PRIVACY POLICY FOR SECURITY ENGINEERS, INC.
Last Updated: August 4, 2026
Security Engineers, Inc. (“SEI”, “we”, “us”, or “our”), operating in California as Vulcan Protection Services (VPS), Bureau of Security and Investigative Services (BSIS) Private Patrol Operator License # PPO122585, respects your privacy. This Privacy Policy describes how we collect, use, disclose, and secure personal information collected through our main website (securityengineersinc.com), our TOPS transition portal, and our Recruitment/Onboarding Portal.
Scope of this Policy
This Privacy Policy also serves as our Notice at Collection under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (collectively, the “CCPA”). We provide it at or before the point at which we collect personal information from you.
This Policy applies to your interaction with SEI/VPS as a website visitor, prospective or current client, or incumbent officer using our TOPS transition portal. It does not apply to personal information we collect in the employment context. If you apply for a position with us or are hired, our separate Job Applicant and Employee Privacy Notice governs that information.
This Policy does not apply to information collected offline, through channels other than those identified above, or by third parties whose websites may be linked from ours.
- Information We Collect and How We Use It
We collect personal information to provide security services, manage operations, and evaluate employment applications. We do not sell your personal information.
We categorize the information we collect as follows:
- General Website Visitors & Client Inquiries
- Categories of Information: Full name, email address, phone number, and any information provided in message forms.
- Purpose of Collection: To respond to business inquiries, send operational or service updates, and manage customer relations.
- Internal Tools Used: Data is transferred internally to Microsoft SharePoint and Microsoft Dynamics for management and tracking.
- Incumbent Officers (TOPS Portal)
- Categories of Information: Full name, phone number, and assigned transition work site location.
- Purpose of Collection: To gather initial contact details for existing, incumbent officers transitioning sites during a Request for Proposal (RFP) takeover. The portal allows officers to review FAQs and contact our team.
- Next Steps & Redirection: Officers can scan a QR code or click an internal link to transition directly to an active job advertisement within our recruitment portal to begin official onboarding.
- Internal Tools Used: Data from this transition workflow is transferred to Microsoft SharePoint, Smartsheet, Hire by Workwave, and WinTeam.
- C. Applicants & Candidates (Recruitment Portal)
- If you apply for a position with us, the personal information we collect about you — including sensitive personal information such as your date of birth and Social Security number — is collected in the employment context and is governed by our separate Job Applicant and Employee Privacy Notice, not by this Policy. That Notice describes the categories we collect, the sources, the purposes of use, the categories of recipients, our retention periods, and your rights. It is provided to you at or before the point of collection in the Recruitment and Onboarding Portal.
- Sources of the Personal Information We Collect
We collect personal information from the following sources: (i) directly from you, when you complete a web form, submit an inquiry, upload a document, or communicate with us by email, mail, or telephone; (ii) automatically from your device, through cookies and similar technologies when you visit our website; (iii) from our clients, when a client identifies incumbent officers at a site subject to a Request for Proposal takeover; and (iv) from our service providers and software vendors acting on our behalf.
- Business and Commercial Purposes for Collection
We collect, use, and disclose personal information for the following business and commercial purposes, as those terms are defined in the CCPA: performing services on behalf of our clients, including providing and staffing security services; responding to inquiries and providing customer service; auditing relating to interactions with our website; detecting, protecting against, and prosecuting security incidents and fraudulent or illegal activity; debugging and repairing errors in our systems; internal research for technological development and demonstration; verifying and maintaining the quality and safety of our services; short-term, transient use of information; and complying with our legal, regulatory, licensing, and contractual obligations, including obligations to the Bureau of Security and Investigative Services.
