Privacy Policy

Last updated
August 5, 2026

1. Overview

This Privacy Policy describes how RemoFirst Inc., a Delaware corporation with its principal offices at 425 1st Street, San Francisco, CA 94105, United States (referred to as “RemoFirst”, “we”, “us” or “our”), collects, uses, discloses, stores, protects and otherwise processes Personal Data through the www.remofirst.com website and related webpages or portals (collectively, the “Website”), the RemoFirst platform (the “Platform”), and RemoFirst products and services, including RemoPlus services (collectively, the “Services”).

“Personal Data” means information relating to an identified or identifiable individual and includes equivalent concepts such as “personal information” under applicable privacy laws. The precise definition may differ depending on the jurisdiction.

This Privacy Policy is a transparency notice. It does not, by itself, determine or alter the allocation of privacy roles between RemoFirst, Clients, Local Partners or other recipients. The applicable role depends on the relevant processing activity, Service, jurisdiction, contractual arrangements and the party that determines the purposes and essential means of processing.

Where RemoFirst processes Personal Data on behalf of a Client, the processing may also be governed by the applicable Master Services Agreement (“MSA”), data processing agreement (“DPA”), Service Annex, order form, documented Client instructions or other data protection terms agreed between the parties. Where there is a conflict concerning processing performed by RemoFirst as a processor, the applicable DPA or specifically negotiated data protection terms will prevail between the contracting parties. This does not reduce or restrict any statutory rights available to individuals.

Where a Local Partner or another recipient acts as an independent controller, its own privacy notice, contractual data protection terms and the laws applicable to its processing may also apply. Additional product-specific, service-specific, workforce, candidate, cookie, country-specific or state-specific notices may supplement this Privacy Policy and will prevail to the extent they provide more specific information for the relevant processing activity.

2. Scope and Data Subjects

This Privacy Policy applies to the following categories of individuals whose Personal Data may be processed in connection with the Website, Platform, Services or RemoFirst business operations:

  • Website visitors and Platform users;
  • Clients and prospective Clients, including representatives, beneficial owners, authorized users and other relevant contact persons;
  • employees, workers, Talents, independent contractors and other individuals engaged, onboarded, managed, paid or otherwise supported through the Services;
  • job applicants, candidates and individuals considered for current or future roles with RemoFirst or, where relevant, with a Client;
  • Local Partners, including employer of record partners, payroll partners and other in-country partners, together with their personnel and representatives;
  • suppliers, vendors, service providers and professional advisors, together with their personnel and representatives;
  • prospects, leads, recipients of marketing communications, newsletter subscribers and participants in events, webinars, surveys, research, campaigns or similar initiatives;
  • family members, dependants, beneficiaries, emergency contacts and other related persons whose information is processed in connection with workforce, benefits, insurance, immigration or related Services; and
  • any other individual whose Personal Data is submitted to, collected by or otherwise processed by RemoFirst in connection with its business operations or Services.

Not every section or data category applies to every individual. The Personal Data processed and the applicable privacy role depend on the individual’s relationship with RemoFirst, the Service requested, the relevant jurisdiction and the purposes of processing.

3. Our Roles and Relationship with Clients, Local Partners and Other Recipients

3.1 RemoFirst as a controller

RemoFirst generally acts as a controller where it determines the purposes and means of processing Personal Data. This may include processing for Website and Platform operation and security, account administration, Client and partner relationship management, billing and collections, service administration, internal business operations, legal and regulatory compliance, Know Your Customer and Know Your Business checks, sanctions and fraud prevention, marketing, recruitment, incident management and the establishment, exercise or defence of legal claims.

3.2 RemoFirst as a processor

In certain circumstances, RemoFirst processes Personal Data on behalf of and in accordance with the documented instructions of a Client. This may include certain processing undertaken to deliver workforce, payroll, onboarding, benefits, immigration, background screening, device-management or other Services requested by the Client. Where RemoFirst acts as a processor, the relevant processing is governed by the applicable DPA and other contractual data protection terms entered into with the Client.

3.3 Clients as controllers

Clients generally act as controllers in relation to Personal Data they submit to RemoFirst and the decisions they make concerning candidates, Talents, employees, workers, contractors or other personnel. Such decisions may include hiring, engagement, compensation, benefits, background screening, device allocation, performance management and termination. Clients are responsible for providing any notices and establishing the lawful basis required for the processing activities they determine. This does not remove any obligations that apply directly to RemoFirst or another recipient.

