Privacy Policy

Empower takes data privacy very seriously and is committed to protecting and respecting the privacy, security, and integrity of your personal information. This policy sets out key information regarding Empower and how your personal information will be collected, used, and protected.

Please note that certain portions of this policy may, or may not, be applicable to you based on the services and products in which you are enrolled and applicable laws. This policy is supplemented by specific notices, set out in links within this policy, that provide additional information pertaining to your relationship with Empower or addressing the requirements of the jurisdiction in which you live. In this policy, the terms “Empower,” “we”, “us” and “our” refer to each and all of the Empower family of companies listed at the end of this policy. 

In this privacy policy, we will cover:

What data we collect

Empower collects your “personal information” or “personal data” (ie: information that when used alone or with other relevant data may be capable of personally identifying you, or as defined by applicable law). Data that does not identify a natural person (such as data that is aggregated and anonymized) is not “personal information” and is not subject to this Privacy Policy.  The information that we collect, and how we use it, depends on your relationship with us and may change as your relationship evolves with us. This Privacy Policy is organized based on those different types of relationships as described below.

  • Visitors: individuals who visit our public website without logging into an account or using our services.
  • Users: individuals who establish an account with us or otherwise use our service offerings, including our financial dashboard software. Together with our Terms of Use, this Privacy Policy governs the use of the Empower Personal Dashboard.
  • Participants: individuals who are enrolled in an employee stock purchase plan (“ESPS participants”); a consumer-directed healthcare plan (“CDH participants”); or retirement plan. Note that in this capacity, Empower is acting as a service provider to provide plan retirement services to your current or former employer (“plan sponsor”). In this context. We collect and process personal data pursuant to the instructions provided by the Plan Sponsor.
  • Retail customers: individuals who are enrolled directly with Empower for financial services. These products and services include but are not limited to: IRA products, Empower brokerage, managed portfolios, Empower Personal Cash™, and advisory services. Please note that data held by Empower for these “retail” products and services are subject to the data-protection requirements of Gramm-Leach-Bliley and, as such, may be exempt from some data privacy laws.
  • Insurance customers: Individuals who have engaged in or purchased insurance products from Empower.
  • Advisory clients: Individuals who open an Empower Personal Strategy®  account and become advisory clients of Empower Advisory Group, LLC or become clients of our Wealth Management and Empower Advisory Services and establish an Empower-managed investment account.
  • California employees, Job applicants, and independent contractors: For information on how we collect, process, and protect your personal information as well as privacy rights applicable to you, please refer to our Privacy Notice for California Employees, Job Applicants, and Independent Contractors.

You may fall into more than one category concurrently, depending on your relationship with us. For example, if you are a Personal Cash customer you may also be a Visitor before logging into your dashboard, wherein you will also be a User. After your relationship with us ends, the terms of this policy shall continue to be applicable to your data for as long as we retain your data.

The table below describes the personal information we have collected and shared in the preceding 12 months and may continue to collect and share.

Identifiers

This may include your real name, alias, postal address, unique personal identifier, online identifier, internet protocol
(IP) address, email address, account name, Social Security number, driver’s license number, passport number, or other
similar identifiers.

To whom this applies

This applies to visitors, users, participants, retail customers, insurance customers, and advisory clients.

Retention

We retain this information until all applicable legal and business obligations are fulfilled.

We do not sell this category of personal information or share it with unaffiliated third parties for the purpose of targeted
advertising; we may, however, disclose this information to third parties for a business purpose as described below.

We collect this information from the following sources:
 
Categories of third parties with
whom we disclose this category of personal information:
 
Business purpose for collecting
and disclosing this information:
 

• From you or your representative when you communicate with us through web, email, phone, or other correspondence; complete applications and forms for various products or services; or provide other information on our websites• From your device when you browse our websites or mobile applications and from tracking technologies in emails that we or our suppliers send to you• From activity in your account (for example, data from the administration of your investments, balances, trades, and elections). If you enroll in account aggregation services, we may also collect information from the accounts that you linked as approved by you.• From our service providers and other third parties• From your plan sponsor (your employer or former employer)• From our suppliers, consumer and insurance reporting companies, data providers, and other third parties as permitted by law• From other sources to complete transactions initiated by you or your representative (for example, to transfer balances from another retirement account into a new retirement account)• We may have also obtained this information from our affiliates or if it was held by a business that we acquired.

