Privacy notice

Healix Travel Safe Privacy Notice

Healix has been appointed by your Employer to provide Healix Travel Safe services. In order to do this efficiently we need to access and process your personal data including any medical data that is relevant to assist you in your business travels and assess the risk associated with traveling to your chosen location based on your personal circumstances including medical information, the chosen destination and geographical and security status at the destination. The purpose of this Privacy Notice is to explain what personal data we will collect from you, what purposes we will process it for and who we will share what data with. Please see Contact Details at the end of this document if you have any questions or wish to exercise your rights.

Who We Are

Healix International Limited is a provider of travel risk management services selected to provide Healix Travel Safe services. Healix International Limited (Healix) has a registered address at Healix House, Esher, KT10 8AB, UK and registration number 3912483. Healix will process your personal data for the purpose of delivering the Healix Travel Safe services on behalf of your employer only.

The Healix Travel Safe service is developed, hosted and administered by Tracker Software Technologies (Ireland) Ltd. who will have access to the data for the purposes of providing support (e.g. re-set passwords), administration and maintenance only. Tracker Software Technologies (Ireland) Ltd. has a registered address at LINC Building, TU Dublin, Blanchardstown Road North, Blanchardstown, Co Dublin, Ireland.

What is Healix Travel Safe?

The Healix Travel Safe application supports the internal travel request approval process by providing an online application that allows employees to submit travel requests for assessment. Healix Travel Safe is provided via Single Sign On or an online portal where you register and then log in and complete a questionnaire.

For each travel request the employee must complete a short questionnaire focused on travel itinerary and medical information. Based on the information entered, the application is able to identify security risks (e.g. unrest at the destination), logistical issues (e.g. travel ban) and medical risks (e.g. issues with providing adequate medical care at the destination). This is an automated assessment based on pre-set triggers and risks. Certain factors will initiate additional manual assessment by medical staff or security staff. Healix Medical Team or Healix Security Team will receive a notification and will access the application to complete the additional assessments which will then be sent to you. 

It is important that the information you provide is accurate to the best of your knowledge as inaccurate information may result in an inappropriate assessment that could expose you to unacceptable risks. Where you enter free text the questionnaire will be sent to the Healix Medical Team for manual assessment. At this point Healix Medical Team will access the questionnaire in the Healix Travel Safe App and a medical professional will review your information to further assess the risks and understand how it may impact the travel request. Healix Medical Team may find it beneficial to discuss the detailed medical result with your employer authorised individual. Healix will obtain your consent before sharing any medical information from the detailed medical assessment.

The results rating of the assessment will be shared with relevant authorised individuals in your organisation to be used in the travel approval decision process. Only Healix medical team will process the medical information you provide unless you provide your consent to share this data.

You will have access to the assessment and the information you have entered in the application at all times. You can monitor the progress of your application and view historical requests as well.  

There are options to configure this tool in accordance with company policies and requirements. 

There may be links to training materials and the option to upload certificates etc. to the platform as part of the assessment.

Employer authorised manager such as Risk Manager are able to log into a dashboard in the portal providing an overview of all active approvals in a consolidated list form and on a global map. Reporting functionality is available based on country security risk ratings. The information is used in the travel approval decision process.

Your Personal Information

Healix always aims to minimise the amount of data processed and in particular the sensitive personal data. Healix has strict organisational and technical measures in place to protect your data at all times.

Healix relies on the legal basis listed below for processing your personal data for the purpose of providing the Healix Travel Safe services. Healix only process Personal Data where necessary to provide the services:

·        You have provided consent to the processing of personal data for one or more specific purposes;

·        Process data as may be required in the public interest, such as detecting and preventing fraud;

·        Pursue the legitimate interests we have as a business in a way which may reasonably be expected as part of running our business and which does not materially impact your rights (for example to improve our services).

Healix will process special category data when:

·        Processing is necessary for the purpose of the assessment of the working capacity of the employee. 

·        You have provided explicit consent;

·        Processing is necessary for the establishment, exercise or defence of legal claims;

·        Processing data may be required in the public interest, such as public health or detection and prevention of fraud.

In certain circumstances your employer may request additional information in order to consider a travel request where there may be complications or identified risks. Healix will obtain your explicit consent before sharing any medical information with the employer.

The consent may be obtained verbally over the phone or by written communication. Consent can be withdrawn at any time up until the moment the personal data is disclosed to your employer.

You can withdraw your consent either by sending an email containing the relevant information to privacy@healix.co.uk or sending a letter to Healix Group Data Protection Officer as detailed below.

Personal Information, Use and Disclosure

The following table lists the main types, but not all, of personal data collected by Healix, the purposes for which it is used and who it is disclosed to.

Personal Data

What it is used for (Purpose)

Who is it disclosed to?

Name, contact details and identification details of the traveller (full name, email address, date of birth etc.).

To identify and authenticate you, confirm eligibility and communication with you in order to provide the service.

·        Healix Medical Team and                      Security Team to complete                  assessments.

·       Tracker Software Technologies          for support purposes only.

·        Employer Authorised Manager          for managing the travel                          request.

·        User: You will be sent updates            on the status of the travel                      request and will also have                    access to your requests via the          portal.

Nationality

 

Enabling the application to apply rules where there might be bans on certain nationals from entering a country.   

·        Healix Medical Team and                      Security Team to complete                  assessments.

·       Tracker Software Technologies          for support purposes only.