3.4 Local Partners as independent controllers

Local employer of record partners, payroll partners and other in-country partners may act as independent controllers where they process Personal Data for their own purposes or to comply with obligations imposed on them under local employment, payroll, tax, social security, benefits, immigration, accounting, regulatory or other applicable laws. A Local Partner acting as the legal employer may be required by local law to determine how certain employment and statutory records are collected, used, retained and disclosed.

Where a Local Partner acts as an independent controller, it is separately responsible for identifying the applicable lawful basis, providing any required privacy information, responding to requests relating to the processing it controls and complying with its other obligations under applicable data protection law. Local Partners may provide individuals with their own privacy notices.

3.5 Other recipients

Other suppliers and service providers may act as processors or sub-processors where they process Personal Data solely on documented instructions. Certain third parties, including insurers, financial institutions, governmental authorities, immigration authorities, professional advisors and screening-data sources, may act as independent controllers in relation to their own processing.

References in this Privacy Policy to a Partner, supplier, service provider or recipient do not, by themselves, mean that the relevant party acts as a processor of RemoFirst. The legal role is determined by the facts of the processing and applicable law.

4. Types of Personal Data We Collect

Depending on the nature of your relationship with RemoFirst and the Services involved, RemoFirst may collect or otherwise process the following categories of Personal Data:

  • Personal and identification details: name, preferred name, username, date of birth, age, gender, nationality, marital status, photograph, signature, government-issued identification information and similar identifiers.
  • Contact details: home, correspondence, billing, delivery or collection address; email address; telephone number; emergency contact information; online messaging details and other communication information.
  • Professional and employment information: job title, employer, work location, employment status, work history, professional background, qualifications, certifications, education, language skills, performance or training information, right-to-work information and other workforce-related records.
  • Payroll, benefits and financial information: salary, compensation, bonus, tax, social security or national insurance information, bank account details, payment records, invoices, billing information, benefits enrolment, expense and reimbursement records and other information necessary for payroll, payments or workforce administration.
  • Immigration and mobility information: passport and identity documentation, nationality, citizenship, residence, visa or permit information, immigration status, travel history, sponsorship and application records and supporting documents.
  • Screening and verification information: identity verification, sanctions and watchlist results, politically exposed person screening, references, employment and education verification, criminal-record information where legally permitted, financial-history information where lawful and relevant, background-screening reports and related authorization records.
  • Health, insurance and benefits information: insurance eligibility and enrolment information, coverage records, dependant or beneficiary information and health-related information where necessary for benefits, insurance, accommodations, leave, employment administration or legal compliance.
  • Device, logistics and asset information: device make, model, serial number, configuration, allocation, delivery, tracking, retrieval, storage, redeployment and data-wipe information.
  • Website, Platform and technical information: IP address, device type, operating system, browser type and settings, login and authentication information, account activity, dates and times of access, log data, security events, cookie identifiers and usage information.
  • Transaction and service information: Services requested, purchased, considered or delivered; quotes, orders, onboarding and offboarding records, account settings, support records, service preferences and communications relating to the Services.
  • Business relationship information: information relating to Clients, employers, Local Partners, suppliers, vendors and other business contacts, including organizational information and contact details.
  • Communications and interaction information: emails, support tickets, chat messages, call or meeting notes, event or webinar participation, survey responses, feedback, reviews and other communications or interactions.
  • Marketing and engagement information: marketing preferences, newsletter subscriptions, event registrations, content downloads, campaign interactions, advertising engagement and related analytics.
  • Consent, notice and preference records: records of consents, authorizations, privacy notices, communication preferences, cookie choices and related dates, times and methods.
  • Other information: Personal Data provided by you or on your behalf, generated through the Services, or otherwise lawfully obtained in connection with RemoFirst business operations.

Not all categories apply to every individual or Service. RemoFirst seeks to collect only the Personal Data reasonably necessary for the relevant purpose.

