PRIVACY NOTICE

EMPEAL PRIVACY NOTICE

Wind-of-Change Total Wellbeing Solutions Limited (WoC) trading as EMPEAL fully respect your right to privacy.

This Privacy Notice applies to the operations of this website operated by WoC.

Wind of Change Total Wellbeing Solutions Ltd Trading as Empeal ("we", "us" or "our") is committed to protecting and respecting your privacy. This Privacy Notice tells you about your privacy rights and sets out how we, as a Data Controller, collect, use, process and disclose your personal data relating to your interactions with us. This Privacy Notice should be read in conjunction with our Cookie Policy.

1. Information we may collect from you

Personal data means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). We may collect and process any type of personal data you provide to us in the course of your interactions with us. You may have provided some of your personal data directly to us such as when you visited our website by volunteering personal data when subscribing to email alerts or by using our online feedback or other forms.

If you do not provide us with your personal data we may not be able to provide you with our services or respond to any questions or requests you submit to us via our website. We will tell you when we ask for personal data which is a contractual requirement or is needed to perform our functions or to comply with our legal obligations.

2. What information do we collect?

Our primary goal in collecting personal data is to provide you with the best and most useful content to help improve your online experience. We may ask, for example, for your name, email address, gender, age, postal address or credit card number or any diseases you suffer.

Visitors should be aware that each time they visit a website two general levels of information about their visit can be retained. The first level comprises statistical and other analytical information collected on an aggregate and non-individual specific basis of all browsers who visit the site, and the second is information that is personal or particular to a specific visitor who knowingly chooses to provide that information. It is the policy of this website to respect and protect the privacy of our Customers and never willfully disclose individually identifiable information about its Customers to any third party without first receiving that Customer’s permission.

We may, however, occasionally email you with information or queries about your registration or accounts, for instance to request permissions or advise you of changes.

No personally identifiable information is collected about you on this website, apart from information which you volunteer (for example by emailing us, using our online forms or by making an inquiry about content or services).

Throughout this website you may have an opportunity to send us information relating to you such as through the “Contact Us” pages. By choosing to participate in these, you will be providing us with some level of personal data relating to you. This information will only be used by WoC for:

• the purposes for which it was provided by you;

• verification purposes and statistical analysis;

• to provide you with details of products, services, contests, competitions or promotions being provided or run by WoC or any of its associated companies or any third party that we may select and which we may think would be of interest to you, in line with your request to receive this information.

3. How we use personal data we collect

The more you tell us about yourself, the more value we can offer you. We will only use your personal data for the purposes and legal bases set out in the table below.

| Data Collected | Purposes/activity | Legal basis for processing

| First and last name, email address, password, DOB, your company name, gender, any allergy information, height, weight | To register you as a new website user. To optimize your experience on our website, or to serve you specific content that is relevant to you | The processing is necessary to perform a contract or enter into a contract with you

| First and last name, email address | To contact you regarding the services provided by us. | The processing is necessary to perform a contract.

| First and last name, email address | To notify you about changes to our Data Privacy Notice | The processing is necessary to support our legitimate interests in managing our business (to keep our records updated and to study how website users use our services) provided such interests are not overridden by your interests and rights

| First and last name, email address | To ask you to complete a Questionnaire | Your consent.

| First and last name, email address, password, date of birth (DOB), your company name, gender, any allergy information, height, weight, biometric data | To facilitate providing wellness programs and online wellbeing resources. To facilitate you achieving your personal goals and/or missions through our Irish and overseas expert network | Your consent.

| First and last name, email address, password, DOB, your company name, gender, any allergy information, height, weight, biometric data | To participate in health assessment tests to enable us design the solution which is right for you | Your consent.

| First and last name, email address | To share information with relevant groups which you are part of | Your consent.

| First and last name, email address | To carry out direct marketing (we use the email address you have used during registration) | Your consent.

| First and last name, email address | To provide you, or permit selected third parties to provide you, with information about events hosted or co-sponsored by us or about events we feel may interest you | Your consent.

| Email address | To send you email alerts and newsletters that you have opted-in to receive by filling in our online forms or contacting us by email or by other means | Your consent.

| Email address, telephone contact details | To contact clients or prospects regarding business opportunities | Your consent.

| Contact details, professional qualifications, work history, CV, references | To process job applications | The processing is necessary to perform a contract or enter into a contract with you.

