
Health Passport Worldwide / HPW.health
Privacy Notice
HPW Digital Health Ltd (”HPW” “we”, “us” or “our”) operates the Health Passport Worldwide (HPW.health) platform (“Platform”) and related mobile applications which allow users to keep a personal health record, which can include test results, vaccinations and scans, on a mobile application (Health Passport Worldwide) which they can then decide to make available to organisations and individuals, if they so wish. HPW Digital Health Ltd is registered in Ireland under company number 720001 with its registered address at Fitzwilliam Hall, Fitzwilliam Place, Dublin 2, D02 T292, Ireland.
In this Privacy Notice, we inform you of the personal data relating to you that we collect as a controller in connection with you and the uses (including disclosures to third parties) that we may make of such data. We are committed to protecting your privacy and ensuring that it is processed in a secure and lawful manner.
If you have any questions about our use of your personal data, please contact us at mydata@healthpassportworldwide.com
PERSONAL DATA COLLECTED AND PROCESSED
In order to use the system, you will require a user account.
Accounts can be created by the user upon downloading and installing the application from the app store(s). You can also ask your healthcare provider to create an account on your behalf.
To complete the creation of your account, the following personal information is required:
-
First Name
-
Surname
-
Date of Birth
-
Mobile Phone Number
-
Email Address
-
Country of Residence
-
Profile picture, used for identification
Health Passport Worldwide uses your camera / local storage to enable you to upload your photos and documents.
You may also choose to provide us with the following OPTIONAL details:
-
Middle Name
-
Contact Address
-
Passport Number
-
Occupation
-
Employer
-
Industry
The following data, in relation to your health records, may be uploaded to your Health Passport by the medical professional that conducts your medical service on your behalf:
-
Test type, test date / time, laboratory used, where the test was administered, medical professional who administered the test, test results, additional comments, certificates / documents.
-
Vaccination type and dose, vaccination date, where it was administered, vaccination provider, batch number, certificates / documents.
-
Scan type, scan date, scan provider, referral doctor, additional comments, certificates / documents.
-
Blood test type, test date, location, medic name, additional comments, certificates / documents.
Note: Information will only be uploaded and accessed pending your approval, by ways of an access request.
Note: Information related to your previous health records will be visible to an authorised medical professional. This, however, remains specific to the health service(s) you have granted access to.
In some cases, at the point of care, you may be offered an optional physical HPW Health Card which contains your name, HPW account number and QR code.
If you decide to use the Travel wallet, Travel Diary, Gatherings, Events, you may be asked to provide the following OPTIONAL information:
-
Travel: Arrival date, Departure City, Arrival City, Booking Reference, Airline, travel documents.
-
Travel Diary: Departure Date, Return Date, personal notes of travel.
-
Gatherings: Start date, End Date, personal notes of gatherings.
-
Events: Event name, event date, booking reference number, booking ID.
Please note that the information you input within your Travel Wallet, Travel Diary and Gatherings is private and is only visible to you.
Health Passport Worldwide uses your camera / local storage to enable you to upload your photos and documents.
If you contact us, including in relation to supporting your use of the Health Passport, we will collect and process any personal data contained in correspondence or other communications with you.
Some of the personal data listed above may be provided to us by third parties. For example, your user account may be created by the medical professional who performs your test, and they may also upload your test result, but only under the circumstances that you have approved and you have given them your consent to do so.
PURPOSES OF PROCESSING AND LEGAL BASIS
We will use personal data relating to you for the purposes of:
-
Registering and activating your user account on our mobile application;
-
Enabling you to store your COVID-19 test results on our mobile application and make it available to others when appropriate and upon your consent to do so;
-
Enabling you to store your vaccination details on our mobile application and make it available to others when appropriate and upon your consent to do so;
-
Enabling you to store additional health records, including records related to blood tests, heart, vision, hearing, allergies, prescriptions, and dental records on our mobile application and make it available to others when appropriate and upon your consent to do so;
-
Responding to any enquiries or other communications that you have submitted to us and also to send you service updates; and
-
Resolving disputes with you, which may involve establishing, exercising, or defending legal claims.
Please note that we DO NOT use your personal data for marketing purposes, tracking or share it with third parties for the purposes of data mining or retargeting.