5. Sensitive Personal Data

The meaning of Sensitive Personal Data differs between jurisdictions. Under EU and UK data protection law, special categories include information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data used for unique identification, health information and information concerning a person’s sex life or sexual orientation. Criminal conviction and offence information is subject to separate legal requirements. Other laws may also treat government identifiers, financial account information, precise geolocation, immigration information or other categories as sensitive.

RemoFirst does not seek to collect Sensitive Personal Data unless it is necessary for a specified purpose, required for the provision of a requested Service, required by law or otherwise permitted under applicable law. Depending on the Service and jurisdiction, RemoFirst may process health and insurance information, government-issued identifiers, tax and payroll information, immigration information, sanctions and background-screening information, criminal-record information where legally authorized, trade union membership where required for employment administration, or other legally protected categories.

Where RemoFirst processes Sensitive Personal Data, it will apply an appropriate lawful basis and any additional condition required under applicable law. Depending on the circumstances, this may include processing necessary for employment, social security or social protection obligations; legal or regulatory compliance; the establishment, exercise or defence of legal claims; protection of vital interests; substantial public interest where expressly authorized by law; or explicit or separate consent where required.

Access to Sensitive Personal Data is restricted to persons who need it for the relevant purpose. RemoFirst applies additional safeguards appropriate to the nature and risk of the information, including access controls, confidentiality obligations, secure transfer methods, retention restrictions and, where appropriate, data minimization or segregation.

6. When and How We Collect Personal Data

RemoFirst may collect or otherwise obtain Personal Data through the following sources and interactions:

  • directly from you, including through the Website, Platform, forms, emails, support channels, applications, surveys, account registration, document uploads, service requests or other interactions;
  • from a Client, employer, Local Partner, payroll partner, supplier or other third party that provides information in connection with onboarding, payroll, workforce administration, benefits, immigration, background verification, device delivery, payment processing or another Service;
  • automatically through your use of the Website, Platform or Services, including through cookies, pixels, software development kits, logs, device information, security events and similar technologies;
  • from communications and correspondence, including email, telephone, chat, support tickets, messaging platforms, video calls or meetings;
  • from publicly available sources, including professional networking sites, company registries, public registers, sanctions lists and other lawful public sources;
  • from business partners, referral partners, recruiters, analytics providers, advertising partners, data enrichment providers, identity verification providers, screening providers, financial institutions, insurers and other service providers;
  • from governmental, regulatory, tax, employment, immigration, judicial or law-enforcement authorities, where collection is lawful and relevant; and
  • from other sources reasonably related to the Services or RemoFirst business operations, where permitted by law.

Where RemoFirst collects Personal Data indirectly, RemoFirst, the relevant Client or the relevant independent controller will provide the information required by applicable law, subject to lawful exceptions.

For information about cookies and similar technologies, please see the Cookie Policy and cookie preference tools made available through the Website or Platform.

7. Personal Data Processed Through RemoPlus Services

RemoPlus currently includes RemoTech, RemoVisa, RemoHealth Global, RemoHealth Local and RemoCheck. Availability and the exact scope of each Service vary by jurisdiction, provider capability and applicable law.

7.1 RemoTech

In connection with device procurement, delivery, management, retrieval, storage, redeployment, mobile-device management configuration and data-wiping services, RemoFirst may process names and contact details; delivery, collection and return addresses; Talent or Contractor identifiers; device make, model, serial number, configuration and allocation information; order, payment, shipment, tracking, delivery, return and storage records; communications concerning device delivery, retrieval, loss, damage or return; and information required to coordinate a secure data wipe.

Procurement, logistics, warehousing, retrieval, repair, mobile-device management and data-wiping activities may be performed by third-party providers. The Client generally owns and controls the relevant device and is responsible for its acceptable-use, monitoring, security, retention and recovery requirements. RemoFirst does not monitor device usage unless a specific device-management or security service has been requested, lawfully implemented and appropriately disclosed.

7.2 RemoVisa

In connection with immigration, visa, work-permit, residency, right-to-work, relocation and related Services, RemoFirst may process identity and contact details; passport, national identity and other government-issued identification information; nationality, citizenship, residence and immigration status; employment, education, professional qualification and compensation information; travel history and intended travel information; visa, permit, sponsorship and application records; information concerning family members or dependants where related Services are requested; photographs, declarations, supporting documents and communications; background or criminal-record information where required and legally permitted; and other information required by immigration advisors or competent authorities.

