Your privacy matters—especially when you seek support for your health, wellbeing, or personal life. This Global Privacy Policy explains how CCA, Inc. (“CCA,” “we,” “us,” or “our”) collects, uses, discloses, protects, and retains personal information when you visit our websites, use our member platforms, communicate with us, or receive employee assistance, counseling, referral, case-management, wellbeing, or related services (collectively, the “Services”).
Our Core Commitment
We do not sell counseling records, diagnoses, case notes, or consumer health data. We do not use counseling records, diagnoses, or case content for targeted advertising. We do not give your employer or program sponsor identifiable clinical information unless you direct or authorize us to do so, or disclosure is otherwise permitted or required by law.
This Policy is designed for a global audience. Local law, a service-specific privacy notice, an informed-consent form, a Notice of Privacy Practices, or a customer or program notice may provide additional information or rights. If a more specific notice applies to particular information or Services, that notice controls to the extent of any conflict.
1. Scope and Our Role
This Policy applies to personal information collected through ccainc.com and other CCA websites that link to it, CCA member portals and digital platforms, online and offline forms, communications with CCA, and the delivery and administration of the Services. It does not govern a third party’s independent privacy practices, even when a link to that third party appears in our Services.
Our legal role depends on the activity. CCA may act as:
The applicable customer agreement, data-processing agreement, informed-consent notice, or service-specific notice may describe these roles in greater detail.
2. Personal Information We Collect
The information we collect depends on your relationship with CCA and the Services you use. It may include:
Category
Examples
Identity, contact, and eligibility data
Name, contact details, date of birth, employee or member identifier, employer or program sponsor, dependent status, language, location, and eligibility or enrollment information.
Account and authentication data
Username, account settings, login and authentication records, access permissions, and security events.
EAP, counseling, and health information
Presenting concerns, intake responses, mental-health or wellbeing information, symptoms, assessments, diagnoses where applicable, counseling and case notes, referrals, treatment or care information, risk and safeguarding information, accommodations, and communications with clinicians or case managers.
Service and communications data
Appointments, referrals, service requests, customer-support records, complaints, survey responses, call or message information, and communications preferences.
Website and device data
IP address, browser and device type, operating system, referring pages, pages viewed, timestamps, approximate location derived from IP address, cookie identifiers, and security or diagnostic logs.
Business and professional data
Employer, role, business contact details, contracting records, and communications with customers, providers, partners, vendors, and prospective customers.
Inferences and derived data
Eligibility status, service recommendations, risk indicators, or other conclusions generated from information described above, where lawful and appropriate.
Aggregated and deidentified data
Statistics or reports that do not reasonably identify an individual. We may use and disclose this information as permitted by law and will not attempt to reidentify it except to test our deidentification processes or as otherwise permitted by law.
Sources of Information
We collect information:
3. How and Why We Use Personal Information
We use personal information only for legitimate, specified purposes, including to:
Lawful bases for EEA and UK processing
Where European Economic Area (“EEA”) or United Kingdom (“UK”) data-protection law applies, we rely on one or more lawful bases, depending on the activity, such as performance of a contract, compliance with a legal obligation, our legitimate interests or those of another party, where those interests are not overridden by your rights, protection of vital interests, performance of a task in the public interest where applicable or consent.
For health information and other special-category data, we also rely on an applicable condition under local law, such as providing health or social care subject to confidentiality duties, substantial public interest, protection of vital interests, establishment or defense of legal claims, or explicit consent where required. Accepting this Policy is not blanket consent to process health information. When consent is required, we request it separately and you may withdraw it prospectively.
4. EAP and Clinical Confidentiality
What your employer or sponsor receives
Customers and program sponsors may receive information needed to confirm eligibility, administer the program, invoice for Services, and understand program utilization through aggregated or deidentified reports. They do not receive counseling notes, diagnoses, treatment content, or identifiable case records unless you specifically direct or authorize the disclosure, or the disclosure is otherwise permitted or required by law.
We may disclose identifiable clinical or health information to clinicians, referral providers, emergency services, or other appropriate recipients when needed to provide or coordinate care, address an emergency or safeguarding concern, comply with law, or protect you or another person from a serious threat, subject to applicable professional and legal requirements.
Some information handled in connection with particular Services may be protected health information subject to the U.S. Health Insurance Portability and Accountability Act (“HIPAA”) or other health-privacy laws. When HIPAA applies, the applicable Notice of Privacy Practices governs protected health information and this Policy is not a HIPAA authorization. Other health or wellbeing information may be protected by state consumer-health, mental-health, medical-record, or confidentiality laws even when HIPAA does not apply.
5. How We Disclose Personal Information
We may disclose personal information to the following recipients, only as appropriate for the relevant purpose:
We do not sell counseling records, diagnoses, case notes, or consumer health data. We do not share those data for cross-context behavioral advertising. If CCA engages in another activity that applicable U.S. state law defines as a “sale” or “sharing” of other personal information, we will provide any required notice and opt-out method.
