1. Introduction
This privacy policy ("Privacy Policy") describes how Diagu Ltd ("Diagu") will gather, use and maintain your Personal Data on the GetLabTest Platform. It will also explain your legal rights with respect to that data.
Diagu gathers specific personally identifiable information about you, which includes data reasonably connectable to your identity (“Personal Data”). Personal information or data (“Personal Data”) is defined as ‘any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier’ by the United Kingdom’s General Data Protection Regulation or “GDPR” (the original EU regulation can be found here EU Regulation 2016/679). We must meet many data protection and privacy law requirements. In simple terms, personal data is information that can be used to identify you. Personal information can be details such as name or gender, but it also applies to more abstract data, such as IP address and location data.
By using the GetLabTest Platform, you confirm that you have read and understand this Privacy Policy, and our Terms of Use (together referred to herein as the"Agreement"). The Agreement governs the use of the GetLabTest Platform. Diagu will collect, use, and maintain information consistent with the Agreement. We respect and are committed to protecting your personal data.
2. General terms
In this Privacy Policy:
Data collection
A. Data that you provide to Diagu
Diagu collects certain personally identifiable information about you, including information that is reasonably capable of being associated with you ("Personal Data"). Examples of Personal Data that Diagu may collect include but are not limited to:
Contact Data. This may include your title, first and last name, address, mobile and/or home phone number, and email address.
Billing Data, including your payment instrument number (such as a credit or debit card number), expiration date and security code as necessary to process your payments. Payments are handled by a third party and payment transactions are integrated with them. If you are a Service Provider, this may include your bank account details (see Financial Data).Identity Data. If you are a Service Provider, we may collect Personal Data, such as your date of birth, address, passport number or medical registration number, together with the result of basic criminal record checks as provided by you, or by our Third-Party Agents (as defined below), as applicable and to the extent permitted by law, and to validate your identity. This information is used for identity verification purposes and to ensure our Clients are kept safe.
Medical Data: We may obtain Personal Data required for you be registered and take a medical test and to conduct our services. This may include, but is not limited to:
If you are taking any medications, or have any pre-existing medical conditions or problems, or concerns such as vulnerabilities, you can discuss this during a medical consultation to a healthcare professional or to a healthcare assistant at a testing location. The healthcare professional or assistant will only use the information you share to provide direct care and will always remain confidential. If the healthcare professional or assistant needs your medical consent to care for you, they will get this from you at the time. The healthcare professional or assistant may note this on your file and notify Diagu and the laboratory. A referring doctor, healthcare professional or laboratory may also pass this information onto us if necessary and this may be stored on your file.
Financial Data. To help Service Providers set up a payment account and help Clients make payments to Service Providers and pay fees to Diagu, we may collect financial information, including debit or credit card numbers, bank account details, tax information, taxpayer identification numbers and other payment information, as applicable. We use Financial Data to operate the GetLabTest Platform and to ensure that Service Providers are paid by Clients. We do this as necessary for our legitimate interests in providing our platform and services and to fulfil our contracts with Users. To keep your financial data secure, we have contracted with a third party to maintain and process your payment information.
Promotional Data. Certain offerings of the GetLabTest Platform, such as newsletters, surveys and the like, are optional and you are not required to enter them or to give us your data in connection with them. Where you do consent to take advantage of such offerings, we will use your data to (as applicable) send you newsletters and other communications that are tailored based on information we have about you, or to operate and manage the survey or similar offering in connection with our legitimate interest in promoting our business and the GetLabTest Platform. To opt out of receiving marketing communications from us, please see theYour rights and choices section below.
Content Data. You also may choose to send Personal Data to Diagu in an email or chat message containing enquiries about the GetLabTest Platform and we use this information in order to help us respond to your enquiry. We also collect content within any messages you exchange with other Users through the Service (such as through our chat functionality), and we will never use or share such information for marketing purposes.
We require that you furnish your Contact Data and Financial Data when you register an account with us in order to provide or receive services through the GetLabTest Platform. For example, if you are a Client, we collect your first and last name, email address and postcode in order to create and administer your GetLabTest account. We also collect additional information in order to facilitate your booking request, such as information about the assignment you are seeking, the time, date and location of the assignment, and Financial Data. If you are a Service Provider, we collect your first and last name, email address, mobile phone number and postcode in order to create and administer your GetLabTest account and facilitate communications between you and your Clients through the GetLabTest Platform. We also collect information about your Assignments, rates and skills, as well as Identity Data and Financial Data.
Third-Party Data. We may receive additional information about you, such as demographic data, Financial Data or fraud detection information, from Third-Party Agents (as defined below) and combine it with other information that we have about you, to the extent permitted by law, in order to comply with our legal obligations and for the legitimate interest in improving the GetLabTest Platform. Diagu may work with Third-Party Agents to perform identity checks, criminal background checks and right-to-work checks on Service Providers, if applicable and permitted by local law, in order to advance our legitimate interests in ensuring the safety of our Users and maintaining the integrity of the GetLabTest Platform.
