Employee Privacy Notice

Jamf Software, LLC

The purpose of this notice is to provide you further details regarding employee personal information that may be processed by Jamf and is intended to supplement our Privacy Policy. Unless otherwise noted or excluded by context, “employee personal information” is included within the definition of “personal information” for the purposes of this notice. Jamf may update this notice from time to time. In the event we make any material changes, we will notify you by email or by posting the revised notice on our corporate website. The date of the most recent revision to this notice will be posted at the end of this notice. Any revisions will become effective upon seven (7) calendar days following such posting on our corporate website.

JAMF Software, LLC, or its affiliates (collectively, “Jamf”) may collect personal information from prospective and present employees only for legitimate business purposes, as described in the Appendix to this notice and in accordance with applicable laws, including data privacy/protection laws and regulations. Employee personal information on health, performance evaluations, disciplinary actions, and other sensitive employee matters, whether it is stored manually or electronically, is accessible by other Jamf employees only, if necessary, with respect to legitimate human resources purposes; however, an employee’s picture and any personal information the employee chooses to provide may be placed on the Jamf intranet. Likewise, from time to time, an employee’s picture along with personal information may be published in Jamf directories, internal websites and used in presentations.

For legitimate human resources purposes, employees may choose to voluntarily disclose personal information about family members and other individuals, including the beneficiaries of employment benefits and emergency contacts. If Jamf employees choose to do this, the individual’s personal information shall be treated, for the purposes of this notice, the same as an employee’s personal information. It is the employee’s responsibility to inform any such individuals about this notice and ensure that the employee has the right to provide the individual’s personal information to Jamf.

Employee personal information is never sold, leased, or rented to any third party. Employee personal information will never be disclosed to third parties except as follows:

  • To those retained by Jamf for processing only for the purposes set forth above;
  • Where required pursuant to an applicable law, governmental or judicial order, law, or regulation, or to protect the rights or property of Jamf;
  • In the event of sale of the business, merger, acquisition, etc.;
  • Where authorized electronically or in writing by the employee; and
  • Where the employee voluntarily provides personal information, and the context makes it clear that employee personal information will be provided to a third party/sub-processor (ex. payroll, benefits, travel, reimbursement, and other systems used in the employment context).

Where personal information is transferred from the EU, UK, or Switzerland to the US in the context of the employment relationship, we will cooperate in investigations by and comply with the advice of relevant data protection authorities.

If you are a resident of California, please see the California Addendum below for additional details on how Jamf handles your personal information.

Appendix – Description and Uses of Employee Personal Information

1. Who is responsible for processing and who can I contact?

The data controller is Jamf Software, LLC, or its affiliates (“Jamf” or the “Company”) and the responsible person can be contacted with any questions about this notice or Jamf’s privacy practices at privacy@jamf.com.

2. What sources and information do we use?

We may obtain your information directly from you (during the recruitment process and during employment) and from third parties, such as recruitment agencies, our affiliates, your colleagues and managers, references you provide, prior employers or schools, pre-employment screening services, such as background check providers (where permitted by law), job board websites, providers of employee benefits, social media networks, and publicly available databases.

Please see point 3 below for more information.

3. What types of personal information do we process, why do we process the personal information (purpose of the processing) and on what legitimate basis?

