Privacy Policy
Data Collection
myBiodentity undertakes that where Your
Data is collected, it will be done by means that are:
- fair;
- legal; and
- transparent.
If you visit myBiodentity's web-site,
your web-browser automatically discloses, and myBiodentity's
web-server automatically logs, the following information:
the date and time, the IP address from which you issued the
request, the type of browser and operating system you are
using, the URL of any page that referred you to the page,
the URL you requested, and whether your request was successful.
This data may or may not be sufficient to identify you.
Any additional data that you provide, e.g. in a web-form,
may also be logged. This data may or may not be sufficient
to identify you.
Any additional data that your web-browser automatically
provides may also be logged. This will be the
case, for example, if your browser has previously been
requested to store data on your computer in 'cookies' and
submits them each time you request a web-page within
a particular domain (such as myBiodentity.com). This data
may or may not be sufficient to identify you.
If you disclose personal data to myBiodentity
in conjunction with an identifier such as your name
or your credit-card details, myBiodentity will
collect Your Data. Moreover, any data that becomes
available to myBiodentity through any of the means described
in the preceding paragraphs may be able to be associated
with that identifier, and hence become Your Data.
Subject to the qualifications immediately below, myBiodentity
undertakes to collect Your Data from you and
not from other parties. This undertaking is qualified as
follows:
- where myBiodentity reasonably considers that the protection
of its financial interests requires that it gather YourData
from other sources, or from additional sources. This
applies in particular where myBiodentity has a lending
exposure to you, and seeks information about your creditworthiness;
- where myBiodentity reasonably considers that its capability
to deliver quality services to you will be materially enhanced
by gathering YourData from other sources. This applies
in particular to consumer profile data.
Where myBiodentity collects Your Data
from sources other than you, it undertakes:
- to do so only by legal means;
- to do so only with your Consent; and
- to declare to you what sources it uses, and under what
circumstances.
myBiodentity undertakes to declare the purpose
of collection in a manner which is clear and meaningful,
and to avoid vague, highly inclusive statements such as
'to support our operations'.
Data Security
myBiodentity undertakes to store Your
Data in a manner that ensures security against unauthorised
access, alteration or deletion, at a level commensurate with
its sensitivity.
myBiodentity undertakes to store Your Data only in jurisdictions where
data protections are at least equivalent to those required
under the OECD Guidelines.
myBiodentity undertakes to transmit Your Data
in a manner that ensures security against unauthorised access,
alteration or deletion, at a level commensurate with its
sensitivity.
myBiodentity undertakes to implement appropriate measures
to ensure security of Your Data against inappropriate behaviour
by myBiodentity's staff-members and contractors. These
include:
- training for staff in relation to privacy;
- access control, to limit access to Your Data to those
staff and contractors who have legitimate reasons to access
it;
- particularly in the case of sensitive data, audit trails
of accesses, including the identities of staff and contractors
accessing the data;
- reminders to staff and contractors from time to time
about the importance of data privacy, and the consequences
of inappropriate behaviour;
- declaration of appropriately strong sanctions that are
to be applied in the event of inappropriate behaviour
- clear communication of policies and sanctions; and
- processes to audit, to investigate and to impose sanctions.
Data Use
Use refers to the application of Your Data
by any part of myBiodentity, or any staff-member or contractor
of myBiodentity in the course of their work.
myBiodentity undertakes to use Your Data only for:
- the purposes for which it was collected;
- such other purposes as are subsequently agreed between
myBiodentity and You;
- such additional purposes as may be required by
law. In these circumstances, myBiodentity will
take any reasonable steps available to it to communicate
to You that the use has occurred, unless it is precluded
from doing so by law; and
- such additional purposes as are authorised by
law (in particular to protect myBiodentity's interests,
e.g. if it believes on reasonable grounds that You have
failed to fulfil your undertakings to myBiodentity or have
committed a breach of the criminal law).
myBiodentity undertakes to use YourData only
if it has demonstrable relevance to the
particular use to which it is being put.
myBiodentity undertakes to use YourData in such a manner as
to take into account the possibility that it is not of sufficient
quality for the purpose, e.g. because it is inaccurate,
out-of-date, incomplete, or out-of-context.
