Member Privacy Notice
Last Updated: March 26, 2021
Virgin Pulse Passport (the “VP Passport”) is a risk management tool used by an organisation to manage and monitor access to its offices, workplaces and business locations and to support the health and safety of its employee base. VP Passport is operated by Virgin Pulse, Inc., a corporation organised under the laws of the State of Delaware, headquartered at 75 Fountain Street, Providence, Rhode Island, 02902, United States (“Virgin Pulse”, “Us”, “We” or “Our”). In this Privacy Notice (the “Notice”), the organisation that has engaged Virgin Pulse to operate VP Passport is referred to as the (the “VP Passport Sponsor”). We process your Personal Information (defined below) on behalf of your VP Passport Sponsor.
We are committed to protecting your rights and your privacy. This Privacy Notice (the “Notice”) explains what data We collect about you and how We store, analyse and share the data We collect about you through the platform (www.virginpulse.com) and the Virgin Pulse mobile application. This Notice applies to all Personal Information whether collected online or offline. The Notice also explains your rights with regard to your data, and how to contact Us to request access, corrections, transfer, restriction or deletion of the data We have collected about you.
We have designed Our Notice in a question and answer format to make it easy to read and understand. Please read through it carefully. If you do not agree with Our policies and practices contained in this Notice, please do not enrol in VP Passport.
Does Virgin Pulse collect information about me?
Yes. We collect anonymous and Personal Information about you to provide you with the VP Passport and Our services. “Personal Information” means any information, including personal and material circumstances, that allows a person to become identifiable. The Personal Information We collect includes, but is not limited to:
- Your contact information, including your first name and last name, home address, personal and business email addresses, and your phone number;
- The email address you use to sign-in;
- Your gender, date of birth and age;
- Your social security number or employee identification number;
- Non-specific information about your overall health status;
- Non-specific information about your daily habits, interaction with at-risk individuals and travel to at-risk areas;
- Additional information that may be collected via the use of customised questions added by your VP Passport Sponsor;
- Information about your utilisation of VP Passport, such as your risk level status;
- The comments and contributions you may make on the web-based platform or mobile application; and
- Additional information you may provide as you submit queries and requests to Us.
Please bear in mind that the extent of the Personal Information you may be able to share with Us will depend on VP Passport design and the features made available to you. If you choose to withhold information in your use of VP Passport, We may be unable to provide you with accurate feedback and services or an accurate status badge. Incorrect information may also result in inaccurate results that can affect your status in the system. Please ensure your answers are accurate and honest before submitting them.
How does Virgin Pulse use my Personal Information?
We will use the Personal Information collected only to provide you with access to Our services, including:
- To administer and manage your VP Passport account;
- To administer and manage VP Passport and related features;
- To identify you when you enrol or sign-in;
- To assess and track your risk status in VP Passport;
- To report on your risk status assessed via VP Passport;
- To provide you with information about VP Passport as well as any relevant resources made available to you or additional services your VP Passport Sponsor may make available to you; and
- To respond to your questions and requests.
Additionally, We may create “Anonymous Data” records by removing any Personal Information (including any contact information) that would allow the remaining data to be linked back to you. We may use the Anonymous Data for internal purposes, such as analysing patterns and VP Passport usage to improve Our services. We may use Anonymous Data to analyse and understand demographic trends, customer behaviour patterns and preferences, and information that can help Us enrich the functionality and quality of VP Passport.
How does Virgin Pulse communicate with me?
If you have opted to receive push notifications on your mobile device, We may, from time to time, send you push notifications to provide you with reminders and notices. If you no longer wish to receive such communications, you may turn them off at the device level.
Depending on how We are engaged to offer VP Passport and the specific approach of your VP Passport Sponsor, We may, from time to time, send you emails or newsletters with information about your VP Passport, any available resources, features, or related services. Depending on your country of residence, you may be given the opportunity to opt-in to receive Our communications as you enrol in the platform. Regardless of your initial selection, you may opt out of Our communications, free of charge, at any time, by updating your preferences in your account profile information, or by contacting Member Services directly.
How does Virgin Pulse collect my Personal Information?
In addition to the data collected from other sources as explained below, We collect Personal Information you voluntarily provide as you submit it through the web-based platform and the mobile application, by reviewing your use of the web-based platform and mobile application (for example through the completion of Our risk assessments).
