This document establishes The Ultimate Software Group, Inc. (“Ultimate Software”) Privacy Policy. This document is in accordance to ISO/IEC 27001:2013 and establishes Control A18.1.4 – Privacy and Protection of Personally Identifiable Information and ISO/IEC 27018:2014 and establishes applicable controls in Annex A – Public cloud PII processor extended control set for PII protection.


This Privacy Policy applies to all Personally Identifiable Information (PII) received by Ultimate Software from its customers, employees, website visitors and job applicants (including its Subsidiaries) (each which may be individually referred to herein as “you” or “your”) in any format including electronic, paper, or verbal. For purposes of this Policy, “PII” means any information collected by Ultimate Software that identifies or could be used by Ultimate Software to identify an individual. As a subset of the larger group listed herein above, Ultimate Software processes information of employees of its customers under the direction of its customers and has no direct relationship with such customers’ employees whose personal data it may process on the customer’s behalf.

Privacy Policy

Ultimate Software respects the privacy of our customers, employees, website visitors, and job applicants. We believe it is important for you to understand the type of information we collect about you and how that information is used. We recognize the need for appropriate safeguards and management of Personally Identifiable Information (PII) you provide to us. This Privacy Policy sets forth the privacy principles Ultimate Software follows with respect to your Personal Information.


Ultimate Software’s privacy practices, described in this Privacy Policy, comply with the APEC Cross Border Privacy Rules System (CBPS). The APEC CBPR system provides a framework for organizations to ensure protection of personal information transferred among participating APEC economies. More information about the APEC Cross Border Privacy Rules System can be found here.

TRUSTe Privacy Certification

Privacy Shield

Ultimate Software participates in and has certified its compliance with the EU-U.S. Privacy Shield Framework. Ultimate Software is committed to subjecting all personal data received from European Union (EU) member countries, in reliance on the Privacy Shield Framework, to the Framework’s applicable Principles. To learn more about the Privacy Shield Framework, visit the U.S. Department of Commerce’s Privacy Shield List.

Ultimate Software is responsible for the processing of personal data, defined as any operation or set of operations which is performed upon personal data, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction, it receives, under the Privacy Shield Framework, and, on occasion, subsequently transfers to a third party acting as an agent on its behalf. Ultimate Software complies with the Privacy Shield Principles for all onward transfers of personal data from the EU, including the onward transfer liability provisions.

With respect to personal data received or transferred pursuant to the Privacy Shield Framework, Ultimate Software is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, Ultimate Software may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.

Under certain conditions, more fully described on the Privacy Shield website, you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.

TRUSTe Privacy

Safe Harbor

Ultimate Software complies with the U.S. – Swiss Safe Harbor Framework as set forth by the U.S. Department of Commerce regarding the collection, use and retention of personal data from Switzerland. Ultimate Software has certified that it adheres to the Safe Harbor privacy principles of notice, choice, onward transfer, access, security, data integrity, and enforcement. More information about the U.S. Department of Commerce’s Safe Harbor program and Ultimate Software’s certification can be found at http://www.export.gov/safeharbor/.


How Personal Information is Collected
Web Visitors
Ultimate Software collects PII about a visitor to our website only when the visitor chooses to provide such information. On certain pages, for example, a visitor has the opportunity to provide his/her PII such as his/her name, company, address, phone number, and e-mail address. By supplying such information to Ultimate Software, a visitor can request details about Ultimate Software, including information about the company’s product line and investor information, or sign up for company-sponsored events or use the company’s support website.

Website / Cookies and other Tracking Technologies
In order to improve the content and format of our site, Ultimate Software uses website tracking software to automatically capture technical information that is then stored in our server’s log files. This information may include, but is not limited to, user domain, the type of Internet browser being used, which of our Web pages is visited, and the amount of time spent on our site.

Ultimate Software and its partners use cookies and similar technologies to analyze trends, administer the website, track users’ movements around the website, and to gather demographic information about our user base as a whole. To manage Flash cookies, please click here: http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager07.html

A cookie is a small amount of data which our website stores on your computer, and which we can later retrieve. The cookie cannot be read by a site other than ours. We use cookies for a number of administrative purposes; for example, to store your preferences for certain kinds of information. No cookie will contain information that will allow anyone to contact you via telephone, e-mail, or any other means. You can monitor our use of cookies on your computer by setting your Web browser to inform you when cookies are set, or you can prevent the cookies from being set entirely. The “help” portion of the toolbar on most browsers will tell you how to prevent your browser from accepting new cookies, how to have the browser notify you when you receive a new cookie, or how to disable cookies altogether. Please understand that if you disable the use of cookies on your computer, you may be unable to access certain portions or services on our websites.

We partner with third parties to manage our advertising on other sites. Our third party partners may use cookies or other similar technologies to provide you advertising based upon your browsing activities and interests. If you wish to opt out of interest-based advertising click here; if you are located in the European Union click here. Please note you will continue to receive generic ads.

Job Applicants and Employees
Ultimate Software collects PII from job applicants and employees of Ultimate Software for, among other things, legitimate human resource business reasons such as payroll administration, filling employment positions, maintaining accurate benefits records, meeting governmental reporting requirements, security, health and safety management, performance management, company network access, and authentication.

Ultimate Software collects PII from customers of Ultimate Software who use our solution. The information may be collected through our SaaS solution, or by members of our support team who provide support to customers. The type of PII collected is similar to the information collected under the “Job Applicants and Employees” paragraph, above.

Ultimate Software collects information under the direction of its customers and has no direct relationship with the individuals whose personal data it processes. If you are an individual of one of our customers and would no longer like to be contacted by one of our customers that use our service, please contact the customer that you interact with directly. We may transfer personal information to companies that help us provide our service. Transfers to subsequent third parties are covered by the service agreements with our customers. The use of information collected through our SaaS solution shall be limited to the purpose of providing the service for which the customer has engaged Ultimate Software.


