Brendan Vacations Covid-19 Privacy Notice
Last updated: September 8 2020
This Privacy Notice supplements our standard Privacy Notice and should be read in conjunction with that Notice. This Privacy Notice gives specific details about how we will deal with personal information in light of Covid-19.
Due to the current public health situation, Brendan Vacations may temporarily collect additional information from customers, including health or biometric information. In some countries, such information is considered as “sensitive” or “special categories of personal data”.
Brendan Vacations will always treat the information we collect from customers, in particular health and biometric information, with the highest standards of care and in line with all applicable legal requirements and guidelines from public authorities. Brendan Vacation's comply with the EU General Data Protection Regulation 2016/679 (GDPR), the UK Data Protection Act 2018 and all amendments, any other legislation relating to personal data and all other local or national legislation and regulatory requirements in force from time to time which apply to us relating to the use of your personal data.
The purpose of this specific privacy notice is to inform our customers of what personal data Brendan Vacations collects, for which purposes and under which legal grounds we may process it during the SARS-CoV-2 pandemic.
Who are we?
Brendan Vacations, Inc. is a company incorporated under the law of California and our registration number is FEIN of 20-5454966. Our registered address is 5551 Katella Ave. Cypress, CA, 90630. All references to Brendan Vacations, 'we', 'us', 'our' are references to Brendan Vacations, Inc., its group, subsidiaries and sister companies. If you have any questions or concerns about this privacy notice, or Brendan Vacation’s personal data policies or practices, please contact us either by e-mail to firstname.lastname@example.org, telephone on (800) 687-1002, or by post to 5551 Katella Ave. Cypress, CA, 90630.
We are the Data Controller for the purposes of the matters detailed in this Privacy Notice.
What personal data do we collect?
Depending on the situation, we may collect the following information:
- Your name and contact details.
- Where you have accepted to take rapid SARS-CoV-2 medical testing, the date and time of the test. If it is negative, we will not record the result of the test, which will only be processed by a qualified health professional in accordance with local regulations. If the result is positive and results in us being unable to continue to provide you with our services, we will retain the information for as long as is necessary to demonstrate that our withdrawal of services was reasonable.
- Where authorised by local regulations or where you agree, we may collect your temperature before giving you access to our services/premises or to a public area. On such occasions we do not record this information, which is deleted immediately, unless the readings are not within acceptable levels in which case we may refuse access and we may retain the data in order to demonstrate that our refusal of access was reasonable.
- If you have agreed to the use of facial recognition, we may collect your biometric information to access certain areas. We will always offer an alternative, such as badges, to the use of facial recognition. Our facial recognition features are not implemented on our CCTV systems, and will always be offered as a separate system.
- When you have accepted or where required by local regulations, we may collect your name, contact details, date, time and location of your presence in the premises we manage for contact tracing purposes. If you notify us that you have been tested positive, we will not record this information, but only the date, time and location of the risk in order for us be able to notify the relevant customers that may have been exposed, unless otherwise required by law.
- Your information regarding pre-existing health conditions, when you choose to share this information with us. We will only record the existence of such pre-existing health condition, and no detail on your health condition itself. Any detailed information will be processed through a qualified health professional in accordance to local regulations.
- Your medical insurance information, as required by tourism and travel regulations.
Why do we collect personal data?
Depending on the situation, we collect and process your personal data for the
- To offer to our customers, on a voluntary basis, rapid SARS-CoV-2 medical tests;
- To check body temperature prior to giving access to public areas and our premises, to protect the health and safety of our customers, staff, contractors and suppliers;
- To offer to our customers, on a voluntary basis, an alternative contact-less authentication method, such as facial recognition;
- To record attendance in certain premises we manage, in order to notify our customers if they have been exposed to a risk and to recommend to self-isolate;
- If you choose to share such information with us, to record if you have a particular risk to your health so we can take any additional measure appropriate to ensure your safety;
- To record your medical insurance information as required by health regulations.
What are our legal grounds to collect and process your personal data?
We rely on the following legal bases to collect and process your personal data:
Your explicit consent.;
- To perform the contract you have with us;
- To comply with a legal obligation: when we are required to collect and process your information because we have a legal requirement to do so in some jurisdictions;
- To protect your vital interest: when required by the circumstances, we may process your data to protect your vital interests or the vital interests of other individuals;
- Our legitimate interests: we may process your data because it is our legitimate interests to do so, or the legitimate interests of others.
Special category data
Depending on the circumstances, we rely on the following legal bases to collect and process your health and biometric data:
- Your explicit consent;
- To comply with a legal obligation: when we are required to collect and process your information because we have a legal requirement to do so in some jurisdictions, in particular to protect and safeguard public health;
- To protect your vital interests, when you are not legally or physically able to give consent.
Who are we sharing your personal data with?
We will not share data with third parties other than as documented in our regular privacy notice. However, in some circumstances, your data may be shared with:
- Public authorities, in particular health authorities, if we have a legal obligation to do so;
- Our providers, including qualified health professionals in line with local regulations, and our biometric solutions providers.
- We will not share your data outside of the European Economic Area (EEA) except when:
- It is necessary to perform your contract with us (for instance, because you are travelling outside the EEA);
- We have the legal obligation to do so.
How long do we keep your data for?
We will endeavour to record your personal data, especially your health data, only for the time strictly necessary for the purposes set out in this privacy notice. This includes the following periods:
For the time of your tour or travel;
- 15 days to one month after your visit to our premises, unless a longer period is required by law;
- For as long as necessary to comply with our legal obligations, contractual requirements or the establishment, exercise or defence of legal claims;
- We will delete/destroy your personal data immediately after the relevant retention period above is reached.
How do we protect your data?
We will always collect and process your data, in particular health and biometric information, with due care and we will keep this data separate from our other regular business processing activities.
The information you share with us under the scope of this Privacy Notice will be secured by additional technical and organisational measures and only staff required to see this information will be able to access it on a “need-to-know” basis.
Paper-based records will be kept securely in locked cabinets. Digital records will be kept in encrypted and separate databases or folders with strict access controls in place.
What are my rights and how do I exercise them?
You have the right to:
- be informed of any data processing;
- access to your personal data;
- rectify your personal data;
- erase your personal data, in some circumstances;
- restrict processing of your personal data, in some applicable circumstances;
- data portability, in applicable circumstances;
- object to the processing of your personal data, in some circumstances;
- to withdraw consent to the processing of your personal data, where applicable.
If you wish to exercise any of your rights, please contact us either by e-mail to email@example.com, telephone on (800) 687-1002, or by post to 5551 Katella Ave. Cypress, CA, 90630.
You will not have to pay a fee to exercise any of your rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances and we will explain the reasons in our response to you.
You also have the right to make a complaint at any time to the relevant supervisory authority, for example the Information Commissioner’s Office in the UK.
Further information about your rights is included in our standard Privacy Notice which this Notice supplements.