• Plan sponsors or their agents• Our service providers• Our banking provider (if you are an Empower Personal Cash customer)• Our custodial brokerage providers (if you are an advisory client)• Third-party identity-verification providers and fraud-analysis providers• Persons acting as a fiduciary or representative capacity on your behalf• Our affiliates and subsidiaries We may also disclose this information in connection with a proposed or actual sale, merger, transfer, or exchange of all or part of our business.For more information on these types of recipients, please see How We Share Data

• To provide our services and products to you or the plan sponsor of your retirement plan.• To detect security incidents and protect against or prevent actual or potential fraud, unauthorized transactions, claims, or other liability.• To comply with federal, state, or local laws, rules, and other applicable legal requirements.• To comply with a properly authorized civil, criminal, or regulatory investigation or subpoena.• For institutional risk control, or for resolving customer disputes or inquiries.• To protect the confidentiality or security of our records pertaining to you, the service or product, or a specific transaction.• To undertake internal research for technological development and demonstration.• To verify, maintain, or improve the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business.• For purposes otherwise permitted or required by law. 

Financial information*

This may include contact and financial information such as your name, signature, Social Security number, address, telephone number, bank account number, or other financial information.

To whom this applies

We may collect this information from users, participants, retail customers, insurance customers, and advisory clients.

Retention

We retain this information until all applicable legal and business obligations are fulfilled. 

We do not sell this category of personal information or share it with unaffiliated third parties for the purpose of targeted advertising; we may, however, disclose this information to third parties for a business purpose as described below.

We collect this information from the following sources:
 
Categories of third parties with
whom we disclose this category of personal information:
 
Business purpose for collecting
and disclosing this information:
 

• From you or your representative when you communicate with us through web, email, phone, or other correspondence; complete applications and forms for various products or services; or provide other information on our websites• From your device when you browse our websites or mobile applications and from tracking technologies in emails that we or our suppliers send to you• From activity in your account (for example, data from the administration of your investments, balances, trades, and elections). If you enroll in account aggregation services, we may also collect information from the accounts that you linked as approved by you.• From our service providers and other third parties• From your plan sponsor (your employer or former employer)• From our suppliers, consumer and insurance reporting companies, data providers, and other third parties as permitted by law• From other sources to complete transactions initiated by you or your representative (for example, to transfer balances from another retirement account into a new retirement account)• We may have also obtained this information from our affiliates or if it was held by a business that we acquired.

• Plan sponsors or their agents• Our service providers• Our banking provider (if you are an Empower Personal Cash customer)• Our custodial brokerage providers (if you are an advisory client)• Third-party identity-verification providers and fraud-analysis providers• Persons acting as a fiduciary or representative capacity on your behalf• Our affiliates and subsidiariesWe may also disclose this information in connection with a proposed or actual sale, merger, transfer, or exchange of all or part of our business.For more information on these types of recipients, please see How We Share Data

• To provide our services and products to you or the plan sponsor of your retirement plan.• To detect security incidents and protect against or prevent actual or potential fraud, unauthorized transactions, claims, or other liability.• To comply with federal, state, or local laws, rules, and other applicable legal requirements.• To comply with a properly authorized civil, criminal, or regulatory investigation or subpoena.• For institutional risk control, or for resolving customer disputes or inquiries.• To protect the confidentiality or security of our records pertaining to you, the service or product, or a specific transaction.• To undertake internal research for technological development and demonstration.• To verify, maintain, or improve the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business.• For purposes otherwise permitted or required by law. 

* This includes categories listed in the California Records Statute [Cal. Civ. Code § 1798.80(e)].

Characteristics of protected classifications under state or federal law

This may include, for example, your age, marital status, gender, race, and medical conditions.

To whom this applies

We may collect this information from visitors, users, participants, retail customers, insurance customers, and advisory clients.

Retention

We retain this information until all applicable legal and business obligations are fulfilled.

We do not sell this category of personal information or share it with unaffiliated third parties for the purpose of targeted advertising; we may, however, disclose this information to third parties for a business purpose as described below.