Data Disclosure
Disclosure refers to making YourData available
to any party other than myBiodentity and You. The term disclosure
may include many different conditions of data transfer, including
selling, renting, trading, sharing and giving.
myBiodentity undertakes to disclose Your Data only under the
following circumstances:
- in the course of business being conducted between
You and myBiodentity, where disclosure is necessary
to a contractor, such as a transport company. Where
Your Data is disclosed in this way, myBiodentity undertakes
to exercise control over myBiodentity's contractors to
ensure that their actions are compliant with these
Terms;
- in other circumstances that are directly implied
by the purpose agreed between You and myBiodentity at
the time of data collection or subsequently. Where Your
Data is disclosed in this way, myBiodentity undertakes
to exercise control over myBiodentity's contractors to
ensure that their actions are compliant with these Terms;
- with your consent, or at your request;
- where required by law, such as a provision
of a statute, or a court order such as a search warrant
or sub poena. In these circumstances, myBiodentity will take
any reasonable steps available to it to communicate to
You that the disclosure has occurred, unless it is precluded
from doing so by law;
- where permitted by law (e.g. the reporting
of suspected breach of the criminal law to a law enforcement
agency; and in an emergency, where myBiodentity believes
on reasonable grounds that the disclosure of YourData will
materially assist in the protection of the life of health
of some person), provided that myBiodentity will apply due
diligence to ensure that the exercise of the permission
is justifiable.
In all cases, myBiodentity undertakes to disclose
only such of Your Data as is necessary in the particular
circumstances.
Data Retention and Destruction
Subject to the qualifications immediately
below, myBiodentity undertakes:
- to retain Your Data only as long as
is consistent with its purpose; and
- to destroy Your Data when its purpose
has expired, and to do so in such a manner that Your Data
is not subsequently capable of being recovered.
This undertaking is qualified as follows:
- Your Data may be retained in myBiodentity's logs,
backups and audit trails within short-term
retention cycles that are devised to protect the company's
operations. In such cases, Your Data will be destroyed
in accordance with those cycles;
- Your Data may be retained beyond the expiry of its purpose
if that is required by law, such as a
provision of a statute, or a court order such as a search
warrant or sub poena, or a warning by a law enforcement
agency that delivery of a court order is imminent. In these
circumstances, myBiodentity:
- will take any reasonable steps available to it to
communicate to You that Your Data is being retained,
unless it is precluded from doing so by law; and
- will only retain Your Data while that provision is
current, and will then destroy Your Data;
- Your Data may be retained beyond the expiry of its purpose
if it is authorised by law (in particular
to protect myBiodentity's interests, e.g. if it believes
on reasonable grounds that You have failed to fulfil your
undertakings to myBiodentity or have committed a breach of
the criminal law). In these circumstances, myBiodentity will
only retain Your Data while that situation is current,
and will then destroy Your Data.
Access by You to Your Personal Data
myBiodentity undertakes to provide you with access to
Your Data, subject to only such conditions and processes
as are reasonable in the circumstances. In particular, myBiodentity
undertakes to enable access:
- conveniently;
- without unreasonable delay; and
- without cost.
myBiodentity undertakes to establish and operate identity
authentication protections for access to Your Data that
are appropriate to its sensitivity, but practical. This
may involve some inconvenience; for example, relatively
straightforward procedures may be involved in order to
provide you with access through a channel that you have
previously registered with myBiodentity (such as a particular
email-address), but may impose more onerous procedures
if you wish to use some other channel.
In the event that you dispute some aspect of Your Data, myBiodentity
undertakes to take reasonable steps in relation to the amendment,
supplementation or deletion of Your Data.
You undertake:
- not to seek access for frivolous purposes, or unreasonably
frequently;
- to accept that deletion of some data may not be consistent
with the provision of particular services by myBiodentity
to you.
Information about Data-Handling Practices
myBiodentity undertakes to make information
available to you about the manner in which myBiodentity handles
your data:
- in general terms, in a readily accessible manner; and
- in more specific terms, on request.
Where Your Data is disclosed to a contractor,
myBiodentity undertakes to make information available to you
on request about the manner in which myBiodentity's contractors
handle your data.
myBiodentity undertakes to ensure that the information provided
is meaningful, and addresses your concerns.
You undertake:
- not to seek such information for frivolous purposes,
or unreasonably frequently; and
- to accept that the disclosure of excessive detail may
harm the security of Your Data and myBiodentity's business
processes, and may harm myBiodentity's commercial interests.
Handling of Enquiries, General Concerns
and Complaints
If you have enquiries, general concerns,
or complaints about these Terms, or about myBiodentity's behaviour
in relation to these Terms, you undertake:
- to communicate them in the first instance:
- to myBiodentity only;
- in sufficient detail;
- through a channel made available by myBiodentity for
that purpose;
myBiodentity undertakes:
- to provide one or more channels for communications to
myBiodentity, which are convenient to users;
- to promptly provide acknowledgement of
the receipt of communications, including the provision
of a copy of the communication, the date and time it was
registered, and myBiodentity's reference-code for the communication;
- to promptly provide a response to the
communication, in an appropriate and meaningful manner.
You further undertake to not pursue myBiodentity
through any Regulator or the media:
- until and unless myBiodentity has had
a reasonable opportunity to respond to the initial communication;
and
- while myBiodentity and you remain are conducting
a meaningful dialogue about the matter.
|