MassMutual provides this Privacy Disclosure (“Disclosure”) to inform you how we process Personal Information that we collect through our websites, social media accounts, online advertisements, and online communications (collectively, our “Platforms”), through communications (such as mail or phone), at in-person meetings and events, and through other online and offline methods.
Changes: We may update this Disclosure from time to time. Any updated Disclosure will be effective when posted. Please check this Disclosure periodically for updates. If required by law, we will contact you directly to provide you with an updated Disclosure.
We collect Personal Information about you from the following sources:
A. Directly from you. We may collect Personal Information you provide to us directly, such as when you contact us through our Platforms, interact with us in person, sign up for offers or newsletters, or otherwise communicate with us.
B. Data collected automatically and through tracking technologies. We may automatically collect information or inferences about you, such as through cookies and other tracking technologies, when you interact with our Platforms. This may include information about how you use and interact with our Platforms or otherwise interact with us, information about your device, and internet usage information. For more information, see “Section 5 – Cookies and Other Tracking Technologies.”
C. From service providers who collect information on our behalf.
D. From our affiliates and subsidiaries.
E. From MassMutual financial professionals (such as agents and brokers).
F. From third parties, such as commercial business partners, data brokers, social media companies or other independent parties who interact with us.
G. From publicly available sources. We may collect Personal Information about you from publicly available sources, such as public profiles and websites.
We may combine information that we receive from the various sources described in this Disclosure, including third party sources, and use or disclose it for the purposes identified below.
We may collect the following types of Personal Information about you:
A. Identifiers, such as your name, email address, physical address, telephone number, and device identifiers.
B. Records about you, such as covered medical or health information, investments, estimated income, and other information that we obtain from commercial data partners.
C. Protected class and demographic information, such as age (including birthdates), gender, and veteran status.
D. Commercial information, such as records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
E. Internet or other electronic network activity information, about you, your device, and how you interact with the Platforms. Data elements may include browsing history, search history, preference information (including marketing and purchasing preferences), account settings (including any default preferences), operating system, browser used, and other information about how you interact with our Platforms (such as pages on our Platforms that you have viewed).
F. Non-precise geolocation data, such as your location as derived from your IP address.
G. Audio, visual, or other sensory information, such as photographs and audio/video recordings.
H. Professional or employment-related information, such as job title, organization and other professional information.
I. Education information.
J. Inferences drawn from any of the information we collect about your preferences or behavior.
K. Sensitive Personal Information, such as health information obtained from commercial data partners or inferred from your interactions with our Platforms.
We may use Personal Information for the following purposes:
A. For our internal business purposes, such as operating our Platforms and customizing the content; maintaining internal business records, such as accounting, document management and other similar activities; enforcing our policies and rules; management reporting; auditing; IT administration of our network, intranet, and other technologies; and IT security management and tasks.
B. For our internal research and business improvement purposes, such as verifying, maintaining, or improving the quality of our business (including our Platforms); evaluating the effectiveness of our advertising or marketing efforts; and debugging and repairing errors with our systems, networks, and equipment.
C. For legal, safety, or security reasons, such as complying with legal, reporting, and similar requirements; investigating and responding to claims against the Company, its personnel, and its customers; for the establishment, exercise or defense of legal claims; protecting Company, your, our customers’, and other third parties’ safety, property or rights; detecting, preventing, and responding to security incidents; and protecting against malicious, deceptive, fraudulent, or illegal activity.
D. In connection with a corporate transaction, such as if we acquire, sell or transfer all or a portion of our business or assets.
E. For marketing and targeted advertising, such as marketing our business or that of our affiliates, business partners, or other third parties (for purposes of this paragraph alone, “we” or ”our” includes our affiliates, business partners, or other third parties we may be working with to provide marketing). For example, we may use Personal Information we collect to personalize advertising to you on our Platforms or third party sites and digital properties; to analyze interactions with our email communications or website areas viewed; to develop product, brand or services audiences (including by identifying you across devices/sites) to better target our advertising to you; or to send you newsletters, surveys, questionnaires, promotions, or information about events or webinars. You can unsubscribe to our email marketing via the link in the email or by contacting us using the information in the Contact Information section below.