We collect this information from the following sources:
 
Categories of third parties with
whom we disclose this category of personal information:
 
Business purpose for collecting
and disclosing this information:
 

• From you or your representative when you communicate with us through web, email, phone, or other correspondence; complete applications and forms for various products or services; or provide other information on our websites• From your device when you browse our websites or mobile applications and from tracking technologies in emails that we or our suppliers send to you• From activity in your account (for example, data from the administration of your investments, balances, trades, and elections). If you enroll in account aggregation services, we may also collect information from the accounts that you linked as approved by you.• From our service providers and other third parties• From your plan sponsor (your employer or former employer)• From our suppliers, consumer and insurance reporting companies, data providers, and other third parties as permitted by law• From other sources to complete transactions initiated by you or your representative (for example, to transfer balances from another retirement account into a new retirement account)• We may have also obtained this information from our affiliates or if it was held by a business that we acquired.

• Plan sponsors or their agents• Our service providers• Our banking provider (if you are an Empower Personal Cash customer)• Our custodial brokerage providers (if you are an advisory client)• Third-party identity-verification providers and fraud-analysis providers• Persons acting as a fiduciary or representative capacity on your behalf• Our affiliates and subsidiariesWe may also disclose this information in connection with a proposed or actual sale, merger, transfer, or exchange of all or part of our business.For more information on these types of recipients, please see How We Share Data

• To provide our services and products to you or the plan sponsor of your retirement plan.• To detect security incidents and protect against or prevent actual or potential fraud, unauthorized transactions, claims, or other liability.• To comply with federal, state, or local laws, rules, and other applicable legal requirements.• To comply with a properly authorized civil, criminal, or regulatory investigation or subpoena.• For institutional risk control, or for resolving customer disputes or inquiries.• To protect the confidentiality or security of our records pertaining to you, the service or product, or a specific transaction.• To undertake internal research for technological development and demonstration.• To verify, maintain, or improve the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business.• For purposes otherwise permitted or required by law. 

Biometric information

We collect government-issued ID images (front/back), selfie images/video, facial templates or embeddings (biometric identifiers), and voice recordings/voiceprints for identity verification and fraud prevention. 

To whom this applies

This applies to participants, retail customers, insurance customers, and advisory clients.

Retention

We retain this information until all applicable legal and business obligations are fulfilled.

We do not sell this category of personal information or share it with unaffiliated third parties for the purpose of targeted advertising; we may, however, disclose this information to third parties for a business purpose as described below.

We collect this information from the following sources:
 
Categories of third parties with
whom we disclose this category of personal information:
 
Business purpose for collecting
and disclosing this information:
 
 • From you or your representative when you communicate with us through web, email, phone, or other correspondence; complete applications and forms for various products or services; or provide other information on our websites
• Plan sponsors or their agents• Our service providers• Our banking provider (if you are an Empower Personal Cash customer)• Our custodial brokerage providers (if you are an advisory client)• Third-party identity-verification providers and fraud-analysis providers• Persons acting as a fiduciary or representative capacity on your behalf• Our affiliates and subsidiariesWe may also disclose this information in connection with a proposed or actual sale, merger, transfer, or exchange of all or part of our business.For more information on these types of recipients, please see How We Share Data

• To provide our services and products to you or the plan sponsor of your retirement plan.• To detect security incidents and protect against or prevent actual or potential fraud, unauthorized transactions, claims, or other liability.• To comply with federal, state, or local laws, rules, and other applicable legal requirements.• To comply with a properly authorized civil, criminal, or regulatory investigation or subpoena.• For institutional risk control, or for resolving customer disputes or inquiries.• To protect the confidentiality or security of our records pertaining to you, the service or product, or a specific transaction.• To verify, maintain, or improve the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business.• For purposes otherwise permitted or required by law. 

Internet or other similar network activity

This includes, but is not limited to, browsing history, search history, and information regarding a consumer’s interaction
with an internet website, application, or advertisement. For example, we collect your IP address and cookies from your
browser to recognize you and deliver a consistent experience when you visit our site and to measure the effectiveness of
our marketing. We also collect information about how you interact with our website as well as your preferences when you
elect to receive or opt out of cookies, communications involving email, texting, or telephone calls; these preferences apply
to Empower communications with you and are not shared with nor transferable to third parties.

To whom this applies

We may collect this information from visitors, users, retirement plan participants, retail customers, insurance customers, and advisory clients.