B. Data that Diagu collects automatically
We automatically collect certain data when you use the GetLabTest Platform (also known as “Usage Data”). The categories of data that we automatically collect (and have collected, including in the last 12 months) are as follows:
Service Use Data, including data about features you use, pages you visit, emails and advertisements you view, portions of the GetLabTest Platform that you view and interact with, the time of day you browse and your referring and exiting pages.
Device Data, including data about the type of device or browser you use, your device’s operating system, your internet service provider, your device’s regional and language settings, and device identifiers such as IP address and Ad Id. When you visit and interact with the GetLabTest Platform, Diagu may collect certain information automatically through cookies or other technologies, including, but not limited to, the type of computer or mobile device you use, your mobile device’s unique device ID, the IP address of your computer or mobile device, your operating system, the type(s) of internet browser(s) you use, and information about the way you use the GetLabTest Platform. We may use Device Data to monitor the geographic regions from which Users navigate the GetLabTest Platform, and for security and fraud prevention purposes. Use of any IP-masking technologies or similar technologies (like the TOR network) may render portions of the GetLabTest Platform unavailable and are forbidden on the GetLabTest Platform.
Location Data, including imprecise location data (such as location derived from an IP address or data that indicates a city or postcode level) and, with your consent, precise location data (such as latitude/longitude data). When you visit the GetLabTest Platform via a native mobile application, we use, with your consent when required under applicable law, GPS technology (or other similar technology) to determine your current location in order to determine the city in which you are located and display a relevant location map. We will not share your current location obtained in this manner with other Users.
We also use various Tracking Technologies ("Tracking Technologies") to automatically collect information when you use the GetLabTest Platform, including the following:
Cookies. When you visit our Sites, your browser may automatically transmit information to the Sites throughout your visit. In a similar way, when you use our Apps, we will access and use mobile device IDs to recognise your device. We use "cookies" and equivalent technologies to collect information through our Sites and Apps. Cookies are small data files stored on your device that act as a unique tag to identify your browser.
Persistent cookies help with personalising your experience, remembering your preferences, and supporting security features. Additionally, persistent cookies allow us to bring you advertising both on and off the GetLabTest Platform. Persistent cookies may remain on your device for extended periods of time, and generally may be controlled through your browser settings. We utilise persistent cookies that only Diagu can read and use, and access mobile device IDs to:
Session cookies make it easier for you to navigate the GetLabTest Platform and expire when you close your browser. We utilise session ID cookies and similar technologies to:
Unlike persistent cookies, session cookies are deleted from your computer when you log off from the GetLabTest Platform and then close your browser.
Exhibit A (at the end of this Privacy Policy) sets out the different categories of cookies that the GetLabTest Platform uses and why we use them.
We may work with third-party advertisers who may also place or read persistent cookies on your browser, and we may use Flash cookies (or local shared objects) to store your preferences or display content based upon what you view on the Sites to personalise your visit.
You can instruct your browser, by changing its options, to stop accepting cookies or to prompt you before accepting a cookie from the Sites. If you do not accept cookies, however, you will not be able to use all portions or all functionalities of the GetLabTest Platform.
You may change your cookie settings for cookies on the Sites by accessing the settings option on your particular browser.
Pixels. We and our Third-Party Agents may also use "pixel tags," "web beacons," "clear GIFs," or similar means in connection with the GetLabTest Platform and HTML-formatted email messages to, among other things, track the actions of Users and email recipients, determine the success of marketing campaigns, and compile statistics about Site usage and response rates.
4. Diagu's use of data
We collect and use information for business and commercial purposes in accordance with the practice described in this Privacy Policy. Our business purposes for collecting and using information include:
Interest-based advertising. Ads are a standard part of user experience on the Internet, and Diagu believes that targeted advertising enhances this experience. Diagu and affiliated third parties may use cookies and other technologies to place ads where they believe interested Users will see them. In addition to banner ads, Diagu may advertise products, companies and events that we think might interest you through the email address you provide. We may incorporate Tracking Technologies into our own service (including the GetLabTest Platform) as well as into our ads displayed on other websites and services. Some of these Tracking Technologies may track your activities across time and services for the purposes of associating the different devices you use and delivering relevant ads and/or other content to you ("Interest-Based Advertising").
For more information and to understand your choices regarding third-party ads, please see Exhibit A (at the end of this Privacy Policy). Advertising and marketing is carried out as necessary for our legitimate interests in providing an engaging and relevant experience, promoting our services and growing our business.
Analytics and Market Analysis. Diagu may analyse information ("Market Analysis") as necessary for our legitimate interests in providing an engaging and relevant experience, and in promoting and growing the GetLabTest Platform.
