You may be asked to provide personal data whilst you are in contact with us. Personal data is information that can be used to identify or contact you. You do not have to provide the personal data that we request, however, if you choose not to, we may not be able to provide you with the services that you have requested.
If we combine personal data with non-personal data, the combined information will be treated as personal data for as long as it remains combined. Personal data does not include data where the identity has been removed (anonymous data).
For the purpose of the General Data Protection Regulations ((EU) 2016/679) and any national implementing laws, regulations and secondary legislation and the Data Protection Act 1998 (“Data Protection Legislation”) the data controller is LumiraDX Care Solutions UK Ltd a company registered in England and Wales with company registration number 03473597 whose address is 1 North Crofty, Tolvaddon Energy Park, Camborne, TR14 0HX. Our Data Protection Registration Number is Z2996445.
INFORMATION WE MAY COLLECT FROM YOU
We may collect and process the following data about you:
WHERE WE STORE YOUR PERSONAL DATA
Some of the third parties which we work closely with are based outside of the EEA so their processing of your personal data will involve a transfer of data outside of the EEA.
Whenever we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
Where we have given you (or where you have chosen) a password which enables you to access certain parts the INRstar Engage App, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to the INRstar Engage App; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
PROCESSING YOUR DATA
We may use data held about you in the following ways:
You have the right to withdraw your consent to us using your personal data (and to request that we delete it) at any time by contacting us.
A cookie is a small file of letters and numbers that is stored on your browser or the hard drive of your computer. Cookies contain information that is transferred to your computer's hard drive.
CHANGE OF PURPOSE
DISCLOSURE OF YOUR DATA
You agree that we may disclose your data (including personal data) to the following categories of third parties:
Your personal data will not be shared with third parties for third party marketing purposes unless you have provided your express consent to this in the communication preferences area of the INRstar Engage App. If you do not want to be contacted with third party marketing information, you can opt out at any time by contacting us or by changing your settings in your communication preferences area of the INRstar Engage App;
We may disclose your personal data to third parties:
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow third parties to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
Under Data Protection Legislation, in certain circumstances you have the following rights in relation to your personal data:
(a) Right to access. You have the right to request access to information held about you. We will provide you with a copy of your personal data held by us free of charge (providing your request is not excessive or for multiple copies, in which case we may charge a reasonable fee to cover our costs) and certain information about the processing of your personal data and the source of such data (if not directly collected from you by us). You also have the right to request that your personal data is transferred to a third party.
(b) Right to object to data processing. You may withdraw your consent to the processing of your personal data at any time by contacting us. Upon receipt of your notification, we shall promptly stop any processing of your personal data and (if requested by you) erase such information if we are not required to retain it for legitimate business or legal purposes.
(c) Right to restrict processing. You may ask us to suspend the processing of your personal data in the following circumstances:
(d) Right of rectification and right of erasure.You have the right to request that we correct any inaccuracies in your personal data if such information would be incomplete, inaccurate or processed unlawfully. You also have the right to request that your personal data be erased providing that we no longer have a lawful reason for processing your data.
Where we are relying on consent to process your personal data, you may withdraw consent at any time. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain services to you. We will advise you if this is the case at the time you withdraw your consent.
You can exercise these rights at any time by contacting us via email at firstname.lastname@example.org. We may reject requests that are unreasonable or require disproportionate effort (for example, such a request would result in a fundamental change to our existing practice) or risk the privacy of others.
The INRstar Engage App may, from time to time, contain links to and from third party applications. If you follow a link to any of these applications, please note that these applications have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these applications.
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
PERSONAL DATA RETENTION
We may retain information about you, including personal data, for the period necessary to fulfil the purposes for which it was first collected unless a longer retention period is required or permitted by law. In determining data retention periods, we take into considerations contractual obligations, legal obligations and the expectation and requirements of our customers. When personal data is no longer needed, we will securely delete or destroy it.
In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.
FAO: Data Protection Officer
LumiraDx Care Solutions UK Ltd
1 North Crofty
Tolvaddon Energy Park
If you have any cause for complaint about our use of your personal data, please contact us using the details provided above and we will do our best to solve the problem for you. If we are unable to help, you also have the right to lodge a complaint with the UK’s supervisory authority, the Information Commissioner’s Office (www.ico.org.uk).