1. Privacy policy
1 September 2022
With this privacy policy, Krisk24 states how to process the Personal Data of users that access Krisk24 services. Krisk24 is committed to protecting personal information and complying with all applicable privacy requirements in a trustworthy, transparent, and responsible manner. This Privacy Policy applies to information we collect when you use our mobile application, website and other products and services (collectively, the “Services”) or when you otherwise interact with us.
1.1 General
1.1.1 Krisk24 is committed to protecting your privacy and complying with applicable data protection and privacy laws. With this privacy policy (the “Privacy Policy”), the term “Personal Data” means any information or set of information relating to an identified or identifiable individual (natural person) who can be identified, directly or indirectly, by reference to an identifier such as an identification number, location data, an online identifier or one or more factors specific to physical, physiological, genetic, mental, economic, cultural, or social identity. For example, Personal Information includes name, address, email address, employer’s company name, job title, phone or fax number, employee ID, travel itineraries, including emergency contact information and, if requested by a client, passport numbers.
1.1.2 This Privacy Policy applies to the processing of Personal Data collected or submitted by you in connection with the use of the products and the Krisk24 Services offered by us and our affiliates, partners, suppliers and customers. Please read this Privacy Policy carefully to understand how we collect, use, transfer, and store your data as you entirely use the Service.
1.1.3 Krisk24 is responsible for protecting the Personal Data and other information you have provided us. We are committed to safeguarding the privacy of our app and website visitors, service users, individual customers and customer personnel. We take appropriate technical and organisational information security measures to safeguard your Personal Data against loss, misuse, and unauthorised access.
1.1.4 This Privacy Policy explains which types of Personal Data we may process about you and for what purpose we process them. We also detail our processing of Personal Data and your choices and rights regarding such processing. We kindly ask you to review our Privacy Policy and acquaint yourself with its content.
1.1.5 Please note that if you use Krisk24 Services as a service provided directly from Krisk24 Limited, then this Privacy Policy relates to processing Personal Data for which we are the controller. This means that we are responsible for the processing of your Personal Data. It also means that you should turn to us with questions or remarks or if you wish to enforce any of your rights regarding our processing of your Personal Data.
1.1.6 Please note that if you use the Krisk24 Services as a service provided by your employer or contracted party, in your capacity as an employee, consultant, agent or another representative, the
employer or contracted party is the responsible controller of your Personal Data within the scope of our provision of the Krisk24 Services. We only process data on behalf of your employer or contracted party.
1.1.7 Unless your employer or contracted party has provided you with a privacy policy informs you about the processing applied to the Krisk24 Services, this privacy policy shall apply between you and your employer or contracted party. Please note that if your employer or contracted party is located outside of the EU/EEA, there may be limitations to which rights you as a data subject may exercise due to local mandatory law. For questions regarding processing your Personal Data in such cases, or if you want to exercise your rights, please get in touch with your employer or contracted party as instructed in your employer’s or contracted party’s general privacy policy.
1.2 The data we collect when we provide the service
1.2.1 We process your Personal Data to provide you with the Krisk24 Services, including tracking your geographical location. Location data is collected when the service is actively and passively in the background. The type of location data that is collected is dependent on your privacy settings. The location data is processed to track the user's location to fulfil the security service. If you use Krisk24 Services as a service provided by your employer or contracted party as an employee, consultant, agent or another representative, your employer or contracted party may have access to the location data and other Personal Data for the purpose of providing security services. The processing is conducted on the basis that it is necessary for the performance of our contract with you regarding the provision of the Krisk24 Services. Please note that you need to enable the real- time location and sharing of the location data if you want to use the functionality of the Krisk24 Services, dependent on location data.
1.2.2 When you first launch any of our mobile applications that collect location information, you will be asked to consent to the application’s collection of this information. If you initially consent to our collection of location information, you can subsequently stop the collection of this information at any time by changing your preferences on your mobile device. If you do so, certain features of our mobile applications will no longer function. You also may stop our collection of this location information by following the standard uninstall process to remove all of our mobile applications from your device.
1.2.3 Personal Data are processed to provide you with a functionality of the Krisk24 Services as agreed between your employer or contracted party and Krisk24. The functionality and the Personal Data are processed by your employer or contracted party, for example, when assessing the medical risks with an upcoming business trip or to ensure that you obtain the correct medical treatment in an emergency. The processing is conducted based on your consent. Your employer or contracted party is the data controller and the party responsible for obtaining your consent.
1.3.4 The Personal Data are processed to improve the Krisk24 Services and provide you with relevant functionality of the Krisk24 Services by understanding how the Users use the Krisk24 Services. The processing is conducted based on our legitimate interest in collecting information to maintain and improve the functionality, content, and security of the Krisk24 Services.
1.2.5 We may also process your data for further analysis and statistical information and to optimise the user experience. Before such processing, your Personal Data will be anonymised, meaning that the Personal Data will no longer be attributable to you and thus not considered Personal Data. The anonymisation is conducted based on our legitimate interest to improve the Krisk24 Services and carry out statistical analysis regarding the usage of the Krisk24 Services for future optimisation.
1.2.6 Collection of user’s image information: All uploaded images or data are secure and will be dealt with confidentially. We collect user's image information to provide certain features and services to our users. We may collect the user’s profile picture or images uploaded by the user to provide some services to our users such as displaying the user's profile picture on our app or displaying the user's image on tracking map. We do not share user's image information with any third-party without their explicit consent.
1.3 Storage of personal data
1.3.1 Krisk24 stores your Personal Data as long as necessary for us to fulfil the purposes of the processing. This means that we will process your Personal Data as long as you are an active user with our Krisk24 Services. However, location data will be kept for a maximum period of eighteen (18) months.
1.3.2 When your Personal Data is no longer necessary for processing, it will be deleted or anonymised. We will, however, store your Personal Data if and to the extent we are required to do so according to law.
1.4 Sharing your personal data
We may disclose your Personal Data to our data processors, for example, companies providing the Krisk24 Services or hosting and cloud services companies. In such cases, a data processing agreement will be entered to ascertain that your Personal Data is processed by this Privacy Policy.
1.5 Third country transfers
To be able to provide the Krisk24 Services, your Personal Data may be transferred to a country outside of the EU/EEA. If your Personal Data are transferred to a country outside the EU/EEA, we will provide adequate safeguards to protect your Personal Data. If Krisk24 is the controller of your Personal Data, you can obtain a copy of the protection applied by contacting us at the e-mail address stated below. Your Personal Data may not be subject to a third country transfer unless your employer or contracted party instructs us explicitly to transfer such Personal Data. If your employer or contracted party is the controller of your Personal Data, you must contact your employer or contracted party to obtain a copy of the applied safeguards.
1.6 Your rights
1.6.1 You have the right to receive a confirmation on whether or not we process Personal Data concerning you, and in such cases, get access to such Personal Data and also information regarding the Personal Data and how we process it.
1.6.2 You have the right to have inaccurate Personal Data concerning you rectified without undue delay. Taking into account the purposes of the processing, you also have the right to have incomplete Personal Data about you completed.