Immigration advisors, visa agents, embassies, consulates, governmental authorities and other competent bodies may act as independent controllers for the processing they determine. RemoFirst does not control immigration or visa decisions made by those authorities.

7.3 RemoHealth Global and RemoHealth Local

In connection with health-insurance enrolment, eligibility, coverage administration, renewal, cancellation and related support, RemoFirst may process identity and contact information; date of birth, age, country of residence and employment information; policy, enrolment, coverage, eligibility and premium information; information concerning dependants and beneficiaries; and health or medical information where strictly necessary for enrolment, underwriting, benefits administration, accommodations or legal compliance.

RemoFirst seeks to process only the minimum health information necessary to coordinate the relevant Service. Insurance providers, underwriters, claims administrators and Local Partners may independently determine eligibility, coverage, underwriting, claims and reimbursement matters and may act as independent controllers under their own privacy notices.

7.4 RemoCheck

In connection with identity verification, background screening, pre-hire verification, sanctions screening and related Services, RemoFirst may process identity and contact information; government-issued identification information; employment history and professional references; education, qualifications and certification records; sanctions, watchlist and politically exposed person screening results; criminal conviction or criminal-record information where processing is lawful and proportionate; credit, insolvency, bankruptcy or financial-history information where lawful, necessary and relevant to the position; screening authorizations and consent records where required; screening status; reports; and communications relating to the screening process.

RemoCheck is generally performed on the Client’s request and instructions through independent screening providers and external data sources. The Client is generally responsible for determining whether a check is necessary, lawful and proportionate and for making any resulting employment or engagement decision. RemoFirst does not determine an individual’s suitability for a role on behalf of the Client.

8. How We Use Personal Data

RemoFirst may process Personal Data for the following purposes, to the extent permitted or required by applicable law and consistent with the privacy role in which RemoFirst acts:

  • To provide, operate and support the Website, Platform and Services, including account creation, onboarding, offboarding, payroll, employer of record, contractor, workforce-management and related services.
  • To manage relationships with Clients, prospective Clients, users, Talents, workers, contractors, candidates, Local Partners, suppliers and other relevant individuals, including customer support, service communications and issue resolution.
  • To verify identity, authenticate users, manage credentials and access controls, enable account recovery, and prevent unauthorized access or misuse.
  • To perform compliance, due diligence and verification activities, including Know Your Customer, Know Your Business, Know Your Worker, anti-money laundering, sanctions, fraud, background, right-to-work and immigration checks.
  • To administer workforce and employment-related processes, including engagement, payroll, tax withholding, benefits, compensation, expenses, leave, performance administration, training, mobility, immigration and offboarding, where relevant.
  • To provide RemoTech Services, including device procurement, delivery, configuration, tracking, retrieval, storage, redeployment, asset administration, mobile-device management where requested and secure data wiping.
  • To provide RemoVisa Services, including assessing and coordinating visa or immigration requirements, collecting and reviewing documents, communicating with advisors and authorities, supporting applications and monitoring status or renewals.
  • To provide RemoHealth Services, including facilitating insurance enrolment, administering eligibility and coverage information, coordinating with Local Partners and insurers, and supporting changes, renewals or cancellation.
  • To provide RemoCheck Services, including identity, employment, education, reference, sanctions, criminal-record and financial-history checks where lawful, preparing or facilitating reports and communicating results securely to authorized Client personnel.
  • To manage payments and financial operations, including quotes, orders, invoicing, billing, collections, reimbursements, accounting, audit and vendor management.
  • To operate, maintain, secure, analyze and improve the Website, Platform, Services and internal business operations, including product development, feature improvement, service optimization and analytics.
  • To personalize content, communications and user experience, maintain preferences and provide information relevant to your relationship with RemoFirst.
  • To send marketing and promotional communications where permitted by law and subject to your choices, including newsletters, updates, surveys, webinars and event invitations.
  • To manage events, surveys, research, advisory activities and promotional initiatives, including registration, participation, communications and feedback.
  • To maintain the security, availability, confidentiality and integrity of systems and operations, including monitoring infrastructure, investigating incidents, protecting against cyber threats and maintaining logs.
  • To detect, prevent and investigate fraud, policy violations, security incidents, unlawful conduct or other risks and to protect RemoFirst, Clients, individuals, Partners and the public.
  • To comply with legal, regulatory, tax, employment, social security, immigration, accounting, audit, reporting and recordkeeping obligations and to respond to lawful requests from competent authorities.
  • To establish, exercise or defend legal rights and claims, manage disputes, complaints, investigations, litigation, enforcement and document preservation.
  • To conduct corporate transactions and business administration, including mergers, acquisitions, financing, restructuring, due diligence, asset sales or similar transactions.
  • To manage and oversee Partners and providers, including due diligence, service coordination, contractual performance, security, compliance, audit and incident management.
  • For another purpose disclosed at the time of collection or otherwise permitted or required by law.

