Legal, Security and Privacy
Universal will only process your personal information in compliance with the applicable privacy laws and our own information security policies.
1. Personal Information We Collect
a) Information you provide to us. We collect personal information users and end-users provide to us when accessing our Platforms. For example:
- Business and personal contact information of healthcare providers, such as your first and last name, email and mailing addresses, physical address, telephone numbers, service hours, professional title and company name may be collected from healthcare providers.
- Content healthcare providers choose to upload to the Service, such as patient names, files, consent forms and health records, along with the metadata associated with the files healthcare providers may upload.
- Personal contact information of patients, such as your first and last name, email and mailing addresses, physical address, telephone numbers, demographic information, emergency contact information and if applicable, health insurance plan information may be collected from patients.
- Content patients choose to upload to the Service, such as profile pictures, images of identity documents and health plan membership cards, along with the metadata associated with the files patients may upload.
- Registration information, such as your username and password that you may set to establish an online account with us.
- Feedback or correspondence, such as information you provide when you contact us with questions, feedback, or otherwise correspond with us online.
- Usage information, such as information about how you use the Service and interact with us.
b) Information we obtain from other third parties. We may receive personal information about you from third-party sources. For example, if you are a patient we may receive your health and immunization records via integrations with third party electronic health record systems in order to make such records available to your healthcare provider. We may also receive immunization records and confirmations from immunization information systems.
2. How We Use Your Personal Information
a) To operate the Service, we use your personal information to:
- Provide, operate and improve the Platform and associated services.
- Provide information about our products and services (subject to opt in and opt out provisions).
- Establish and maintain your user profile on the Platform.
- Enable security features of the Service, such as by sending you security codes via email or SMS, and remembering devices from which you have previously logged in.
- Communicate with you about the Service, including by sending you appointment reminders and support and administrative messages.
- Provide support and maintenance for the Service.
- To respond to your requests, questions and feedback.
b) To comply with law:
- We use your personal information as we believe necessary or appropriate to comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities.
c) For compliance, fraud prevention, and safety:
- We may use your personal information and disclose it to law enforcement, government authorities, and private parties as we believe necessary or appropriate to: (a) protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims); (b) enforce the terms and conditions that govern the Service; and (c) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.
d) With your consent:
- In some cases, we may specifically ask for your consent to collect, use or share your personal information in a manner that you are satisfied with.
e) To create anonymous, aggregated, or de-identified data:
- Subject to any obligations or restrictions we may have under any applicable data processing agreements, we may create anonymous, aggregated or de-identified data from your personal information and other individuals whose personal information we collect.
- We convert personal information into anonymous, aggregated or de-identified data by removing information that makes the data personally identifiable to you.
- We may use this anonymous, aggregated or de-identified data and share it with third parties for our lawful business purposes, including to analyze and improve the Platform and research and development purposes.
General. Universal does not engage in any automated processing or profiling of users nor do we sell any personal information. When services provided by users are recorded, we do not access the contents of the recordings.
We do not share Personal Information with third parties for the third parties’ direct marketing purposes.
3. How We Share your Personal Information
To provide access to the Platform we need to share your personal information with the following parties, subject to clause 5 (Safeguards) and in addition to the legal justifications contained in the applicable laws, you consent to the sharing of your information with:
b) Healthcare Providers. If you use the Platform as a patient, we may share your personal information with your selected healthcare provider and/or health establishment.
c) Government or federal departments. Healthcare Reporting. Universal and/or healthcare providers may be required to report statistics and other healthcare information such as your vaccination status. We may also share your personal information for the compliance, fraud prevention and safety purposes described above.
d) Healthcare Funders or Insurers. Where applicable, we may share your information with your health funder for billing purposes.
f) Professional advisors. We may disclose your personal information to professional advisors, such as lawyers, bankers, auditors and insurers, where necessary in the course of the professional services that they render to us.
4. Your Rights and Choices
a) As a user you have the right to:
- File a privacy complaint if you believe your privacy rights have been violated.
- Request a paper copy of this notice, even if you have agreed to receive it electronically.
- Request a restriction on certain uses and disclosures.
- Inspect and obtain a copy of your personal information.
- Request a correction or amendment of your personal information.
- Access or update your personal information.
- Request a list of disclosures made of your personal information within the previous 6 year period.
- To update your preferences on how and where we communicate with you.
- Opt-out of marketing communication that we or our partners send to you, at any time. Not all of our communications are for marketing, and you’ll continue to receive messages related to your products and services, such as bills, transactional notices, or customer service.
- Appeal a denial of your request by sending a notice to our Privacy Officer via the contact details provided below
b) As a user you have the following choices when it comes to the processing of your personal information:
- Do Not Track. Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit. We currently do not respond to “Do Not Track” or similar signals. To find out more about “Do Not Track,” please visit http://www.allaboutdnt.com.
- Choosing not to share your personal information. Where we are required by law to collect your personal information, or where we need your personal information in order to provide the Service to you, if you do not provide this information when requested (or you later ask to delete it), we may not be able to provide you with our services. We will tell you what information you must provide to receive the Service by designating it as required at the time of collection or through other appropriate means.
5. Security Practices
The security of your personal information is important to us. We employ a number of organizational, technical and physical safeguards designed to protect the personal information that we process. We have comprehensive information security policies. We constantly perform risk assessments on our information security to ensure that we have adequate controls in place.
Depending on the relevant laws of the country or state wherein the minor resides and the nature of the services accessed on the Platform, a child might have to be assisted by a parent or legal guardian. We encourage parents with queries to contact us at email@example.com.
8. How to Contact Us
Please direct any questions or comments about this Policy or privacy practices to:
a) For South Africa:
Universal House, 15 Tambach Road, Sunninghill Park, Sandton, 2191, South Africa (with email address firstname.lastname@example.org).
b) For the US:
68 T.W. Alexander Drive, Research Triangle Park, NC 27709 (with email address email@example.com).
10. International Data Transfers
a) Universal operates globally, which means personal information may be transferred, stored (for example, in a data center), and processed outside of the country or state where it was initially collected and where some of our users like health care professionals are based.
b) Therefore, by accessing the Platform and the services offered by users or disclosing your personal information while using the Platform, you acknowledge and consent to the transfer of your data subject to applicable laws, security safeguards and binding corporate rules. In most instances information will only be hosted in the US and South Africa which both have adequate data protection laws.
Range of services and/or products
uVax.one™ is a vaccination management system designed to support vaccination programs of any size and scale, ranging from large federal, state, county, and city vaccination programs as well as vaccination programs of large health delivery systems, to programs set up and run by solo independent community pharmacists or physicians.