- Categories of Third Parties to Whom We Disclose Personal Information
We disclose each of the categories of personal information described above to the following categories of recipients for the business purposes identified above:
- Service providers and contractors, including information technology, hosting, cloud storage, and email and communications providers (Microsoft, Smartsheet, Workwave, and WinTeam);
- Our clients, with respect to information necessary to staff and administer security services at their sites;
- Professional advisors, including legal counsel, auditors, and insurers, where reasonably necessary;
- Government agencies and regulators, including the Bureau of Security and Investigative Services, where required by law, licensing obligation, subpoena, court order, or other legal process; and
- Acquirers or successors, in connection with a merger, acquisition, reorganization, financing, or sale of assets, subject to appropriate confidentiality protections.
We do not disclose personal information to third parties for their own independent commercial purposes.
- Data Retention and Sharing Limitations
- No Sale or Sharing: SEI/VPS does not sell personal information to third parties, nor do we share it for cross-context behavioral advertising.
- Third-Party Advertisements: Our website does not host external advertisements.
- Service Providers: Your data is only shared with our internal software vendors (Microsoft, Smartsheet, Workwave, and WinTeam) acting as contracted service providers bound by strict confidentiality agreements.
- Retention Periods: We retain personal information only as long as reasonably necessary for the purposes described in this Policy, and thereafter as required to comply with our legal, tax, licensing, and recordkeeping obligations or to resolve disputes. Our general retention periods are as follows:
- Website inquiries and client contact information: two (2) years from the date of last contact, unless an ongoing business relationship requires longer retention;
- TOPS transition portal records for incumbent officers: two (2) years from the conclusion of the applicable transition, unless the officer becomes an employee, in which case personnel retention periods apply;
- Operational and client service records: four (4) years from the end of the applicable contract term;
- Cookie, analytics, and website usage data: no longer than twenty-six (26) months from collection; and
- Records subject to a legal hold, audit, investigation, or litigation: until the matter is resolved and the hold is released.
Sensitive Personal Information: We collect Sensitive Personal Information only in the employment context, as described in our Job Applicant and Employee Privacy Notice. We do not collect Sensitive Personal Information from general website visitors. We do not use or disclose Sensitive Personal Information for purposes other than those permitted under CCPA Regulations section 7027(m), and accordingly we are not required to offer a right to limit its use with respect to website visitors.
Data Security: We maintain reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, destruction, use, modification, or disclosure. These measures include access controls, role-based permissions within our systems, encryption in transit, and contractual confidentiality obligations imposed on our service providers. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
- Cookie Management & Opt-Outs
We utilize functional and analytical cookies to optimize your experience on our website. We do not use advertising or tracking cookies from third-party networks.
- Cookie Control: Visitors can manage preferences or choose to opt-out of optional cookies at any time via the cookie banner toggle link posted directly on our homepage.
Do Not Track and Global Privacy Control: Because we do not sell or share personal information for cross-context behavioral advertising, there is no sale or sharing for us to apply an opt-out preference signal to, and no opt-out is necessary to prevent the sale or sharing of your personal information. We do not respond to Do Not Track browser signals, for which no common standard has been adopted. If our practices change such that we sell or share personal information, we will process opt-out preference signals, including Global Privacy Control, as required by the CCPA regulations.
Analytics: Our analytical cookies are used solely to measure site performance and improve our website. Information collected through these cookies is processed on our behalf by our service providers and is not used to build advertising profiles or disclosed for advertising purposes.
- Your California Privacy Rights (CCPA/CPRA)
If you are a California resident, you hold the following rights with respect to the personal information described in this Policy. If you are a job applicant, employee, former employee, or independent contractor, your rights are described in our Job Applicant and Employee Privacy Notice:
- Right to Know/Access: You can request a disclosure of the specific data categories we have collected about you.
- Right to Delete: You can request that we delete personal information, subject to legal compliance exceptions (e.g., mandatory payroll or tax record retention).
- Right to Correct: You can request that we amend or fix inaccurate personal or employment records.
- Right to Limit the Use of Sensitive Personal Information: Where a business uses sensitive personal information beyond the purposes permitted by the CCPA regulations, consumers may direct it to limit that use. We use sensitive personal information only for permitted purposes, and we do not collect sensitive personal information from website visitors, so no separate limitation mechanism is required. Applicants and employees should see our Job Applicant and Employee Privacy Notice.