Retention

We retain this information until all applicable legal and business obligations are fulfilled.

While we do not share your personal information with third parties for monetary gain, some data privacy laws have a broader
definition of “sale” and “share” that may be applicable to the use of certain third-party cookies, tags, pixels, or web beacons
(collectively, “cookies”) on our websites or mobile applications. In this context, Empower and our advertising partners use cookies
and the advertising identifier associated with your mobile or internet-connected device.

We collect this information from the following sources:
 
Categories of third parties with
whom we disclose this category of personal information:
 
Business purpose for collecting
and disclosing this information:
 
 • From you or your representative when you communicate with us through web, email, phone, or other correspondence; complete applications and forms for various products or services; or provide other information on our websites• From our service providers and other third parties• From your device when you browse our websites or mobile applications and from tracking technologies in emails that we or our suppliers send to you• We may have also obtained this information from our affiliates or if it was held by a business that we acquired.
• Plan sponsors or their agents• Our service providers• Our banking provider (if you are an Empower Personal Cash customer)• Our custodial brokerage providers (if you are an advisory client)• Third-party identity-verification providers and fraud-analysis providers• Persons acting as a fiduciary or representative capacity on your behalf• Our affiliates and subsidiariesWe may also disclose this information in connection with a proposed or actual sale, merger, transfer, or exchange of all or part of our business.For more information on these types of recipients, please see How We Share Data

• To provide our services and products to you or the plan sponsor of your retirement plan.• To detect security incidents and protect against or prevent actual or potential fraud, unauthorized transactions, claims, or other liability.• To comply with federal, state, or local laws, rules, and other applicable legal requirements.• To comply with a properly authorized civil, criminal, or regulatory investigation or subpoena.• For institutional risk control, or for resolving customer disputes or inquiries.• To protect the confidentiality or security of our records pertaining to you, the service or product, or a specific transaction.• To undertake internal research for technological development and demonstration.• To verify, maintain, or improve the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business.• For purposes otherwise permitted or required by law. 

Geolocation data

We collect your IP address from you when you visit our websites.

To whom this applies

This applies to visitors, users, retirement plan participants, retail customers, insurance customers, and advisory clients.

Retention

We retain this information until all applicable legal and business obligations are fulfilled.

We do not sell this category of personal information or share it with unaffiliated third parties for the purpose of targeted
advertising; we may, however, disclose this information to third parties for a business purpose as described below.

We collect this information from the following sources:
 
Categories of third parties with
whom we disclose this category of personal information:
 
Business purpose for collecting
and disclosing this information:
 

• From you or your representative when you communicate with us through web, email, phone, or other correspondence; complete applications and forms for various products or services; or provide other information on our websites• From your device when you browse our websites or mobile applications and from tracking technologies in emails that we or our suppliers send to you• From activity in your account (for example, data from the administration of your investments, balances, trades, and elections). If you enroll in account aggregation services, we may also collect information from the accounts that you linked as approved by you.• From our service providers and other third parties• From your plan sponsor (your employer or former employer)• From our suppliers, consumer and insurance reporting companies, data providers, and other third parties as permitted by law• From other sources to complete transactions initiated by you or your representative (for example, to transfer balances from another retirement account into a new retirement account)• We may have also obtained this information from our affiliates or if it was held by a business that we acquired.

• Plan sponsors or their agents• Our service providers• Our banking provider (if you are an Empower Personal Cash customer)• Our custodial brokerage providers (if you are an advisory client)• Third-party identity-verification providers and fraud-analysis providers• Persons acting as a fiduciary or representative capacity on your behalf• Our affiliates and subsidiariesWe may also disclose this information in connection with a proposed or actual sale, merger, transfer, or exchange of all or part of our business.For more information on these types of recipients, please see How We Share Data

• To provide our services and products to you or the plan sponsor of your retirement plan.• To detect security incidents and protect against or prevent actual or potential fraud, unauthorized transactions, claims, or other liability.• To comply with federal, state, or local laws, rules, and other applicable legal requirements.• To comply with a properly authorized civil, criminal, or regulatory investigation or subpoena.• For institutional risk control, or for resolving customer disputes or inquiries.• To protect the confidentiality or security of our records pertaining to you, the service or product, or a specific transaction.• To undertake internal research for technological development and demonstration.• To verify, maintain, or improve the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business.• For purposes otherwise permitted or required by law. 