The legal basis on which we collect and process your personal data in the manner described above are:
(a) where any such processing is necessary for the performance of a contract with you (e.g. terms of use for Health Passport Worldwide) or for taking steps at your request with a view to entering into a contract with you (e.g. processing your registration details).
(b) our legitimate interests in operating our business. We will not process your personal data for these purposes if to do so would constitute an unwarranted interference with your own interests, rights, and freedoms. Such interests include:
(i) facilitating your access and use of our services;
(ii) measuring engagement by users with our app and services and improving such as we see fit;
(iii) enabling us to manage our relationship with you which includes responding to enquiries and other communications received from you and communicating with you about service updates; and
(iv) resolving disputes and establishing, exercising, and safeguarding our rights, including taking legal claims and other actions, where necessary and to respond to claims and allegations made against us or investigations involving us.
(c) to comply with our legal and regulatory obligations.
The legal basis on which we collect and process your health data is your explicit consent. The health service provider who conducts your test will ask you for your consent to upload your health records and related health data to your Health Passport. You can withdraw your consent at any time by emailing us at mydata@healthpassportworldwide.com
SOURCES OF DATA
As well as collecting information from you directly, we also receive or obtain information relating to you from those conducting tests (e.g. diagnostic labs and medical practitioners) or your employer’s health service provider in the case where testing has been arranged for you at your place of work.
RECIPIENTS OF DATA
We may disclose your personal data to other organisations in connection with the above purposes, including:
-
To third parties who we engage to provide services to us in connection with the Platform and apps and our business, such as, IT services providers, and auditors; and
-
To competent regulatory and law enforcement authorities and bodies as requested or required by law.
You may decide to make your Health Passport available to third parties whenever you deem necessary or convenient (e.g. in connection with a healthcare provider, travel, events, work-related activities, etc). The sharing of your health records is entirely at your discretion and under your control. If any third party requires you to provide access to your Health Passport, please contact us at mydata@healthpassportworldwide.com so that we can investigate, if necessary.
RETENTION
We will not hold your personal data for longer than is necessary. We retain your personal data for as long as needed for the duration of our relationship with you and for a period of time after that as necessary to comply with our obligations under applicable State law and, if relevant, to deal with any claim or dispute that might arise between you and us. Typically, your account is held for a maximum period of up to one (1) year after you cease being an active user of our service(s).
Data relating to your COVID-19 test results is generally held for a period of up to 180 days, after which point it may be deleted.
You may also permanently delete your account and all associated data at any time from Account Settings in the app's menu.
If you choose to delete your account, your account and all associated data will usually be permanently deleted immediately. This cannot be undone. The only exception to this is in the event that a legal dispute has arisen, in which case we may retain your personal data solely in connection with that legal dispute.
REQUIREMENT TO PROVIDE PERSONAL DATA
As we set out above in the “Personal Data that we Collect and Process” section, the provision of certain items of your personal data is required for the performance of your relationship with us. If you do not provide us with the information that we need then we will not be able to provide you with certain services such as access to the Health Passport Worldwide system.
TRANSFER ABROAD
In connection with the above, your personal data is hosted within the European Economic Area at all times.
YOUR RIGHTS
You have the following rights, in certain circumstances and subject to certain restrictions, in relation to your personal data:
the right to access your personal data;
-
The right to request the rectification and/or erasure of your personal data;
-
The right to restrict the use of your personal data;
-
The right to object to the processing of your personal data; and
-
The right to receive your personal data, which you provided to us, in a structured, commonly used, and machine-readable format or to require us to transmit that data to another controller.
If you wish to exercise any of the rights set out above, please contact us at mydata@healthpassportworldwide.com
DATA PROTECTION OFFICER
We have appointed a data protection officer, who you can contact using the following details:
Liam McKenna, Data Protection Officer dpo@healthpassportworldwide.com
UPDATES
We may occasionally update this notice. We encourage you to periodically review this notice for the latest information on our privacy practices.
COMPLAINTS
If you are not happy with the way we are using your personal data or how we facilitate your rights or comply with our obligations under applicable data protection law, you have the right to make a complaint to the Data Protection Commission (www.dataprotection.ie).