Privacy Notice

At Rise IQ we recognise the importance of personal information entrusted to us. It is one of our fundamental responsibilities to ensure that we protect the information entrusted to us by our clients and our website visitors. Please find below security measures we established to protect your privacy.

Scope

Data subjects whose personal data is collected (whether they are users of the Company’s services or contracted with the Company as the provider of medical advice to users of the Company’s services) in line with the requirements of the GDPR.

Responsibilities

The GDPR Owner is responsible for ensuring that this notice is made available to data subjects prior to Rise IQ collecting/processing their personal data.

THE GENERAL DATA PROTECTION REGULATION 16/679

We have used certain terms which are set out in the EU’s General Data Protection Regulation (GDPR or the Regulation):
  • personal data means: any information relating to an identified or identifiable natural person (data subject)
  • controller means: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data
  • processor means: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller
  • processing means: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction
  • sensitive personal data means: personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation

Who are we?

We are Rise IQ Limited, a company registered in England and Wales under company number 11282602.
For the purpose of the Data Protection Act 1998 and the General Data Protection Regulation 16/679, the data controller is Rise IQ which has ICO registration number ZA450564

What we do

We offer a health navigation service to corporate employers under which prospective corporate employees can contact Medical Doctors with a view to receiving medical advice and treatment.

Our Status under GDPR

As we determine the purposes and means of the processing of your personal data, we are a controller under GDPR. In certain circumstances, such as where we are subject to the instructions of the Medical Doctors who we introduce to you, we are a processor.

Contacting Us

Our GDPR Owner can be contacted directly here: team@riseiq.com

The Personal Data We Collect

The personal data we collect will be used for the following purposes:
1. To establish the suitability of our service for the data subject
2. To connect the data subject with a Medical Doctor qualified to provide tailored medical advice and as necessary, diagnosis

Recipients of the Personal Data We Collect

Personal data will be shared with Medical Doctors whom are contracted by the client employer in addition to third party service providers for the purposes of secure retention of personal data under the terms of a data processing agreement.

The Legal Basis under Which We collect Personal Data

The two lawful reasons Rise IQ uses to process personal data are set out in Article 6 of the Regulation. Processing will only be lawful if and to the extent that at least one of the following applies:
 
1. The data subject has given consent to the processing of his or her personal data for one or more specific purposes (Article 6 (1) (a) (Consent).
2. processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child (Article 6 (1) (f) (Legitimate Interest).

Consent

By consenting to our processing personal data as set out in this privacy notice you are giving us permission to process your personal data specifically for the purposes identified. Consent is required for Rise IQ to process your personal data, and it must be freely given, specific and informed and established by a clear affirmative act. Where we are asking you for Sensitive Personal Data we will always tell you why and how the information will be used.

Withdrawing Consent

You may withdraw consent at any time by emailing us at the following address: team@riseiq.com with the following statement:
WITHDRAWAL OF CONSENT
I [STATE YOUR NAME] hereby withdraw my consent for Rise IQ to process my personal data. Signed by data subject: [STATE YOUR NAME]

Disclosure

Rise IQ will periodically disclose your personal data to third parties. The recipients of your personal data are as follows:
1. Service providers to you, being Medical Doctors whom you have contracted to provide medical services.
2. Businesses which specialise in marketing, such as Mailchimp with whom we have entered into data processing agreements pursuant to Article 28 GDPR
3. Occasional access, which is limited to the specific needs of the Company, subject at all times to the provisions of Article 5 GDPR

Your rights as a data subject

At any point while we are in possession of or processing your personal data, you, the data subject, have the following rights:
1. Right of access: you have the right to request a copy of the information that we hold about you.
2. Right of rectification: you have a right to correct data that we hold about you that is inaccurate or incomplete.
3. Right to be forgotten: in certain circumstances you can ask for the data we hold about you to be erased from our records.
4. Right to restriction of processing – where certain conditions apply to have a right to restrict the processing.
5. Right of portability: you have the right to have the data we hold about you transferred to another organisation.
6. Right to object: you have the right to object to certain types of processing such as direct marketing.
7. Right to object to automated processing, including profiling: you also have the right to be subject to the legal effects of automated processing or profiling.
 
All of the above requests will be forwarded on should there be a third party involved in the processing of your personal data.