Last Updated: 31 July 2019
The Virgin Pulse programme (the “Programme”) is a voluntary employee health programme that encourages healthy lifestyle changes. The Programme is paid for by your employer, your spouse’s employer or other sponsoring organisation (the “Programme Sponsor”) and operated by Virgin Pulse, Inc., a corporation organised under the laws of the State of Delaware, headquartered at 75 Fountain Street, Providence, Rhode Island 02902, United States (“Virgin Pulse”, “Us”, “We” or “Our”).
We are committed to protecting your rights and your privacy. This Privacy Notice (the “Notice”) explains what data We collect about you and how We store, analyse and share the data We collect about you through the platform (www.virginpulse.com) and the Virgin Pulse mobile application. This Notice applies to all Personal Information whether collected online or offline. The Notice also explains your rights with regard to your data, and how to contact Us to request access, corrections, transfer, restriction or deletion of the data We have collected about you.
We have designed Our Privacy Notice in a question and answer format to make it easy to read and understand. Please read through it carefully. If you do not agree with Our policies and practices contained in this Notice, please do not enrol in the Virgin Pulse Programme.
What laws, regulations or frameworks does Virgin Pulse comply with?
The level of data protection established in the USA is lower than the one established in the European Union. We therefore take measures to ensure that your Personal Information is stored safely with Us, meeting regulatory privacy and security requirements imposed on European Union businesses. Nothing in this Notice limits or attempts to limit your rights under applicable laws, including your ability, depending on your country of residence, to file a complaint with your local Data Protection Authority.
Virgin Pulse participates in and has certified its compliance with the EU-U.S. Privacy Shield and Swiss-U.S. Privacy Shield Framework, as set forth by the U.S. Department of Commerce regarding the collection, use and retention of Personal Information from the European Economic Area, the United Kingdom and Switzerland to the United States. Virgin Pulse is committed to subjecting all personal data received from European Economic Area (EEA) member countries, the United Kingdom and Switzerland, in reliance on the Privacy Shield Framework, to the Framework’s applicable Principles. To view the Virgin Pulse Privacy Shield Notice, please visit [https://cdn.virginpulse.com/content/en-gb.pdf]. To learn more about the Privacy Shield Framework, visit the U.S. Department of Commerce’s Privacy Shield website at https://www.privacyshield.gov/list. To view and learn more about Our certification, please visit https://www.privacyshield.gov/participant?id=a2zt0000000TOtTAAW&status=Active.
Virgin Pulse’s privacy practices, described in this Privacy Notice, comply with the APEC Cross Border Privacy Rules System. The APEC CBPR system provides a framework for organisations to ensure protection of Personal Information transferred among participating APEC economies. For more information about the APEC framework, please visit http://www.apec.org/Groups/Committee-on-Trade-and-Investment/~/media/Files/Groups/ECSG/CBPR/CBPR-PoliciesRulesGuidelines.ashx
Does Virgin Pulse collect information about me?
Yes. We collect anonymous and Personal Information about you in order to provide you with the Virgin Pulse services. “Personal Information” means any information, including personal and material circumstances, that allows a person to become identifiable. The definition of “Personal Information” includes, but is not limited to:
Please bear in mind that the extent of the Personal Information you may be able to share with Us will depend on the Programme design and the features made available to you, as well as your level of participation in the Programme. You are under no obligation to provide any Personal Information to Us at any time. However, if you choose to withhold some Personal Information, We may be unable to provide you with certain services.
How does Virgin Pulse use my Personal Information?
We will use the Personal Information collected only to provide you with access to Our services, including:
Additionally, We may use your Personal Information to create “Anonymous Data” records by removing any information (including any Contact Information) that would allow the remaining data to be linked back to you. We may use the Anonymous Data for internal purposes, such as analysing patterns and programme usage to improve Our services. Additionally, We may use Anonymous Data to analyse and understand demographic trends, customer behaviour patterns and preferences, and information that can help Us enrich the content and quality of the Virgin Pulse Programme.
How does Virgin Pulse communicate with me?
If you have opted to receive push notifications on your mobile device, We may, from time to time, send you push notifications to provide you with reminders and notices. If you no longer wish to receive such communications, you may turn them off at the device level.
