01 Who we are & what this policy covers
This policy is primarily about our website — what we collect on renewhr.com, why, and the controls you have. Where a section also covers our Benefits Reimagined platform, it says so explicitly.
Renew HR (“Renew HR,” “we,” “us,” or “our”), headquartered in Dallas, Texas, provides HR advisory and SAP SuccessFactors consulting services and operates Benefits Reimagined (BR), an AI-powered employee benefits administration platform built on SAP Business Technology Platform (BTP).
This Privacy Policy applies to:
- Our websites — renewhr.com and any Renew HR-operated subdomains, including forms, downloads, chat, and event registrations;
- The Benefits Reimagined platform — the employee benefits enrollment, administration, and service-delivery applications we host for employer clients, including Athena (our AI benefits assistant), BR IntelliSuggest, BR IntelliMap, the Document Center, Communication HUB, and Intelligent Service Delivery (ISD) case management;
- Business interactions — sales, marketing, events, webinars, support, and partner engagement.
It does not apply to third-party websites we link to (for example, benefit carriers, HSA custodians, or SAP properties), which maintain their own privacy notices.
02 Our two roles: controller and processor
For website visitors, we decide how data is used (we’re the “controller”). For employees using Benefits Reimagined through their employer, your employer decides — we process data strictly on their instructions.
Like other benefits administration providers, we operate in two distinct capacities, and your rights differ depending on which applies:
When we are the controller
For visitors to renewhr.com, prospects, event attendees, and business contacts, Renew HR determines the purposes and means of processing. This policy fully governs that processing, and you can exercise the rights in Section 11 directly with us.
When we are the processor (service provider)
When your employer or plan sponsor uses Benefits Reimagined to administer its benefits program, your employer is the data controller and Renew HR processes your personal data only as instructed and permitted under our written agreement with them. In that capacity we do not use employee benefits data for our own marketing, do not sell it, and honor deletion and correction instructions from the plan sponsor. If you are an employee with a question or request about data in Benefits Reimagined, please contact your employer’s HR or benefits team first — they direct how your data is handled, and we support them in fulfilling your request. We will notify the relevant employer without undue delay if we receive a rights request that belongs with them.
03 Information we collect
The categories below reflect what we actually collect, from whom, and why. We collect nothing beyond what the stated purpose requires.
| Category | Examples | Source | Context |
|---|---|---|---|
| Identifiers & contact | Name, work email, phone, company, job title | You (forms, registrations) | Website & sales |
| Enrollment & eligibility data | Employee ID, date of birth, dependents, plan elections, coverage tiers, life events, salary band (for contribution calculations) | Your employer / HRIS (e.g., SAP SuccessFactors) and your entries during enrollment | Benefits Reimagined (processor role) |
| Benefits account data | HSA/FSA elections, retirement plan deferrals, COBRA qualifying events, ACA measurement data | Your employer, carriers, and your platform activity | Benefits Reimagined (processor role) |
| Documents | Dependent verification documents, EOI forms, uploaded evidence in the Document Center | You / your employer | Benefits Reimagined (processor role) |
| Support & case data | ISD tickets, HR case history, Athena chat transcripts | You, during support interactions | Both |
| Usage & device data | IP address, browser type, pages viewed, session analytics (ElasticSearch/Kibana), cookie identifiers | Automatic | Both — see our Cookie Policy |
| Marketing preferences | Subscriptions, webinar attendance, content downloads | You | Website & sales |
We do not collect precise geolocation, biometric identifiers, or data from data brokers.
04 How we use information
We use personal information to:
- Deliver the services — run enrollment, calculate eligibility and contributions, generate carrier files, process life events, verify dependents, and administer COBRA, ACA, HSA/FSA, retirement, and voluntary benefits;
- Provide support — route and resolve ISD cases, answer questions through Athena, and maintain audit trails required for benefits compliance;
- Meet legal obligations — ACA reporting (Forms 1094-C/1095-C), COBRA notice timelines, ERISA record-keeping, and responses to lawful requests;
- Secure and improve the platform — monitor for fraud and abuse, debug, and analyze aggregate usage to improve features (aggregate or de-identified data only, which we commit not to re-identify);
- Communicate — respond to inquiries, send service notices, and (for business contacts who have not opted out) share relevant content and event invitations.
We do not use personal information for purposes that are incompatible with these, and we do not use client employee data to train generalized AI models.
05 AI features & automated processing
Our AI features suggest and assist — they never make final decisions about your benefits, and a human path is always available.
Benefits Reimagined includes AI-assisted features: BR IntelliSuggest (plan recommendations based on your household profile and elections), BR IntelliMap (vendor data mapping), Athena (a conversational benefits assistant), and AI-powered document verification. For these features:
- AI outputs are decision support, not decisions — enrollment eligibility, approvals, and appeals are governed by your employer’s plan rules and human review, not by an algorithm;
- Athena conversations are logged for quality and audit purposes within your employer’s tenant and are subject to the same processor obligations as other platform data;
- Prompts and data sent to third-party AI model providers are governed by contracts that prohibit use of that data to train the provider’s models;
- You may always decline AI-generated recommendations and complete any transaction through standard forms or a human case worker via ISD.