- Right to Data Portability: You can request that the personal information we disclose to you be provided in a portable and, to the extent technically feasible, readily usable format that allows you to transmit it to another entity without hindrance.
- Right to Opt Out of Sale or Sharing: California residents have the right to direct a business not to sell or share their personal information. SEI/VPS does not sell personal information and does not share personal information for cross-context behavioral advertising. We therefore do not offer a “Do Not Sell or Share My Personal Information” link, because there is no such activity to opt out of. If our practices change, we will update this Policy and provide the required opt-out mechanism before engaging in any sale or sharing.
- Right to Non-Discrimination: We will not discriminate or retaliate against you for exercising any of your rights under the CCPA. We will not deny you goods or services, charge you a different price or rate, provide you a different level or quality of service, or suggest that you will receive a different price or quality of service because you exercised your rights. We do not offer financial incentives or price or service differences in exchange for the retention or sale of personal information.
- Frequency and Fees: You may submit a request to know twice within a twelve (12) month period. We do not charge a fee to process or respond to a verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that a request warrants a fee, we will tell you why we made that decision and provide a cost estimate before completing your request.
- Requests We Cannot Fulfill: There are circumstances in which we may be unable to comply with a request, including where we cannot verify your identity, where an exception under the CCPA applies, or where compliance would conflict with our obligations under other law, our licensing obligations to the Bureau of Security and Investigative Services, or a legal hold. If we deny a request in whole or in part, we will explain the reasons in our response.
- How to Exercise Your Rights
To submit a verifiable request to exercise your data rights, please use any of the following dedicated contact pathways:
- Email Request: Send an email specifying your request to [email protected].
- Telephone Request: Call us at (205) 251-0566.
- Mail Request: Write to Security Engineers, Inc. d/b/a Vulcan Protection Services, Attn: Privacy, 1617 3rd Avenue North, Birmingham, AL 35203.
We will verify your identity before processing the request to protect your security. We confirm receipt of your request within ten (10) business days and respond substantively within forty-five (45) calendar days. If we need more time, we will notify you in writing and may take up to an additional forty-five (45) days, for a maximum of ninety (90) days from the date we received your request.
Verification Process
To protect your personal information, we must verify your identity before responding to a request. The verification steps depend on the nature and sensitivity of the information requested and the risk of harm from unauthorized disclosure.
For a request to know categories of personal information, we will ask you to provide at least two data points that we can match against information already in our records. For a request to know specific pieces of personal information, a request to delete, or a request to correct, we will ask you to provide at least three such data points, together with a signed declaration under penalty of perjury that you are the consumer whose personal information is the subject of the request.
We will only use information you provide for verification purposes to verify your identity, to comply with the CCPA, and for security and fraud prevention. We will not use it for any other purpose, and we will delete it as soon as practicable after processing your request, except where retention is required by law.
We will only send verification correspondence from [email protected]. If you receive a message that appears to come from us but originates from a different address, do not respond to it, and please notify us at the address above.
Authorized Agents
You may designate an authorized agent to submit a request on your behalf. If you use an authorized agent, we will require the agent to submit written permission signed by you authorizing the agent to act on your behalf, and we may also require you to verify your own identity directly with us and to confirm that you provided the agent that authorization. These requirements do not apply where the agent presents a valid power of attorney executed under California Probate Code sections 4000 through 4465. We may deny a request from an agent who does not submit proof of authorization when we request it.
Requests on Behalf of Minors
Our website and portals are not directed to children, and we do not knowingly collect personal information from consumers under sixteen (16) years of age. We do not sell or share the personal information of consumers of any age. If you believe a child under sixteen has provided personal information to us, please contact us at [email protected] and we will delete it. A parent or legal guardian may submit a request on behalf of their minor child by contacting us and providing proof of the parent-child relationship and of the parent’s own identity.
- California Regulatory Disclosures
Pursuant to California Department of Consumer Affairs requirements, security services rendered within the state of California are operated under:
- Legal Entity Name: Security Engineers, Inc.