From time to time, We may send you emails or newsletters with information about your Programme and the Virgin Pulse platform and services. Depending on your country of residence, you may be given the opportunity to opt-in to receive these communications as you enrol in the platform. Regardless of your initial selection, you may opt-out of these communications, free of charge, at any time during your Membership, by updating your preferences in your account profile information, or by contacting Us directly.
Can Virgin Pulse contact me directly?
You may share your phone number with Us or We may receive it from your Programme Sponsor or third party. If you are a US resident, by accepting this Agreement, you expressly consent and give your permission for Us to contact you directly, including, but not limited to, via phone, the use of an Automated Telephone Dialling System, pre-recorded and/or artificial voice, SMS, MMS, text, fax or other similar means, at any phone number whether such information is provided by you, your Programme Sponsor or another third party.
How does Virgin Pulse collect my Personal Information?
We collect Personal Information you voluntarily provide as you submit it through the web-based platform and the mobile application, by reviewing your use of the web-based platform and mobile application (for example through the completion of a health assessment), your use of a synced tracking device such as a MAX or MAX BUZZ and when you participate in Our phone or on-site services and events. Depending on the Programme design chosen by your Programme Sponsor, We may collect Personal Information through your use of additional services such as the Virgin Pulse Activity Tracking Devices and the Health Stations (additional information on these is provided below). Virgin Pulse may also collect information about you and your participation in the Programme through engagement surveys. Depending on your Programme design, your Programme Sponsor may have the opportunity to create surveys (the “Virgin Pulse Surveys”) for its Members to complete.
We may also automatically collect additional information when you visit Our web-based platform or mobile application, including the type of browser used, the internet service provider (ISP), referring and exit pages, the files viewed on Our site (e.g. HTML pages, graphics, etc.), date and time stamps of activity on the platform, the accessing IP address (the unique address that identifies your device on the internet) and the operating system your device uses. We use this additional information to derive a broad, non-specific understanding of the locations from which Our Members access Our services, and to enhance the security controls around platform access. We also use it to analyse trends, administer the web-based platform, track Members’ movements on the platform and around the website, and to gather demographic information about Our Member base as a whole.
What information do Virgin Pulse Surveys collect from me?
Depending on your Programme design, your Programme Sponsor may be able to create and submit customised Virgin Pulse Surveys for its Members to complete. Virgin Pulse does not contribute to the creation of the questions in these surveys and does not review the questions in these surveys. If you decide to take part in a Virgin Pulse Survey, the results will be shared with your Programme Sponsor in aggregated reports. Your Programme Sponsor will not be able to identify you from these reports. However, if the survey offered gives you the ability to respond to a question by writing in a response, the response will be shared with the Programme Sponsor. If you include identifiable Personal Information in these open-ended responses, your Programme Sponsor may be able to identify you.
What information does Virgin Pulse collect through the health assessment?
Depending on your Programme design, you may have access to a health assessment questionnaire. Health assessments can be customised by Programme Sponsors and may be used to assess your overall health, your lifestyle across multiple areas of wellbeing, or both. You do not have to complete the health assessment if you do not want to share this type of information with Us.
What are the activity tracking devices and how do they track my activity?
As a Programme Member, you will be able to connect activity trackers to your account. If you choose to synchronise an activity tracker with the Programme, We will receive limited information about your activity to populate your account. Activity tracking devices can track a wide number of different aspects of your daily activities, including, among others, your daily steps and fitness activity, your heartbeat and sleep pattern. Depending on the brand and model of activity tracker you use, the data collected may vary. In general, companies selling activity tracking devices have specific privacy policies available, which outline what data the specific activity tracking device collects. We strongly suggest you review the right privacy notice to know what specific data points your activity tracking device collects about you.
The Virgin Pulse activity tracking devices are the MAX and the MAX BUZZ. These devices track your step activity per minute. From this information, Virgin Pulse is able to determine your total active fitness minutes and calories consumed. Additionally, if you wear the MAX BUZZ to sleep, it can recognise the length of your sleep from how long you lie still.
What are Health Stations and what information can I submit by using them?
Depending on the type of Programme made available to you by your Programme Sponsor, you may have access to Health Stations. Health Stations are measurement tracking stations that allow you to measure your blood pressure and weight and input that information in the Programme. Health Stations may be located, for example, in your office. Depending on your Programme, you may receive access to Health Stations in your area at no additional cost.