We may also automatically collect additional information when you visit Our web-based platform or mobile application, including the type of browser used, the internet service provider (ISP), referring and exit pages, the files viewed on Our site (e.g. HTML pages, graphics, etc.), date and time stamps of activity on the platform, the accessing IP address (the unique address that identifies your device on the internet) and the operating system your device uses. We use this additional information to derive a broad, non-specific understanding of the locations from which Our Users access Our services, and to enhance the security controls around platform access. We also use it to analyse trends, administer the web-based platform, track Users’ movements on the platform and around the website, and to gather demographic information about Our User base as a whole.
What information does Virgin Pulse collect through VP Passport risk assessments?
VP Passport relies on risk assessments to assess your status in accordance with the applicable return-to-work strategy defined by your VP Passport Sponsor. These risk assessments follow the guidance provided by expert resources (such as the Centers for Disease Control and Prevention or the World Health Organization) but can be customised by your VP Passport Sponsor.
Does Virgin Pulse collect Personal Information about children?
As is explained in the Membership Agreement, the Programme is designed for adults over the age of 18, but minors as young as 16 may participate in the Programme under the supervision of a responsible adult. We do not knowingly collect Personal Information about children under the age of 13. If you have reason to believe that We have collected Personal Information about anyone under the age of 13, you can contact Us to remove the Personal Information.
Does Virgin Pulse receive information about me from other sources?
Yes. We may receive information about you from various sources to support VP Passport and services included in it. The sources may include:
Your VP Passport Sponsor
Depending on your VP Passport Sponsor’s approach, your VP Passport Sponsor may provide Us your Personal Information to identify you as an individual who can access VP Passport and become a User. We call this an “Eligibility File”. Please contact your VP Passport Sponsor directly if you have concerns or questions about what data is included in the Eligibility File or why your VP Passport Sponsor is sending Us this information.
We may receive information about you from other sources, including publicly available databases or third parties from whom We have purchased data. We combine this data with information We already have about you. We may also combine publicly available aggregated census and demographical data with your Personal Information. This can help Us analyse Our records to better evaluate the effectiveness of Our services.
Examples of the types of Personal Information that We may obtain from public databases include:
- Address information about you from third-party sources, such as the U.S. Postal Service, to verify your address before We send you mail or fulfil orders from the Virgin Pulse Online Store; or
- The U.S. Federal Do Not Call registry, to verify do not call preferences recorded there.
What Tools does Virgin Pulse use to Collect my Personal Information?
Virgin Pulse and its vendors use tools such as Cookies, tags, scripts and other similar technologies to enhance and support your experience on the platform. These technologies help Us administer the web-based platform and mobile application, measure traffic patterns and the total number of users, as well as to personalise and customise the platform’s content, so that your settings are “remembered” when you login.
- To remember that you have used the website before, allowing Us to identify you, as well as the number of unique visitors We receive, and manage capacity;
- To allow you to navigate the website more quickly and easily;
- To remember your login session as you move from one page to the next within the platform;
- To store your settings and preferences;
- To customise some aspects of the platform to reflect your interests and preferences; and
- To collect statistical information about how you use the website, allowing Us to improve Our services over time.
Does Virgin Pulse use mobile analytics?
We use mobile analytics software to allow Us to review the functionality of Our mobile software on your phone, and how to improve its quality and Our services. The mobile analytics software may record information such as how often you use the mobile application, the events that occur within the mobile application, crash reports and performance data, where the application was downloaded from and other metrics, such as aggregated usage. The information collected by the mobile analytics software is managed separately from other Personal Information you submit within the mobile application.
Are there links to third-party websites and mobile applications on the Virgin Pulse platform or mobile application?
Our web-based platform and mobile application may contain links to other websites that We do not own or control. We provide these links and connections for your convenience. We have no control over these third parties, their privacy policies, and the content they display on their websites or mobile applications. If you choose to submit Personal Information while visiting these websites or using these mobile applications, please be aware that your rights will be governed by the third parties’ privacy policies. We strongly encourage you to carefully read the privacy notice of any website or mobile application you visit or use.
Who at Virgin Pulse has access to my Personal Information?