- California DBA: Vulcan Protection Services (VPS)
- Licensing Authority: Bureau of Security and Investigative Services (BSIS)
- License Type: Private Patrol Operator (PPO)
- License Number: PPO122585
- Additional California Privacy Rights (Shine the Light)
California Civil Code section 1798.83, known as the “Shine the Light” law, permits California residents to request information about our disclosure of personal information to third parties for those third parties’ direct marketing purposes. SEI/VPS does not disclose personal information to third parties for their direct marketing purposes. To submit a Shine the Light request, send an email to [email protected] with the subject line “Shine the Light Request.”
- Changes to this Privacy Policy
We reserve the right to amend this Privacy Policy at our discretion and at any time. When we make material changes, we will post the updated Policy on our website and revise the “Last Updated” date above. We will review and update this Policy at least once every twelve (12) months as required by the CCPA. We encourage you to review this Policy periodically. If we intend to use personal information we previously collected for a purpose that is materially different from the purposes disclosed at the time of collection, we will notify you and obtain your consent before doing so.
- Accessibility
We are committed to making this Privacy Policy accessible to individuals with disabilities. If you use an assistive technology and are unable to access or read any portion of this Policy, or if you would like to receive it in an alternative format, please contact us at [email protected] and we will provide the information to you in a format you can access.
- Contact Us
If you have questions or concerns about this Privacy Policy or our privacy practices, or if you would like additional information about how we handle personal information, contact us at:
Security Engineers, Inc. d/b/a Vulcan Protection Services (VPS)
Attn: Privacy
1617 3rd Avenue North, Birmingham, AL 35203
Email: [email protected]
BSIS Private Patrol Operator License No. PPO122585
JOB APPLICANT AND EMPLOYEE PRIVACY NOTICE AND NOTICE AT COLLECTION
Security Engineers, Inc. d/b/a Vulcan Protection Services (VPS)
Last Updated: August 4, 2026
Scope of this Notice
Security Engineers, Inc. (“SEI,” the “Company,” “we,” “us,” or “our”), operating in California as Vulcan Protection Services (VPS), Bureau of Security and Investigative Services (BSIS) Private Patrol Operator License No. PPO122585, has developed this Privacy Notice out of respect for the privacy of our job applicants, employees, and independent contractors. This Notice describes the personal information we collect, use, and disclose about individuals who apply for or hold a position with us, and it serves as our Notice at Collection under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (collectively, the “CCPA”).
We provide this Notice at or before the point at which we collect personal information from you, so that you are informed of what information we collect, how we use it, how long we retain it, and whether we sell it or share it for cross-context behavioral advertising. We do not sell or share personal information.
This Notice applies only to your interaction with the Company in the capacity of a job applicant, employee, former employee, or independent contractor, including your use of our Recruitment and Onboarding Portal and our TOPS transition portal. It does not apply to other contexts. If you visit our public-facing website or transact with the Company as a client, customer, or vendor, our general Privacy Policy governs those interactions.
- Categories of Personal Information We Collect
When you apply for a position, are hired, or interact with us regarding potential job openings, we may collect personal information from you in a variety of situations and by a variety of methods, including but not limited to through our Recruitment and Onboarding Portal, in person, by mail, by email, and over the telephone. Generally, and in the last twelve (12) months, we have collected the following categories of personal information from or about job applicants and employees. For each category, we identify the sources from which it is collected, the purposes for which it is used, and the categories of third parties to whom we have disclosed it in the last twelve (12) months. The examples provided are not intended to be an exhaustive list or an indication of all specific pieces of information we collect about you in each category, but rather to give you a meaningful understanding of the types of information that may be collected within each category.