4. Who do we share your information with?

To make our offerings more targeted towards our users’ goals, Empeal App connects with external applications to gather ‘Fitness and Wellness Data’ through third party wearable interfaces or infer such data from mobile device sensors. Third party external wearables are devices like Fitbit, Garmin or Samsung, etc. These connections are made with users’ EXPLICIT permission on those platforms. "Fitness and Wellness Data" includes data you provide related to your lifestyle (e.g., sleeping habits, activity, stress score), life events, dietary restrictions, fitness goals, height, weight, measurements, fitness level, heart rate, sleep data, BMI, biometric data, and similar types of data relating to physiological condition and activity. We collect this data in order to provide the Services and to tailor features, products, advertising, and services to your interests and goals, including providing meal suggestions, workout plans, training- and coaching-related services and recommendations.

WoC retains your personal data to deliver services to you individually and/or together with the wellness improvement group you belong to. Your individual data is not disclosed or presented to the group and/or other officers of your organization. This data, however, may be used for analysis of relevant trends and patterns which could be beneficial to the legitimate business interests for WoC or our client companies. In specific conditions, WoC may disclose personal data only as is necessary to provide our services, and under the conditions stipulated below:

Business Partners: Partners who we work together with to provide you the Services you’ve requested or bought. For example, we may work with a bank so that you can use one of our Services to make faster and more efficient payments. These business partners control and manage your personal information.

Service Providers: Carefully selected companies that provide services for or on behalf of us, such as companies that help us with repairs, customer contact centers, customer care activities, advertising (including customised advertising on our websites, third-party websites, or online platforms), conducting customer satisfaction surveys, or billing, or that send emails on our behalf. These providers are also committed to protecting your information.

Other Parties When Required by Law: For example, it may be necessary by law, legal process, or court order from governmental authorities to disclose your information. They may also seek your information from us for the purposes of law enforcement, national security, anti-terrorism, or other issues that are related to public security.

Other Parties with Your Consent or at Your Direction: In addition to the disclosures described in this Privacy Policy, we may share information about you with third parties when you separately consent to or request such sharing.

Our website may, from time to time, contain links to and from other websites. If you follow a link to any of those websites, please note that those websites have their own privacy policies and we do not accept any responsibility or liability for those policies. Please check those policies before you submit any personal data to those websites.

5. Security and where we store your personal data

We are committed to protecting the security of your personal data. We use a variety of security technologies and procedures to help protect your personal data from unauthorised access and use. Data provided to us is stored using AWS secure infrastructure, and is hosted in Dublin, Ireland. As effective as modern security practices are, no physical or electronic security system is entirely secure. We cannot guarantee the complete security of our database, nor can we guarantee that information you supply will not be intercepted while being transmitted to us over the Internet. We have implemented strict internal guidelines to ensure that your privacy is safeguarded at every level of our organization. We will continue to revise policies and implement additional security features as new technologies become available. Where we have given you a password which enables you to access certain parts of our website, you are responsible for keeping that password confidential. We ask you not to share your password with anyone.

6. Retention of your personal data

We will store your personal data only for as long as necessary for the purpose(s) for which it was obtained. The criteria used to determine our retention periods include (i) the length of time we have an ongoing relationship and/or provide our services; (ii) whether there is a legal requirement to which we are subject; and (iii) whether the retention is advisable in light of our legal position (such as in regard to applicable statutes of limitations, litigation or regulatory investigations). Please contact us if you wish to obtain further information concerning our retention periods (see Contact Us below). You may request at any time a copy of the personal data held about you and request its correction or deletion. To obtain a copy of this information, please send an email to info@empeal.com. Upon receipt of your request and within one month we will inform you about the type of personal data we hold about you, the purposes for which we hold it and the possible recipients or types of recipients.

7. Your rights

You have several rights in relation to your personal data under applicable privacy and data protection law, which may be subject to certain limitations and restrictions. We will respond to any valid requests within one month, unless it is particularly complicated or you have made repeated requests in which case we will respond, at the latest, within three months. We will inform you of any such extension within one month of receipt of your request, together with the reasons for the delay. You will not be charged a fee to exercise any of your rights unless your request is clearly unfounded, repetitive or excessive, in which case we will charge a reasonable fee in the circumstances or refuse to act on the request.