We may use anonymized, de-identified, or aggregated information for any purpose permitted by law.
We may disclose Personal Information to third parties, including the categories of recipients described below. Although we do not “sell” Personal Information for money, we engage in routine practices involving third parties that could be considered a "sale" (meaning a disclosure of Personal Information to a third party for consideration) or “sharing” (meaning a disclosure of Personal Information to a third party for targeted advertising purposes), as defined under the CCPA. We do not knowingly sell or share Personal Information about minors.
Categories of Personal Information We Collect | Categories of Third Parties With Whom We Disclose Personal Information for a Business Purpose | Categories of Third Parties to Whom Personal Information is Sold* or Shared* |
---|---|---|
Identifiers (Section 2.A) | • Affiliates and subsidiaries • Professional consultants • Vendors necessary to complete transactions you request • Law enforcement, government, agencies, and other recipients for legal, security, or safety purposes • Other entities in connection with a corporate transaction • Entities to which you have consented to the disclosure | • Advertisers, ad platforms and networks, and social media platforms • Third parties whose cookies and tracking tools we use as described in Section 5 (Cookies and Tracking Technologies) • Commercial data partners to whom we make information available for their own marketing purposes • Partners who work with us on promotional or sponsorship opportunities, including co-branded products and services |
Records about you (Section 2.B) | • Affiliates and subsidiaries • Professional consultants • Vendors necessary to complete transactions you request • Law enforcement, government, agencies, and other recipients for legal, security, or safety purposes • Other entities in connection with a corporate transaction • Entities to which you have consented to the disclosure | • Not sold or shared |
Characteristics of protected classifications under California or federal law (Section 2.C) | • Affiliates and subsidiaries • Professional consultants • Vendors necessary to complete transactions you request • Law enforcement, government, agencies, and other recipients for legal, security, or safety purposes • Other entities in connection with a corporate transaction • Entities to which you have consented to the disclosure | • Not sold or shared |
Commercial information (Section 2.D) | • Affiliates and subsidiaries • Professional consultants • Vendors necessary to complete transactions you request • Law enforcement, government, agencies, and other recipients for legal, security, or safety purposes • Other entities in connection with a corporate transaction • Entities to which you have consented to the disclosure | • Advertisers, ad platforms and networks, and social media platforms • Third parties whose cookies and tracking tools we use as described in Section 5 (Cookies and Tracking Technologies) • Commercial data partners to whom we make information available for their own marketing purposes • Partners who work with us on promotional or sponsorship opportunities, including co-branded products and services |
Internet or other electronic network activity (Section 2.E) | • Affiliates and subsidiaries • Professional consultants • Vendors necessary to complete transactions you request • Law enforcement, government, agencies, and other recipients for legal, security, or safety purposes • Other entities in connection with a corporate transaction • Entities to which you have consented to the disclosure | • Advertisers, ad platforms and networks, and social media platforms • Third parties whose cookies and tracking tools we use as described in Section 5 (Cookies and Tracking Technologies) • Commercial data partners to whom we make information available for their own marketing purposes • Partners who work with us on promotional or sponsorship opportunities, including co-branded products and services |
Geolocation data (Section 2.F) | • Affiliates and subsidiaries • Professional consultants • Vendors necessary to complete transactions you request • Law enforcement, government, agencies, and other recipients for legal, security, or safety purposes • Other entities in connection with a corporate transaction • Entities to which you have consented to the disclosure | • Advertisers, ad platforms and networks, and social media platforms • Third parties whose cookies and tracking tools we use as described in Section 5 (Cookies and Tracking Technologies) • Commercial data partners to whom we make information available for their own marketing purposes • Partners who work with us on promotional or sponsorship opportunities, including co-branded products and services |