Category | Examples | Sources | Purpose of Collection |
Identifiers | Name, alias, Social Security number, date of birth, driver’s license or state identification card number, passport number, employee ID number, BSIS guard card number. At the application stage we ask only whether you meet the minimum age for the position; we collect your date of birth later, after a conditional offer, for background screening and BSIS registration. | Directly from you; from background check and consumer reporting agencies; from BSIS licensing records. | To evaluate your application, verify your identity and work authorization, conduct background screening, register you with BSIS, and administer payroll and benefits. |
Contact Information | Home, postal, or mailing address, email address, home phone number, cell phone number, emergency contact information. | Directly from you. | To communicate with you about your application and employment, and to reach you or your designated contact in an emergency. |
Professional or Employment-Related Information | Employment history, work history, job title, dates of employment, prior compensation, reasons for separation, references, uploaded resumes and documents, performance and disciplinary records, timekeeping and scheduling records, post assignments. | Directly from you; from your references and prior employers; from our clients regarding site performance; from our timekeeping systems. | To assess your qualifications, verify the information you provide, make employment decisions, schedule and assign posts, administer compensation, and manage performance. |
Education Information | Schools attended, degrees, diplomas, certificates, training records, licenses and certifications. | Directly from you; from educational institutions and certifying bodies. | To verify your qualifications and confirm that you hold the licenses and training required for the position and by BSIS. |
Characteristics of Protected Classifications Under California or Federal Law | Race, ethnicity, color, national origin, sex, gender, age, marital status, military or veteran status, disability, medical condition, religion. | Directly from you, on a voluntary basis. | To comply with equal employment opportunity recordkeeping and reporting obligations, to administer requests for reasonable accommodation and protected leave, and to support voluntary diversity reporting. Providing this information is voluntary and a decision not to provide it will not affect your application. |
Sensory Information | Audio and visual recordings, including security camera footage at our facilities and client sites, recorded telephone calls where permitted by law, and, in jurisdictions where the system is deployed, road-facing and in-cab video recorded by our vehicle safety monitoring system while a Company vehicle is in operation. In-cab video is transmitted when the system detects a safety event, such as distracted-driving behavior, and exterior video is transmitted on events such as hard braking, speeding, or collision impact. The audio recording function of the system is turned off, and we do not record, intercept, or monitor oral communications in the vehicle; because the equipment retains audio capability, we obtain your separate written all-party consent before you are assigned to operate a monitored vehicle, as described in our Authorized Driver Policy. | From our security systems, our clients’ security systems, and in-vehicle camera and telematics systems installed in Company vehicles. | To maintain the security and safety of our premises, our personnel, and our clients’ sites, to investigate incidents, and to support driver safety, coaching, and corrective action relating to the operation of Company vehicles. |
Internet or Other Electronic Network Activity Information | Login records, IP address, browsing and search history on Company systems, and information regarding your interaction with our portals and Company-issued devices and applications. | Automatically from our systems and portals when you use them. | To administer and secure our systems, authenticate users, troubleshoot errors, and enforce Company policies. |
Geolocation Data | Approximate or precise location derived from Company-issued devices, mobile timekeeping applications, and patrol tracking systems. This includes location captured when you scan a patrol tour checkpoint; location captured when you clock in or out through our mobile timekeeping application, which confirms that you are within a designated geofenced area at your assigned job site; and, in jurisdictions where the system is deployed, vehicle location, route, speed, braking, and related driving-behavior data collected by our vehicle safety monitoring system and by the driver beacon issued to you. Our mobile timekeeping application reads your location only while the application is open for a clock-in or clock-out; it does not track your location in the background. Under our Authorized Driver Policy, your driver beacon is to be carried only while you are clocked in and operating or riding in a monitored Company vehicle. | From Company-issued devices and applications, from our mobile timekeeping application, and from our vehicle safety monitoring system and the driver beacons issued to drivers for use in monitored Company vehicles. | To verify post coverage and patrol completion, administer timekeeping and confirm that clock-ins occur at the assigned job site, dispatch personnel, provide for officer safety, and support vehicle safety, driver coaching, and corrective action. |
