Milliman Personal Information Privacy Policy - China
Last Updated – August 2024
Where Milliman is Acting as a Data Controller
Milliman, Inc. and its affiliates (“Milliman” or “we”) take data privacy very seriously. This Privacy Policy sets out the principles governing use and protection of personal information that website visitors, prospective/current clients (“you”) residing within China share with us (“Personal Information”). Milliman is committed to handling Personal Information in accordance with this Privacy Policy, the Personal Information Protection Law (“PIPL”), and any other data protection and privacy laws, as applicable (“Applicable Laws”).
Milliman, Inc. having its address at 1301 5th Ave, Seattle, WA 98101, USA and Milliman (Shanghai) Co. Ltd (“Milliman China”) having it address at 1106D No. 288 Xiang Cheng Road Pudong, Shanghai 200122 are Personal Information Handlers with respect to the processing of Personal Information described in this Privacy Policy. This means that Milliman, Inc. and Milliman China are both responsible for the compliance with Applicable Laws. The Personal Information Handlers can be contacted at [email protected] in relation to any queries.
Collection of Information/Data
Aggregate Data
Like many companies, Milliman monitors the use of its websites by collecting aggregate data. No Personal Information is collected in this process. Typically, Milliman collects data about the number of visitors to the website, to each web page, and the originating domain name of the visitor's Internet Service Provider. This data is used to improve the usability, performance and effectiveness of Milliman’s website.
Cookies, Third-Party Embedded Content and Do Not Track
For more detailed information describing how Milliman uses cookies and your choices surrounding the use and opt out of such cookies, including information about third party embedded content on Milliman’s website and how Milliman responds to Do Not Track signals in browsers please review our Cookie Policy which can be found here.
Processing of Personal Information
As we describe below in this Privacy Policy, we may collect, store and otherwise process Personal Information of visitors to our websites, employees, officers, partners or other representatives and agents of our clients, business partners, and other individuals. This Privacy Policy does not apply to the collection and processing of Personal Information of job applicants and candidates or employees and non-employee workers. The processing of such Personal Information is subject to specific privacy policies and notices that are communicated to individuals in the context of their candidacy, employment or working relationship with Milliman.
The Personal Information we collect varies depending upon the nature of the services provided and our interactions with individuals. In the context of the collection of data through this website, Milliman’s marketing activities and contract administration, we may collect the following categories of Personal Information.
-Visitors to our website https://cn.milliman.com/ :we may collect the first name, last name, title, company, phone number, location, email address, subject of the request and message provided by you through the “Contact us” link for the purpose of management of relationship with you, to facilitate communication, to fulfill requests or respond to inquiries about Milliman products or services and to provide offers and information (as permitted by law) about products, services, or events offered by Milliman or that Milliman thinks may be of interest and the administration of the website. Milliman will seek your consent prior to collecting the above information from you as per Article 13 (1) of PIPL.
.-Clients’ representatives, officers, agents and employees, business partners, providers, parties to a contract (name, professional address, title, email address and other professional contact details) for contract administration purposes. The professional contact details of clients’ representatives, their employees and business partners are also used to activate and maintain client accounts, including for billing purposes, formal communications in relation to the scope of contract, due diligence and conflict checks. Milliman conducts the above processing activities in order to fulfill the contractual obligations with you as per Article 13 (2) of PIPL.
Milliman may also use professional contact details of its clients’ employees for the purpose of sending surveys, questionnaires or for the purpose of organizing contests, to provide offers and information (as permitted by law) about the products, services, or events offered by Milliman or that Milliman thinks may be of interest. We may also collect, and process limited Personal Information about you from public resources (such as LinkedIn) including your name/surname, email address, telephone number, organization, title/position, profession, professional interests, to allow us to assess a potential interest in our services and to contact you for marketing purposes.