Where certain Personal Data is required for contractual, legal, operational or compliance purposes, failure to provide it may prevent RemoFirst, the Client or a Local Partner from providing the relevant Service, completing onboarding, administering employment or benefits, processing a payment, completing a check or meeting a legal obligation.

9. Legal Bases for Processing

Where applicable law requires a lawful basis, RemoFirst relies on one or more of the bases described below. The applicable basis depends on the purpose, jurisdiction, the individual’s relationship with RemoFirst and whether RemoFirst acts as a controller or processor. Where RemoFirst acts as a processor, the Client determines the applicable lawful basis for the processing it controls, and RemoFirst processes the data under documented instructions and the applicable DPA.

Purpose Typical lawful basis Additional notes
Website, Platform and account operation Performance of a contract where the individual is a party; legitimate interests in providing, administering and improving the Services. Necessary cookies may also be used to provide the requested service. Non-essential cookies are subject to applicable consent requirements.
Client and business relationship management Performance of a contract; legitimate interests; legal obligation. A contract with an organization is not automatically a contract with each representative. Legitimate interests may apply to business-contact processing.
Workforce, payroll, benefits and EOR administration Performance of a contract where applicable; legal obligation; legitimate interests. Where RemoFirst acts as a processor, the Client or relevant controller determines the basis. Local Partners may rely on local employment and statutory obligations.
KYC, KYB, sanctions, fraud and compliance checks Legal obligation; legitimate interests in preventing fraud and managing regulatory and business risk. Consent is used only where required or appropriate under applicable law.
RemoTech Performance of a contract; legitimate interests; Client instructions where RemoFirst acts as a processor. Device monitoring or MDM processing requires an appropriate basis and specific transparency.
RemoVisa Performance of a contract or steps at the individual’s request where applicable; legal obligation; legitimate interests; consent where required. Competent authorities and advisors may rely on separate legal bases as independent controllers.
RemoHealth Performance of a contract; legal obligation; legitimate interests; explicit or separate consent where required. Health data requires an additional condition, such as employment/social-protection necessity or explicit consent, depending on law.
RemoCheck Legitimate interests; legal obligation; performance of a contract where applicable; consent or authorization where required. Criminal and financial-history checks are performed only where authorized, necessary and proportionate.
Security and incident management Legitimate interests; legal obligation. Interests include protecting systems, individuals, Clients and business operations.
Marketing and events Consent or legitimate interests, depending on jurisdiction, communication channel and relationship. Individuals may opt out of direct marketing at any time.
Recruitment Steps prior to entering a contract; legitimate interests in recruitment and workforce planning; legal obligation. Additional local recruitment notices may apply.
Legal claims and corporate transactions Legitimate interests; legal obligation. Special-category data may be processed where necessary for legal claims under an applicable additional condition.

Where processing is based on consent, consent may be withdrawn at any time without affecting processing lawfully undertaken before withdrawal. Withdrawal may affect the availability of a Service where the relevant information cannot lawfully or practically be processed on another basis.

