This document can be printed for reference by using the print command in the settings of any browser.
We are X Medical Ltd, 224 Shoreditch High St, London, E1 6PJ
We are a "data controller" in respect of the information we hold about you. This means that we are responsible for deciding how we use your personal information.
You can contact us at: firstname.lastname@example.org
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
Where we need to collect personal data by law, or under the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with goods or services). In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case at the time.Unless specified otherwise, all data requested by Tests For Travel is mandatory and failure to provide this data may make it impossible for Tests For Travel to provide its services.
You are responsible for any third-party Personal Data obtained, published or shared through Tests For Travel and confirm that you have the third party's consent to provide their data to us.
We use different methods to collect data from and about you including through:
We takes appropriate security measures to prevent unauthorised access, disclosure, modification, or unauthorised destruction of your data. Our data processing is carried out using computers and/or IT enabled tools, following organisational procedures and modes strictly related to the purposes indicated. In some cases, your data may be accessible to certain types of persons in charge, involved with the operation of Tests For Travel (administration, sales, marketing, legal, system administration) or external parties (such as third-partytechnical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by us. The updated list of these parties may be requested from us at any time.
We use the types of personal data listed above for a number of purposes, each of which has a "lawful basis". In accordance with the data protection laws, we need a "lawful basis" for collecting and using information about you. There are a variety of different lawful bases for using personal data which are set out in the data protection laws.
We may process your Personal Data if one of the following lawful bases applies:
We may also process Special Categories of Personal Data. This is personal data that includes details on your race or ethnicity and information about your health. Where we do so, we will process this data where processing is necessary for the provision of health care or treatment or management of health care systems and services.
In any case, we will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
Your data is processed at our operating offices and in any other places where the parties involved in the processing are located.
Depending on your location, data transfers may involve transferring your data to a country other than your own. To find out more about the place of processing of such transferred data, you can check the section containing details about the processing of Personal Data.
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying legal, accounting or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements. Therefore:
We may be allowed to retain Personal Data for a longer period when you have given consent to such processing, as long as such consent is not withdrawn. Furthermore, we may be obliged to retain Personal Data for a longer period whenever required to do so for the performance of a legal obligation or upon order of an authority.
Once the retention period expires, Personal Data shall be deleted. Therefore, the right of access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.
Your data is collected to allow us to:
For specific information about the Personal Data used for each purpose, you may refer to the section “Detailed information on the processing of Personal Data”.
We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. [We have established [a privacy centre where you can view and make certain decisions about your personal data use [privacy centre link] OR the following personal data control mechanisms]:
You will receive marketing communications from us if you have subscribed to receive news from us, and you have not opted out of receiving that marketing.
We will get your express opt-in consent before we share your personal data with any other company for marketing purposes.
You can ask us to stop sending you news at any time by following the unsubscribe links on any message sent to you or by contacting us at any time.
Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of any other interaction you have had with us
We may have to share your personal data with the parties set out below:
We require all third parties to respect the security of your personal data and to treat it in accordance with the law.
Some of our external third parties are based outside the UK, so their processing of your personal data will involve a transfer of data outside the UK. Whenever we transfer your personal data outside of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:
Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the UK.
Personal Data is collected for the following purposes and using the following services:
This type of service allows Tests For Travel to access data from your account on a third-party service and perform actions with it. These services are not activated automatically, but require explicit authorisation by you.
This service allowsTests For Travel to connect with your account on Stripe, provided by Stripe, Inc.
Tests For Travel uses your data to propose services and products provided by third parties or unrelated to the product or service provided by Tests For Travel.
Personal Data processed: first name; last name; phone number.
By filling in the contact form with your data, you authorise Tests For Travel to use these details to reply to requests for information, quotes or any other kind of request as indicated by the form’s header.
Personal Data processed: email address; first name; last name.
By registering on the mailing list or for the newsletter, your email address will be added to the contact list of those who may receive email messages containing information of commercial or promotional nature concerning Tests For Travel. Your email address might also be added to this list as a result of signing up to Tests For Travel or after making a purchase.
Personal Data processed: email address.
If you provided your phone number you might be contacted for commercial or promotional purposes related to Tests For Travel, as well as for fulfilling support requests.
Personal Data processed: phone number.
The Sassy People Ltd provide us with Customer Service functions to its customers including contacting the customer about their appointment(s), their questions and their test results, where applicable.
This type of service allows you to view content hosted on external platforms directly from the pages of Tests For Travel and interact with them.
This type of service might still collect web traffic data for the pages where the service is installed, even when you do not use it.
Google Fonts is a typeface visualization service provided by Google Ireland Limited that allows Tests For Travel to incorporate content of this kind on its pages.
Unless otherwise specified, Tests For Travel processes any payments by credit card, bank transfer or other means via external payment service providers. In general and unless where otherwise stated, you are requested to provide your payment details and personal information directly to such payment service providers. Tests For Travel isn't involved in the collection and processing of such information: instead, it will only receive a notification by the relevant payment service provider as to whether payment has been successfully completed.
Stripe is a payment service provided by Stripe Inc.
PayPal is a payment service provided by PayPal Inc., which allows you to make online payments.
This type of service has the purpose of hosting data and files that enable Tests For Travel to run and be distributed as well as to provide a ready-made infrastructure to run specific features or parts of Tests For Travel.
Some services among those listed below, if any, may work through geographically distributed servers, making it difficult to determine the actual location where the Personal Data are stored.
Amazon Web Services (AWS) is a hosting and backend service provided by Amazon Web Services, Inc.