·        Employer Authorised Manager          for managing the travel request.

·        User: You will be sent updates            on the status of the travel                      request and will also have                    access to your requests via the          portal.

Itinerary information (entry point and final destination, dates of travel etc.)

To identify security risks and logistical risks in your chosen destination.      

·        Healix Medical Team and                      Security Team to complete                  assessments.

·       Tracker Software Technologies          for support purposes only.

·        Employer Authorised Manager          for managing the travel request.

·        User: You will be sent updates            on the status of the travel                      request and will also have                    access to your requests via the          portal.

Medical information (e.g. asthma, heart complications etc.)

To assess the medical risk associated with travel to certain destination including the availability and quality of the health system.

·        Healix Medical Team to                          complete assessments.

·       Tracker Software Technologies          for support purposes only.

·        Employer Authorised Manager          for managing the travel request          (ONLY with your consent where          information is provided to                      Healix Medical Team).

Vaccination information, visa status, previous denied entry, completion of eLearning etc.

Client defined pre-requisites to complete the travel request in compliance with company specific policies. 

·        Healix Medical Team and                      Security Team to complete                  assessments.

·       Tracker Software Technologies          for support purposes only.

·        Employer Authorised Manager          for managing the travel request.

·        User will have access via the                portal.

Results and rating of the assessments in the form of a report.

To support the travel request decision making process. 

·        Healix Medical Team and                      Security Team to complete                  assessments.

·       Tracker Software Technologies          for support purposes only.

·        Employer Authorised Manager          for managing the travel request.

·        User: You will have access to a            copy of the report via the portal.

 

Healix may furthermore disclose limited personal data to:

·        Public authorities in order to comply with legal and regulatory obligations such as public health, fraud and money laundering prevention.

·        Organisations involved in maintaining, reviewing and developing our business systems, procedures and infrastructure including maintaining or upgrading our computer systems. Access is always limited by organisational                      and technical access controls.

Collection of Data

Whenever it is reasonable or practicable to do so, Healix will collect your personal data directly from you and your employer.

How Long We Keep the Data

All personal data processed in the Healix Travel Safe application is subject to the following automated data deletion rules:

·        The User Profile data will be kept until the end of our contract with your employer and will then be deleted. This is an automated process triggered by the end of contract.

·        Travel Request Management information will be kept until the end of our contract with your employer and will then be deleted. This is an automated process triggered by the end of contract.

·        User Medical Information entered by you in the questionnaire for each travel request will be deleted 7 years after the relevant travel return date entered in the questionnaire by you.

·        Medical Data entered by the Healix Medical Team will be deleted 7 years after the medical assessment of the case has been completed. 

The application allows for the User Profile data and Travel Request Management data to be anonymised or deleted upon requests or as required for example when an individual leave employment.

Healix has a legal requirement to retain a copy of the User Medical Information entered by you in the questionnaire and the Medical Data entered by the Healix Medical Team for a period of 7 years.  

International Transfer

Where necessary in order to provide the service, we will transfer your personal data cross border for the purposes and to the recipients outlined in the table above. This will include any country in which you or the employer is receiving the services, as applicable.

Children

Healix may collect personal data from dependants under the age of 16 but will only do so with the consent of the holder of parental responsibility over the child. If we learn that we have collected personal data from a child under the age of 16 without the appropriate consent, we will take action to delete that information as quickly as possible.

Your Rights

You have the right to: 

·        Request access to a copy of the personal data held by Healix.

·        Request the correction of the information if it is factually inaccurate. 

·        Request the completion or clarification of the information if it is incomplete or equivocal. 

·        Request the erasure of your personal data if it has been collected in breach of the Principles of the Data Protection or if it is irrelevant or excessive.

·        Complain if you consider Healix has breached its privacy obligations.

Subject Access Right

You have the right to access personal data held about you. To do so you must provide a written request to Healix including as much information as possible (reference number, dates, specific issue etc.) to enable us to comply with your request as quickly as possible. Please see contact details below.

How to Make a Complaint

If you have any concerns or a complaint regarding our collection and use of your personal data, or a possible breach of your privacy, please send them to: privacy@healix.com or write to us at the address listed below.

We will treat your requests or complaints confidentially and contact you within a reasonable time after receipt of your complaint to address your concerns and outline options regarding how they may be resolved. We will aim to ensure that your complaint is resolved in a timely and appropriate manner.

If you do not believe your complaint is managed appropriately you have the right to escalate the complaint to the Data Protection Authority. In the UK you can make a complaint to the Information Commissioner, the UK independent regulator at casework@ico.org.uk

Please contact the Data Protection Officer using the Contact Details below if you require any further information regarding your rights.

Contact Details

Any questions, comments or requests regarding this notice should be addressed to the Data Protection Officer at: privacy@healix.com

Or by mail:

 

Group Data Protection Officer

Healix, Healix House, Esher Green, Esher, Surrey, KT10 8AB, UK

 

You can also find the regulatory information on the Healix Group of Companies at http://healix.com/regulatoryinfo.

This Privacy Notice is subject to regular review and was last updated September 2024

We use cookies and similar technologies to provide certain features, enhance the user experience and deliver content that is relevant to your interests. By clicking on "Agree and continue", you declare your consent to the use of the technically necessary cookies. Here you can at any time withdraw your consent from the Cookie Declaration on our website. For further information, please refer to our Privacy Policy