Audio, electronic, visual, thermal, olfactory, or similar information

We collect voice recordings, voiceprint data, and pictures to verify your identity.

To whom this applies

This applies to retirement plan participants, retail customers, insurance customers, and advisory clients.

Retention

We retain this information until all applicable legal and business obligations are fulfilled.

We do not sell this category of personal information or share it with unaffiliated third parties for the purpose of targeted
advertising; we may, however, disclose this information to third parties for a business purpose as described below.

We collect this information from the following sources:
 
Categories of third parties with
whom we disclose this category of personal information:
 
Business purpose for collecting
and disclosing this information:
 

• From you or your representative when you communicate with us through web, email, phone, or other correspondence; complete applications and forms for various products or services; or provide other information on our websites• From your device when you browse our websites or mobile applications and from tracking technologies in emails that we or our suppliers send to you• From activity in your account (for example, data from the administration of your investments, balances, trades, and elections). If you enroll in account aggregation services, we may also collect information from the accounts that you linked as approved by you.• From our service providers and other third parties• From your plan sponsor (your employer or former employer)• From our suppliers, consumer and insurance reporting companies, data providers, and other third parties as permitted by law• From other sources to complete transactions initiated by you or your representative (for example, to transfer balances from another retirement account into a new retirement account)• We may have also obtained this information from our affiliates or if it was held by a business that we acquired.

• Plan sponsors or their agents• Our service providers• Our banking provider (if you are an Empower Personal Cash customer)• Our custodial brokerage providers (if you are an advisory client)• Third-party identity-verification providers and fraud-analysis providers• Persons acting as a fiduciary or representative capacity on your behalf• Our affiliates and subsidiariesWe may also disclose this information in connection with a proposed or actual sale, merger, transfer, or exchange of all or part of our business.For more information on these types of recipients, please see How We Share Data

• To provide our services and products to you or the plan sponsor of your retirement plan.• To detect security incidents and protect against or prevent actual or potential fraud, unauthorized transactions, claims, or other liability.• To comply with federal, state, or local laws, rules, and other applicable legal requirements.• To comply with a properly authorized civil, criminal, or regulatory investigation or subpoena.• For institutional risk control, or for resolving customer disputes or inquiries.• To protect the confidentiality or security of our records pertaining to you, the service or product, or a specific transaction.• To undertake internal research for technological development and demonstration.• To verify, maintain, or improve the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business.• For purposes otherwise permitted or required by law. 

Professional or employment-related information

This may include information such as your job title, date of hire, employer name, and industry.

To whom this applies

This applies to retirement plan participants, retail customers, insurance customers, and advisory clients.

Retention

We retain this information until all applicable legal and business obligations are fulfilled.

We do not sell this category of personal information or share it with unaffiliated third parties for the purpose of targeted
advertising; we may, however, disclose this information to third parties for a business purpose as described below.

We collect this information from the following sources:
 
Categories of third parties with
whom we disclose this category of personal information:
 
Business purpose for collecting
and disclosing this information:
 

• From you or your representative when you communicate with us through web, email, phone, or other correspondence; complete applications and forms for various products or services; or provide other information on our websites• From your device when you browse our websites or mobile applications and from tracking technologies in emails that we or our suppliers send to you• From activity in your account (for example, data from the administration of your investments, balances, trades, and elections). If you enroll in account aggregation services, we may also collect information from the accounts that you linked as approved by you.• From our service providers and other third parties• From your plan sponsor (your employer or former employer)• From our suppliers, consumer and insurance reporting companies, data providers, and other third parties as permitted by law• From other sources to complete transactions initiated by you or your representative (for example, to transfer balances from another retirement account into a new retirement account)• We may have also obtained this information from our affiliates or if it was held by a business that we acquired.

