Privacy Policy for Vitality at Work Enterprise customers
This Privacy Policy covers our Vitality at Work programme provided by Vitality Healthy Workplace Ltd. It's part of the Vitality Member app.
To help you we have set out the meaning of certain words and terms used in this section as well as for our products and services.Please make anyone whose personal information you have provided to us aware of this Privacy Policy. You must make sure any information you supply about anyone else is accurate and that they’ve agreed to their information being supplied.
How we use your information
If you have a service with us or you are considering getting a service with us, we collect information about you to keep your profile up-to-date.
We only collect information that is relevant and necessary for us to provide the services and to provide you with rewards, discounts, offers or other benefits.
If you contact us by telephone, we may record calls for training and monitoring purposes to help us improve our service and to detect and prevent fraud.
What type of information do we collect?
- Personal information provided by you or your employer:
- Name
- Address
- Contact details
- Date of birth
- Joining date
- Reporting classifications (e.g. which department you are in)
- Your employee ID Number, and
- Leave data (if relevant)
- Activation code, and
- Vitality Health/Life number (if applicable)
- Questionnaires (about your health and wellbeing)
- Devices and wearable technology - Personal data will include your:
- Mobile number
- Email address
- Date of birth
- Post Code; and
- an authorisation token allocated to you. - Sensitive information provided by you, directly or via our strategic partner:
- Health information including medical conditions and your doctor/hospital details
Why do we use your information | Our lawful bases for processing | Our legitimate business interest, where applicable |
---|---|---|
To administer and manage your programme
|
Personal Information:
|
|
To resolve any complaints you may have
|
Personal Information:
|
|
To prevent, detect and investigate fraud or money laundering
|
Personal Information:
|
|
For management information purposes and internal analysis of products and services
|
Personal Information:
|
|
For training purposes to improve your customer experience
|
Personal Information:
|
|
Fraud prevention and detection
In certain circumstances, where we suspect fraudulent behaviour, we will carry out checks with fraud prevention agencies and databases. We also conduct searches with publicly available sources of information including internet searches and social media searches.
If we suspect fraudulent behaviour, we may not offer you access to our programme and may void your profile. We investigate potentially fraudulent activities and where appropriate, we will use surveillance to assist our investigation. We appoint fraud investigation and surveillance suppliers to conduct these investigations on our behalf.
We will keep a record of individuals and any associated investigations to prevent and detect future fraud or money laundering
How we share your information
- Our auditors (for management information purposes)
Vitality will only share your personal data with other companies or organisations where there is a legitimate reason for doing so. For example we are obligated to provide information to specific Government departments such as HM Revenue and Customs and to regulatory bodies who govern our activity such as:
- Information Commissioner’s Office (ICO)
- Financial Conduct Authority (FCA)
- Prudential Regulation Authority (PRA)
- Financial Ombudsman Service (FOS)
We may also share your personal data where we conduct further investigations with law enforcement and fraud prevention agencies and databases, our regulators (such as the FCA, PRA and ICO) as well as other insurers, to facilitate the prevention and detection of fraud or crime.
- Fraud prevention agencies
- Crime prevention agencies, including the police
- Our use of other companies to provide our products and services to you
To assist us in the provision of administration, services or benefits for you, we use other companies who work under contracts with us. We ensure that the level of security and the quality of service provided by those other companies is equivalent to the standard of services we provide to you.
We need to advise you that as part of the application process we will share your data with credit reference agencies for security purposes. This check (known as a “soft search” or “quotation search”) will not affect your credit score or be visible to lenders.
Some of the companies who work under contracts with us are located in countries outside of the European Economic Area. Where this is the case we transfer your personal data to them on terms that are approved by the Information Commissioner. This is to ensure the appropriate security for your information, both in the transfer stage and when it is processed, and that your rights and confidentiality are protected in the same way as they would be if your personal data was processed in the UK.
Please click here to see the list of other companies who assist us in the provision of administration services.
- Sharing your personal data with benefit providers
The Vitality group’s products are designed to enable you to accrue points related to your fitness and this in turn enables you to access a number of rewards and benefits. The exchange of your personal data, health and medical information will only occur with your consent and only with the benefit providers you choose to engage with.
The full list of benefit and reward providers can be found here.
- Vitality Group
Marketing
International Transfers
Under data protection law, when personal information is being transferred outside the EEA, we as data controller, are under an obligation to ensure that such transfers are performed in a manner that ensures that your personal information is adequately protected.
In the event that we transfer your personal information outside of the EEA, we will always put in place adequate safeguards to ensure that your personal information is protected.
Adequate safeguards may include placing contractual obligations on the third party that we are transferring your information to or ensuring that the third party is certified to the EU-US Privacy Shield Framework, if we are making transfers to third parties located in the United States.
How long we keep your information for
In most cases, we will keep your information for seven years from the expiry date of your entitlement to Vitality at Work Enterprise access ends, after which it will be deleted or anonymised.
If we suspect, detect or investigate fraud or money laundering, information will be held on a case by case basis for up to seven years.
Your rights
How to contact us
In the first instance we would ask that you notify us of any concerns you have about how we handle your data but if you are still unhappy then you can contact the Information Commissioners Office here.