This type of service allows you to interact with third-party live chat platforms directly from the pages of Tests For Travel, in order to contact and be contacted by Tests For Travel‘s support service. If one of these services is installed, it may collect browsing and Usage Data in the pages where it is installed, even if you do not actively use the service. Moreover, live chat conversations may be logged.
The Facebook Messenger Customer Chat is a service for interacting with the Facebook Messenger live chat platform provided by Facebook Ireland Ltd
Personal Data processed: Cookies; data communicated while using the service; Usage Data.
This type of service allows you to interact with third-party online survey platforms directly from the pages of Tests For Travel.
If one of these services is installed, it may collect browsing and Usage Data in the pages where it is installed, even if you do not actively use the service.
The Hotjar Poll & Survey widgets are services that enable interaction with the Hotjar platform provided by Hotjar Ltd.
Hotjar honors generic „Do Not Track” headers. This means the browser can tell its script not to collect any of the your data. This is a setting that is available in all major browsers. Find Hotjar’s opt-out information here.
Personal Data processed: Cookies; Usage Data; various types of data.
This type of service makes it possible to manage a database of email contacts, phone contacts or any other contact information to communicate with you.
These services may also collect data concerning the date and time when the message was viewed by you, as well as when you interacted with it, such as by clicking on links included in the message.
Customer.io is an email address management and message sending service provided by Peaberry Software Inc.
Personal Data processed: email address; Usage Data.
This type of service allows Tests For Travel to manage the creation, deployment, administration, distribution and analysis of online forms and surveys in order to collect, save and reuse Data from any responding users.
The Personal Data collected depend on the information asked and provided by you in the corresponding online form.
These services may be integrated with a wide range of third-party services to enable us to take subsequent steps with the data processed - e.g. managing contacts, sending messages, analytics, advertising and payment processing.
Facebook lead ads is an advertising and data collection service provided by Facebook Ireland Ltd that allows form-based ads to be shown to you pre-populated with Personal Data from their Facebook profiles, such as names and email addresses. Depending on the type of advertisement, you may be requested to provide further information.
Personal Data processed: email address; Usage Data.
Hotjar surveys respects the Do Not Track option available in most modern browsers that, if activated, sends a special signal to stop tracking user activity. You can find more information on how to enable Do Not Track for each supported browser here.
Personal Data processed: email address; Usage Data.
These services have the purpose of hosting and running key components of Tests For Travel, therefore allowing the provision of Tests For Travel from within a unified platform. Such platforms provide a wide range of tools to the Owner – e.g. analytics, user registration, commenting, database management, e-commerce, payment processing – that imply the collection and handling of Personal Data.
Some of these services work through geographically distributed servers, making it difficult to determine the actual location where the Personal Data are stored.
Webflow is a platform provided by Webflow, Inc. that allows the Owner to build, run and host Tests For Travel. Webflow is highly customizable and can host websites from simple blogs to complex e-commerce platforms.
Shopify is a platform provided by Shopify Inc. that allows the Owner to build, run and host an e-commerce website.
Personal Data processed: billing address; email address; first name; last name; phone number; shipping address.
By registering or authenticating, you allow Tests For Travel to identify them and give them access to dedicated services.
Depending on what is described below, third parties may provide registration and authentication services. In this case, Tests For Travel will be able to access some data, stored by these third-party services, for registration or identification purposes.
Some of the services listed below may also collect Personal Data for targeting and profiling purposes; to find out more, please refer to the description of each service.
By registering or authenticating, you allow Tests For Travel to identify you and give you access to dedicated services. The Personal Data is collected and stored for registration or identification purposes only. The data collected are only those necessary for the provision of the service requested by you.
You register by filling out the registration form and providing the Personal Data directly to Tests For Travel.
Personal Data processed: date of birth; email address; first name; last name; phone number; various types of Data; ZIP/Postal code.
Tests For Travel may use the Personal Data provided to allow you to invite your friends - for example through the address book, if access has been provided - and to suggest friends or connections inside it. Personal Data processed: various types of data.
This type of service allows us to build user profiles by starting from an email address, a personal name, or other information that you provides to Tests For Travel, as well as to track your activities through analytics features. This Personal Data may also be matched with publicly available information about you (such as social networks' profiles) and used to build private profiles that the Owner can display and use for improving Tests For Travel.
Some of these services may also enable the sending of timed messages to you, such as emails based on specific actions performed on Tests For Travel.
Intercom is a user database management service provided by Intercom Inc. Intercom can also be used as a medium for communications, either through email, or through messages within Tests For Travel.
HubSpot CRM is a user database management service provided by HubSpot, Inc.
Mercury Digital Assets Ltd provide us with IT development services to operate and maintain the services that we own and operate for the benefit of its users.
The Personal Data collected are used to provide you with services or to sell goods, including payment and possible delivery.
The Personal Data collected to complete the payment may include the credit card, the bank account used for the transfer, or any other means of payment envisaged. The kind of data collected by Tests For Travel depends on the payment system used.
Under certain circumstances, by law you have the right to:
If you want to review, verify, correct or request erasure of your personal information, object to the processing of your personal data, or request that we transfer a copy of your personal information to another party, please contact us.
You have the right to complain to the Information Commissioner's Office (the "ICO") if you are not satisfied with the way we use your information. You can contact the ICO by writing to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
Your Personal Data may be used for legal purposes by us in Court or in the stages leading to possible legal action arising from improper use of Tests For Travel or the related Services.
For operation and maintenance purposes, Tests For Travel and any third-party services may collect files that record interaction with Tests For Travel (System logs) use other Personal Data (such as the IP Address) for this purpose.
More details concerning the collection or processing of Personal Data may be requested from us at any time. Please see the contact information at the beginning of this document.
Should the changes affect processing activities performed on the basis of your consent, we shall collect new consent from you, where required.