Milliman may rely on your consent (Article 13 (1) of PIPL) for the sending of the above-mentioned marketing communications when so required as per PIPL, in which case we will seek your consent prior to sending such communication. When we communicate with you regarding the products and services we offer or develop, you will be given the opportunity in each communication to unsubscribe and prevent future communications of that sort. If you do not want us to collect your Personal Information for our marketing emails, you have the right to withhold your consent. If you wish to withdraw your consent or unsubscribe from direct marketing communications from us, you may write to us at [email protected] requesting the same. We will cease using your Personal Information for direct marketing purposes once you have requested us to do so.
If you provide us with Personal Information of another individual, it is your duty to make sure that these individuals have consented to or are appropriately informed about the processing of their Personal Information by Milliman.
You should also ensure that all Personal Information submitted to us is complete, accurate, true and correct. Failure on your part to do so may result in our inability to provide you with the products and services you have requested.
No automated decision-making, including profiling, is undertaken based on the Personal Information collected from you.
Personal Information Collection on Milliman’s Proprietary Platforms
For some unique services, Milliman hosts and maintains its own proprietary software platforms (“Platforms”). These Platforms allow Milliman to offer enhanced services and specialized products to our customers. In some cases, these software platforms may require the submission of Personal Information by customers. In cases where our data collection is materially different than described in this Privacy Policy, and may be subject to local data privacy laws, we will provide additional information regarding such data collection on the applicable Platforms.
Methods of Processing
We process your Personal Information by means of the following methods:
-Manual processing: We may employ manual processing without the use of computers or automated tools, e.g., generating, consulting, storage, etc. of hard copy documents.
-Automated processing: We may use computers and other electronic and automated means of processing, e.g., use of software, storage of data in electronic format on our servers or in the cloud, etc.
Transfer of Your Personal Information to Affiliates and Third-Party Agents.
All Milliman websites, products, and services are provided in cooperation with Milliman, Inc., U.S.A and Milliman India Private Limited, India. Personal Information as specified under this Privacy policy may be shared between Milliman China and Milliman, Inc. or other entities controlled by or under common control with Milliman, Inc. ( “Data Recipients”), for purposes of centralization of Milliman’s administrative, contract management, Client Relationship Management (CRM), IT maintenance, marketing and IT security practices, for the purpose of the website’s management and security, and to provide information about Milliman products, services, or events. You can exercise your rights with respect to the above Data Recipients by reaching out on the contact information as stated in the section “How to Contact Us” of the Privacy Policy.
Milliman has taken all reasonable and appropriate measures (technical, organisational and contractual) to provide an adequate level of data protection for any Personal Information collected, processed, transferred, and shared globally by us. As Milliman Inc. will be processing your Personal Information as a Personal Information Handler, and your Personal Information is being transferred to a country outside China for the purposes as described above, we will ensure that we have obtained your consent to such cross-border transfer when legally required and that we comply with relevant regulatory requirements prescribed under Applicable Laws.
Milliman also may share Personal Information with authorized third-party agents or contractors that perform services for Milliman. If Milliman shares Personal Information with a third party, Milliman requires that those third parties agree to process Personal Information based on Milliman’s instructions and in compliance with this Privacy Policy.
Please note that in accordance with PIPL, we will be conducting a Personal Information Protection Impact Assessment prior to making any such data transfers, to assess the impact on personal rights, and security risks of the transfer; and to ensure that the protection measures adopted are legal, effective, and compatible with the degree of risk. We ensure that we take all necessary steps for the protection of your Personal Information in accordance with the requirements prescribed under the PIPL law.
Other Disclosures
Milliman may also disclose Personal Information and other related information in response to subpoenas, court orders, or other lawful requests by public authorities, and to meet national security or law enforcement requirements. Milliman may collect and share Personal Information in order to investigate or take action regarding illegal activities, suspected fraud, violations of Milliman's Terms of Use, or as otherwise required by law or regulation.