Categories of personal information Purpose of processing Legitimate basis
Name and surname, date of birth, contact details (address, phone number, e-mail address), PESEL number, ID number, education, qualifications, previous employment, tax number (NIP), place of birth, information on family members, bank account number, information on contract of employment (start and end dates, role and location, working hours, salary, benefits and holiday entitlement), information related to pension schemes, performance at work, training records, absences (sick leave, holiday, etc.), information on disciplinary measures, image, information about military duty and other information required by employment and social security laws or needed to carry out Jamf’s business Realization of employment duties and carrying out Jamf’s business
  • Compliance with legal obligations of Jamf as an employer
  • Jamf’s legitimate interests consistent with carrying out business activity
  • Necessity to perform employment contract
  • Employee’s consent (image)
  • Jamf’s legitimate interest consistent with carrying out emergency notification
  • Racial or ethnic origin, gender, veteran status, disability, marital status, LGBTQIA+ status
  • DEIB analysis and reporting
  • Employee’s explicit consent
  • Information needed through the carrier service includes name, e-mail address, phone number, call history, SMS history (not messages), aggregated data usage, network traffic, SIM, device identifiers (if device is managed)
  • Provide optional Jamf-purchased telecommunication service and/or hardware
  • Compliance with legal obligations
  • Jamf’s legitimate interests consistent with ensuring that its business activities and continuity
  • Geolocation coordinates (optional)
  • Geolocation data, such as device location and approximate location derived from IP address
  • Emergency notification based on dynamic location for business continuity
  • Relative location, like IP address, is used for dynamic management of devices and protecting Jamf’s networks
  • Jamf’s legitimate interest consistent with carrying out emergency notification
  • Jamf’s legitimate interests consistent with carrying out business activity
Name, position, father’s name, PESEL, NIP, date and place of birth, contact details, information about accident, information about suffered harm, ID number, position, name, surname and contact details of the third party - contact person in case of accidents at work Documenting accidents at work Compliance with legal obligations of Jamf as an employer
Information relating to the course of employment, including appraisals, efficiency / utilization reports and evaluation reports Promotion and career development opportunities
  • Compliance with legal obligations of Jamf as an employer
  • Necessity to perform employment contract
  • Legitimate interest pursued by Jamf consistent with promotion of Jamf as an employer
Name, passport details, nationality, date of birth, address, work phone numbers, e-mail and other information required for organizing business travel or visas Business travel & visas
  • Necessity for performance of a contract between employee and Jamf (including with regard to business travel outside of the EEA)
  • Legitimate interests pursued by Jamf consistent with ensuring travel documents where necessary
Name, e-mail address, phone number, role in the company, image Promotion of Jamf (e.g., through promotional materials)
  • Jamf’s legitimate interests consistent with promoting its business
  • Necessity for the performance of employment contract
  • Employee’s consent (image)
Name and surname, information relating to conduct subject to disciplinary investigations or proceedings, information on actions or omissions necessary to detect fraud or other criminal offenses related to Jamf’s business
  • Carrying out disciplinary investigations
  • Prevention and detection of fraud or criminal offenses related to Jamf’s business
  • Compliance with legal obligations, including employment law
  • Jamf’s legitimate interests consistent with ensuring that its business activity is compliant with law
Personal information concerning health, to the extent permitted by law
  • Initial and periodic medical check-ups, sick leave, adjustment of workplace in case of disabilities
  • Post-accident documentation
Carrying out legal obligations of employer
Name, position in the company, work phone numbers and e-mail, business correspondence and any other information required in legal proceedings Participating in legal proceedings by Jamf
  • Legitimate interests pursued by Jamf consistent with establishment, exercise or defense of legal claims
  • Compliance with legal obligations
Racial or ethnic origin, information concerning health or any other information of special categories — only if needed in legal proceedings Participating in legal proceedings Establishment, exercise or defense of legal claims by Jamf
  • Cameras on external doors and in sensitive areas
  • Information related to the use of Jamf assets, productivity applications and systems
Monitoring of activity relevant to protecting employees and company assets Legitimate interests pursued by Jamf consistent with ensuring security and privacy

Occasionally, and where appropriate, we may seek your consent in writing to process specific personal information. If we do that, we will explain the purpose of the processing. In these situations, you have the right to refuse or withdraw your consent at any time by contacting the appropriate person named in the consent document.

4. Who is the recipient of my information?

We will share your personal information with:

  • Jamf affiliates;
  • Jamf’s customers and vendors;
  • private health and benefit providers;
  • insurers and pensions scheme providers;
  • federal and state authorities, e.g., tax authority, social security authority, law enforcement;
  • entities providing services to Jamf, such as IT or payroll services;
  • potential purchasers and their professional advisers in the context of the sale or restructuring of the whole or part of our business,
  • hotels, airlines, reservation centres (for business travel purposes).

