Effective Date: May 7, 2020
Sources of Personal Data
We collect Personal Data about you from:
Personal Data We Collect
We collect and process of the following types of Personal Data about you:
We collect personal identifiers from you and your device such as your name (optional), email address (optional), phone number (optional), a user name and password, IP address, device ID, location (zip code) and other identifiers including your year of birth. Note that providing your name and phone number is optional. We also collect your IP address (All of the foregoing, “Personal Identifiers.”)
We process Personal Identifiers for the purposes of providing you the Services and developing, improving, promoting and running the Services. For example, we share some of these personal identifiers with medical researchers at Harvard T Chan School of Public Health, Massachusetts General Hospital, King's College London and Stanford University School of Medicine. We may ask for your feedback on the app and we may conduct other surveys (which are of course voluntary). We may also send you information about new versions of the app or similar apps we may have in the future. Every marketing email sent by us will include a link you can click to opt-out from receiving such emails.
Health data and other protected classification characteristics:
Through our Service, you may choose to submit health related information about yourself, such as your sex at birth and how you identify today, your age, your height, weight and information about your health, pre-existing conditions and symptoms (including your body temperature). You may also submit your COVID-19 test status and details of any treatment, whether you are a healthcare worker and your use of protective equipment, and visits to hospital or clinics. (All of the foregoing, “Health Data and Other Protected Classifications”)
We process Health Data and Other Protected Classifications for the following purposes:
Personal Data of Children
Sharing of Personal Data
Third party processors: We use third parties to process some of your Personal Data on our behalf, for example security and fraud prevention providers, hosting and other technology and communications providers, analytics providers, and staff augmentation and contract personnel. When we allow them access to your data, we do not permit them to use it for their own purposes. We have in place with each processor a contract that requires them only to process the data on our instructions and to take proper care in using it.
These processors include:
Research Partners and Other Third Parties:
Research Partners: The purpose of our Services is to understand and prevent the spread of COVID-19. In order to do this, we share data with people doing health research, for example, people working in:
For example, doctors and scientists at Massachusetts General Hospital, Harvard School of Public Health, Stanford University, and King's College London will have access to your Personal Data for the foregoing purpose. Below is a list of institutions with whom we share your Personal Data. (Please note that this list is provided as an example only, and we may add institutions to this list.) Data shared with research partners other than hospitals and teaching institutions will be de-identified.
Institutions we share data with include (without limitation):
Transfer: We may restructure how we provide the Services, and as part of that, your Personal Data may be transferred to one of our affiliates or to a not-for-profit organization.
Data Security and Retention
We seek to protect your Personal Data from unauthorized access, use and disclosure using appropriate physical, technical, organizational and administrative security measures based on the type of Personal Data and how we are processing that data. Although we work to protect the security of your account and other data that we hold in our records, please be aware that no method of transmitting data over the Internet or storing data is completely secure. We cannot guarantee the complete security of any data you share with us, and except as expressly required by law, we are not responsible for the theft, destruction, loss or inadvertent disclosure of your information or content.
We are unable today to set any particular time limit on the storage of your sensitive personal data, but we will keep it under regular review and ensure that it is not kept longer than is necessary. By way of example, we currently collect your name so that we are able to pass this on to health care professionals if it is necessary to protect your vital interests or the vital interests of another person. Once this is no longer required, we will delete all names from our records. In contrast, data about the spread of the virus is likely to be extremely valuable for researchers studying both this virus and in understanding epidemic spread for the future. We are likely, therefore, to retain this information for much longer.
In some cases we retain Personal Data for longer, if doing so is necessary to comply with our legal obligations, resolve disputes or is otherwise required by applicable law, rule or regulation. We may further retain information in an anonymous or aggregated form where that information would not identify you personally.
California Resident Rights California privacy law requires us to provide the following information, even though we do not sell your data:
You have the right to request certain information about our collection and use of your Personal Data over the past 12 months. We will provide you with the following information:
If we have disclosed your Personal Data for a business purpose over the past 12 months, we will identify the categories of Personal Data shared with each category of third party recipient.
You have the right to request that we delete the Personal Data that we have collected from you.
Exercising Your Rights
To exercise the rights described above, you must send us a request that (1) provides sufficient information to allow us to verify that you are the person about whom we have collected Personal Data, and (2) describes your request in sufficient detail to allow us to understand, evaluate, and respond to it. Each request that meets both of these criteria will be considered a “Valid Request.” We may not respond to requests that do not meet these criteria. We will only use Personal Data provided in a Valid Request to verify you and complete your request. You do not need an account to submit a Valid Request.