10. Personal Data Disclosure

RemoFirst may disclose Personal Data where necessary for the purposes described in this Privacy Policy, to provide the Services, to comply with law or where otherwise permitted. Depending on the relevant activity, recipients may include:

  • RemoFirst affiliates and group companies for internal administration, service delivery, security, compliance, finance, reporting and other legitimate business purposes;
  • Clients and their authorized representatives where necessary for service delivery, workforce administration, decisions requested by the Client or compliance;
  • Local Partners, employer of record partners, payroll partners and other in-country partners involved in employment, payroll, benefits, tax, social security, immigration or related Services;
  • hosting, cloud, IT, identity verification, communications, customer support, analytics, security, payment, accounting, audit, legal, tax, insurance and other suppliers or professional advisors;
  • device manufacturers, distributors, suppliers, logistics providers, couriers, warehouses, MDM providers, repair providers and data-wiping providers;
  • immigration advisors, visa agents, translation and legalization providers, embassies, consulates, government agencies and immigration authorities;
  • insurers, underwriters, benefits providers, insurance administrators and claims administrators;
  • background-screening and identity-verification providers, educational institutions, former employers, references, sanctions and PEP database providers, financial-record sources, courts, public registries and other official-record providers;
  • banks, payment processors and other financial institutions involved in payroll, payments, reimbursements or financial operations;
  • regulators, courts, law enforcement, tax authorities, immigration authorities and other governmental or competent bodies where disclosure is legally required or permitted;
  • actual or prospective purchasers, investors, lenders, merger partners and their advisors in connection with a corporate transaction; and
  • other recipients where you request or authorize the disclosure or where disclosure is otherwise permitted or required by law.

The privacy role of a recipient depends on the processing activity. Some recipients process Personal Data on behalf of RemoFirst or a Client and are subject to processor or sub-processor obligations. Other recipients determine their own purposes and means and act as independent controllers.

Independent controllers may include Local Partners acting as legal employers or statutory payroll providers, insurance providers, banks, governmental and immigration authorities, embassies, consulates, regulated professional advisors, screening-data sources and other entities processing Personal Data to meet their own legal, regulatory, professional or operational obligations. Their processing is governed by their own privacy notices and applicable law.

Where required by law, RemoFirst will implement appropriate contracts and safeguards, provide relevant notices and obtain any required consent before disclosing Personal Data. RemoFirst does not sell Personal Data in the ordinary meaning of that term. Broader statutory concepts of “sale” or “sharing” are addressed in applicable jurisdiction-specific notices.

11. AI, Profiling and Automated Decision-Making

RemoFirst may use artificial intelligence, machine learning, automation and similar technologies (“AI”) to support customer service, workflow automation, fraud detection, compliance support, analytics, service optimization and internal operational efficiency. The use of AI depends on the relevant product, feature and jurisdiction.

RemoFirst does not use Personal Data submitted by users through the Website, Platform or Services to train or develop general-purpose AI models unless this is expressly disclosed in a product-specific notice or other applicable documentation and is lawful. RemoFirst may use anonymized, aggregated or otherwise non-identifiable information to improve, test, monitor or validate AI-enabled systems and analytics.

RemoFirst does not make final hiring, engagement, immigration, visa, insurance-underwriting, insurance-claims or background-screening suitability decisions on behalf of Clients, governmental authorities or insurance providers. Those independent parties may make decisions based on information processed in connection with the Services and are responsible for their own legal obligations and notices.

RemoFirst will not subject an individual to a decision based solely on automated processing that produces legal or similarly significant effects unless the processing is lawful, appropriately disclosed and subject to the safeguards required by applicable law. Such safeguards may include information about the logic or criteria involved, the ability to request human review, to express a point of view and to contest the decision, where applicable.

AI-enabled processing is subject to appropriate governance, security, access control, testing, monitoring, data minimization and human oversight measures proportionate to the relevant use case. Additional product-specific or service-specific AI notices may apply.

12. Data Retention

RemoFirst retains Personal Data only for as long as necessary for the purposes for which it was collected, including to provide the Services, comply with legal and regulatory obligations, resolve disputes, enforce agreements, establish or defend legal claims, maintain security and conduct legitimate business operations.

Retention periods vary by data category, Service, jurisdiction and privacy role. In determining the appropriate period, RemoFirst considers the nature and sensitivity of the data, the relevant purpose, the duration of the relationship, contractual requirements, legal and regulatory obligations, applicable limitation periods, security and fraud-prevention needs, audit requirements and whether the purpose can be achieved through anonymization or another less intrusive method.

Relevant categories include, among others, Client and account records; contracts, quotes, orders and billing records; workforce, payroll, tax, benefits and employment records; KYC, KYB and sanctions records; support communications and security logs; recruitment records; RemoTech order, delivery, retrieval, allocation and wipe records; RemoVisa application and supporting records; RemoHealth enrolment and dependant records; and RemoCheck authorizations, reports and screening results.