Inferences | Profiles reflecting preferences, characteristics, aptitudes, and abilities drawn from the information above. | Derived internally from the categories above. | To evaluate candidate fit, assign personnel to appropriate posts, and support internal workforce planning. Our online application includes threshold screening questions regarding minimum age, authorization to work in the United States, and willingness to consent to background screening and drug and alcohol testing where required for the position. Your answers may cause our applicant tracking system to flag or sort your application, but the system does not by itself reject any applicant. Every application is reviewed by a member of our recruiting team, who compares it against the applicable job description and makes the hiring decision. We do not use automated decision-making technology or artificial intelligence to make, or to substantially replace human decision-making in, employment decisions about you, including hiring, assignment, promotion, discipline, or termination. If we adopt any such technology, we will update this Notice and provide the pre-use notice required by the CCPA regulations, including how you may opt out and request an explanation of the decision. |
Categories of Third Parties to Whom We Disclose Personal Information
In the last twelve (12) months, we have disclosed each of the categories of personal information identified above to the following categories of recipients for the business purposes described: Government agencies and regulators (including the Bureau of Security and Investigative Services and the Department of Justice); talent acquisition management systems and applicant tracking systems (Hire by Workwave); vendors providing services for purposes of our human resources information system and management of applicant and employee data (Microsoft SharePoint, Smartsheet, WinTeam); our vehicle safety monitoring provider, which processes in-cab and road-facing video and driving-behavior data on our behalf as a service provider and is contractually prohibited from using it for its own purposes; background check and consumer reporting agencies; Live Scan fingerprinting vendors; drug and alcohol testing laboratories; payroll, benefits, and workers’ compensation administrators; IT, cybersecurity, and privacy vendors and consultants, including the third-party provider that hosts our Company email system within the United States; our clients, with respect to information necessary to staff and administer their sites; recruiting and staffing firms or agencies; and professional advisors, including legal counsel, auditors, and insurers.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We have not sold or shared the personal information of applicants or employees in the preceding twelve (12) months, and we do not knowingly sell or share the personal information of individuals under sixteen (16) years of age.
- Sensitive Personal Information
Because we collect sensitive onboarding data, we treat the following categories with heightened security. We collect and use Sensitive Personal Information only as reasonably necessary and proportionate to perform the employment-related services described in this Notice and for the purposes permitted under CCPA Regulations section 7027(m), including to verify identity and work authorization, prevent and investigate security incidents, comply with legal obligations, and ensure the safety of our personnel and clients.
Category of Sensitive PI | Examples | Sources | Purpose of Collection and Use |
Social Security Number and Government Identifiers | Social Security number, driver’s license number, state identification card number, passport number. | Directly from you. | To verify your identity and work authorization, complete Form I-9, conduct background screening, register you with BSIS, and report and remit payroll taxes. |
Citizenship and Immigration Status | Citizenship, immigration status, and work authorization documents submitted with Form I-9. | Directly from you. | To verify your legal authorization to work in the United States as required by federal law. |
Racial or Ethnic Origin | Voluntary self-identification of race and ethnicity. | Directly from you, on a voluntary basis. | To comply with equal employment opportunity recordkeeping and reporting obligations. Providing this information is voluntary. |
Health Information | Pre-employment and post-accident drug and alcohol test results, fitness-for-duty evaluations, medical certifications supporting accommodation or leave requests, workers’ compensation records, and injury and illness reports. | Directly from you; from testing laboratories and medical providers with your authorization; from our workers’ compensation carrier. | To determine fitness for duty, administer drug and alcohol testing consistent with law and client requirements, evaluate accommodation and leave requests, and administer workers’ compensation and safety programs. |
Biometric Information | Fingerprints submitted through a third-party Live Scan vendor for BSIS guard registration and Department of Justice and Federal Bureau of Investigation criminal history review. | Collected by a third-party Live Scan vendor at your appointment. We do not collect or retain fingerprint images; the vendor transmits results to BSIS and the Department of Justice. | To satisfy the criminal history background check required for BSIS guard registration. We receive only the licensing determination, not the underlying fingerprint data. |
Contents of Communications | Contents of mail, email, and text messages sent through or stored on Company systems where the Company is not the intended recipient. | From our systems and communications platforms. | To administer and secure our systems, including automated scanning and filtering of messages for malware, phishing, and data-loss prevention; to archive communications as required for legal, regulatory, and client obligations; to investigate suspected policy violations or unlawful conduct; and to comply with legal obligations and preserve records subject to a legal hold. You should have no expectation of privacy in communications sent or received through Company systems. |
Your Right to Limit the Use of Sensitive Personal Information
Because we use Sensitive Personal Information only for the purposes permitted under CCPA Regulations section 7027(m), we are not required to offer, and do not offer, a separate mechanism to limit its use. We do not use Sensitive Personal Information to infer characteristics about you.