• Plan sponsors or their agents• Our service providers• Our banking provider (if you are an Empower Personal Cash customer)• Our custodial brokerage providers (if you are an advisory client)• Third-party identity-verification providers and fraud-analysis providers• Persons acting as a fiduciary or representative capacity on your behalf• Our affiliates and subsidiariesWe may also disclose this information in connection with a proposed or actual sale, merger, transfer, or exchange of all or part of our business.For more information on these types of recipients, please see How We Share Data

• To provide our services and products to you or the plan sponsor of your retirement plan.• To detect security incidents and protect against or prevent actual or potential fraud, unauthorized transactions, claims, or other liability.• To comply with federal, state, or local laws, rules, and other applicable legal requirements.• To comply with a properly authorized civil, criminal, or regulatory investigation or subpoena.• For institutional risk control, or for resolving customer disputes or inquiries.• To protect the confidentiality or security of our records pertaining to you, the service or product, or a specific transaction.• To undertake internal research for technological development and demonstration.• To verify, maintain, or improve the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business.• For purposes otherwise permitted or required by law. 

Inferences drawn from personal information

This includes inferences about your preferences, characteristics, psychological trends, predispositions, behavior, attitudes,
intelligence, abilities, and aptitudes to create a profile about you.

To whom this applies

This applies to visitors, users, retirement plan participants, retail customers, insurance customers, and advisory clients.

Retention

We retain this information until all applicable legal and business obligations are fulfilled.

We do not sell this category of personal information or share it with unaffiliated third parties for the purpose of targeted
advertising; we may, however, disclose this information to third parties for a business purpose as described below.

We collect this information from the following sources:
 
Categories of third parties with
whom we disclose this category of personal information:
 
Business purpose for collecting
and disclosing this information:
 

• From you or your representative when you communicate with us through web, email, phone, or other correspondence; complete applications and forms for various products or services; or provide other information on our websites• From your device when you browse our websites or mobile applications and from tracking technologies in emails that we or our suppliers send to you• From activity in your account (for example, data from the administration of your investments, balances, trades, and elections). If you enroll in account aggregation services, we may also collect information from the accounts that you linked as approved by you.• From our service providers and other third parties• From your plan sponsor (your employer or former employer)• From our suppliers, consumer and insurance reporting companies, data providers, and other third parties as permitted by law• From other sources to complete transactions initiated by you or your representative (for example, to transfer balances from another retirement account into a new retirement account)• We may have also obtained this information from our affiliates or if it was held by a business that we acquired.

• Plan sponsors or their agents• Our service providers• Our banking provider (if you are an Empower Personal Cash customer)• Our custodial brokerage providers (if you are an advisory client)• Third-party identity-verification providers and fraud-analysis providers• Persons acting as a fiduciary or representative capacity on your behalf• Our affiliates and subsidiariesWe may also disclose this information in connection with a proposed or actual sale, merger, transfer, or exchange of all or part of our business.For more information on these types of recipients, please see How We Share Data

• To provide our services and products to you or the plan sponsor of your retirement plan.• To detect security incidents and protect against or prevent actual or potential fraud, unauthorized transactions, claims, or other liability.• To comply with federal, state, or local laws, rules, and other applicable legal requirements.• To comply with a properly authorized civil, criminal, or regulatory investigation or subpoena.• For institutional risk control, or for resolving customer disputes or inquiries.• To protect the confidentiality or security of our records pertaining to you, the service or product, or a specific transaction.• To undertake internal research for technological development and demonstration.• To verify, maintain, or improve the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business.• For purposes otherwise permitted or required by law. 

Sensitive personal information

Certain information may be considered sensitive personal information depending on your state of residence. We may
collect the following sensitive personal information: government identifiers, certain financial account information, status as
a victim of a crime (in order to process certain hardship distributions for retirement plan participants), demographic information
that may be considered sensitive, your citizenship status (in order to verify eligibility as an Empower Personal Cash
customer), and biometric data. If you are a CDH participant, we will also collect your health information to provide our services
to you. We limit our collection, use, and disclosure of this category of personal information to that which is necessary
to provide our services to you or for another permitted business purpose under applicable data privacy laws, such as
detecting security incidents. We do not use this information to infer characteristics about you.

To whom this applies

This applies to retirement plan participants, retail customers, insurance customers, and advisory clients.

Retention

We retain this information until all applicable legal and business obligations are fulfilled.

We do not sell this category of personal information or share it with unaffiliated third parties for the purpose of targeted
advertising; we may, however, disclose this information to third parties for a business purpose as described below.