5. Is personal information transferred to a third country or to an international organization?

Jamf is a global organization and to ensure the provision of effective and efficient services and communication throughout Jamf, we are required to transfer your personal information internationally.

Your personal information may therefore be stored and processed abroad in countries that may have different data protection rules. However, Jamf will only transfer your personal information outside of the EEA and the UK where appropriate safeguards have been put in place. Jamf will ensure that the employee personal information will remain protected as required by applicable law and regulations, even when transferred across borders to a third party including, but not limited to, the use of European Commission-approved model clauses, UK Addendum, and other data transfer safeguards.

For more information on how Jamf safeguards employee personal information, please contact privacy@jamf.com.

6. How long will my personal information be retained?

Jamf retains your employee personal information (including your sensitive personal information) for as long as needed or permitted in light of the purposes for which it was collected and in accordance with applicable laws, including data privacy/protection laws and local labor laws. The criteria used to determine our retention periods include:

  • The duration of your employment or contract with us;
  • The length of time we have an ongoing relationship with you or your dependents/beneficiaries and the length of time thereafter during which we may have a legitimate need to reference your personal information to address issues that may arise;
  • Whether there is a legal obligation to which we are subject, for example, certain laws may require us to keep your employment records for a certain period of time; and
  • Whether retention is advisable in light of our legal position, such as in regard to applicable statutes of limitations, litigation, or regulatory investigations.

7. What choices and rights do I have?

You may request further details regarding Jamf’s processing of your employee personal information in accordance with local applicable law.

You may have certain rights over your personal information, depending on the applicable jurisdiction, including but not limited to:

  • A right to receive details about or access to your personal information;
  • A right to erase certain personal information;
  • A right to stop your personal information being processed in certain circumstances;
  • A right related to automated profiling;
  • A right to portability;
  • A right to correct your personal information; and
  • A right to opt-out of the sale of your personal information.

There are limitations in relation to these rights. Please contact privacy@jamf.com or your human resources representative for more details.

8. Do I have an obligation to make personal information available?

Providing the following personal information is necessary for the conclusion and performance of your employment with Jamf and has its legal basis in employment law: (a) first name (names) and surname; (b) date of birth; (c) contact details that you share with us (at least residential address); (d) education; (e) qualifications, if required to perform work in a given position or of a given type; (f) work experience (previous employment); (g) your personal identification number or type and series number of another document confirming your identity (e.g., government issued identification card); (h) your other personal information, as well as names and dates of birth of your children and other members of your immediate family, if the provision of such information is necessary due to the use of special rights provided for in the labour law; and (i) bank account number, unless you have requested cash payment of your remuneration. It is not possible to create and sustain an employment relationship or perform an employment contract (as applicable) without processing your personal information within the above scope.

Jamf as your employer may also request you to provide other personal information, if the obligation to provide it results from other provisions of law or if another lawful purpose exists.

California Addendum—For Residents of California

This California Addendum applies to California residents and supplements the information provided above in the Employee Privacy Notice.

Collection and Disclosure of Personal Information

The following chart details which categories of personal information we may collect and process, as well as which categories of personal information we may disclose to which third parties for our operational business and employment purposes, including within the 12 months preceding the date this notice was last updated.