Diagu uses information to offer services to Users who express an interest in these services, through a poll for example, or to Users who can be presumed to have an interest based on results from our Market Analysis. We do this as necessary for our legitimate interests in providing an engaging and relevant experience, promoting our services and growing our business.
Mobile phone numbers. Diagu may use your mobile phone number to call or send recurring text messages to you, using an auto-dialler or pre-recorded voice, in order to provide you with notifications about Assignments, for marketing purposes (with your consent where required by law) and to administer the GetLabTest Platform. If you would like more information about our policy, or how to opt out, please review the Your rights and choices section below or Section 9 of our Terms of Use. You may be liable for standard SMS and per-minute charges by your mobile carrier. Diagu may also message you via push notifications (with your consent when required under applicable law), which you can opt out of on your mobile device. Data rates may apply.
5. Data sharing
We only share the Personal Data we collect about you as described in this Privacy Policy or as described at the time of collection or sharing, including as follows:
Third-Party Agents. We may share your Personal Data (including Identity Data) with our agents, representatives, vendors, service providers and other entities that process information on our behalf for our business purposes ("Third-Party Agents"). Third-Party Agents assist us with services such as:
We contractually prohibit our Third-Party Agents from retaining, using or disclosing information about you for any purposes other than performing the services for us, although we may permit them to use information that does not identify you (including information that has been aggregated or de-identified) for any purpose except as prohibited by law.
Medical Obligations. To help us deliver our services and provide the test(s) administration, we may share Personal Data with our medical practitioners, referral laboratories or external organisations who may provide you with the results of your test and analyse data from a laboratory or referral laboratories. They will be under a duty of confidentiality and will handle your data securely. In some cases, we may use a laboratory or company outside the United Kingdom to process, analyse and/or interpret a sample.
Organisations we may share your Personal Data with include:
We may share your Personal Data, medical history and test results with your medical professional, doctor or the NHS if they have requested or referred a test to us. We will not share your Personal Data, medical history and test results unless explicitly authorised by yourself or your authorised representative.
Public Health England (PHE). Certain diseases are classified as notifiable by the United Kingdom government. Therefore, our laboratories and providers have a legal obligation to report such results and associated patient data to PHE. Your data will be transferred to PHE using only the methods approved by the standard reporting protocols. Further details and information about notifiable diseases and reporting to Public Health England is availablehere. Further details on how Public Health England uses, discloses and processes all personal data we share with them can be found in its privacy notice here.
If we share your Personal Data these organisations or entities, we will have contracts with them to make sure they keep your data safe in line with Data Protection Law and this Privacy Policy.
6. Your rights and choices
You may opt out of receiving promotional communications from us and our Partners, remove your information from our database, choose to not receive future promotional communications related to the GetLabTest Platform, or cancel your account by logging on to a Site or App and changing your account settings, or by contacting us at cs@getlabtest.com
7. Data retention policy
We retain Personal Data for as long as you are a User in order to meet our contractual obligations to you, and for such longer period as may be in our legitimate interests and to comply with our legal obligations or to establish, exercise or defend a legal claim. In most circumstances, this means we will not keep your data for more than 8 (eight) years after the end of your relationship with us. According to theNHS Records Management Code of Practicewe are required to hold all Covid-19 records until necessary, which is currently indefinitely. Please note that laboratory results and records will be kept indefinitely on our secured systems or kept until no longer required.
Subject to the below, in some cases biological samples may be stored by our laboratories after the initial analysis has been carried out to give you the opportunity to order further tests or to repeat the analysis at an additional cost (‘Storage Period’). Samples will be destroyed once the laboratory’s Storage Period has expired, which is typically four (4) weeks. We may also be requested by regulatory authorities (such as Public Health England) to store samples for longer or even send samples to referral laboratories for additional analysis.
We may also retain information from which you cannot directly be identified, for example where stored against a randomly-generated identifier so we know that the information relates to a single User, but we cannot tell who that User is. We use this kind of information for research purposes and to help us develop and improve our services, and we take appropriate measures to ensure you cannot be re-identified from this information.
8. Security of collected data
Your GetLabTest account is password-protected so that only you and authorised Diagu staff have access to your account information. In order to maintain this protection, do not give your password to anyone. Also, if you share a computer, you should sign out of your GetLabTest account and close the browser window before someone else logs on. This will help protect your information entered on public terminals from disclosure to third parties.
Diagu implements and maintains reasonable administrative, physical and technical security safeguards to help protect information about you from loss, theft, misuse, unauthorised access, disclosure, alteration and destruction. Diagu is dedicated to maintaining this Privacy Policy and other privacy initiatives, periodically reviewing security and making sure that every Diagu employee is aware of our security practices. Nevertheless, transmission via the Internet is not completely secure and we cannot guarantee the security of information about you.