- Background Screening and Consumer Reports
As a licensed private patrol operator, we are required by law and by our clients to screen personnel. Where permitted by applicable law and consistent with the California Fair Chance Act, we may obtain consumer reports and investigative consumer reports about you, including criminal history records, employment and education verifications, and, for positions involving driving, motor vehicle records. For a limited number of positions involving access to cash, financial accounts, or client financial information, we may obtain credit reports where permitted under California Labor Code section 1024.5.
These reports are obtained through third-party consumer reporting agencies. Before obtaining any such report, we will provide you with the separate written disclosures and obtain the written authorizations required by the federal Fair Credit Reporting Act, the California Investigative Consumer Reporting Agencies Act, and the California Consumer Credit Reporting Agencies Act. Those disclosures are provided as standalone documents and are not part of this Notice. If we intend to take adverse action based in whole or in part on a report, we will follow the pre-adverse and adverse action notice procedures required by law, including the individualized assessment required under the California Fair Chance Act.
We may also require pre-employment, post-accident, reasonable-suspicion, or client-mandated drug and alcohol testing, in each case as permitted by applicable law. Testing results are treated as Sensitive Personal Information and are maintained separately from your general personnel file with restricted access.
- Retention of Your Personal Information
We retain personal information only as long as reasonably necessary for the purposes described in this Notice, and thereafter as required to comply with our legal, tax, licensing, and recordkeeping obligations or to resolve disputes. Our general retention periods are as follows:
- Applications and recruiting records for candidates who are not hired: two (2) years from the date of the employment decision;
- TOPS transition portal records for incumbent officers who do not become employees: two (2) years from the conclusion of the applicable transition;
- Personnel files and employment records for employees: four (4) years following separation of employment;
- Payroll, wage, and hour records: four (4) years from the date the record was created;
- Form I-9 and work authorization records: three (3) years after the date of hire or one (1) year after separation, whichever is later;
- Drug and alcohol testing records and medical or accommodation records: maintained in confidential files separate from the personnel file, for the duration of employment plus four (4) years, or longer where OSHA or workers’ compensation rules require;
- Workplace injury and illness records: five (5) years following the end of the calendar year the record covers, consistent with OSHA requirements;
- Security camera footage and access records: thirty (30) to ninety (90) days, unless retained longer in connection with an investigation, claim, or legal hold;
- Geolocation and timekeeping data from Company devices: four (4) years, consistent with wage and hour recordkeeping requirements; and
- Records subject to a legal hold, audit, investigation, or litigation: until the matter is resolved and the hold is released.
Retention periods required by BSIS licensing regulations control where they exceed the periods above.
- Your California Privacy Rights
If you are a California resident, you have the following rights with respect to the personal information we collect about you as an applicant, employee, former employee, or independent contractor:
- Right to Know and Access: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which it was collected, the business or commercial purposes for collecting it, and the categories of third parties to whom we disclosed it. You may submit this request twice in a twelve (12) month period.
- Right to Delete: You may request that we delete personal information we collected from you. This right is subject to significant exceptions in the employment context, including where retention is necessary to comply with payroll, tax, immigration, wage and hour, safety, workers’ compensation, or BSIS licensing obligations, to complete a transaction, to detect security incidents, or to exercise or defend legal claims.
