We are éclateral Limited and are responsible for the o~pal diagnostic device and its associated online Application (App), which has been used to conduct your test. To enable us to provide a test result, the device and App will require some personal data from you, for which we will be responsible.
Your privacy matters to us and we are committed to the highest data privacy standards, confidentiality and adherence with the Data Protection Act 2018 and UK GDPR. We are registered with the Information Commissioners Office (ICO) Reg No. ZB268331
We will apply the six core principles of data protection legislation in handling your personal data.
When we have collected personal data directly from you, we will be responsible as Data Controller for your data. In situations where someone else has conducted your test and passed on your personal data to us, we will be responsible as a Data Processor. In both cases this Privacy Notice outlines our intentions for the processing of your data.
If you took part in one of our development trials, you should refer to the privacy information provided to you at the time. If you need any assistance with this, please use the contact details given below.
Categories and Type of Personal Data Collected and processed
In order to conduct your test, we will require all or some of the following data from you:
• Personal contact details, including name, address, personal email addresses
• Date of Birth and NHS number
• Results of the test provided via the test device
• Location travelled from (If returning to the UK)
We treat all personal data as sensitive but acknowledge that your test results are special category data.
Our use of your Personal Data
We will be processing your personal data on a contractual basis for the provision of a test result to you directly, to those providing your test or both.
The o~pal diagnostic device digitises your test sample, passing the data via Bluetooth to the o~pal App which you or your test provider will have downloaded to a compatible device. These results can be saved on the App if desired. Following analysis of your sample a test certificate will be sent to you using the contact details provided.
We will not use your personal data for any other purposes than the provision of test related services.
Sharing of your Personal Data
Access to your personal data by our staff or those of our contractors, is strictly controlled and restricted to only those few that need such access.
The relevant information we hold about you will be shared with a contracted partner, who provides your test certificate and who also share the information with Public Health England, where there is a legal requirement to do so.
Our online o~pal App retains your personal data in a contracted and secure data centre located within Europe.
These companies are contractually required to maintain the confidentiality of your personal data and operate in full compliance with data protection legislation.
Securing and Processing of your Personal Data
Your data will be stored by the above contractors on secure encrypted storage systems, with limited and monitored access controls.
We have also implemented appropriate data protection policies and procedures to ensure all staff maintain the confidentiality of your data.
Your personal data will not be transferred or stored outside the European Economic Area (EEA) or any country that does not have a legal framework which protects your privacy rights.
In the unlikely event that your data is lost or it is accessed by someone unauthorised, we have a duty to inform you immediately. If the loss or unauthorised access of your data has potential to cause you harm, we will also report this to the Information Commissioners Office, who are responsible for regulating data protection legislation in the UK: https://ico.org.uk/
How long do we keep your personal data for?
Your personal data will remain on record for up to 8 years, unless there are changes to legal requirements or there is no longer a need to hold it.
Your rights in relation to personal data
Under the UK GDPR, you have the following rights related to the personal data collected for the test:
- The right to be informed
- The right of access, commonly referred to as subject access
- The right to rectification
- The right to restrict processing
- The right to data portability
- The right to object
You can exercise your rights by emailing our Data Protection Officer on: eclateralDPO@clinicaldpo.com
If you are unhappy with anything we have done with your data, you have the right to complain to the Information Commissioners Office.
To make a complaint to the Information Commissioners Office use the link below or call their hotline on Tel No.: 0303 123 1113