We rely on role-based access and only grant access to Our employees, contractors and agents who are involved with delivering the Programme services to you according to Our policies and procedures. As a global company, We have a number of offices and subsidiaries around the world. We have office locations or subsidiaries in the United States, the United Kingdom, Canada, Bosnia, Switzerland, Singapore and Australia. Our employees at these locations may be required to access your Personal Information to provide you with quality services, including Member Services through the Virgin Pulse Call Centre. Our employees are obligated to respect the confidentiality of your Personal Information and are only authorised to access your Personal Information as necessary to provide you with services or support. Examples of the employees who have access to your Personal Information include Our Member Services staff, billing staff and Our data reporting staff.
Does Virgin Pulse disclose my Personal Information to third parties?
We may, from time to time, share your Personal Information with third parties to allow Us to provide you with Our services. If We need to share your Personal Information with third parties, We will limit the information disclosed to the minimum amount necessary to ensure the provision and quality of the services We offer you. We never use, disclose or share your Personal Information for marketing purposes, and We never sell, rent or lease your Personal Information. Subject to any limitations imposed by applicable laws, We reserve the right to disclose Anonymous Data at Our discretion.
In the event that We (a) undergo reorganisation or liquidation under bankruptcy, or (b) are sold to a third party, any Personal Information We hold about you may be transferred to the reorganised entity or third party, in accordance with applicable laws. In any such event, the new entity will continue to use your Personal Information in accordance with and within the limits of this Notice to ensure continuation of service.
Who does Virgin Pulse disclose my Personal Information to?
Agents and contractors
In some instances, We may disclose your Personal Information to agents or contractors that work on Our behalf and assist Us in providing and supporting the services We offer. This may include fulfilling your requests, analysing your data, or helping Us to communicate important information about VP Passport.
Your VP Passport Sponsor
Your VP Passport Sponsor will be able to review your status to manage its workplace access policies and return-to-work strategy. If you have questions about the use of VP Passport by your VP Passport Sponsor or concerns around how your status information is accessed, reviewed or used by your VP Passport Sponsor, please contact your VP Passport Sponsor directly.
We may share anonymised and aggregated data with your VP Passport Sponsor. Your VP Passport Sponsor will not be able to use such anonymised information or aggregated reports to directly identify you. Your VP Passport Sponsor may use the anonymised information at its discretion, including to evaluate the overall success of VP Passport, as well as to make determinations around the provision of additional benefits, resources, programmes and services.
If your activity information indicates there may be an abnormality or VP Passport abuse, We may share your activity information with your VP Passport Sponsor and make adjustments, suspend or terminate your account, in accordance with your VP Passport Sponsor’s instructions.
We may provide information in an anonymous and aggregated format or provide your Personal Information in a group format to third parties that process that Personal Information (“Analytics Processors”) to generate Anonymous Information and derive analytical information. The Analytics Processors do not have any independent right to use your Personal Information, except to provide the aggregation and analysis services. You can request the names of such Analytics Processors by contacting Us.
We may be required to disclose your Personal Information if:
- Legally required to do so by governments, tribunals, law enforcement and regulatory agencies (for example as part of an ongoing investigation, subpoena, similar legal process or proceeding);
- As otherwise required under any applicable law, regulation, or rule; and
- If We believe, in good faith, that such disclosure is necessary to protect or defend Our rights or the rights of others, to assist in an investigation or to prevent illegal activity.
Why may Virgin Pulse disclose my Personal Information?
From time to time We may need to disclose limited amounts of your Personal Information. We limit Our disclosures to the least amount of information required to meet the permissible purpose. We disclose your Personal Information for the following limited purposes:
- At your request to whomever you direct Us to disclose the information;
- To administer VP Passport and associated reporting;
- To administer any services that your VP Passport Sponsor engaged Us to provide;
- To coordinate enrolment in additional services made available to you;
- To enhance your experience;
- To provide you with information about the services and resources available to you through VP Passport or provided to you by your VP Passport Sponsor;
- To evaluate the overall quality and effectiveness of VP Passport;
- To conduct in-depth analytics about VP Passport; and
- To comply with applicable laws.
Where and how is my Personal Information and other data stored?