Where RemoFirst acts as a processor, deletion or return of Personal Data is handled in accordance with the applicable DPA and documented Client instructions, subject to legal retention requirements applicable to RemoFirst. Local Partners and other independent controllers determine their own retention periods under the laws and obligations applicable to their processing.

When Personal Data is no longer required, RemoFirst will delete, anonymize or securely dispose of it in accordance with applicable law and internal retention procedures. Backup copies may remain for a limited period until they are overwritten or securely deleted, subject to access restrictions and no further use except for restoration, security or legal requirements.

13. Data Subject Rights

Subject to applicable law, individuals may have rights in relation to their Personal Data, including the right to:

  • be informed about the processing of Personal Data;
  • request access to Personal Data;
  • request correction or completion of inaccurate or incomplete Personal Data;
  • request deletion or erasure where applicable;
  • request restriction of processing where applicable;
  • object to processing based on legitimate interests and object to direct marketing at any time;
  • request portability of certain Personal Data where applicable;
  • withdraw consent at any time where processing is based on consent;
  • request information about recipients, international transfers or applicable safeguards where required;
  • request human review of certain automated decisions where applicable;
  • not be subjected to unlawful discrimination or retaliation for exercising privacy rights; and
  • lodge a complaint with a competent data protection or supervisory authority.

These rights are not absolute and may be subject to limitations, exemptions, identity-verification requirements or the rights of others. RemoFirst may request information reasonably necessary to verify identity and authority before responding.

13.1 Requests where RemoFirst acts as controller

Where RemoFirst acts as a controller, RemoFirst will respond to the request in accordance with applicable law. Requests may be submitted using the details in the Contact Us section.

13.2 Requests where RemoFirst acts as processor

Where RemoFirst processes Personal Data on behalf of a Client, the Client may be responsible for responding. RemoFirst may refer the request to the Client or assist the Client in accordance with the applicable DPA and documented instructions.

13.3 Requests concerning Local Partners or other independent controllers

Where a request concerns processing controlled by a Local Partner, insurer, authority or another independent controller, the individual may need to submit the request directly to that controller. Where reasonably possible and legally permitted, RemoFirst will help identify the relevant controller or route the request appropriately.

The existence of an MSA, DPA, Local Partner agreement or other commercial arrangement does not limit statutory rights available to individuals. Separate agreements may impose additional obligations, assistance duties, response procedures or contractual rights between the parties.

14. International Data Transfers

Due to the global nature of RemoFirst’s business and Services, Personal Data may be transferred to, accessed from, stored in or otherwise processed in countries other than the country in which it was collected. Those countries may have different data protection laws.

Where RemoFirst transfers Personal Data internationally, it takes appropriate steps to ensure that the transfer is lawful and that appropriate safeguards are implemented. Depending on the jurisdiction and transfer, these safeguards may include an adequacy decision, approved standard contractual clauses, the UK International Data Transfer Agreement or UK Addendum, controller-to-controller or processor contractual safeguards, another approved mechanism, or a lawful derogation or exception.

Where RemoFirst acts as a processor, transfer arrangements may be set out in the applicable DPA, including documented instructions, sub-processing terms and applicable transfer clauses. Where Personal Data is disclosed to a Local Partner or another independent controller, the transfer may be governed by controller-to-controller safeguards or another mechanism permitted by law. The independent controller remains responsible for transfers it subsequently initiates or controls.

RemoFirst may also implement supplementary technical, organizational and contractual measures, such as encryption, access restrictions, transfer assessments, data minimization and enhanced contractual commitments, where appropriate.

Individuals may contact RemoFirst for additional information about safeguards applicable to a relevant transfer or to request a copy of applicable contractual protections, subject to necessary redactions to protect confidential information and the rights of others.

15. Security Measures

RemoFirst implements technical, organizational and administrative measures designed to protect Personal Data against unauthorized or unlawful access, collection, use, disclosure, alteration, loss, destruction, misuse or other unauthorized processing. Measures are selected having regard to the nature, scope, context and purposes of processing and the risks to individuals.

These measures may include access controls, role-based permissions, authentication and multi-factor authentication, encryption in transit and at rest, confidentiality obligations, logging and monitoring, vulnerability and incident management, business continuity, vendor risk management, security training, secure development and internal governance.