Use of Your Personal Information
We use your PII to provide you with the services, which Ultimate Software is contractually obligated to provide to you, or to assist you in completing a transaction, or communicate with you about our products or services. We use PII from website visitors to respond to any inquiries such visitors make to our website and to provide you with related information of interest to you. We do not sell or rent your PII to third parties.

We may disclose your PII if we are required to do so by law or we in good faith believe that such action is necessary to (1) comply with the law or with legal process; (2) protect and defend our rights and property; (3) protect against misuse or unauthorized use of our website; or (4) protect the personal safety or property of our users or the public (among other things, this means that if you provide false information or attempt to pose as someone else, information about you may be disclosed as part of any investigation into your actions).

Other than as stated in this Privacy Policy, we will endeavor not to release your PII to unknown or unaffiliated third parties, and we will not cross-reference your PII with that of any other customer or entity.

Onward Transfer

Sharing of Your Personal Information
Ultimate Software may contract with third-party providers to perform certain functions on our behalf or to enhance our existing product and service offerings. Examples include providing marketing assistance, product, and service support. These third parties may have access to your PII only to the extent necessary to provide these services, however, they are bound by confidentiality agreements before any information is provided to them, and they are restricted from using the information for other purposes.

If you do not wish your information shared with third-party providers for the purposes of providing services you may opt-out by contacting us at privacy@ultimatesoftware.com.

Links to Non-Ultimate Software websites and Third Parties

Ultimate Software’s websites may contain links to third-party sites for your convenience and/or information. If you access those links, you will leave Ultimate Software’s website and be re-directed to a third-party site. Ultimate Software does not control those sites or the privacy practices of those third-party sites, which may differ from Ultimate Software’s privacy practices. We do not endorse or make any representations about third-party websites, and the personal data you choose to provide to third-party websites is not covered by this Privacy Policy. We encourage you to review the privacy policy of any website or company before submitting your PII to them.


As to its own employees and its own job applicants, Ultimate Software will take reasonable steps to provide that your PII is accurate, complete, and current, to its intended use. We provide individuals with reasonable access to the PII that they provide to us, as well as the ability to review and correct such information. For access requests please contact us at privacy@ultimatesoftware.com. We will respond to your request within a reasonable timeframe.

The Privacy Shield framework provides EU citizens with a right to access their PII. Ultimate Software has no direct business relationship with the individuals whose personal data it processes (individuals of our customers). If you are an individual of one our customers or an EU citizen seeking access to your personal information please direct your query to Ultimate Software’s customer with whom you do have a business relationship.

To protect your privacy and security, we also take reasonable steps to verify your identity, before granting access to your PII. In addition, we may limit or deny access to PII where providing such access would be unreasonably burdensome or expensive in the circumstances, or as otherwise permitted by the Privacy Shield and Swiss Safe Harbor Framework.

For access requests please contact us at privacy@ultimatesoftware.com. We will respond to your request within a reasonable timeframe.


To prevent unauthorized access or disclosure, to maintain data accuracy, and to allow only the appropriate use of your PII, we utilize physical, technical, and administrative controls and procedures to safeguard the information we collect.

To protect the confidentiality, integrity, and availability of your PII, Ultimate Software utilizes a variety of physical and logical access controls, firewalls, intrusion detection/prevention systems, network and database monitoring, anti-virus, and backup systems. We use encrypted sessions when collecting or transferring sensitive data through our websites.

We limit access to your PII and data to those persons who have a specific business purpose for maintaining and processing such information. Ultimate Software’s employees who have been granted physical access to your PII are made aware of their responsibilities to protect the confidentiality, integrity, and availability of that information and have been provided training and instruction on how to do so.

Data Integrity

As to its own employees and its own job applicants, Ultimate Software will take reasonable steps to provide that PII is accurate, complete, and current, to its intended use. Ultimate Software will only use PII in ways that are compatible with the purposes for which it was collected or subsequently authorized by the individual.

Enforcement and Verification

Ultimate Software will conduct periodic assessments to validate its continued adherence to this Privacy Policy.

Where Ultimate Software has knowledge that one of Ultimate Software’s employees or third parties is using or disclosing PII in a manner contrary to this Policy, Ultimate Software will take reasonable steps to prevent or stop the use or disclosure. Ultimate Software holds its employees and agents accountable for maintaining the trust that our customers place in our company. 

Dispute Resolution

Ultimate Software will investigate and attempt to resolve complaints and disputes regarding the use and disclosure of PII in accordance with the principles contained in this Policy. Ultimate Software agrees to cooperate with data protection authorities located in the European Union and Switzerland or authorized representatives for disputes specific to Human Resource information received from the European Union and Switzerland. All other disputes that cannot be resolved between Ultimate Software and the complainant will be handled in accordance with applicable dispute resolution procedures through our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request. We strongly encourage you to raise any complaints you may have with regard to this Privacy Policy and/or our activation of this Policy to us prior to proceeding to the arbitration procedure described in this Policy.

Changes to This Privacy Policy

The practices described in this Policy are the current PII protection policies approved on September 1, 2016. Ultimate Software reserves the right to modify or amend this Policy at any time consistent with the requirements Privacy Shield and of the Swiss Safe Harbor Principles. If we make any material changes we will notify you or our customer by email (sent to the email address specified in your account) or by means of a notice on this website prior to the change becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices.

Contact Information

At any time you may contact Ultimate Software with questions or concerns about this Privacy Policy at privacy@ultimatesoftware.com. Written responses may also be submitted to:

The Ultimate Software Group
Attention: Vice President of Privacy, Risk & Compliance
1485 North Park Drive
Weston, FL 33326