All your data, including any Personal Information We collect about you, is stored at Amazon Web Services data centres located in the United States of America (USA). Because your data is stored on USA soil, it may be subject to USA laws, including the “Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001” (USA PATRIOT Act), as well as the jurisdiction of the USA government, tribunals, law enforcement and regulatory agencies, which may require Us to grant them access to your data.
How does Virgin Pulse Secure my Personal Information?
We are committed to protecting your data and your privacy. To ensure data security, We follow reasonable physical, electronic and managerial procedures designed to safeguard and secure your data and Personal Information. However, no company can fully eliminate security risks associated with the provision of online services.
Among the security features We use to protect your Personal Information and other data, We require that you create and use a username and unique password to access the web-based platform and mobile application. We use multiple layers of security to protect your Personal Information and data, including firewalls, intrusion detection tools and antivirus software.
How does Virgin Pulse protect my Personal Information during transfers with authorised parties?
When We receive Personal Information from a third party, or share Personal Information with a third party, We execute appropriate written agreements based on the applicable jurisdiction. For example, We execute EU-approved standard contractual clauses with EU-based Programme Sponsors that send Us Eligibility Files as the data importer, as that term is defined in the GDPR. We also execute EU-approved standard contractual clauses with Our subcontractors that assist Us in processing EU-based data, as the data exporter.
Virgin Pulse is responsible for the processing of personal data it receives and subsequently transfers to a third party acting as an agent on its behalf, under the Privacy Shield Framework. Virgin Pulse complies with the Privacy Shield Principles for all onward transfers of personal data from the European Economic Area (EEA), the United Kingdom and Switzerland, including the onward transfer liability provisions.
Can I submit a request or enforce my rights with regard to my Personal Information?
To submit a request to access, change or correct, transfer, delete or otherwise alter the processing of your Personal Information, please utilise the “Manage Data” feature within VP Passport. Requests will be submitted to your VP Passport Sponsor for its review. Once We receive a response from your VP Passport Sponsor, We will follow its instructions for the fulfilment of your request. We follow strict procedures to ensure your identity is verified prior to fulfilment of any requests. Should a request be denied by your VP Passport Sponsor, We will promptly communicate their denial to you. If you have any questions or concerns regarding the fulfilment or denial of a request, please contact your VP Passport Sponsor. If you have submitted a request and would like to get an update on its status, please contact Our Support team. Alternatively, you can contact your VP Passport Sponsor directly to submit your request and they will instruct Us how to proceed.
How can my account be terminated?
Your VP Passport Sponsor may terminate your account or cease to use or require the use of VP Passport for any reason at any time, which will result in cancellation of your account.
You may request that your VP Passport account be cancelled by submitting a cancellation request to Our Support team. You may also submit a request to your VP Passport Sponsor for your account to be cancelled and your Personal Information to be deleted from Our systems through the “Manage my Data” option in the platform or mobile application.
Your VP Passport Sponsor may require you to use VP Passport to access your workplace. Please note that if VP Passport is required by your VP Passport Sponsor, you may be required to retain an account until your VP Passport Sponsor chooses to make VP Passport voluntary. If you have any questions about whether VP Passport is required by your VP Passport Sponsor or why, please contact your VP Passport Sponsor.
Can I opt out of Virgin Pulse selling my Personal Information?
Virgin Pulse recognises that you have a right to opt out of any “sale” of your Personal Information. We do not, however, provide your Personal Information to anyone in exchange for consideration that would be considered a sale. Because We do not sell your information, We have not implemented an opt-out process.
How long will Virgin Pulse keep my Personal Information?
We will retain the information associated with your account, including your risk assessments and statuses, as long as you have a VP Passport account and up to sixty-two (62) days after the termination of your VP Passport account. Upon the end of this retention period, your Personal Information will be permanently and irreversibly de-identified.
How does Virgin Pulse make changes to this Privacy Notice?
We may update this Notice from time to time to reflect changes in Our information practice and services offered. If We make any material changes to this Notice, you will be notified via an update notification, and you will be given the opportunity to review and accept the new Notice prior to being able to access the platform or continue to use VP Passport. The date indicating the last update can be found at the top of the Notice. If there are typographical mistakes, such as grammar or spelling errors, in the Notice We may correct them without notifying you.
What should I do if I have a concern or complaint against Virgin Pulse and its data privacy practices?