If you wish to exercise any of these rights, please contact us. We may request proof of identification to verify your request.

| Your Rights | What this Means |

| Right to be informed | You have the right to information about processing of your personal details.

| Right of Access | You can request a copy of the personal data we hold about you. You may make Subject Access Requests (“SARs”) at any time to find out more about the personal data which Empeal holds about you, what it is doing with that personal data, and why.

Data subjects wishing to make a SAR may do so in writing, using Empeal’s Subject Access Request Form, or other written communication. SARs should be addressed to Empeal’s Data Protection contact at info@empeal.com .

| Right to Rectification | You have the right to request that we correct any inaccuracies in the personal data we hold about you and complete any personal data where this is incomplete. |

| Right to Erasure ('Right to be Forgotten') | You have the right to request that your personal data be deleted in certain circumstances including:

  1. It is no longer necessary for Empeal to hold that personal data with respect to the purpose(s) for which it was originally collected or processed;
  2. The data subject wishes to withdraw their consent to Empeal holding and processing their personal data;
  3. The data subject objects to Empeal holding and processing their personal data (and there is no overriding legitimate interest to allow Empeal to continue doing so)
  4. The personal data has been processed unlawfully;
  5. The personal data needs to be erased in order for Empeal to comply with a particular legal obligation

Unless Empeal has reasonable grounds to refuse to erase personal data, all requests for erasure shall be complied with, and the data subject informed of the erasure, within one month of receipt of the data subject’s request. The period can be extended by up to two months in the case of complex requests. If such additional time is required, the data subject shall be informed.

In the event that any personal data that is to be erased in response to a data subject’s request has been disclosed to third parties, those parties shall be informed of the erasure (unless it is impossible or would require disproportionate effort to do so).

| Right to Restriction of Processing | You can ask that we restrict your personal data (i.e., keep but not use) where:

  • The accuracy of the personal data is contested;
  • The processing is unlawful but you do not want it erased;
  • We no longer need the personal data but you require it for the establishment, exercise or defense of legal claims; or
  • You have objected to the processing and verification as to our overriding legitimate grounds is pending.

We can continue to use your personal data:

  1. Where we have your consent to do so;
  2. For the establishment, exercise, or defence of legal claims;
  3. To protect the rights of another;

| Right to Data Portability | Where you have provided personal data to us, you have a right to receive such personal data back in a structured, commonly used, and machine-readable format, and to have that data transmitted to a third-party data controller without hindrance but in each case only where:

  1. The processing is based on your consent or on the performance of a contract with you.

| Right to Object | You have the right to object to us processing your personal data.

| Right to lodge a complaint |You also have the right to lodge a complaint with a supervisory authority, although we encourage you to contact Empeal first. Contact details for the Data Protection Commission can be found at https://www.dataprotection.ie

| Right to withdraw consent | where we process your data on the basis of consent, you have a right to withdraw your consent.

| Rights in relation to automated decision making | we do not use automated decision making with legal or other significant effects.

International transfers

Your use of our services may also involve the transfer, storage, and processing of your personal data to other countries outside of the European Economic Area. We will take appropriate measures, in compliance with applicable law, to ensure that your personal data remains protected. Such measures include the use of Standard Contractual Clauses to safeguard the transfer of data outside of the EEA.

Changes to this Privacy Notice

If there are updates to the details of this Privacy Policy, we will post those changes and update the revision date at the top of this document, so you will always know what information we collect online, how we use it, and what choices you have.

This notice was last updated on 27th October 2021

Contacting Us

If you have any questions about this Privacy Statement or you wish to make a complaint, please feel free to contact us through our info@empeal.com email or write to us at:

Wind-of-Change Total Wellbeing Solutions Ltd, 55 Warren Avenue, Castleknock, Dublin D15RKV6, Ireland

Wind of Change Total Wellbeing Solutions Ltd Trading as Empeal

Dogpatch Labs, The CHQ Building Custom House Quay, North Dock, Dublin, D01 Y6H7

Email: info@empeal.com

© Copyright 2021 Empeal

How Healthy are You?

Get a picture of your current health status and habits by taking our short Health and Wellbeing Check!