Employee and Employee-Applicant Privacy Notice

Effective Date: January 1, 2020

Affinity Gaming is committed to protecting the privacy and security of your personal information. This Privacy Notice describes how we collect and use personal information about you before, during and after your working relationship with us, in accordance with applicable data protection laws.

This notice applies to all U.S.-based current and former employees, workers and contractors. It also applies to all applicants. This notice does not form part of any contract of employment or other contract to provide services. We may update this notice at any time.

It is important that you read this notice, together with any other privacy notice we may provide on specific occasions when we are collecting or using personal information about you, so that you are aware of how and why we are using such information.

I. DATA PROTECTION PRINCIPLES

We will comply with applicable data protection law. The personal information we hold about you will be:

  1. Used lawfully, fairly and in a transparent way;
  2. Relevant to the purposes we have told you about;
  3. Accurate and kept up to date;
  4. Kept only as long as necessary for the purposes we have told you about; and
  5.  Kept securely.

II. CATEGORIES OF PERSONAL INFORMATION COLLECTED

We collect personal information about applicants, employees, workers and contactors through the application and recruitment process, either directly from candidates or sometimes from an employment agency or background check provider. We may sometimes collect additional information from third parties including former employers, credit reference agencies or other background check agencies.

Personal information means any information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a person or household. It does not include data that is publicly available or data where the identity has been removed (de-identified or aggregate data). We may collect, store, and use categories of personal information about you, depending on your relationship with the Company (e.g., applicant v. employee), including but not limited to:

  • Personal contact details such as name, title, addresses, telephone numbers and personal email addresses;
  • Identifiers such as Social Security number, date of birth, driver’s license information, gender, ethnicity;
  • Marital status and dependents;
  • Next of kin and emergency contact information;
  • Financial information such as bank account details, payroll records and tax status information;
  • Salary, annual leave, retirement and benefits information;
  • Start date, rehire date, seniority date and termination date;
  • Location of employment or workplace;
  • Information about your use of our information and communications systems;
  • Application information, which could include employment records (including job titles, work history, working hours, training records and professional memberships) and education information;
  • Medical information;
  • Insurance information;
  • Biometric information; and,
  • Photographs.

III. INFORMATION USE

We will use your personal information:

  1. to perform the contract we have entered into with you;
  2. to comply with a legal obligation;
  3. where it is necessary for our business purpose provided that the use of your personal information is reasonably necessary and proportionate to achieve the operational purpose for which the personal information was collected.
  4. to protect your interests (or someone else’s interests); and/or
  5. in the public interest or for official purposes.

We may need all the categories of information in the list above for purposes related to your potential employment or employment with us. Specifically, we will use your:

Application information to:

    • Make a decision about your employment;
    • Confirm your education level;
    • Determine the terms on which you work for us;
    • Determine if you are legally entitled to work in the US;
    • Communicate with references;

Personal contact details to:

  • communicate with you about your application, employment, and any applicable benefits;
  • administer the contract we have entered into with you (if applicable);

Emergency contact information in the event of an emergency;

Financial information to pay you and, if you are an employee, to deduct tax;

Social Security number, date of birth, driver’s license, and other identifiers to:

  • Provide benefits to you such as: retirement, health insurance, , ability to drive company cars or operate a vehicle on behalf of the company (if applicable), travel and entertainment expenses;o Work with your retirement provider;

Marital status and dependent information to provide benefits to our spouse and/or dependents;

Employment related information to:

  • Conduct performance reviews, managing performance and determining performance requirements;
  • Make decisions about salary reviews and compensation;
  • Assess qualifications for a particular job or task, including decisions about promotions;
  • Gather evidence for possible grievance or disciplinary hearings;
  • Make decisions about your continued employment or engagement;
  • Make arrangements for the termination of our working relationship;
  • Ensure you fulfil education, training and development requirements;
  • Address legal disputes involving you, or other employees, workers and contractors, including accidents at work;
  • Comply with health and safety obligations;
  • prevent fraud;
  • monitor your use of our information and communication systems to ensure compliance with our IT policies;
  • ensure network and information security, including preventing unauthorized access to our computer and electronic communications systems and preventing malicious software distribution;
  • conduct data analytics studies to review and better understand employee retention and attrition rates;
  • engage in business management and planning, including accounting and auditing; and

Medical information to:

  • Ascertain your fitness to work;
  • Address legal disputes involving accidents at work; and
  • Manage sickness absences.

If you fail to provide personal information

If you fail to provide certain information when requested, we may not be able to contact you regarding your application, perform the contract we have entered into with you (such as paying you or providing a benefit), or we may be prevented from complying with our legal obligations (such as to ensure the health and safety of our workers).

Change of purpose

We will only use your personal information for the purposes for which we collected it. If we intend to use your information for a purpose not outlined within this Privacy Notice, we may be required to obtain your consent.

IV. INFORMATION SHARING/DISCLOSURE

We may have to share your data with third parties, including third-party service providers. We require third parties to respect the security of your data and to treat it in accordance with the law.

Why might we share your personal information with third parties?

We will share your personal information with third parties where required by law, where it is necessary to administer the working relationship with you or where we have another business purpose for doing so.

Which third-party service providers receive and use personal information?

We will provide your personal contact details, financial information, identifiers, employment-related information, and medical information to third-party service providers (including contractors and designated agents) who provide the following services:

  • payroll,
  • retirement administration,
  • benefits provision and administration, and
  • IT services.
  • HR services

We may also share your personal information with:

  • Law enforcement or other governmental entities. If we receive a valid subpoena or other service of process, we may share the requested information, which could include your identifiers and personal contact details, your financial information, medical information and/or employment-related information.
  • Successor Company or Companies. In the event that we are acquired or merge with another company or companies, we may share your identifiers and personal contact details with the successor company or companies.

How secure is information with third-party service providers?

All of our third-party service providers are required to take appropriate security measures to protect your personal information. We do not allow our third-party service providers to use your personal information for their own purposes. We only permit them to use your personal information for specified purposes and in accordance with our instructions.

V. DATA SECURITY

We maintain reasonable measures to protect the security of your information. We maintain appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your personal information to those employees, agents, contractors and other third parties who have a business need to know. They will only use your personal information in accordance with our instructions and they are subject to a duty of confidentiality.

In the event of an actual or suspected data security breach, we will notify you and any applicable regulator where we are legally required to do so.

VI. DATA RETENTION

We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. Details of retention periods for different aspects of your personal information are available in our retention policy, which is available upon request from privacy@affinitygaming.com. To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal information, the reasons we collect your personal information, and the applicable legal requirements.

In some circumstances we may anonymize your personal information so that it can no longer be associated with you, in which case we may use such information without further notice to you. Once you are no longer an employee, worker or contractor of the company we will retain and securely destroy your personal information in accordance with applicable laws and regulations.

VII. RIGHTS AND DUTIES RELATING TO PERSONAL INFORMATION

Your duty to inform us of changes.

It is important that the personal information we hold about you is accurate and current. Please keep us informed if your personal information changes during your working relationship with us.

Your rights in connection with personal information

You have the right to request information about the categories of personal information that we collect about you. We have provided specific information about what personal information is collected, and for what purpose, in this Privacy Notice. If you have further questions, you may contact privacy@affinitygaming.com.

What we may need from you

We may need to request specific information from you to help us confirm your identity and ensure your right to request information about the categories of personal information that we collect about you. This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.

VIII. CHANGES TO THIS PRIVACY NOTICE

We reserve the right to update this privacy notice at any time, and we will provide you with a new privacy notice when we make any substantial updates.