VDI Programme Privacy Notice
1. Overview and Consent
VG Group International, Inc and/or its Affiliates (“VG”; “We”; “Us”; “Our”; “Drive”) owns and operates the Vitality Drive International Open App (“VDI Programme”/ “Drive Programme”/ VDI Open App).
This Privacy Notice applies to Personal Information (defined below) collected by or received VG whether online or offline in connection with the VDI Programme.
By accessing or using the Drive Programme, you agree and accept the terms of this Privacy Notice.
Where consent is required to collect location data in terms of your applicable law:
● you consent to VG receiving your physical location when you use the VDI Programme. We may use various technologies to determine your location, within the borders of the territory in which you use the VDI Programme, such as the location services on your mobile phone.
● you consent to your Personal Information and location being shared with our contracted third party providers in order to i) administer and provide the services and benefits associated with the VDI Programme , ii) communicate with you.
You are entitled to discontinue your use of the VDI Programme at anytime by uninstalling the VDI Programme. You also have additional rights in terms of section 10 below.
2. Roles
The VDI Open App is made available to you (“the User”) through and on behalf of your employer or another provider (“Programme Provider”). VG acts on the Programme Provider’s instructions in providing the VDI Programme to you. The Programme Provider requires that you participate in a proof of concept (“POC”) whereby the VDI App will be made available to you. The Programme Provider is the Controller/Responsible Party and VG is the Processor (or equivalent under applicable laws).
3. Why do We collect Personal Information and how do We use it?
Personal Information: definition
For the purposes of this Privacy Notice, VG’s definition of Personal Information is any information relating to an identified or identifiable natural person specifically you as the User.
Personal Information: Source
We collect your mobile number from your Programme Provider. All other Personal Information collected directly from you.
Personal Information: types collected
● Your basic personal details which may include first name, last name, e-mail, mobile number and/or unique identifier.
● Your device ID
● Drive information relating to your driving behavior such as Acceleration, Braking, cornering, phone use and speeding.
● Technical information such as log data, IP address, the type of device, operating system.
● Location data, we may use various technologies to determine your location within the borders of the territory in which you use
the VDI Programme , such as the location services on your mobile phone.
● VDI Programme engagement information which identifies or can be used to identify you.
● Rewards details regarding rewards you have earned and your reward redemptions.
● Additional information provided by you when engaging with the VDI Programme and/or by otherwise contacting VG.
Personal Information: purpose of processing
The Personal Information that you submit when using the VDI Programme or which is made available as a result of your use of the VDI Programme will be used as follows:
● To facilitate the POC;
● To administer and provide the services and benefits associated with the VDI Programme including but not limited to determining your driving score;
● To communicate with you;
● To resolve any complaints or queries that you may have;
● To detect and investigate fraud or security incidents;
● To improve the VDI App and improve your in app experience.
● To fulfil any legal obligations; and
● For research and development purposes. ( Such information will be anonymized prior to such use case occurring.)
4. Legal basis for processing
We process your Personal Information based on the contract in place with your Programme Provider. As a Processor We sign data protection clauses with your Programme Provider, the Controller/ Responsible Party (“the Agreement”). Such Agreement provides the legal basis for which Vitality may process your Personal Information.
In addition to the above, in instances where VG collects Personal Information from you directly We may rely on the legal basis of consent or the Agreement. In such instances: (i) VG will be acting in accordance with the Programme Provider’s instructions which are set out in the Agreement and will remain a Processor; and where applicable (ii) VG will collect your consent and you will be entitled to revoke the provided consent in terms of your rights set out under section 10 below, as applicable. Please note that such revocation will make you ineligible to participate in the POC.
5. International transfers
All Personal Information which is processed as a result of your engagement with the VDI Programme will be processed in the US, European Union and in South Africa. Such Personal Information may be subject to foreign laws and may be disclosed to foreign authorities under such law. Where the GDPR applies, VG and the Programme Provider have entered into the Standard Contractual Clauses, issued by the European Commission, to make provision for the applicable transfer. In terms of other jurisdictions which laws require consent or a written agreement to be in place for the cross border transfer of Personal Information, Vitality relies on the consent you provide to your Programme Provider and/or the data Agreement for the transfer.
6. Data security
VG employs great efforts regarding technologies and organizational measures to protect your Personal Information against loss, corruption and unauthorized access pursuant to the applicable data privacy law.
Personal Information that you share through the VDI Programme is kept strictly confidential and fully secure. We follow generally accepted industry standards to protect the Personal Information We receive, both during transmission and upon receipt.
No method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, while We strive to use reasonable and commercially acceptable means to protect your Personal Information, We cannot guarantee absolute security.
7. How long will my Personal Information be retained?
Unless otherwise specified in this Privacy Notice, Personal Information will only be retained for as long as is required for Us to administer the VDI Programme , subject to: legislative or regulatory retention periods; requirements by the Programme Provider; or as required for Our legitimate business reasons - after which any Personal Information will be anonymized, archived or destroyed.
Note that if a right to erasure request (or equivalent) is exercised in in terms of section 10 below, Personal Information may be retained for 60 days post you exercising such request. Such Personal Information will be retained in accordance with our back up and retention time lines.