- Right to Correct: You may request that we correct inaccurate personal information we maintain about you, including inaccurate personnel or employment records, taking into account the nature of the information and the purposes of processing.
- Right to Data Portability: You may request that the personal information we disclose to you be provided in a portable and, to the extent technically feasible, readily usable format.
- Right to Limit the Use of Sensitive Personal Information: As described in Section 2 above, we use Sensitive Personal Information only for permitted purposes, so no separate limitation mechanism is required.
- Right to Opt Out of Sale or Sharing: We do not sell personal information and do not share it for cross-context behavioral advertising, so there is no sale or sharing to opt out of. If our practices change, we will update this Notice and provide the required opt-out mechanism before engaging in any sale or sharing.
- Right to Non-Discrimination and Non-Retaliation: We will not discriminate or retaliate against you for exercising any of these rights. Exercising a privacy right will not affect your application, your employment, your compensation, your assignments, or your standing with the Company in any way.
- How to Exercise Your Rights
To submit a verifiable request, use either of the following pathways:
- Email Request: Send an email specifying your request to [email protected].
- Telephone Request: Call us at (205) 251-0566.
- Mail Request: Write to Security Engineers, Inc. d/b/a Vulcan Protection Services, Attn: Privacy, 1617 3rd Avenue North, Birmingham, AL 35203.
Verification: To protect your information, we must verify your identity before responding. We will ask you to provide information we can match against our records, and for requests involving specific pieces of personal information, deletion, or correction, we may require a signed declaration under penalty of perjury that you are the individual whose information is the subject of the request. Information you provide for verification will be used only for verification, CCPA compliance, security, and fraud prevention, and will be deleted as soon as practicable after we process your request.
Timing: We will confirm receipt of your request within ten (10) business days and respond substantively within forty-five (45) calendar days. If we need more time, we will notify you in writing and may take up to an additional forty-five (45) days, for a maximum of ninety (90) days from receipt.
Authorized Agents: You may designate an authorized agent to submit a request on your behalf. We will require the agent to provide written permission signed by you, and we may require you to verify your own identity directly with us and confirm that you granted the agent authority. These requirements do not apply where the agent presents a valid power of attorney executed under California Probate Code sections 4000 through 4465.
Requests We Cannot Fulfill: We may be unable to comply with a request where we cannot verify your identity, where a CCPA exception applies, or where compliance would conflict with our obligations under other law, our BSIS licensing obligations, or a legal hold. If we deny a request in whole or in part, we will explain why in our response.
Fees: We do not charge a fee to process a request unless it is excessive, repetitive, or manifestly unfounded. If we determine a fee is warranted, we will explain why and provide a cost estimate before proceeding.
- Data Security
We maintain reasonable administrative, technical, and physical safeguards designed to protect your personal information against unauthorized access, destruction, use, modification, or disclosure. These measures include role-based access controls limiting access to personnel with a business need, encryption in transit, separate confidential storage of medical and testing records, and contractual confidentiality and security obligations imposed on our service providers and contractors. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
- California Regulatory Disclosures
Security services rendered within the state of California are operated under the following licensure:
- Legal Entity Name: Security Engineers, Inc.
- California DBA: Vulcan Protection Services (VPS)
- Licensing Authority: Bureau of Security and Investigative Services (BSIS)
- License Type: Private Patrol Operator (PPO)
- License Number: PPO122585
- Changes to this Notice
We reserve the right to amend this Notice at our discretion and at any time. When we make material changes, we will post the updated Notice and revise the “Last Updated” date above. We will review and update this Notice at least once every twelve (12) months as required by the CCPA.
- Accessibility and Contact
If you use an assistive technology and are unable to access any portion of this Notice, or would like it in an alternative format, contact us and we will provide it in a format you can access. For questions about this Notice or our privacy practices, contact:
Security Engineers, Inc. d/b/a Vulcan Protection Services (VPS)
Attn: Privacy
1617 3rd Avenue North, Birmingham, AL 35203
Email: [email protected]
BSIS Private Patrol Operator License No. PPO122585