Does Virgin Pulse receive information about me from other sources?
Yes. We may receive information about you from various sources to support the Programme and services included in it. The sources may include:
Your Programme Sponsor
Your Programme Sponsor may provide Us with your Personal Information to identify you as an individual who is able to join the Programme and become a Member. We call this an “Eligibility File”. Please contact your Programme Sponsor directly if you wish for your Programme Sponsor to stop sending Us information about you. Bear in mind that if you are removed from the Eligibility File, you will no longer have access to the Virgin Pulse Programme.
The Virgin Pulse Programme Partners
With your prior approval, and depending on your Programme design, you may have access to organisations that provide biometric or lab testing services or companies that provide you with additional services (Our Programme Partners). If you use these services, the Programme Partners may share activity information and results with Us.
Your Healthcare or Insurance Provider
With your prior approval, We may receive healthcare-related information from your healthcare provider and any clinics or organised care facility with which your provider is associated. At the direction of your Programme Sponsor, your health insurance provider may share claims-related information with Us.
We may receive information about you from other sources including publicly available databases or third parties from whom We have purchased data. We combine this data with information We already have about you. This can help Us analyse Our records to better evaluate the effectiveness of Our services.
Examples of the types of Personal Information that We may obtain from public databases include:
What tools does Virgin Pulse use to collect my Personal Information?
Virgin Pulse and its Programme Partners and vendors use tools such as Cookies, tags, scripts and other similar technologies to enhance and support your experience on the platform. These technologies help Us administer the web-based platform and mobile application, measure traffic patterns and the total number of users, as well as to personalise and customise the platform’s content, so that your settings are “remembered” when you login.
Does Virgin Pulse use mobile analytics?
We use mobile analytics software to allow Us to review the functionality of Our mobile software on your phone, and how to improve its quality and Our services. The mobile analytics software may record information such as how often you use the mobile application, the events that occur within the mobile application, crash reports and performance data, where the application was downloaded from and other metrics, such as aggregated usage. The information collected by the mobile analytics software is managed separately from other Personal Information you submit within the mobile application.
Are there links to third-party websites and mobile applications on the Virgin Pulse platform or mobile application?
Yes. Our web-based platform and mobile application may contain links to other websites that are not owned or controlled by Virgin Pulse. We provide these links and connections for your convenience. Virgin Pulse has no control over these third parties, their privacy policies, and the content they display on their websites or mobile applications. If you choose to submit Personal Information while visiting these websites or using these mobile applications, please be aware that your rights will be governed by the third parties’ privacy policies. We strongly encourage you to carefully read the privacy notice of any website or mobile application you visit or use.
Who at Virgin Pulse has access to my Personal Information?
As a global company, Virgin Pulse has a number of offices and subsidiaries around the world. Virgin Pulse has office locations in the United States, the United Kingdom, Canada, Bosnia, Switzerland, Singapore, Brazil and Australia. Our employees at these locations may be required to access your Personal Information to allow Us to provide you with quality services, including Member support services through the Virgin Pulse Call Centre. Our employees are obligated to respect the confidentiality of your Personal Information and are only authorised to access your Personal Information as necessary to provide you with services or support.
Can other Members or my Programme Sponsor view my Virgin Pulse profile?
You can become “Friends” with other Members of the Programme offered by your Programme Sponsor. You are able to send “Friend” requests to other Members taking part in your Programme, and they will be able to send you “Friend” requests. You can choose to accept or decline these “Friend” requests. You can also choose to remove a “Friend” any time after adding him or her. If you become “Friends” with another Member, that person will have access to (a) certain portions of your profile, (b) the number of steps you have taken in challenges you choose to participate in, and (c) other activity data related to your participation in the Programme.
To the extent that you participate in any wellness challenges or competitions as part of the Virgin Pulse Programme, please be aware that your name and performance information will be available to other Members participating in the challenge or competition, and to your Programme Sponsor. Additionally, the Virgin Pulse Programme may make message boards and messaging forums available to you. Please be aware that any information disclosed in these settings may become public information. You should exercise caution if disclosing Personal Information while using these features.