RemoFirst maintains a security and compliance framework aligned with recognized industry standards and applicable contractual and legal requirements. RemoFirst has obtained SOC 2 Type I and Type II attestations and ISO/IEC 27001 certification, subject to their applicable scope and validity periods.

No method of transmission or storage is completely secure. RemoFirst cannot guarantee absolute security. Where required by law, RemoFirst will investigate, mitigate and notify affected parties and competent authorities of qualifying Personal Data breaches or security incidents within the applicable timeframes.

16. Cookies and Tracking Technologies

RemoFirst may use cookies, pixels, tags, software development kits and similar technologies on the Website, Platform and in connection with the Services. These technologies may support functionality, authentication, security, preferences, performance, analytics, communications and marketing.

Information collected may include IP address, browser type, device identifiers, operating system, language preferences, pages viewed, links clicked, dates and times of access, referring URLs, account activity and other interaction information.

Some technologies are necessary for the operation and security of the Website, Platform or Services. Others are used for analytics, personalization, performance measurement or advertising, subject to applicable law and, where required, consent. You can manage available choices through the cookie settings or consent-management tools made available on the Website or Platform.

Further information about the categories of cookies, their purposes, duration and available choices is provided in the Cookie Policy made available through the Website. If certain technologies are disabled, some functionality may not operate correctly.

17. Children and Dependants

The Website and Platform are not intended for children acting independently. RemoFirst does not knowingly solicit Personal Data directly from children for general Website or marketing purposes.

RemoFirst may, however, process Personal Data concerning children or other dependants where necessary to provide benefits, health-insurance, immigration, visa, relocation, emergency-contact, family-leave or related workforce Services. Such information may include identity details, date of birth, relationship to the relevant worker, identification documents, immigration information and insurance or health-related information where necessary.

Where required by applicable law, RemoFirst or the relevant controller will obtain authorization from a parent, guardian or other authorized person and apply safeguards appropriate to the nature of the information and the age of the individual.

18. Jurisdiction-Specific Privacy Notices

Additional privacy disclosures may apply depending on where an individual is located or the law applicable to a processing activity. The appendices to this Privacy Policy include disclosures for Brazil, the People’s Republic of China and California. Additional local or service-specific notices may also be provided.

If a jurisdiction-specific notice conflicts with this Privacy Policy, the jurisdiction-specific notice will prevail to the extent required by the applicable law and only in relation to the relevant processing. Additional obligations, assistance duties and contractual rights may also arise under an applicable DPA, controller-to-controller data-sharing agreement, Service Annex, Local Partner agreement or other service-specific data protection terms. Such agreements supplement this Privacy Policy but do not limit statutory privacy rights.

19. Changes to this Privacy Policy

RemoFirst may update this Privacy Policy from time to time to reflect changes in law, regulatory guidance, business practices, the Website, Platform, Services, providers or processing activities. The updated version will be made available through relevant RemoFirst channels and will state the date of the latest update.

Where required by applicable law, RemoFirst will provide additional notice of material changes or obtain consent before applying a change to processing that requires consent.

20. Contact Us

Questions, requests or concerns regarding this Privacy Policy or RemoFirst’s processing of Personal Data may be submitted to:

Email: dpo@remofirst.com

When contacting RemoFirst, please provide sufficient information to understand and respond to the request. Do not send unnecessary Sensitive Personal Data by unencrypted email.

21. European Union and United Kingdom Representatives

Where RemoFirst is subject to the EU General Data Protection Regulation or the UK General Data Protection Regulation and is required to appoint a representative, RemoFirst has appointed the following representatives under Article 27 of the applicable legislation. The representatives act as points of contact for individuals and supervisory authorities regarding relevant processing by RemoFirst.

European Union Representative

Prighter EU Rep GmbH

Schellinggasse 3/10

1010 Vienna

Austria

Privacy portal: Prighter Privacy Portal

United Kingdom Representative

Prighter Ltd

20 Mortlake High Street

London SW14 8JN

United Kingdom

Privacy portal: Prighter Privacy Portal

Individuals may contact the relevant representative or RemoFirst directly. Contacting a representative does not prevent an individual from contacting RemoFirst or lodging a complaint with the competent supervisory authority.