Audio, visual, or other sensory information (Section 2.G) | • Affiliates and subsidiaries • Professional consultants • Vendors necessary to complete transactions you request • Law enforcement, government, agencies, and other recipients for legal, security, or safety purposes • Other entities in connection with a corporate transaction • Entities to which you have consented to the disclosure | Not sold or shared |
Professional or employment-related information (Section 2.H) | • Affiliates and subsidiaries • Professional consultants • Vendors necessary to complete transactions you request • Law enforcement, government, agencies, and other recipients for legal, security, or safety purposes • Other entities in connection with a corporate transaction • Entities to which you have consented to the disclosure | Not sold or shared |
Education information (Section 2.I) | • Affiliates and subsidiaries • Professional consultants • Vendors necessary to complete transactions you request • Law enforcement, government, agencies, and other recipients for legal, security, or safety purposes • Other entities in connection with a corporate transaction • Entities to which you have consented to the disclosure | Not sold or shared |
Inferences (Section 2.J) | • Affiliates and subsidiaries • Professional consultants • Vendors necessary to complete transactions you request • Law enforcement, government, agencies, and other recipients for legal, security, or safety purposes • Other entities in connection with a corporate transaction • Entities to which you have consented to the disclosure | • Advertisers, ad platforms and networks, and social media platforms • Third parties whose cookies and tracking tools we use as described in Section 5 (Cookies and Tracking Technologies) • Commercial data partners to whom we make information available for their own marketing purposes • Partners who work with us on promotional or sponsorship opportunities, including co-branded products and services |
Sensitive Personal Information (Section 2.K) | • Affiliates and subsidiaries • Professional consultants • Vendors necessary to complete transactions you request • Law enforcement, government, agencies, and other recipients for legal, security, or safety purposes • Other entities in connection with a corporate transaction • Entities to which you have consented to the disclosure | Not sold or shared |
The categories of recipients in the chart above are used to mean:
A. Affiliates and subsidiaries, including parent entities, corporate affiliates, subsidiaries, business units, and other companies that share common ownership.
B. Professional consultants, such as accountants, lawyers, financial advisors, and audit firms.
C. Vendors necessary to complete a transaction that you request, such as shipping companies.
D. Law enforcement, government agencies, and other recipients for legal, security, or safety purposes, such as when we share information to comply with laws or legal requirements, to enforce or apply our Terms of Use, Terms of Service and other agreements or policies and to protect Company, our customers’, or third parties' safety, property, or rights.
E. Other entities in connection with a corporate transaction, such as if we, or some or all of our assets, are acquired by another entity, including through a sale in connection with bankruptcy or other forms of corporate change.
F. Entities to which you have consented to the disclosure.
Our Platforms (and authorized third parties) use cookies and other tracking technologies to collect information about you, your device, and how you interact with our Platforms. This section contains additional information about:
Our Platforms and the third parties that we authorize may use the following tracking technologies:
We and authorized third parties use these technologies for purposes including:
These tracking technologies collect data about you and your device, such as your IP address, cookie ID, device ID, AdID, operating system, browser used, browser history, search history, and information about how you interact with our Platforms (such as pages on our Platforms that you have viewed, including your specific mouse movements, page clicks, and other session replay information).
We may disclose information to third parties or allow third parties to directly collect information using these technologies on our Platforms such as social media companies, advertising networks, companies that facilitate session replay recordings and analysis, companies that provide analytics including ad tracking and reporting, security providers, and others that help us operate our business and Platforms.
Some of the third parties we work with participate with the Digital Advertising Alliance ("DAA") and Network Advertising Initiative ("NAI"). The DAA and NAI provide mechanisms for you to opt out of interest-based advertising performed by participating members at http://www.aboutads.info/choices/ and https://optout.networkadvertising.org/.
