- what information we collect from you
- how we use that information
- whether the information is disclosed to others and under what circumstances
- how we protect your privacy
People who may use the websites include:
- our clients and prospective clients (organisations that contract us to provide services)
- our customers (the end users of our services, for example, UK citizens or our clients’ employees)
Information we collect from you
When you contact us about our services or to get information available on the website, we collect only the information we need, including:
- any questions, queries or feedback you send us about using the website
- your email address if you send an email to us
- details you send to us about our services, such as:
- your name, address and email address
- your work and education history
- information about your health or disability which is required as part of any relevant process
- information from third party device manufacturers – for example, your activity such as walking or cycling (please note: we do not receive this information from the manufacturer without your explicit consent)
- information on how you use the website or online services, collected automatically using cookies; this includes the internet browser you used, the site you came to our site from and your IP address (please see our Cookies Policy for more information).
How we use the information we collect
We use the information we collect to:
- provide services to you if you are a customer, including providing you with:
- user account access to our online systems or portals
- your wellbeing score and wellbeing advice
- improve the website by monitoring how you use it (we might also use aggregated or non-identifiable information to help with this)
- respond to any feedback or questions you send us, if you’ve asked us to respond
- give you information you request about other services we provide
We ordinarily share information about use of our systems in aggregated format so individuals are not identifiable. We do not share your identifiable data with your employer except in rare circumstances, for example, where there is a serious risk to your or someone else’s health.
Keeping your information secure
We store all customer information on secure servers in line with our data retention policies, client requirements and data protection legislation. We take extensive technical and operational steps to protect the data we keep against unauthorised access, unlawful processing, accidental loss or destruction, damage, or misuse.
Although we do our best to protect the information we collect and store about you, we cannot guarantee the security of any information sent to us via the internet.
Revitalised aligns to the international information security standard ISO27001.
Disclosing your information
We will not share your information with any other organisations for their own marketing, market research or commercial purposes. We may pass on the information we collect about you:
- in an anonymised way to our client
- if we need to disclose your personal information to any law enforcement agency, court, regulator, government authority or other third party where we believe this is necessary to comply with a legal or regulatory obligation, or otherwise to protect our rights or the rights of any third party
- to other parties where we identify serious concerns about your wellbeing
- to any third party or supplier for the purposes of providing the services, where you have provided consent (where appropriate)
Under data protection laws, you have a number of rights. For example, you can ask us:
- for a copy of the information we hold about you
- to delete information or correct any inaccuracies
- to update any out-of-date information
If you have access to one of our wellbeing applications or websites, you can correct, delete or retrieve a copy of the information from within the system.
If we hold your information for the purposes of services we provide on behalf of another organisation (we do this in very limited circumstances, for example, to allow you to access our system using your login credentials for your employers systems), any request you make may be more relevant to them and we may ask you to contact them directly. If you do send your request to us and we pass it to another organisation, we will tell you.
When making your request outside the system you should provide us with enough information to allow us to confirm your identity. We may ask for more information, for example to allow us to locate that information or if someone else makes the request to us on your behalf we may ask for a specific form of authority by which you allow them to receive your information from us on your behalf.
Revitalised is the Controller for information we collect from you to deliver wellbeing services to you. We hold your personal data in our system based on your consent. If you ask us to delete all data we hold about you, we will delete it. This will result in the termination of our services.
How to contact us
When contacting our Data Protection Team (including our Data Protection Officer), please let us know:
- That your request relates to Revitalised
- What your request relates to – e.g. right of access request
- Any other information we might require – e.g. time period you were involved in one of our programmes
You can contact our Data Protection Team by:
Post: Data Protection Officer/Team
First Floor, Boston House, 63-64 New Broad Street, London EC2M 1JJ. United Kingdom.
Links to other websites
Changes to this policy