We will work to respond to your Valid Request within 45 days of receipt. We will not charge you a fee for making a Valid Request unless your Valid Request(s) is excessive, repetitive, or manifestly unfounded. If we determine that your Valid Request warrants a fee, we will notify you of the fee and explain that decision before completing your request.
You may submit a Valid Request using the following methods:
Visit us at: https://privacy.zoe.com/zoe
Personal Data Sales
We do not sell your Personal Data.
We Will Not Discriminate Against You for Exercising Your Rights Under the CCPA
We will not discriminate against you for exercising your rights under the CCPA.
Other State Law Privacy Rights
California Resident Rights
We will not provide your Personal Data to third parties for such third parties’ direct marketing purposes.
Your browser may offer you a “Do Not Track” option, which allows you to signal to operators of websites and web applications and services that you do not wish such operators to track certain of your online activities over time and across different websites. Our Services do not support DO Not Track requests at this time. To find out more about “Do Not Track,” you can visit www.allaboutdnt.com.
Nevada Resident Rights
Nevada law requires the following wording even though we do not sell your data: If you are a resident of Nevada, you have the right to opt-out of the sale of certain Personal Data to third parties who intend to license or sell that Personal Data. You can exercise this right by contacting us at email@example.com with the subject line “Nevada Do Not Sell Request” and providing us with your name. We do not sell your Personal Data as defined in Nevada Revised Statutes Chapter 603A.
European Union Data Subject Rights
You may have additional rights under the EU General Data Protection Regulation (the “GDPR”) with respect to your Personal Data, as outlined below.
For this section, we use the terms “Personal Data” and “processing” as they are defined in the GDPR, but “Personal Data” generally means information relating to an identifiable person, and “processing” generally covers actions that can be performed in connection with data such as collection, use, storage and disclosure. Zoe Global Limited will be the controller of your Personal Data processed in connection with the Services.
Personal Data Use and Processing Grounds
We will only process your Personal Data if we have a lawful basis for doing so. Lawful bases for processing include consent and our “legitimate interests” or the legitimate interest of others, as further described below.
Legitimate Interests: Our legal basis for processing your Personal Identifiers is our legitimate interest in providing you the Services and developing, improving, marketing and running the Services.
Consent: In some cases, we process Personal Data based on the consent you expressly grant to us at the time we collect such data. When we process Personal Data based on your consent, it will be expressly indicated to you at the point and time of collection. Specifically, we process the category of Health Data and Other Protected Classifications based on your consent. Because of the tight regulatory requirements placed on us, we need your consent to process data about your health, which means that if you do not consent (or withdraw your consent), we cannot allow you to use the app. This is not meant unkindly, we are simply not able to provide you with the service without your consent.
If you wish us to stop processing Health Data and Other Protected Classifications, you may withdraw your consent at any time by visiting https://privacy.zoe.com/zoe.
When you withdraw your consent, we will delete all Health Data and Other Protected Classifications we hold about you.
Other Processing Grounds: From time to time we may also need to process Personal Data to comply with a legal obligation, if it is necessary to protect the vital interests of you or other data subjects, or if it is necessary for a task carried out in the public interest.
EU Data Subject Rights
Under the GDPR you have a number of important rights with respect to your Personal Data, including those set forth below. For more information about these rights, or to submit a request, please visit https://privacy.zoe.com/zoe. Please note that in some circumstances, we may not be able to fully comply with your request, such as if it is frivolous or extremely impractical, if it jeopardizes the rights of others, or if it is not required by law, but in those circumstances, we will still respond to notify you of such a decision. In some cases, we may also need to you to provide us with additional information, which may include Personal Data, if necessary to verify your identity and the nature of your request.
For further information on each of those rights, including the circumstances in which they apply, see the Guidance from the United Kingdom Information Commissioner’s Office (ICO) on individuals rights under the General Data Protection Regulation.
If you would like to exercise any of those rights, please email, call or write to our data protection officer using the contact details given below.
The General Data Protection Regulation also gives you the right to lodge a complaint with a supervisory authority, in particular in the European Union (or European Economic Area) state where you work, normally live or where any alleged infringement of data protection laws occurred. The supervisory authority in the UK is the Information Commissioner who may be contacted at https://ico.org.uk/make-a-complaint/your-personal-information-concerns/ or telephone: +44 0303 123 1113.
Transfers of Personal Data
Our address is: Zoe Global Limited, 164 Westminster Bridge Road, London SE1 7RW, United Kingdom Data Protection Officer: https://privacy.zoe.com/zoe