Privacy Notice & Notice at Collection

Last Updated 2/17/2026

Notice at Collection

At or before the time of collection of your Personal Information, you have a right to receive notice of our privacy practices.  We provide this information through our Privacy Policy and within our California Privacy Notice.  There are links to our Privacy Notices appearing at the bottom of our website pages. This Notice includes information concerning the categories of Personal Information and Sensitive Personal Information we may collect, the purposes for which such information is collected or used, whether such information is “sold or shared” as defined under California law and how long such information is retained.

Privacy Notice

BerkOne is a privacy conscious organization and is committed to your right to privacy and safeguarding the privacy of visitors to our website and users of our services. We recognize that consumer information is valuable, and we take reasonable measures to protect your information while it is in our care.

BerkOne adheres to high standards of integrity in the performance of our business services.  We continually take steps to ensure that our software, networks, policies, and procedures comply with the applicable legal and regulatory requirements. BerkOne has established administrative, physical, and technical safeguards to reasonably protect the confidentiality, integrity, and availability of consumers’ personally identifiable information PII and sensitive PII that is created, received, maintained, or transmitted on behalf of BerkOne or our clients, including:

  • When information is provided to BerkOne, we use it only for the purposes for which it was provided.
  • BerkOne prohibits the sale or unauthorized distribution of any consumer data we receive, including, but not limited to: personally identifiable information to third parties, sensitive PII, PCI information, protected health information. 
  • We process information in accordance with our Information Security Policy which is reviewed and updated annually.
  • An external auditing firm performs an annual SSAE18 Audit Type II “Report on Controls at a Service Organization Relevant to Security, Availability, and Processing Integrity”, commonly referred to as a SOC2 Report. BerkOne has been certified as SOC2 compliant since 2012. Prior to SOC2, BerkOne was certified compliant with the previous standard – SAS070 – since 2002.
  • An external security firm performs an annual external penetration test to assess our cyber-security controls.

Introduction

This Privacy Notice explains how BerkOne handles and protects information provided to us by our clients, customers and prospective customers. It also explains the rights of individuals to their information under certain US and foreign laws.

Our Privacy Notice is the complete agreement between you, as an individual, and BerkOne with respect to our use of your information. You agree to the most recent version of our Privacy Notice by using our website(s) or portals(s). We encourage you to read this Privacy Notice each time you visit our website. BerkOne may change this Privacy Notice any time and for any reason. The current version supersedes all prior versions.

You may be subject to additional Terms of Service that may apply when you access particular materials in this website, follow a link from this website or use a BerkOne service.  Throughout this statement, “we”, “us” and “our” refers to BerkOne, Inc.

Organization

The remainder of this Privacy Notice is arranged as follows:

  • Section 1: How information is provided to BerkOne
  • Section 2: What kind of information is provided to BerkOne
  • Section 3: How BerkOne handles information is provided to BerkOne
  • Section 4: Whether the information will be sold or shared with third parties.
  • Section 5: The length of time the information will be retained.
  • Section 6: Children Under 18
  • Section 7: Contacting BerkOne
  • Section 8: Privacy Regulations
  • Section 9: Multi-State Addendum 

Section 1: How information is provided to BerkOne

BerkOne provides business services to entities of all types: for-profit companies across all industries; governments and their agencies, departments and bureaus; school districts; and non-profit organizations. We define these entities as BerkOne’s “clients”. Consequently, BerkOne is primarily considered a business-to-business (“B2B”) / business-to-government (“B2G”) company. As a B2B / B2G company, BerkOne provides services to our clients and does not directly communicate with our client’s customers. Direct contact between our clients and their individual customers is solely and completely managed by BerkOne’s client organizations.

Information is provided to BerkOne in four ways:

  1. BerkOne’s clients provide information regarding their customers, suppliers, vendors or other stakeholders to BerkOne. Examples of BerkOne’s clients are other companies, governmental units, school districts, non-profits or similar organizations. BerkOne provides our clients with specific agreed-upon services.
  2. Individuals representing our clients and individual customers may access BerkOne’s website(s) or portal(s) in the course of receiving services, may choose to provide personally identifiable information (“PII”) (defined in Section 2), Sensitive Personal Information (“SPI”) (defined in section 2), organizational information or information regarding stakeholders.
  3. Visitors to our website may choose to voluntarily provide PII or sensitive PII in order to request more information regarding BerkOne’s products and services.
  4. BerkOne may acquire information from third parties to assist BerkOne in sales, marketing, promotional, analytical or other activities.

