Your privacy is protected
Health Passport Europe / Health Passport Worldwide
ROQU Group Limited (”ROQU” “we”, “us” or “our”) operates the Health Passport Europe platform (“Platform”) and related mobile applications which allow users to keep a personal health record containing the result of their COVID-19 test on a mobile application (the “Health Passport”) which they can then decide to make available to organisations and individuals if they so wish. ROQU is registered in Ireland under company number 671430 with its registered address at 303 Block C, 77 Sir John Rogersons Quay, Dublin 2, D02VK60, Ireland.
In this Privacy Notice, we inform you of the personal data relating to you that we collect as a controller in connection with you and the uses (including disclosures to third parties) that we may make of such data. We are committed to protecting your privacy and ensuring that it is processed in a secure and lawful manner.
If you have any questions about our use of your personal data, please contact us at firstname.lastname@example.org
Personal Data Collected and Processed
In order to use the Health Passport, you will require a user account. Accounts can be created by the user upon downloading and installing the application or by an authorised medical professional, acting as an Account Administrator.
To complete the creation of your account, the following information is required:
Name, date of birth
Mobile phone number, email address
Profile picture used for identification
Country of residence
If the account is created by an Account Administrator, you may also choose to provide us with the following OPTIONAL details:
You may consent to the following data in relation to your COVID-19 test results and vaccination details being uploaded to your Health Passport:
Type of test, date of test, test lab and test result
Type of vaccination, date, where administered, reference number and certificate
A status will be automatically generated based on your most recent COVID-19 test result.
Pending your approval of an access request, please note that information related to previous tests will be visible to an authorised Medical Professional accessing your account details at the moment of inputting information following a new test.
If you decide to use our travel and gathering personal diary, you may be asked to provide the following OPTIONAL information:
Travel: Start and end dates of travel, and details of the location of the travel
Gathering: Start and end dates of the gathering, and details of the gathering
Please note that the information you input within your Travels and Gatherings diary is private and is only visible to you.
When a COVID-19 vaccination becomes available, you may choose to include your vaccination information if you willingly consent for it to be uploaded to your Health Passport:
Vaccination date, type of vaccination, and details of its effective timeframe (if relevant).
If you contact us, including in relation to supporting your use of the Health Passport, we will collect and process any personal data contained in correspondence or other communications with you.
Some of the personal data listed above may be provided to us by third parties. For example, your user account may be created by the medical professional who performs your test and they may also upload your test result, but only under the circumstances that you have approved and you have given them your consent to do so.
Purpose of Processing and Legal Basis
We will use personal data relating to you for the purposes of:
Registering and activating your user account on our mobile application;
Enabling you to store your COVID-19 test result on our mobile application and make it available to others when appropriate and upon your consent to do so;
Responding to any enquiries or other communications that you have submitted to us and also to send you service updates; and
Resolving disputes with you, which may involve establishing, exercising or defending legal claims.
Please note that we DO NOT use your personal data for marketing purposes or share it with third parties for the purposes of data mining or retargeting.
The legal basis on which we collect and process your personal data in the manner described above are:
(b) our legitimate interests in operating our business. We will not process your personal data for these purposes if to do so would constitute an unwarranted interference with your own interests, rights and freedoms. Such interests include:
(i) facilitating your access and use of our services;
(ii) measuring engagement by users with our app and services and improving such as we see fit;
(iii) enabling us to manage our relationship with you which includes responding to enquiries and other communications received from you and communicating with you about service updates; and
(iv) resolving disputes and establishing, exercising and safeguarding our rights, including taking legal claims and other actions, where necessary and to respond to claims and allegations made against us or investigations involving us.
(c) to comply with our legal and regulatory obligations.
The legal basis on which we collect and process your health data is your explicit consent. The health service provider who carries out your test will ask you for your consent to upload your test result and related health data to your Health Passport. You can withdraw your consent at any time by emailing us at email@example.com.
Source of Data
As well as collecting information from you directly, we also receive or obtain information relating to you from those conducting tests (e.g. diagnostic labs and medical practitioners) or your employer’s health service provider in the case where testing has been arranged for you at your place of work.
Recipients of Data
We may disclose your personal data to other organisations in connection with the above purposes, including:
To third parties who we engage to provide services to us in connection with the Platform and apps and our business, such as, IT services providers, and auditors; and
To competent regulatory and law enforcement authorities and bodies as requested or required by law.
You may decide to make your Health Passport available to third parties whenever you deem necessary or convenient (e.g. in connection with travel, events or work-related activities). This sharing of your test or vaccination status is entirely at your discretion and under your control. If any third party requires you to provide access to your Health Passport, please contact us at firstname.lastname@example.org so that we can investigate.
We will not hold your personal data for longer than is necessary. We retain your personal data for as long as we need it for the duration of our relationship with you and for a period of time after that as necessary to comply with our obligations under applicable law and, if relevant, to deal with any claim or dispute that might arise between you and us. Typically, your account data is held for a period of up to one (1) year from when you cease being an active user of our service. Data relating to your test result is generally held for a period of up to 180 days.
You may also delete your account and all associated data at any time by emailing email@example.com. When you choose to delete your account your data will usually be permanently destroyed within 48 hours. The only exception to this is in the event that a legal dispute has arisen, in which case we may retain your personal data solely in connection with that legal dispute.
Requirement to Provide Personal Data
As we set out above in the “Personal Data that we Collect and Process” section, the provision of certain items of your personal data is required for the performance of your relationship with us. If you do not provide us with the information that we need then we will not be able to provide you with certain services such as access to the Health Passport system.
In connection with the above, your personal data is hosted within the European Economic Area at all times.
You have the following rights, in certain circumstances and subject to certain restrictions, in relation to your personal data:
the right to access your personal data;
the right to request the rectification and/or erasure of your personal data;
the right to restrict the use of your personal data;
the right to object to the processing of your personal data; and
the right to receive your personal data, which you provided to us, in a structured, commonly used and machine-readable format or to require us to transmit that data to another controller.
If you wish to exercise any of the rights set out above, please contact us at firstname.lastname@example.org
Data Protection Officer
We have appointed a data protection officer, who you can contact using the following details:
Data Protection Officer email@example.com
We may occasionally update this notice. We encourage you to periodically review this notice for the latest information on our privacy practices.
If you are not happy with the way we are using your personal data or how we facilitate your rights or comply with our obligations under applicable data protection law, you have the right to make a complaint to the Data Protection Commission (www.dataprotection.ie).