You can also refuse or delete cookies using your browser settings. If you refuse or delete cookies, some of our Platforms’ functionality may be impaired. Please refer to your browser’s Help instructions to learn more about how to manage cookies and the use of other tracking technologies. If you change computers, devices, or browsers; use multiple computers, devices, or browsers; or delete your cookies, you may need to repeat this process for each computer, device, or browser. Opting out of interest-based advertising will not opt you out of all advertising, but rather only interest-based advertising from us or our agents or representatives.
Some browsers have incorporated Do Not Track (“DNT”) preferences. We do not currently honor such signals.
Our Information Governance and Records Management Program establishes and maintains company policies and procedures governing the creation, retention, storage, and disposition of corporate records and information, provided that such information to be deleted or destroyed is not subject to regulatory requirement to retain it or a legal hold. We retain corporate records for the minimum time period required by law or regulation and/or for a longer period of time consistent with business needs. We determine retention periods for corporate record information using both legal/regulatory citations and business requirements. Citations for retention periods are regularly reviewed by outside counsel and updated as necessary. CCPA rights request records are subject to a two year retention period as required by California law.
California Consumers may have certain rights, subject to legal limitations, regarding the collection, use, and sharing of Personal Information under the CCPA, such as:
You may exercise a Right to Know, Right to Delete, Right to Correct, and Right to Limit Sensitive Personal Information Processing via our webform.
You may exercise your preferences and learn about the Right to Opt-Out of Sale/Sharing by visiting our Preference Center. To the extent required by law, we will honor opt-out preference signals sent in a format commonly used and recognized by businesses, such as an HTTP header field or JavaScript object. We will process opt-out preference signals at the browser level.
If you need assistance submitting a request or have questions regarding this Disclosure or how the Company uses your Personal Information, please contact us at 1-877-777-9154 or email us at privacyrequest@massmutual.com
Non-Discrimination: We will not discriminate against you in any manner prohibited by law for exercising your privacy rights.
Verification: In order to process requests, we may need to obtain information to locate you in our records or verify your identity using reasonable methods. For Right to Know, Right to Delete, Right to Correct, and Right to Limit Processing of Sensitive Personal Information, we will collect some or all of the following data elements: Name, Date of Birth, Email, Phone Number, and Address. We use a third party identity verification and fraud prevention service to verify the information you provide on your rights request form and which may present you with additional knowledge-based questions. When it comes to identity verification, our third party only tells us whether your identity passes verification and we do not use this information for any other purpose. In some cases, we may ask for more or different information if needed to otherwise support you request such as in cases of authorized agents. To exercise the Right to Opt Out of Sale/Sharing, you may be asked to provide and verify your email address.
Authorized Agents: Authorized agents may exercise rights on behalf of consumers by submitting a rights request via our online webform and indicating that they are submitting the request as an agent. Agents should provide their own information to verify the agent’s identity, after which we will contact the agent with additional instructions to complete the consumer right submission process. We may require agents to demonstrate authority to act on behalf of a consumer by providing signed permission and may require consumers to directly verify their identity with us using the methods described above.
Timing: We will respond to Right to Know, Right to Delete, and Right to Correct requests within 45 days, unless we need more time, in which case, we will notify you and may take up to 90 days total to respond to your request. We will respond to Right to Limit Sensitive Personal Information Processing and Right to Opt Out of Sale/Sharing requests within 15 days.
January - December 2023
Category | Received | Complied with (whole/in part) | Denied | Median Days to respond |
---|---|---|---|---|
Request To Know | 5 | 5 | 0 | 14 |
Request To Delete | 2 | 2 | 0 | 49.5 |
Request To Correct | 0 | 0 | 0 | 0 |
Request to Limit use of Sensitive Personal Information | 6 | 6 | 0 | 14.5 |
Requests To Opt-Out | 124,099 | 124,099 | 0 | 0 |
If you need assistance submitting a request or have questions regarding this Privacy Disclosure or how MassMutual uses your Personal Information, please contact us at 1-877-777-9154 or email us at privacyrequest@massmutual.com