Does Virgin Pulse disclose my Personal Information to third parties?
We may, from time to time, share your Personal Information with third parties to allow Us to provide you with Our services. If We need to share your Personal Information with third parties, We will limit the information disclosed to the minimum amount necessary to ensure the provision and quality of the services We offer you. We do not make your Personal Information available to any third parties without your permission. We never use, disclose or share your Personal Information for marketing purposes, and We never sell, rent or lease your Personal Information. Subject to any limitations imposed by applicable laws, We reserve the right to disclose Anonymous Data at Our discretion.
In the event that We (a) undergo reorganisation or liquidation under bankruptcy, or (b) are sold to a third party, any Personal Information We hold about you may be transferred to the reorganised entity or third party, in accordance with applicable laws. In any such event, the new entity will continue to use your Personal Information in accordance with and within the limits of this Notice to ensure continuation of service.
Who does Virgin Pulse disclose my Personal Information to?
Agents and contractors
In some instances, We may disclose your Personal Information to agents or contractors that work on Our behalf and assist Us in providing and supporting the services We offer. This may include processing transactions in the online store, fulfilling your requests, analysing your data, or helping Us to communicate important information about the Programme.
Your Programme Sponsor
We may share anonymised and aggregated data with your Programme Sponsor. In specific circumstances and for limited purposes, such as to ensure you are rewarded for your participation in the Programme or to support tax compliance, We may share reports containing identifiable information with your Programme Sponsor. Your Programme Sponsor will not be able to use such anonymised information or aggregated reports to directly identify you. Your Programme Sponsor may use the anonymised information at its discretion, including to evaluate the overall programme, as well as to provide additional benefits, programmes and services.
If your activity information indicates that there may be an abnormality or Programme abuse, We may share your activity information with your Programme Sponsor and make adjustments, suspend or terminate your account, in accordance with your Programme Sponsor’s instructions.
If your Programme Sponsor is your Health Plan, We may share additional information about you and your participation in the Programme, to ensure you are provided access to any additional services, rewards and benefits that may be offered through your Health Plan.
We may use or disclose your Personal Information to allow your participation in additional third-party provided wellness services. These additional wellness services may be offered to you by Our partners (“Programme Partners”), your Programme Sponsor, or other entities your Programme Sponsor contracts with directly (“Third-Party Providers”). We may provide information in an anonymous and aggregated format or provide your Personal Information in a group format to third parties that process that Personal Information (“Analytics Processors”) to generate anonymised information and derive analytical information. The Analytics Processors do not have any independent right to use your Personal Information, except to provide the aggregation and analysis services. You can request the names of such Third-Party Providers and partnering organisations by contacting Us.
Virgin Pulse may be required to disclose your Personal Information if:
Why does Virgin Pulse disclose my Personal Information?
We will only disclose your Personal Information for the following limited purposes:
Where and how is my Personal Information and other data stored?
All your data, including any Personal Information We collect about you, is stored at Amazon Web Services data centres located in the United States of America (USA). Because your data is stored on USA soil, it may be subject to USA laws, including the “Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001” (USA PATRIOT Act), as well as the jurisdiction of the USA government, tribunals, law enforcement and regulatory agencies, which may require Virgin Pulse to grant them access to your data.
How does Virgin Pulse secure my Personal Information?
Virgin Pulse is committed to protecting your data and your privacy. To ensure data security, We follow reasonable physical, electronic and managerial procedures designed to safeguard and secure your data and Personal Information. However, no company can fully eliminate security risks associated with the provision of online services.
Among the security features We use to protect your Personal Information and other data, We require that you create and use a username and unique password to access the web-based platform and mobile application. We use multiple layers of security to protect your Personal Information and data, including firewalls, intrusion detection tools and antivirus software.
Can I access or change the Personal Information Virgin Pulse has collected about me?
Yes, you can review and change your Personal Information by logging into the platform or mobile application. All Our Members, regardless of residency, except in specific circumstances identified by local laws, have a legal right to access and correct or update the information Virgin Pulse has collected about you. You can also request a copy of all the Personal Information and data We hold about you. We will provide you with a copy of all the data We have collected about you in a standard format (such as Excel) through a secure channel. You can contact Us to request a copy of all your Personal Information or to request a change in your Personal Information through the “Data Requests” option in the platform or mobile application. We will respond to your request within a reasonable timeframe.