We collect this information from the following sources:
 
Categories of third parties with
whom we disclose this category of personal information:
 
Business purpose for collecting
and disclosing this information:
 

• From you or your representative when you communicate with us through web, email, phone, or other correspondence; complete applications and forms for various products or services; or provide other information on our websites• From your device when you browse our websites or mobile applications and from tracking technologies in emails that we or our suppliers send to you• From activity in your account (for example, data from the administration of your investments, balances, trades, and elections). If you enroll in account aggregation services, we may also collect information from the accounts that you linked as approved by you.• From our service providers and other third parties• From your plan sponsor (your employer or former employer)• From our suppliers, consumer and insurance reporting companies, data providers, and other third parties as permitted by law• From other sources to complete transactions initiated by you or your representative (for example, to transfer balances from another retirement account into a new retirement account)• We may have also obtained this information from our affiliates or if it was held by a business that we acquired.

• Plan sponsors or their agents• Our service providers• Our banking provider (if you are an Empower Personal Cash customer)• Our custodial brokerage providers (if you are an advisory client)• Third-party identity-verification providers and fraud-analysis providers• Persons acting as a fiduciary or representative capacity on your behalf• Our affiliates and subsidiariesWe may also disclose this information in connection with a proposed or actual sale, merger, transfer, or exchange of all or part of our business.For more information on these types of recipients, please see How We Share Data

• To provide our services and products to you or the plan sponsor of your retirement plan.• To detect security incidents and protect against or prevent actual or potential fraud, unauthorized transactions, claims, or other liability.• To comply with federal, state, or local laws, rules, and other applicable legal requirements.• To comply with a properly authorized civil, criminal, or regulatory investigation or subpoena.• For institutional risk control, or for resolving customer disputes or inquiries.• To protect the confidentiality or security of our records pertaining to you, the service or product, or a specific transaction.• To undertake internal research for technological development and demonstration.• To verify, maintain, or improve the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by the business.• For purposes otherwise permitted or required by law. 

We do not collect nonpublic personal education information as defined in the Family Educational Rights and Privacy Act (20 U.S.C. Sec. 1232g; 34 C.F.R. Part 99).

How we use data

Empower uses your personal information to respond to your requests and inquiries and to provide you with services and products you receive from us. In the event you are enrolled in a retirement plan that is administered by Empower pursuant to a services agreement with the plan sponsor of your retirement plan (your employer or former employer), Empower will process your data to perform its services to the plan sponsor. If you contract directly with Empower or its affiliates for other services offered by Empower to individual customers, such as advisory services, financial products or financial wellness services, Empower will use your data to process transactions and perform its obligations in connection with such services. Empower will also use your data as permitted by law to make you aware of other financial products or services that may be of interest to you. Empower may use your data on an anonymized basis to conduct and publish aggregated research about the retirement or investment industries.

Empower will use your data for other purposes as permitted by law, including to protect your interests and ours in the detection, prevention and mitigation of fraud, to meet the requirements of applicable laws and regulations, to comply with requests of regulators with jurisdiction over our services, and for product development and delivery.

How we share data

We limit the information we share and the parties we share it with. What we share depends on the types of products or services you have procured and applicable law.

Further, personal information may be shared as necessary to effect, administer, or enforce a transaction you request or authorize, with your consent, at your direction, or as allowed by applicable law. Your health information will not be shared except as required or permitted by law. The chart below describes the categories of third parties with whom we share your data.