8. Categories of recipients to whom the Personal Information may be communicated
● Public authorities that receive data due to legal regulations
● VG Internal departments involved in the execution of the respective business processes
● External contractors (service companies) whose services are required to make the VDI Programme
● The Programme Provider in order to facilitate the POC.
9. Modification of this privacy notice
VG reserves the right to modify this privacy notice at any time without notification. You should therefore refer to this privacy policy each time you make use of the VDI Programme.
10. Your rights
10.1 Brazil
If you Receive the VDI Programme in Brazil you have the below rights
Under the General Personal Data Protection Law, (as amended by Law No. 13.853 of 8 July 2019) (LGPD) you have the following rights regarding your Personal Information collected by VG:
● The right to be informed
● The right of access
● The right to rectification
● The right to erasure
● The right to data portability
● The right to object or blocking
● The right not to be subject to automated decision making
In order to exercise rights enumerated above, please initiate your request with your Programme Provider, as they are the Controller, and they will make this request to VG as their Processor. If you would like VG to support you in making this request, please contact VG directly by using the details set out at the end of the Privacy Notice. Where you submit a request directly to VG, We will first contact your Programme Provider to inform them of the request and then work with them to complete the request.
In the first instance We ask that you notify your Programme Provider and/or Us of any concerns you have about how We handle your Personal Information but if you are still unhappy you can contact the Brazilian Data Protection Authority, the details of which can be found using this link https: https://www.gov.br/anpd/pt-br
10.2 California (USA)
If you reside in California you have the below rights.
Under California Civil Code Section 1798.83 California residents have the right to request from companies conducting business in California a list of all third parties to which the company has disclosed certain personally identifiable information as defined under California law during the preceding year for third party direct marketing purposes. You are limited to one request per calendar year. Note that VG does not disclose any Personal Information to third parties for their direct marketing purposes.
Under the California Consumer Privacy Act (“CCPA”), if you are a California Consumer, or an authorized representative of a California Consumer as defined by the CCPA, you have the following rights regarding your Personal Information collected during the 12 months before your request:
● The right to request disclosure of the categories and specific pieces of Personal Information collected about you;
● The right to request deletion of Personal Information collected about you;
● The right to request disclosure of the categories of sources from which your Personal Information is collected;
● The right to request disclosure of the business or commercial purpose for collecting or selling your Personal Information. Note that We do not sell Personal Information;
● The right to request the categories of third parties with whom the business shares your Personal Information;
● The right to request a copy of the specific Personal Information collected about you; and
● The right not to be discriminated against because you have exercised any of these rights.
In order to exercise rights enumerated above, please initiate your request with your Programme Provider and they will make this request to VG. If you would like VG to support you in making this request, please contact VG directly by using the details set out at the end of the Privacy Notice. Where you submit a request directly to VG, We will first contact your Programme Provider to inform them of the request and then work with them to complete the request.
VG or your Programme Provider will attempt to verify your request by using information related to your account, but in some cases additional information may be required. Subject to certain exceptions that may apply, if We are able to verify your request, We will accommodate your request in accordance with the CCPA.
10.3 EU
If you reside and use the VDI Programme in the European Union you have the below rights under the GDPR.
Under the GDPR, you have the following rights regarding your Personal Information collected by VG:
● The right to be informed
● The right of access
● The right to rectification
● The right to erasure
● The right to restrict processing
● The right to data portability
● The right to object
● Rights in relation to automated decision making and profiling
In order to exercise rights enumerated above, please initiate your request with your Programme Provider, as they are the Controller, and they will make this request to VG as their Processor. If you would like VG to support you in making this request, please contact VG directly by using the details set out at the end of the Privacy Notice. Where you submit a request directly to VG, We will first contact your Programme Provider to inform them of the request and then work with them to complete the request.
In the first instance We ask that you notify your Programme Provider and/or Us of any concerns you have about how We handle your Personal Information but if you are still unhappy you can contact your applicable Supervisory Authority, the details of which can be found using this link: https://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm
10.4 Mexico
If you reside and use the VDI Programme in Mexico you have the below rights.
Under Federal Law on the Protection of Personal Data held by Private Parties (and the Regulations Relating thereto), you have certain rights to access, rectification, cancellation or objection in relation to the Personal Information We have collected from you or received from your Programme Provider or authorized third party, in order to provide the VDI Programme to you.
In order to exercise rights enumerated above, please initiate your request with your Programme Provider, as they are the Responsible Party, and they will make this request to VG as their Processor. If you would like VG to support you in making this request, please contact VG directly by using the details set out at the end of the Privacy Notice. Where you submit a request directly to VG, We will first contact your Programme Provider to inform them of the request and then work with them to complete the request.
11. How can I contact VG with my privacy concerns or inquiries?
Individuals with inquiries or complaints regarding the privacy of their Personal Information at VG or this Privacy Notice should first contact Vitality International, Inc at:
Vitality Group International, Inc
Attn: Data Privacy Officer
200 W. Monroe St., Suite 1900
Chicago, IL 60606
VGI Privacy Team <privacy@vitalitygroup.com>