06 When we share information
We share personal information only with:
- Benefit carriers, custodians & vendors you or your employer select — medical, dental, vision, life, and disability carriers; HSA/FSA custodians; retirement record-keepers; COBRA and EAP administrators — via secure EDI/API integrations mapped through BR IntelliMap;
- Your employer / plan sponsor — enrollment status, eligibility, and reporting for the plans they sponsor;
- Subprocessors — hosting (SAP BTP data centers in the United States), analytics infrastructure, email delivery, and AI model providers, each bound by written data protection terms; a current subprocessor list is available on request at privacy@renewhr.com;
- Professional advisors and authorities — where required by law, subpoena, or to protect rights, safety, or property;
- A successor entity — in a merger, acquisition, or asset sale, with notice to affected clients.
07 We do not sell your personal information
Renew HR does not sell personal information and has not sold it in the preceding 12 months, and we do not “share” personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act (as amended by the CPRA). We do not knowingly sell or share the personal information of anyone under 16. If our practices ever change, we will update this policy and provide the required opt-out mechanisms before doing so.
08 Health & benefits data (HIPAA)
Benefits data can include protected health information. Where it does, HIPAA — not just this policy — governs how we handle it.
Some data processed in Benefits Reimagined — for example, enrollment in a group health plan, FSA claims substantiation, or evidence-of-insurability workflows — may constitute protected health information (PHI) under the Health Insurance Portability and Accountability Act (HIPAA). Where Renew HR acts as a business associate to a covered entity or group health plan, we process PHI under a Business Associate Agreement (BAA), apply the HIPAA Security Rule safeguards, limit uses and disclosures to those the BAA permits, and report security incidents as HIPAA requires. Nothing in this policy reduces protections that HIPAA or your plan documents provide.
09 How we protect information
We maintain administrative, technical, and physical safeguards proportionate to the sensitivity of benefits data, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256) on SAP BTP and SAP HANA;
- Role-based access control, least-privilege administration, and multi-factor authentication for privileged access;
- Tenant isolation between employer clients, with audit logging of access to employee records via ElasticSearch-backed audit trails;
- Vendor security review for all subprocessors and integration partners;
- An incident response plan with client notification commitments consistent with state breach notification laws and applicable BAAs.
No system is perfectly secure; if a breach affecting your personal information occurs, we will notify affected clients and individuals as applicable law requires.
10 How long we keep information
We retain personal information only as long as needed for the purposes described above, then delete or de-identify it. Representative periods:
| Data type | Retention | Why |
|---|---|---|
| Website inquiry & marketing data | Up to 24 months after last interaction | Relationship management; deleted sooner on request |
| Benefits enrollment & ACA records | Duration of client contract + statutory period (e.g., IRS/ERISA record-keeping) | Legal reporting and audit obligations |
| ISD cases & Athena transcripts | Per client-configured retention schedule | Client controls retention in processor context |
| Server & security logs | 12–18 months | Security monitoring and forensics |
At contract end, client employee data is returned or destroyed per the client agreement, subject to legal holds.
11 Your U.S. state privacy rights
Depending on your state, you can ask what we hold about you, get a copy, correct it, delete it, or opt out of certain uses. We extend these rights to all U.S. residents regardless of state.
Twenty states — including California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Texas (TDPSA), Oregon, Montana, Florida, Iowa, Tennessee, Delaware, New Jersey, New Hampshire, Nebraska, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island — have comprehensive privacy laws in effect as of 2026. Rather than gate rights by ZIP code, Renew HR honors the following requests from any U.S. resident where we act as controller:
Know & access
Confirm whether we process your personal information and receive a copy of it in a portable format.
Correct
Fix inaccurate personal information we hold about you.
Delete
Request deletion, subject to legal retention obligations we must meet (e.g., ACA records).
Opt out
Opt out of targeted advertising and any sale of personal data (we conduct neither), and of profiling in furtherance of significant decisions.
How to exercise your rights
Email privacy@renewhr.com with the subject “Privacy Rights Request,” or call +1-(972) 440-0306. We verify identity using information we already hold, respond within 45 days (extendable once by 45 days with notice), and never discriminate against you for exercising a right. You may designate an authorized agent; we will verify the agent’s authority. If we decline a request, we explain why and how to appeal — appeals are reviewed by someone other than the original decision-maker, and unresolved appeals may be directed to your state Attorney General.
Universal opt-out signals
Our website recognizes the Global Privacy Control (GPC) browser signal and treats it as a valid opt-out of any applicable sale/sharing and targeted advertising for that browser, as required in California, Colorado, Texas, and other states.
If your data lives in Benefits Reimagined
Most state privacy laws exempt data processed on behalf of an employer (and HIPAA-covered data). For that data, contact your employer’s benefits team; we will support their response as processor.
12 Children's privacy
Our website and marketing are directed to business professionals, not children, and we do not knowingly collect personal information from anyone under 13 (or sell/share data of anyone under 16). Dependent information in Benefits Reimagined — including minor dependents enrolled in coverage — is processed solely on the plan sponsor’s instructions for benefits administration, never for marketing or profiling.
13 Changes to this policy
When we make material changes, we will update the effective date above, post the revised policy here, and — for significant changes affecting platform data — notify client administrators in advance through the Communication HUB. Prior versions are available on request. We encourage you to review this page periodically.
14 Contact us
Privacy Office — Renew HR
Email: privacy@renewhr.com · Phone: +1-(972) 440-0306
Mail: Renew HR, Attn: Privacy Office, Dallas, Texas, USA
For general inquiries: info@renewhr.com · For accessibility of this notice in an alternative format, see our Accessibility Statement.