Categories of personal information Disclosed to which categories of third parties for operational business purposes
Identifiers, such as name, contact details (address, phone number, email), unique personal identifiers, IP address, account name, online identifiers, photo badges, beneficiary designations, and government-issued identifiers (e.g., Social Security number, driver’s license number, passport number) Our affiliates; our customers; service providers that provide services such as payroll, background check vendors (where permitted by law), consulting, training, expense management, medical/health, IT, and other services; health, insurance, and benefits providers; professional advisors, such as accountants, auditors, bankers, and lawyers; third-party travel providers, for business travel purposes; public and governmental authorities, such as regulatory authorities and law enforcement
Personal information as defined in the California customer records law such as name, contact information, signature, Social Security number, passport number, and medical, insurance, financial, education and employment information. Our affiliates; our customers; service providers that provide services such as payroll, background check vendors, consulting, training, expense management, medical/health, IT, and other services; health, insurance, and benefits providers; professional advisors, such as accountants, auditors, bankers, and lawyers; third-party travel providers, for business travel purposes; public and governmental authorities, such as regulatory authorities and law enforcement
Characteristics of protected classifications under California or federal law, such as sex, age, gender, race, disability, religion, medical conditions, citizenship, military/veteran status, gender identity and expression, primary language, immigration status, and requests for leave Our affiliates; service providers that provide services such as payroll, consulting, training, expense management, medical/health, IT, and other services; health, insurance, and benefits providers; professional advisors, such as accountants, auditors, bankers, and lawyers; third-party travel providers, for business travel purposes; public and governmental authorities, such as regulatory authorities and law enforcement
Commercial information, such as purchasing information and payment history related to business and travel expenses Our affiliates; service providers that provide services such as payroll, consulting, training, expense management, medical/health, IT, and other services; health, insurance, and benefits providers; professional advisors, such as accountants, auditors, bankers, and lawyers; third-party travel providers, for business travel purposes; public and governmental authorities, such as regulatory authorities and law enforcement
Internet or network activity information, such as browsing history and interactions with our and others’ websites, applications, and systems Our affiliates; service providers that provide services such as payroll, consulting, training, expense management, medical/health, IT, and other services; health, insurance, and benefits providers; professional advisors, such as accountants, auditors, bankers, and lawyers; public and governmental authorities, such as regulatory authorities and law enforcement
Telecommunication information, such as name, e-mail address, phone number, call history, SMS history (not messages), data usage, network traffic, SIM, device identifiers (if device is managed) Our affiliates; service providers that provide services such as payroll, consulting, training, expense management, IT, and other services; professional advisors, such as accountants, auditors, bankers, and lawyers; public and governmental authorities, such as regulatory authorities and law enforcement
Geolocation data, such as device location, approximate location derived from IP address Our affiliates; service providers that provide services such as payroll, consulting, training, expense management, medical/health, IT, and other services; health, insurance, and benefits providers; professional advisors, such as accountants, auditors, bankers, and lawyers; public and governmental authorities, such as regulatory authorities and law enforcement
Audio, electronic, visual, and similar information, such as call and video recordings, security camera footage, and information about the use of electronic devices and systems Our affiliates; service providers that provide services such as payroll, consulting, training, expense management, medical/health, IT, and other services; health, insurance, and benefits providers; professional advisors, such as accountants, auditors, bankers, and lawyers; public and governmental authorities, such as regulatory authorities and law enforcement
Education information subject to the federal Family Educational Rights and Privacy Act, such as student transcripts and confirmation of graduation Our affiliates; service providers that provide services such as payroll, training, expense management, medical/health, IT, and other services; professional advisors, such as accountants, auditors, bankers, and lawyers; public and governmental authorities, such as regulatory authorities and law enforcement
Professional or employment-related information, such as work history and prior employer, information from reference checks, employment application, membership in professional organizations, personnel files, personal qualifications and training, eligibility for promotions and other career-related information, work preferences, business expenses, wage and payroll information, benefit information, information on leaves of absence or PTO, performance reviews, and information on internal investigations Our affiliates; service providers that provide services such as payroll, consulting, training, expense management, medical/health, IT, and other services; health, insurance, and benefits providers; professional advisors, such as accountants, auditors, bankers, and lawyers; third-party travel providers, for business travel purposes; public and governmental authorities, such as regulatory authorities and law enforcement
Inferences drawn from any of the personal information listed above to create a profile about, for example, an individual’s preferences, characteristics, predispositions, and abilities Our affiliates; service providers that provide services such as payroll, training, expense management, medical/health, IT, and other services; professional advisors, such as accountants, auditors, bankers, and lawyers; public and governmental authorities, such as regulatory authorities and law enforcement
  • Sensitive Personal Information
  • Personal information that reveals an individual’s Social Security, driver’s license, state identification card, or passport number; account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account; precise geolocation; racial or ethnic origin, religious or philosophical beliefs, citizenship, immigration status, or union membership; the contents of mail, email, and text messages unless Jamf is the intended recipient of the communication;
  • The processing of biometric information for the purpose of uniquely identifying an individual;
  • Personal information collected and analyzed may include an individual’s racial and ethnic origin, gender, veteran status, disability status, marital status, and LGBTQIA+ status , for DEIB reporting and government employment reporting. These identifiers may be optional, except where required by law;
  • Personal information collected and analyzed concerning an individual’s health; and
  • Personal information collected and analyzed concerning an individual’s sex life or sexual orientation.
Our affiliates; service providers that provide services such as analysis, payroll, benefits, consulting, reporting, training, expense management, medical/health, IT, and other services; health, insurance, and benefits providers; professional advisors, such as accountants, auditors, bankers, and lawyers; third-party travel providers, for business travel purposes; public and governmental authorities, such as regulatory authorities and law enforcement