6. International Processing and Transfers
CCA is based in the United States and works with customers, members, clinicians, providers, and service partners internationally. Personal information may therefore be processed in the country where you receive Services and in other countries where CCA or approved service providers operate. Privacy laws and government-access rules may differ across those countries.
When personal information is transferred from the EEA, UK, Switzerland, or another jurisdiction that restricts cross-border transfers, we use a lawful transfer mechanism as required. Depending on the circumstances, this may include an adequacy decision, the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, an applicable data-privacy framework where the recipient is eligible and certified, or another legally recognized mechanism. We also use risk assessments and supplementary contractual, technical, and organizational safeguards where appropriate.
Our systems and providers may use regional hosting and approved remote support. We apply access controls, confidentiality obligations, logging, and transfer safeguards to authorized cross-border access. You may contact us for more information about safeguards applicable to your information.
7. Cookies, Similar Technologies, and Marketing
Our member platforms use technologies needed to provide requested functionality, authenticate users, maintain security, remember accessibility or user settings, and operate the Services. Our corporate websites may also use analytics, communications, or marketing technologies. Where law requires consent, nonessential technologies will not be activated until consent is obtained, and you may change your preferences through the cookie controls made available on the relevant site.
We do not use counseling records, diagnoses, or case content for targeted advertising. You may opt out of marketing emails through the unsubscribe link in the message or by contacting us. Even if you opt out of marketing, we may continue to send service, safety, transactional, or legal communications. Where required, we honor legally recognized browser-based opt-out preference signals.
8. Security
CCA maintains administrative, technical, physical, and organizational safeguards designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Depending on the system and risk, these safeguards include:
No security measure can eliminate all risk. Please protect your credentials, use available security features, and notify us promptly if you suspect unauthorized access to your account or information.
9. Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, including to provide Services and to meet safety, safeguarding, legal, regulatory, contractual, tax, insurance, and audit requirements. Retention periods vary by record type, jurisdiction, age of the individual, service context, and applicable professional requirements.
When information is no longer required, we delete, destroy, or anonymize it in accordance with our retention procedures, unless continued preservation is required or permitted by law. Backup copies may remain for a limited period under controlled access and deletion cycles.
10. Your Privacy Rights
Depending on where you live and the law that applies, you may have the right to:
These rights are not absolute. For example, we may need to preserve clinical records, comply with professional or legal duties, protect safety, maintain legal claims, or retain information that is exempt from a particular law. If we deny a request, we will explain the basis when required and provide an appeal process where applicable.
How to make a request
Email hello@ccainc.com with the subject line “Privacy Request.” Please describe your request and your relationship with CCA. We may need to verify your identity and authority before acting. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and direct identity verification. We will respond within the period required by applicable law.
We will not discriminate against you for exercising a privacy right. However, limiting processing or deleting information may affect our ability to provide a requested Service when the information is necessary for that Service.
Additional U.S. state disclosures
U.S. state privacy laws may require disclosure of the categories of personal information collected, sources, purposes, recipients, retention criteria, and available rights. Sections 2, 3, 5, 7, 9, and 10 provide that information. We process sensitive information, including health information and information concerning mental or physical health, only for lawful and reasonably necessary purposes, with consent where required. We do not use or disclose sensitive personal information for purposes that require a right to limit under applicable law unless we provide that right.
Residents of states with consumer-health-data laws may have additional rights and disclosures under a separate Consumer Health Data Privacy Notice made available where required.
11. Responsible AI and Automated Decision-Making
CCA approaches artificial intelligence (“AI”), machine learning, and automated decision systems with particular care because our Services may involve sensitive health and wellbeing information. Our governance principles include:
Automated decisions
CCA does not use solely automated processing to make decisions that produce legal or similarly significant effects about you without meaningful human involvement, unless the processing is lawful and accompanied by required safeguards. Where applicable, you may request information, express your point of view, contest the outcome, and request human review.
12. Children and Dependents
CCA Services may be available to eligible dependents, including minors. We collect and use a minor’s information only as permitted by applicable law and the relevant service arrangement. Depending on the minor’s age, location, and the Service, we may require authorization from a parent or guardian, the minor, or both. Confidentiality and access rights for minors’ health or counseling records vary by jurisdiction and may limit information available to a parent, guardian, employer, or sponsor.
Our general corporate website is not directed to children under 13, and we do not knowingly collect personal information from a child under 13 through that website without legally required authorization. If you believe a child provided information improperly, contact us.
13. Changes to This Policy
We may update this Policy to reflect changes in our Services, practices, technology, or legal obligations. We will post the updated Policy with a revised effective date. If a change materially affects how we use personal information, we will provide additional notice or seek consent when required by law.
14. Contact Us
Questions, concerns, complaints, and privacy requests may be directed to:
CCA, Inc. Privacy Office Email: hello@ccainc.com Website: https://ccainc.com
If EEA or UK data-protection law applies, you may also lodge a complaint with the supervisory authority in the country where you live, work, or believe an infringement occurred. We encourage you to contact us first so we can address your concern.
Get support that’s custom built for your company and delivered with care