Employee, Job Applicant and Contractor Notice

Your privacy is a top priority for NONGSHIM AMERICA, INC. (the “Company”), and we make every reasonable effort to protect the information we hold about you.

Under the California Consumer Privacy Act, Company employees, job applicants and contractors who are California residents have the right to be informed as to the categories of personal information collected about them, and the purposes for which the information will be used.

In addition, California consumers, including Company customers who are California residents, have specific rights under the California Consumer Privacy Act of 2018. These rights are described in Company’s Privacy Policy.

Information We Collect and Disclose

Personal information that we collect and disclose about employees, job applicants and contractors

If permitted by law, we collect information about employees, retirees, job applicants and contractors from a variety of sources, including:

  • Directly or indirectly from you: In the context of your role or former role as a job applicant to, or an employee, retiree or contractor of Company. This may be collected by phone, by mail, by text, by email, through our website at https://nongshimusa.com, as well as from your use of Internet, our website, tracking devices, or through vendors who provide or deliver services on our behalf.
  • From Company equipment: Through devices installed in our facility and used in the context of your employment with Company.
  • From third parties: When we work with third parties such as recruiters, consumer reporting agencies, service providers, vendors, contractors, credit agencies, market researchers, or service providers who provide services on our behalf.
  • From other sources: We may supplement the information described above with information we obtain from other sources, including from both online and offline data providers.

For each category of personal information, the category of sources from which that information is collected, if permitted by law, is indicated in the table below:

Source of Personal Information Categories of Personal Information
Information You Provide •Identifiers
  • Personal information categories listed in the California Customer Records statute
  • Protected classifications characteristics underCalifornia or federal law
  • Commercial information
  • Biometric information
  • Sensory data
  • Professional or employment-related information
  • Non-public education information
Information We Collect by AutomatedMeans Online
  • Identifiers
  • Internet or other similar network activity
Information We Collect By Automated or Manual Means Through Company Equipment
  • Commercial information
  • Biometric information
  • Internet or other similar network activity
  • Geolocation data
  • Sensory data
  • Inferences drawn from other personal information
Information We Collect from Other Sources
  • Identifiers
  • Personal information categories listed in the California Customer Records statute
  • Protected classifications characteristics under California or federal law
  • Commercial information
  • Professional or employment-related information
  • Non-public education information
  • Inferences drawn from other personal information
  • Examples of information that we collect about you include:

    • Personal information you provide us when applying for employment or a contract with Company, or as a current or former employee or contractor of Company, or that we collect about you and use in the context of your current or former role as a job applicant to, an employee, retiree or contractor of Company. Such information may include your name, address, phone number, email address, date of birth, current or past job history, gender, languages, veteran status, financial information, Social Security number and other unique identifying numbers, background checks, including drug and other tests, academic/professional qualifications, education, résumé, reference letters and interview notes, your job title/position, office location, hire dates, employment contracts, emergency contacts information, performance evaluations and other information, awards and achievements, training and development records, compensation, time off information, eligibility to work in the United States, including information related to your immigration status, IT information, including information required to provide access to Company systems and networks such as IP addresses, log files, login information, software/hardware inventories, etc.; information regarding your compliance with our Code of Conduct and laws and regulations, information regarding workplace training, conduct performance-related reviews, monitor employment-related licenses and credentials, photographs, videos and other recordings, termination and post-employment data, grievance procedures. Such information also includes information that you choose to share with Company, for example hobbies, social preferences, etc.
    • Information used to determine eligibility in and administer certain employee compensation and benefits programs, including but not limited to issuance of benefits, to pay and reimburse for expenses, to provide you with employment or retiree-related services, to maintain your and your beneficiaries and dependents contact information, to conduct healthcare-related services. Such information includes employee benefit plans information, health-related information, special accommodations information, national insurance numbers, marital status, information related to your dependents, financial information such as banking details, tax information, payroll information, withholdings, salary, benefits, expenses, company allowances, stock and equity grants, various types of leave information (including sick leave, vacation, paid time off, FMLA leave, maternity/paternity leave, etc.).
    • Information that we collect to support work (including remote) environment, and to maintain its safety, security, and integrity of our work environment, facilities, systems, website, services, databases and other technology assets, and business. Such information includes tracking and monitoring information, including related to access badge readers, sign-in sheets, surveillance cameras, information related to use of our IT and communications systems, including online activity on work-authorized computers, devices and systems, information that we collect through ergonomic and other assessments, etc.
    • Information used to visit, register for, manage, or access your online or other Company employee or retiree accounts, such as your Company account number, name, address, phone number, and email address.
    • Information you give us when you communicate with Company and/or any of its representatives.
    • As described to you when collecting your personal information or as otherwise set forth in the California Consumer Privacy Act or subsequently agreed to by you.
    • We may supplement the information described above with information we obtain from other sources, including from both online and offline data providers. Such supplemental information may include contact information, such as your email address, demographic data, or other relevant information.

    In addition to the information above, within the preceding twelve (12) months, Company may have collected and may continue to collect, directly or indirectly from you, through its website or otherwise, and disclosed to service providers and third parties the categories of personal information identified below in the context of your role or former role as a job applicant to, or an employee, retiree or contractor of Company, or as required by law, or otherwise.

    In addition to Company, service providers and third parties to whom personal information has been disclosed on behalf of Company include contractors, vendors, service providers, government regulatory agencies, courts, labor unions, and other third parties with a legal right to the information. See also Information we obtain from your use of our website and How We Use Information below.