Please bear in mind that We may not be able to accommodate your request if We reasonably believe that the change would violate any laws or cause the information to be inaccurate or incorrect. Additionally, We may not be able to fulfil a request where it would impose a burden on Us that is disproportionate to the risk to your privacy, or where your request may affect another individual’s rights to privacy. If We are unable to fulfil a request, We will provide you with the reasons why We are unable to comply.
What Privacy Rights do I have under California law?
In accordance with the California Civil Code Section 1798.83, you may contact Us at the address above to request certain information about the disclosure of Personal Information (as defined in Section 1798.83) to third parties for their direct marketing purposes. However, please bear in mind that We do not share your Personal Information with third parties for their direct marketing purposes.
Can my Personal Information and other data be transferred to a different company?
Yes, you can request that all your Personal Information and other data be transferred to a different wellness services provider. To complete the transfer, We will require additional information about the new vendor to ensure a secure channel is used, so that your Personal Information and other data remain protected. Depending on the circumstances, We may be unable to support a transfer. However, We will be able to provide you with your Personal Information which you will be able to disclose to anyone you choose. To request such transfer, you may contact Us through the “Data Requests” option in the platform or mobile application. We will respond to your request within a reasonable timeframe.
Can my Personal Information and data be deleted from Virgin Pulse databases?
Yes, you can request that the data collected about you be deleted from Our system. You may terminate your Programme membership at any time by submitting a deletion request to Our Member Services team, or through the “Data Requests” option in the platform or mobile application. Your membership will terminate 30 days after We receive your request. Your Personal Information will be permanently and irreversibly de-identified at the end of an additional 30 day grace period.
Can I request that Virgin Pulse restrict processing for some of my data?
Beyond the information necessary for enrolment, you are not required to share any additional information with Us. However, choosing not to share information may limit your ability to earn Rewards if they are made available to you by your Programme Sponsor. You can choose to limit the data you share with Us by not inputting or not using certain features. However, once you have shared information, We are unable to accommodate requests to restrict the processing of certain sets of data. If you wish for Us to stop processing parts of your data, you can request that all data be deleted by cancelling your account.
Can I object to Virgin Pulse’s processing of my data?
Yes, you can object to Our processing of your data by contacting the Privacy Officer and notifying Us that you wish for your account to be suspended while your concerns about the processing of your data are resolved. Once you feel comfortable resuming use of the Virgin Pulse Programme, you can contact Us to unlock your account. If you realise during the time your account is suspended that you do not feel comfortable resuming use of the Virgin Pulse Programme, you can cancel your account. Your data will be deleted in accordance with Our standard process, except that you will not be able to access your account while the cancellation process takes place unless you first request for the suspension to be lifted.
How does Virgin Pulse make changes to this Privacy Notice?
We may update this Notice from time to time to reflect changes in Our information practice and services offered. If We make any material changes to this Notice, you will be notified via an update notification, and you will be given the opportunity to review and accept the new Notice prior to being able to access the platform or continue to use the Programme. The date indicating the last update can be found at the top of the Notice. If there are typographical mistakes, like grammar or spelling errors, in the Notice We may correct them without notifying you.
What should I do if I have a concern or complaint against Virgin Pulse and its data privacy practices?
If you have an unresolved privacy or data use concern that We have not addressed satisfactorily, please contact Our U.S.-based third-party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.
Which translation of the Virgin Pulse Privacy Notice is the official version?
Please note that any translation of this Notice is intended solely to facilitate your access to this information. The English version is the only official version of this Notice and any translation inaccuracies or discrepancies are not binding and have no legal effect for compliance or enforcement purposes.
How can I contact Virgin Pulse or its Data Protection Officer (DPO)?
If you have any questions, comments or concerns about this Notice, or your rights and obligations under this Notice, you may contact Us via email at firstname.lastname@example.org or via the “Contact Us” section of the Virgin Pulse web-based platform and mobile application.
Alternatively, you can contact Us by writing to:
The Virgin Pulse Data Protection Officer
Virgin Pulse, Inc.
75 Fountain Street, Providence, Rhode Island 02902, United States.