1. Scope and roles
This policy covers information processed through the BlueJay platform (the “Service”), our public website, and our business communications. BlueJay is used by employers and other organizations (“Customers”) to manage their workforce. For information a Customer or its users submit about the Customer’s personnel, dependents, and beneficiaries (“Customer Data”), the Customer is the business, controller, or equivalent under applicable privacy laws, and CultureNest LLC acts as its service provider, processor, or contractor, processing Customer Data on the Customer’s behalf and instructions. CultureNest LLC is the business or controller only for limited information it processes for its own purposes, such as website inquiries, account security, and business contacts. Each Customer’s own privacy notices govern its practices. A signed Data Processing Agreement controls over this policy where one exists.
2. Information processed through the Service
Depending on the features a Customer enables, the Service may process:
- Profile and employment information — name, work and personal contact details, pronouns, job title, department, location, manager, employment type and status, hire and termination dates, pay frequency, and related fields.
- Benefits information — plan-year and plan configuration, eligibility results, enrollment elections and waivers with reasons, coverage tiers, cost snapshots, dependents and beneficiaries (such as name, relationship, date of birth, allocation percentage, and an optional last four digits of an identifier), acknowledgments, receipts, and payroll/carrier export records. The Service is designed not to collect full Social Security numbers.
- HR operations — HR requests and cases, time off, performance reviews, onboarding and workflow tasks, policies and acknowledgments, documents and their versions, and in-app messages and announcements.
- Account and authentication — email address, sign-in method, invitations and their status, session information, and legal-acceptance records (versions accepted, timestamp, IP address, and user agent).
- Security, audit, and access logs — records of security-relevant actions, administrative overrides, exports, and access to restricted fields, plus IP address, user agent, and related technical data.
- Integration data — data exchanged with services a Customer enables.
- Contact-form and support information — information you send us through our website or by email.
3. Sensitive information
Some Customer Data, such as dependent details, benefit elections, leave, or HR case information, may be sensitive. Customers should submit only information reasonably necessary for their purposes and must not submit data the Terms of Service prohibit, including full government identifiers, payment card data, or protected health information that would require a Business Associate Agreement unless one has been executed. CultureNest LLC does not claim HIPAA compliance. Its legal status under HIPAA is determined by applicable law and the facts, not by this policy.
4. How we use information
- To provide, operate, maintain, support, and secure the Service as instructed by Customers.
- To authenticate users, enforce permissions, detect and prevent fraud, abuse, and security incidents, and maintain audit records.
- To send transactional, administrative, and security communications.
- To respond to inquiries and support requests.
- To create aggregated or de-identified information that does not identify any individual or Customer, for analytics, security, and product improvement.
- To comply with law, legal process, and our agreements, and to establish or defend legal claims.
Some features use third-party AI services to generate outputs. We send such services only the information needed for the feature. We do not make statements here about any third-party provider’s model-training practices beyond what our agreements with them provide; contact hello@culturenest.io with questions.
5. Customer administrator visibility
Authorized administrators and personnel of your organization can view, edit, export, and delete information about you according to the roles and permissions your organization configures. For example, HR administrators with benefits permissions may view your benefit elections, dependents, and beneficiaries. Your organization, not CultureNest LLC, decides who has access.
6. How information is disclosed
- Service providers and subprocessors — hosting, database, authentication, storage, email delivery, AI, and similar providers acting on our behalf under contractual obligations. A current list is available on request to hello@culturenest.io.
- Customer-directed disclosures — to integrations, carriers, payroll providers, or others a Customer directs, including through exports.
- Legal and safety — where we believe disclosure is required by law or legal process, or necessary to protect the rights, property, or safety of CultureNest LLC, our Customers, users, or others, or to investigate misuse.
- Business transfers — in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to applicable law.
CultureNest LLC does not sell personal information and does not use Customer Data for targeted (cross-context behavioral) advertising.
7. Retention
Customer Data is retained as needed to provide the Service, according to Customer configuration and instructions, any signed agreement, and applicable law. Certain records, such as audit logs, legal-acceptance records, submitted benefit election history, and records under legal hold, are retained in append-only or immutable form and may be kept longer to support legal, security, and compliance obligations. Backups may persist for a period after deletion.
8. Security
We use technical and organizational safeguards designed to protect information, as described in our Security Overview. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please report suspected security issues to hello@culturenest.io.
9. U.S. state privacy rights and workforce data
Depending on the facts, applicable thresholds, and where you live, California law and other U.S. state privacy laws may apply to workforce, applicant, dependent, or beneficiary information. Whether a law applies, and whether CultureNest LLC acts as a service provider, processor, contractor, business, or controller, depends on the actual processing and applicable law, not on labels in this policy. We do not represent that any particular law or right applies universally.
- Customer Data. Where CultureNest LLC processes Customer Data on a Customer’s behalf, the Customer is responsible for its notices (including any notice at collection), for responding to rights requests, and for any supplemental state notices. Submit requests to your employer or organization. If you contact CultureNest LLC, we may forward your request to the relevant Customer and will assist as required by our agreement and applicable law.
- Information CultureNest LLC controls. Where applicable law gives you rights to know or access, correct, delete, obtain a copy of, or limit or opt out of certain processing of personal information CultureNest LLC controls, contact hello@culturenest.io. We will verify requests as required by law, will not discriminate against you for exercising your rights, and will accept requests from authorized agents where permitted by law.
- Automated decision-making and AI. Where state law requires notices, risk assessments, opt-outs, appeals, or human review for automated decision-making or AI tools used in employment or similar decisions, the Customer deciding to use those tools is responsible for meeting those requirements for its decisions, and CultureNest LLC will meet the obligations applicable to its actual role.
- Data processing terms. Where required by law or agreed, a data processing agreement or addendum governs CultureNest LLC’s processing of Customer Data.
10. Business use; children
The Service is intended for business use by adults. It is not directed to children, and CultureNest LLC does not knowingly collect personal information directly from children. Information about minor dependents may be entered by an authorized employee or administrator solely for benefits purposes on the Customer’s behalf.
11. International processing
CultureNest LLC is based in the United States, and information is processed in the United States and other locations where our service providers operate. Customers are responsible for their own lawful basis, instructions, and any transfers of Customer Data they initiate or direct. CultureNest LLC is responsible for the transfer obligations that applicable law imposes on it in its actual role and will use appropriate safeguards where required by law or a signed agreement.
12. Statements we do not make
CultureNest LLC does not claim HIPAA compliance, SOC 2 or ISO certification, perfect security, or specific deletion timelines. Any certification will be described only after it is independently obtained.
13. Changes
We may update this policy. Material changes will be posted with a new version and effective date, and users may be asked to re-acknowledge the current version.
14. Contact
CultureNest LLC, Arizona. Privacy questions and requests: hello@culturenest.io.