9. Security of collected data
In order to provide and operate the GetLabTest Platform or otherwise to exercise our rights and obligations under this Agreement, we and our affiliates and Third-Party Agents may send data about you, including Personal Data, to countries outside the United Kingdom, and store such data on servers located and operated outside the United Kingdom (including in the European Union or the United States). If we or our affiliates or Third-Party Agents do send or store Personal Data outside the United Kingdom, Diagu undertakes to ensure an adequate level of protection thereof in accordance with applicable legislation.
10. Your rights
You have the following rights under certain circumstances:
More detailed information on your rights and privacy laws can be found at the ICO website. If you have an issue or complaint, you can contact us or lodge a complaint with the ICO.
If you make a request, where required, we will confirm your identity and ask you for more information to help us with your request.
We will keep a copy of your request. Further, we may charge a reasonable fee or refuse to act on your request if such a request is excessive, repetitive or manifestly unfounded.
We have 1 (one) month from receiving your request (provided we have verified your identity and have enough information to locate your data) to respond.
You can exercise your rights by contacting the Data Protection Officer at cs@getlabtest.com.
11. Minors
This service is intended for a general audience and is not directed at persons under 18 years of age. We do not knowingly gather personal data of persons under 18 years of age. If you are a parent or guardian and you believe that we have collected information from your child in a manner not permitted by law, please let us know by contacting us at cs@getlabtest.com. We will remove the data.
12. Notification of changes
This Privacy Policy is periodically reviewed and enhanced as necessary, and may change as Diagu updates and expands the GetLabTest Platform. Diagu will endeavour to notify you of any material changes by email or via the GetLabTest Platform. Diagu also encourages you to review this Privacy Policy periodically.
13. Contacting us or making a complaint
If you have any questions about this Privacy Policy or the manner in which we or our Third-Party Agents treat your Personal Data, the practices of the Site, your dealings with the GetLabTest Platform, or if you have technical problems, you may contact the Data Protection Officer at cs@getlabtest.com. Once we have received your request we will respond as soon as possible, and certainly within the regulatory time limit (one month).
Diagu's staff will respond to all mail or email from Users with questions about privacy, including the types of Personal Data stored on the Diagu database, and requests to delete or rectify such Personal Data.
Type of Cookie | Purpose | Who Serves (for example) |
---|---|---|
Authentication Cookies | These cookies (including local storage and similar technologies) tell us when you’re logged in, so we can customise your experience and connect your account information and settings. | Diaguy |
Localisation | These cookies help provide a localised experience by showing you your local metro area. | Diagu |
Site features and services | These provide functionality that helps us deliver products and the GetLabTest Platform. For example, cookies help you log in by pre-filling fields or help ensure older versions of web browsers can still view our Site(s). We may also use cookies and similar technologies to help us provide you with social plugins and other customised content and experiences, including customised fonts. |
|
Analytics and research | These are used to understand, improve, and research products and services, including when you access the GetLabTest Platform and related websites and apps from a computer or mobile device. For example, we may use cookies to understand how you are using site features, to report on any errors in how the Site is functioning, to report to our vendors when content licensed from them is assessed, and to segment audiences for feature testing. We and our partners may use these technologies and the information we receive to improve and understand how you use websites, apps, products, services and ads. |
|
Interest-Based Advertising | Things like cookies and pixels are used to deliver relevant ads, track ad campaign performance and efficiency, and to understand your interests from your online activity on the Site, mobile applications and other websites and apps. For example, we and our ad partners may rely on information gleaned through these cookies to serve you ads that may be interesting to you on other websites and in doing that your information (which will not contain your name, email address or other "real-world" identifiers) will be shared with other platforms in the digital advertising ecosystem all involved in assisting the delivery, purchase, reporting and analysis of digital advertising. Similarly, our advertisers may use a cookie, attribution service or another similar technology to determine whether we’ve served an ad and how it performed, or provide us with information about how you interact with them. Please note that even if you opt out of interest-based advertising by a third party, these tracking technologies may still collect data for other purposes, including analytics, and you may still see ads from us, but the ads will not be targeted based on behavioral information about you and may therefore be less relevant to you and your interests. You can instruct your browser, by changing its options, to stop accepting cookies or to prompt you before accepting a cookie from the websites you visit. To successfully opt out, you must have cookies enabled in your web browser. Please see your browser’s instructions for information on cookies and how to enable them. Your opt-out only applies to the web browser you use so you must opt out of each web browser on each device that you use. Once you opt out, if you delete your browser’s saved cookies, you may need to opt out again. For more information about targeting and advertising cookies and how you can opt out, you can visit the Network Advertising Initiative opt-out page. |
|
Social media and digital advertising cookies and widgets
Other cookies
14. Mobile Information
No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.