
- Fulfillment of Legal Obligations. This includes responses to subpoenas, court orders, or other lawful requests by public authorities, and to meet national security or law enforcement requirements; compliance with legal or regulatory obligations; asserting or defense of legal claims; prevention of misconduct, compliance violations.
For the avoidance of doubt, Milliman does not process, collect, use, or disclose Sensitive Personal Information (as that term is defined in § 1798.140(ae) of the CCPA) beyond the purposes authorized by the CCPA.
Retention of Personal Information
Milliman retains Business Contacts Personal Information for as long as necessary to fulfill the purposes outlined in this Notice, unless a longer retention period is required by law. If Personal Information must be kept for administrative, legal, or regulatory purposes, Milliman will keep the minimum amount of Personal Information necessary to comply with such purposes.
Disclosure of Personal Information
To carry out the purposes outlined above, Milliman may disclose Personal Information to third parties and other recipients for a business purpose, such as:
- Affiliates, subsidiaries, and business partners;
- Service providers, contractors, and vendors;
- Advisors, auditors, consultants, and representatives;
- Regulators, government entities, and law enforcement;
- Operating systems and platforms; and
- Others as required by law.
Milliman does not sell or share the above categories of Personal Information. The CCPA defines “sell” as the disclosure of Personal Information for monetary or other valuable consideration, and “share” as the disclosure of Personal Information by a business to a third party for cross-context behavioral advertising, whether for monetary or other valuable consideration. Milliman may add to the categories of Personal Information it collects and the purposes for which it uses Personal Information. In such cases, Milliman will inform Business Contacts. We do not sell or share the Personal Information of individuals under 16 years of age.
California Resident Individual Rights Requests
Individuals who are residents of the State of California have certain individual rights as outlined below.
Upon receipt of a verifiable Consumer request, and as required by the CCPA, Milliman will provide a response to such requests in accordance with § 1798.130 of the CCPA.
Right To Know About Personal Information Collected or Disclosed. You have the right to request more information regarding the following topics, to the extent applicable:
- the categories of Personal Information,
- the categories of sources from which the Personal Information is collected,
- the business or commercial purpose for collecting, selling, or sharing Personal Information, if applicable,
- the categories of third parties to whom the business discloses Personal Information, and
- the specific pieces of Personal Information the business has collected about you.
Right To Request Deletion of Your Personal Information. You have the right to request that Milliman delete the Personal Information it has collected or maintains about you. Once a verified request is received, Milliman will let you know what, if any, Personal Information can be deleted from its records, and Milliman will direct any service providers and contractors to whom it disclosed your Personal Information to also delete your Personal Information from their records.
There may be circumstances where Milliman cannot delete your Personal Information or direct service providers or contractors to delete your Personal Information from their records. Such instances include, but are not limited to, enabling solely internal uses that are reasonably aligned with your expectations based on your relationship with Milliman and compatible with the context in which you provided the information or to comply with a legal obligation.
Right to Request Correction. You have the right to request that Milliman correct any inaccurate Personal Information it maintains about you, taking into account the nature of that information and purpose for processing it.
Right to Opt-Out. You have the right to opt-out of the “sale” and “sharing” of your Personal Information, as those terms are defined under the CCPA. As described above, we do not “sell” or share your Personal Information, and therefore do not offer a mechanism to exercise the right to opt-out.
Right to Limit the Use and Disclosure. We use and/or disclose sensitive personal information for the permitted purposes specified in the CCPA and therefore do not offer a mechanism to exercise the right to limit the use of sensitive personal information.
Right to Non-Discrimination for the Exercise of Your Privacy Rights. Milliman will not discriminate or retaliate against you for exercising any of your rights as described above.
Requests for the application of your rights may be submitted by either:
- Calling us at 1-866-467-8688 + service code 740 at prompt; or
- By accessing our webform Privacy Web Form (onetrust.com). You will be asked to provide certain personal information when submitting your request including your first and last name, email address for us to determine if your information is in our systems.
Milliman reserves the right to only respond to verifiable Consumer requests to know, delete, or correct.
Milliman reserves the right to amend this Notice at any time without advance notice.
If you have any questions or comments about this Notice, you may contact us at [email protected].