    Category Examples Information collected and disclosed
    A. Identifiers. A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s licensenumber, passport number, or other similar identifiers. Yes
    B. Personal information categories listed in the California Customer Records statute. A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identificationcard number, insurance policy number, education, employment, employment history,bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories. Yes
    C. Protected classification characteristics under California or federal law. Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancyor childbirth and related medical conditions),sexual orientation, veteran or military status,genetic information (including familial geneticinformation). Yes
    D. Biometric information. Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier oridentifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans,keystroke, gait, or other physical patterns. Yes
    E. Location data. Physical location or movements when at our facility. Yes
    F. Professional or employment-related information. Current or past job history or performance evaluations. Yes
    G. Non-public education information. Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financialinformation, or student disciplinary records. Yes

    Personal information does not include:

    • Publicly available information from government records
    • De-identified or aggregated consumer information
    • Information excluded by law from the definition of personal information, such as
    • Health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data; and
    • Personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FRCA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver’s Privacy Protection Act of 1994.

    Information we obtain from your use of our intranet that we make available

  • Your visits to Company’s intranet: We collect information about visits to our intranet, such as your employee number, name, department, position, access IP, access date and time, and use of the intranet.
  • Log Data: We receive information that is automatically recorded by our servers when you visit our website, including the type of web browser being used, the type of the operating system (OS) being used, the Network location, and your Internet Protocol (“IP”) Address. An IP address is a number automatically assigned to your computer every time you browse the Internet. When you visit the website, our servers log your current IP address. Your IP address is not associated with your personal information and we do not use it to identify you when logging IP address data.
  • Targeted Communications on Social Media Sites

    We use social media sites like Instagram, Facebook, Tik Tok, YouTube and Twitter to communicate with you about our products and services. You can follow us on these social media sites to receive regular updates. These social media sites also allow us to target ads to you using the information they maintain about you with your consent, even if you do not specifically follow us on their site. We may target ads to you using information such as cookies, pixels, zip codes, and interests.

    You will only see our targeted ads if you agreed to receive this type of communication through your social media provider. You may be able to disable some or all of the advertising targeted to you on a social media site by adjusting your privacy settings on their site.

    Links to other websites

    While browsing Company’s website or online services not sponsored by Company, you may encounter and choose to access websites or online services operated by Nongshim Korea, Nongshim Japan and/or Nongshim China by clicking on hypertext links or icons. These websites may send their own cookies to you, log your IP address, and/or otherwise collect data or personal information about you and your online activities. Company does not control and is not responsible for what outside entities do in connection with their websites or online services, or how they handle your personal information. Please use caution and consult the privacy policies posted on each outside website that you visit for further information.

    How We Use Information and Share Information with Service Providers and Third Parties

    Company collects, uses, and discloses your personal information to fulfill the following business and legally required purposes:

    • In the context of your current or former role as a job applicant to, or an employee, retiree or contractor of Company, including for recruitment purposes, to administer benefits, pay and reimburse for expenses, conduct performance-related reviews, monitor employment-related licenses and credentials, provide you with employment or retirement-related services, maintain your and your beneficiaries and dependents contact information, monitor eligibility to work in the United States, conduct healthcare-related services, monitor your compliance with our Code of Conduct and law and regulations, maintain security of our internet-connected assets and systems.
    • Support our work (including remote) environment and maintain the safety, security, and integrity of our work environment, systems, website, apps, services, databases and other technology assets, and business.
    • Comply with a valid warrant, subpoena, or court order, or exercise or defend legal claims.
    • Comply with applicable law or regulatory requirements, or comply with a request or order from other local, state or federal governmental agencies with legal authority to obtain the personal information from Company.
    • Develop and implement marketing, education and outreach plans in the context of your employment or past employment with Company.
    • Protect the safety and security of Company’s customers, visitors, employees and contractors by collecting and reviewing personal information to protect against fraud, other crimes and threats to safety.
    • For any other business or lawful purpose reasonably anticipated within the context of Company’s relationship with you.

    Sharing Personal Information with Service Providers and Third Parties

    In the context of your role or former role as a job applicant to, or an employee, retiree or contractor of Company, and in order to provide you with services or to complete transactions requested by you, we may transfer your personal information to service providers who act on our behalf. Service providers acting on Company’s behalf are required to follow the similar privacy and security practices as Company and are subject to an extensive security review of their data handling processes before Company permits any sharing of personal information, except as subject to different requirements under applicable laws or regulations.

    Company does not disclose an employee’s, former employee’s, retiree’s, job applicant’s, or contractor’s personal information to any other person or business entity without your prior consent, except as necessary for the purposes listed above.

    Company may share aggregated, non-employee specific data and information derived from personal information with other entities for the purpose of:

    • Maintaining safe and healthy workplace and the health and safety of our employees, customers and communities, among other things due to the COVID-19 pandemic.

    If permitted by law, we typically disclose the following categories of personal information to the following categories of entities for a business purpose or to comply with legal obligations:

    Categories of Entities Categories of PI Disclosed
    Third Parties Receiving Personal Information Pursuant to a Valid Legal Warrant, Subpoena, Court Order or Legal or Regulatory Mandate, or Necessary for Company to Defend or Assert Legal Claims
    • Identifiers
    • Personal information categories listed in the California Customer Records statute
    • Protected classification characteristics under California or federal law
    • Commercial Information
    • Biometric information
    • Internet or other similar network activity
    • Geolocation data
    • Sensory data
    • Professional or employment-related information
    • Non-public education information
    • Inferences drawn from other personal information
    Service Providers, Contractors, Vendorsand Other Third Parties Which Provide Support for Company General Business Processes and Purposes
    • Identifiers
    • Personal information categories listed in the California Customer Records statute
    • Protected classification characteristics under California or federal law
    • Commercial Information
    • Biometric information
    • Internet or other similar network activity
    • Geolocation data
    • Sensory data
    • Professional or employment-related information
    • Non-public education information
    • Inferences drawn from other personal information