Section 2:  What kind of information is provided to BerkOne

BerkOne may receive the following types of information in a variety of formats, both electronically and via paper:

  1. Personally Identifiable Information (“PII”) is information that may uniquely identify a single individual, including information defined in the California Consumer Protection Act of 2018 (“CCPA”) as personal consumer information.
  2. Sensitive Personal Information (“SPI”) which is personal information that reveals private personal information, like a consumer’s SSN, driver’s license, passport number, state identification card, financial information, or other information as defined under the California Privacy Regulations Act (“CPRA”)
  3. Protected Health Information (“PHI”) which is health or medical information that pertains to an individual, as defined under HIPAA. 
  4. Payment Card Information (“PCI”) which is cardholder information.

Section 3: How BerkOne handles information
(the purpose for which the information is collected and used)

When information is provided to BerkOne, we use it only for the purposes for which it was provided, as follows: 

In the course of providing services to BerkOne’s clients: Our clients may provide records containing personal consumer information to BerkOne. Once BerkOne receives the records containing personal consumer information provided by our clients, our usage is directed exclusively by our clients and governed by our information security policies. We would only contact you if directed by our client. Any request for “no further contact” from BerkOne or our client should be sent to BerkOne’s client who would, in turn, communicate to BerkOne concerning the client’s directives. Note: “Records” means any material, regardless of the physical form, on which information is recorded or preserved by any means, including in written or spoken words, graphically depicted, printed, or electromagnetically transmitted. “Records” does not include publicly available directories containing information an individual has voluntarily consented to have publicly disseminated or listed, such as name, address, or telephone number.

For website visitors: BerkOne uses cookies on our website and we will ask you to consent to our use of cookies when you first visit our website. While cookies are not fundamental to our website operation, they may enhance your service experience. A visitor to our website(s) or portals(s) may choose to provide PII in order to request more information about our products and services. When a visitor provides this type of identifiable information to us, we use it solely for the purposes for which it was provided, and we may contact you via email, mail or telephone. At any time, a visitor may submit a website contact form requesting no further communication from BerkOne.  See Section 5.

For marketing purposes: BerkOne may receive or acquire personal identifiable information of B2B / B2G contacts solely for marketing purposes, which may take the form of direct mail, email, telephone or other communication. To request no further communication from BerkOne, a contact may submit a website contact form or reply to an email with an unsubscribe request. See Section 5.

BerkOne will comply with requests for information required by law.

If your communication requests a response from BerkOne, we will send you a response via e-mail.

Section 4: Whether the information will be sold or shared with third parties

BerkOne prohibits the sale or unauthorized distribution of any consumer data we receive to third parties, including personally identifiable information PII, sensitive PII, PCI information, and protected health information PHI.

Section 5: Contacting BerkOne

If you have questions or comments about this Privacy Notice or wish to change your communication preferences, please use the Contact Us link or you may call toll-free: 866-396-8194.

Section 6: Children Under 18

BerkOne cares about protecting the online privacy of children. We will not intentionally collect any personal information, such as a child’s name or email address, from or about children under the age of 18. If you believe that BerkOne has collected personal information from or about a child under the age of 18, or if you are a parent of a minor and would like to specify that the consumer is between 13 and 18 years of age, or under age 13, please use the “Contact Us” link in section 5 or you may call toll-free: 866-396-8194.

Section 7: Privacy Regulations

BerkOne is subject to privacy regulations, such as HIPAA and CCPA, as amended by the CPRA. The U.S. Department of Health and Human Services (“HHS”) issued the Standards for Privacy of Individually Identifiable Health Information (“Privacy Rule”) to implement requirements of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). Organizations subject to the Privacy Rule — called “covered entities” must follow the Privacy Rule standards regarding the use and disclosure of individuals’ health information—called “protected health information” (“PHI”). BerkOne is considered a covered entity, as we are considered a “business associate” and have entered into a HIPAA Business Associate Agreement with certain clients considered “covered entities” under HIPAA and handle PHI on their behalf. For more information on HIPAA, please visit this Health and Human Services website.

Section 8: Multi-State Privacy Addenda

Certain states, including California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Montana, Nebraska, Nevada, New Hampshire, Rhode Island, Texas, Utah, Virginia, and Washington have enacted consumer privacy laws that grant their residents certain rights and require additional disclosures.  This U.S. Multi-State Privacy Notice addresses these state-specific requirements. This section applies only to personal information we collect that is subject to any of the applicable U.S. state privacy laws. If you are a resident of one of the foregoing states, click below for our Multi-State Privacy Notice found within BerkOne’s Notice at Collection & Privacy Notice for California Residents: Privacy Notice For California Residents.