We do not “sell” or “share” your personal information, including your sensitive personal information, as defined under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act. We have not engaged in such activities in the 12 months preceding the date this notice was last updated. Without limiting the foregoing, we do not “sell” or “share” the personal information, including the sensitive personal information, of minors under 16 years of age.

Purposes for the Collection, Use, and Disclosure of Sensitive Personal Information

We collect, use, and disclose sensitive personal information for purposes of performing services for our business, providing services as requested by you, ensuring the security and integrity of our business, infrastructure, and the individuals we interact with, establishing and maintaining your employment relationship with us, ensuring the diversity of our workforce, complying with legal obligations, managing payroll and corporate credit card use, administering and providing benefits, securing the access to, and use of, our facilities, equipment, systems, networks, applications, and infrastructure, preventing, detecting, and investigating security incidents, resisting, and responding to fraud or illegal activities, and ensuring the physical safety of individuals, and other collection and processing that is not for the purpose of inferring characteristics about an individual. We do not use or disclose sensitive personal information for additional purposes.

Individual Requests

You may, subject to applicable law, make the following requests:

  1. You may request that we disclose to you the following information:
    a. The categories of personal information we collected about you and the categories of sources from which we collected such personal information;
    b. The business or commercial purpose for collecting personal information about you; and
    c. The categories of personal information about you that we otherwise disclosed, and the categories of third parties to whom we disclosed such personal information.
  2. You may request to correct inaccuracies in your personal information.
  3. You may request to have your personal information deleted.
  4. You may request to receive the specific pieces of your personal information, including a copy of the personal information you provided to us in a portable format.

We will not unlawfully retaliate against you for making an individual request. To make a request, please contact us at either privacy@jamf.com or 888-755-1421. We will verify and respond to your request consistent with applicable law, taking into account the type and sensitivity of the personal information subject to the request. We may need to request additional personal information from you to verify your identity and protect against fraudulent requests. If you maintain a password-protected account with us, we may verify your identity through our existing authentication practices for your account and require you to re-authenticate yourself before disclosing or deleting your personal information. If you make a request to delete, we may ask you to confirm your request before we delete your personal information.

Authorized Agents

If an agent would like to make a request on your behalf as permitted by applicable law, the agent may use the submission methods noted in the section entitled “Individual Requests.” As part of our verification process, we may request that the agent provide, as applicable, proof concerning their status as an authorized agent. In addition, we may require that you verify your identity as described in the section entitled “Individual Requests” or confirm that you provided the agent permission to submit the request

Last updated: May 30, 2024