Security
Milliman stores Personal Information on a secure server that is password protected and shielded from unauthorized access by a firewall. Milliman has in place security policies that are intended to ensure the security and integrity of all Personal Information. Milliman has appropriate technical and organisational measures in place to protect against unauthorised or unlawful processing of Personal Information and against accidental loss or destruction of, or damage to, Personal Information held or processed by Milliman. If Milliman forwards Personal Information to any third party, Milliman requires that those third parties have appropriate technical and organisational measures in place to comply with this Privacy Policy and Applicable Laws.
Data Retention
Milliman retains Personal Information only as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required under Applicable Laws. If you have unsubscribed from receiving marketing information from us, we will continue to retain your Personal Information as long it is necessary to comply with mandatory retention requirements prescribed under Applicable Laws and we will maintain limited Personal Information (such as your email address) about you on record, so as to be able to ensure for the future that such marketing communications are no longer sent to you.
Children
Milliman’s websites, products, and services are not directed to children, and Milliman does not knowingly collect Personal Information from children. If a parent or legal guardian becomes aware that his or her child has provided Milliman with Personal Information without their consent, the parent or legal guardian should contact Milliman at [email protected], and Milliman will take steps to delete any such Personal Information.
Third-party Links
Milliman’s website may contain links to websites hosted and operated by companies other than us (“Third-Party Websites”) to which you can export (part of) your Personal Information.
We do not disclose your Personal Information to these Third-Party Websites without your explicit consent. Note that any information you disclose to Third-Party Websites is no longer under our control and no longer subject to this Privacy Policy.
You should review the privacy policy practices of any such Third-Party Website to understand how that Third-Party Website collects and uses your Personal Information should you have decided to disclose your Personal Information to them. We are not responsible for the content or performance of these Third-Party Websites. We are in no way responsible or liable for the manner in which a Third-Party Website treats any Personal Information that you choose to provide to such a Third-Party Website and use of Third-Party Websites is strictly at your own risk.
Policy Updates
Milliman may change its Privacy Policy from time to time. Milliman therefore asks all concerned person to check it occasionally to ensure that they are aware of the most recent version.
Rights
We are committed to ensuring that any Personal Information that we collect about you is accurate, complete, and up to date and is required for the purposes for which it was collected.
You have specific rights in relation to the way that we use your Personal Information under Applicable Laws. These include the right to:
- be informed: you may ask us to confirm what Personal Information we hold and process about you at any time.
- access your Personal Information: you have the right to request a copy of the Personal Information held about you. However, the request may be assessed on the basis of “reasonableness” with consideration given to the difficulty, practicality, and expense of providing the requested information.
- ask to correct: you are entitled to have any inaccurate or incomplete Personal Information held about you corrected or amended.
- object to the processing of your Personal Information: this right enables you to object to us processing your Personal Information, unless we can demonstrate compelling legitimate grounds for the processing which override your interests and rights. This right does not apply where we are processing your Personal Information for the performance of your contract or for compliance with a legal obligation.
- restrict processing: you have the right to request, at any time, that we restrict the processing of your Personal Information where you believe the Personal Information we hold about you is inaccurate, or our processing is unlawful.
- request data portability: under certain circumstances, we can provide you with your Personal Information in a structured, commonly used, machine readable form which provides the ability to move, copy or transfer your Personal Information to another service; and
- ask for the deletion of your Personal Information: you have the right to have your Personal Information erased (also referred to as the right to be forgotten) where, for example, retaining your Personal Information is no longer necessary in relation to the purpose for which it was originally collected/processed, where you have withdrawn consent, subject to there being no overriding legal bases or legal requirement for continuing to hold your Personal Information.
You can exercise any of your rights as stated above, by filling out the applicable form available here .
Where we process your Personal Information based on your consent, you can withdraw your consent at any time. However, your withdrawal of consent only applies to how we use your Personal Information in the future and not to processing activities we have done in the past.
If you do not provide your Personal Information, provide it inaccurately or require us to delete it, then we may not be able to provide you with the product or services you have requested.
How to Contact Us
If you have any questions or feedback relating to your Personal Information or about this Privacy Policy, please contact Milliman’s Data Protection Officer at [email protected].