Sharing CategoryWhat do we share and why?
Plan SponsorsIf you are enrolled in a retirement plan offered by a plan sponsor (your employer or former employer), your personal information may be shared with the plan sponsor and with that plan sponsor’s third-party administrators, advisors, service providers, and other third parties as authorized or directed by the plan sponsor.
Our service providersLike most businesses, we use third-party service providers to deliver some of the services mentioned in this Privacy Policy. In doing so, we provide some of your data (including your personal information) to those third-party service providers, on a need-to-know basis. Our contracts with those service providers require them to safeguard your information and prohibit them from using your data for any purpose other than to provide services to us or to improve their services.
Empower Personal Cash account service providerIf you are an Empower Personal Cash customer, you will own a program account provided through the bank provider. The bank provider for our Empower Personal Cash customer program accounts is UMB Bank, National Association (“UMB”), and we will share detailed account information with UMB. Our contract with UMB requires them to treat your information as confidential information. UMB’s Privacy Policy is available here
Identity verification and fraud analysis providersWe will share some of your personal information and detailed account information with third-party identity verification providers and fraud-analysis providers for the sole purpose of verifying your identity and preventing fraudulent transactions. These providers are required under contract with us to safeguard your information and not provide it to any third parties except as required to provide the services or as otherwise required by law, regulation, or court order.
Your brokerage account(s)If you are an Advisory Client of Empower, you will have a custodial brokerage account that will hold your personal portfolio. Our custodial brokerage provider for our Advisory Clients’ accounts is Pershing, and we will share detailed advisory account information with them. You will have direct visibility, access, and interaction with Pershing while you are an Empower Advisory Client. Pershing’s Privacy Policy is available here
Affiliate sharingCertain personal information may be shared among our affiliates as permitted by law to provide our services to you, to make it easier to do business with us, and for their everyday business purposes.  We do not share your personal information with affiliates for their marketing purposes. From time to time, we may make you aware of products and services that are available from our affiliates. Our affiliates are listed below in this policy and include, but are not limited to, our broker-dealer, our advisory service provider, and our trust company.
Nonaffiliated third partiesYour personal information may be shared with nonaffiliated third parties to provide services on our behalf. These third parties agree to maintain the confidentiality of the personal information and use it solely to provide their services to us.
Security, legal, and regulatory sharingWe also reserve the right to disclose information about you that we believe, in good faith, is appropriate or necessary to (i) take precautions against liability; (ii) protect ourselves or others from fraudulent, abusive, or unlawful uses or activity; (iii) investigate and defend ourselves against any third-party claims or allegations; (iv) protect the security or integrity of the services we provide and any facilities or equipment used to make those services available; (v) comply with any law or regulatory requirement, including pursuant to a subpoena, court order, or other legal process; or (vi) protect our property or other legal rights (including, but not limited to, enforcement of our agreements) or the rights, property, or safety of others.

Deidentified or pseudonymous data

We maintain and use deidentified data in such a way that any information can no longer be linked to you or any device associated with you. After data has been deidentified, i) we maintain and use such deidentified data without attempting to reidentify the data or re-associate it with specific individuals; ii) we take reasonable measures to ensure that the information cannot be reassociated with you or your household; and iii) we have implemented technical and organizational safeguards as well as business processes designed to prohibit the reidentification of your information. Such data is used for research and benchmarking purposes. We contractually obligate all recipients of the deidentified data to comply with applicable laws pertaining to deidentification and we monitor compliance with any contractual commitments.

Children

Empower does not knowingly collect personal information from children under the age of 16 without seeking prior parental consent (if required by applicable law). We only use or disclose personal information about a child to the extent permitted by law, to seek parental consent pursuant to local law and regulations or to protect a child. The definitions of “child” or “children” may be slightly different as set forth in various applicable laws.

Security

We use physical administrative, and technical safeguards designed to protect the confidentiality, integrity and availability of your personal information. Any third-party service providers with whom we share your personal information agree to maintain the confidentiality and security of the personal information and use it solely to provide their services to us. In addition, Empower provides the Empower Security Guarantee to its customers and participants as described here.

Website and mobile application use

When you access our websites or mobile applications, we or our third-party suppliers use a variety of technologies, such as tags and web beacons, that automatically collect data (such as: without limitation, your device type, browser type, internet protocol address, operating system used, number of visits, average time spent on the site and pages viewed). This data is used to operate the websites more efficiently, maintain the security of your online session, improve our websites’ design and navigation, and perform online advertising (where permitted by law). If you have created an account with us, we may combine the data collected through the tracking systems described herein with other information we know about you, as permitted by law. We use this information internally to provide you with a better user experience and to offer you products and services that may be of interest to you.

We use session replay technology to help us understand how you interact with our website and to improve your experience. This technology captures your interactions—such as clicks, scrolling, and typing behavior—so we can identify usability issues and optimize our content. Sensitive information is automatically masked, and we do not use Session Replay to collect or store passwords, credit card numbers, or other sensitive data.

Some of our websites include links or navigation to third-party sites. These third-party sites may include informational sites, sites providing financial wellness tools and services, or services offered to you solely by a third party, as further described in the disclosures provided on such sites.