If you have an unresolved privacy or data use concern that We have not addressed satisfactorily, please contact Our U.S.-based third-party dispute resolution provider (free of charge) at TRUSTe Feedback and Resolution System.
If you have any questions or concerns with regard to your VP Passport Sponsor’s policies, use of VP Passport or how the data provided to your VP Passport Sponsor is used by your VP Passport Sponsor, please contact your VP Passport Sponsor.
What laws, regulations or frameworks does Virgin Pulse comply with?
We comply with any applicable laws and regulations based on the geographical location you select. You are asked to input your country and, if applicable, state of residence during enrolment. Any discrepancy between your true residence and the information disclosed to Us, and how that may affect the functionality of the platform, remains your responsibility.
The level of data protection established in the USA is generally lower than the one established in the European Union (EU) and other countries with data protection laws similar to the EU. We therefore take measures to ensure that your Personal Information is stored safely with Us, meeting regulatory privacy and security requirements imposed on EU businesses. Nothing in this Notice limits or attempts to limit your rights under applicable laws, including your ability, depending on your country of residence, to file a complaint with your local Data Protection Authority.
Virgin Pulse participates in and has certified its compliance with the EU-U.S. Privacy Shield and Swiss-U.S. Privacy Shield Framework, as set forth by the U.S. Department of Commerce regarding the collection, use and retention of Personal Information from the European Economic Area (EEA), the United Kingdom and Switzerland to the United States. Virgin Pulse is committed to subjecting all personal data received from EEA member countries, the United Kingdom and Switzerland to the Framework’s applicable Principles. To learn more about the Privacy Shield Framework, visit the U.S. Department of Commerce’s Privacy Shield website. Click to view and learn more about Our certification. With respect to Personal Information received or transferred pursuant to the Privacy Shield Framework, Virgin Pulse is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, Virgin Pulse may be required to disclose Personal Information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
As a result of the decision of the Court of Justice of the European Union in Case C-311/18 (“Schrems II”) on 16 July 2020, the EU-U.S. Privacy Shield Framework is no longer suitable as a mechanism to ensure the lawfulness of transfers of personal data from the EEA, UK and Switzerland to the US. We maintain adherence to this Framework as required to maintain Our Privacy Shield certification, and particularly with regard to personal data already transferred from the EEA, UK or Switzerland to the US. We continue to ensure the lawful transfer of personal data from the EEA, UK and Switzerland to the US through alternative mechanisms such as the Standard Contractual Clauses, as approved by the European Commission. These were not invalidated by the decision of the Court of Justice of the European Union as a lawful transfer mechanism. We are monitoring the situation as it develops and will update this information with any amendments needed to remain compliant.
Virgin Pulse’s privacy practices, described in this Privacy Notice, comply with the APEC Cross Border Privacy Rules System. The APEC CBPR system provides a framework for organisations to ensure protection of Personal Information transferred among participating APEC economies. For more information about the APEC framework, please download and review this document.
Which Translation of the Virgin Pulse Privacy Notice is the Official Version?
Please note that any translation of this Notice is intended solely to facilitate your access to this information. The English version is the only official version of this Notice and any translation inaccuracies or discrepancies are not binding and have no legal effect for compliance or enforcement purposes.
How can I contact Virgin Pulse or its Data Protection Officer (DPO)?
If you have general questions about your Programme, you can contact Member Services by calling 1-888-671-9395 (in the US) or by sending an email to firstname.lastname@example.org.
If you have any questions, comments or concerns about this Notice, or your rights and obligations under this Notice, you may contact Us via email at email@example.com or via the “Contact Us” section of the Virgin Pulse web-based platform and mobile application.
Alternatively, you can contact Us by writing to:
The Virgin Pulse Data Protection Officer
Virgin Pulse, Inc.
75 Fountain Street, Providence, Rhode Island 02902, United States.
You may also contact the data protection officer for your VP Passport Sponsor directly using the contact information available from your VP Passport Sponsor.
Representation for data subjects in the EU
We value your privacy and your rights as a data subject and have therefore appointed Prighter as Our privacy representative and your point of contact.
Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact Us via Our representative Prighter or make use of your data subject rights, please visit: https://prighter.com/q/12992072071