Privacy Policy
Updated August 1, 2020

At Gopass Global, we care about the privacy of your data and are committed to protecting it. This Privacy Policy explains what information we collect about you and why , what we do with that information, and how we handle that information. We will also explain what choices you have with respect to the information. Gopass Global Pte Ltd is a Singapore company and complies with the Privacy Act (1988). The Act provides Consumer Data Rights (see https://www.oaic.gov.au/consumer-data-right/about-the-consumer-data-right/).

Applicability of this Privacy Policy

This Privacy Policy applies to Gopass Global desktop and mobile applications (collectively, the “Products”), Gopass Global.com and other Gopass Global websites (collectively, the “Sites”) and other interactions (e.g., customer service inquiries, user conferences, etc.) you may have with Gopass Global. If you do not agree with the terms, do not access or use the Products, Sites or any other aspect of Gopass Global’s business. This policy applies to the Company’s employees, contractors and officers.

The Company has a contract with all Data Processors that it uses in compliance with Article 28 & Article 29 of the GDPR and ensures that all Data Processors are compliant with Data Protection Legislation. The policy does not apply to third party services. Where third party services are used, and the third party is not a Data Processor, no Relevant Data (as defined below) is shared with them, or the Relevant Data has been anonymised such that the GDPR does not apply. Information collected by third parties is governed by their privacy practices. We encourage you to learn about the privacy practices of those third parties. In addition, a separate agreement governs delivery, access and use of the Products (the “User Agreement”), This policy applies to Relevant Data received and processed only.

Definitions

Capitalised terms used in this Policy and not otherwise defined shall have the meanings provided below:
Gopass Global Family of Companies – the list of the Gopass Global family of companies is as follows:
Gopass Global Pte Ltd.

Products:
Gopass Global Risk Map, Gopass Global Health Rating Tool, Gopass Global Corporate Suite
Relevant Data – Personal Data and Special Categories of Data are the Relevant Data covered by this policy and as defined in the Data Protection Legislation.
Personal Data – any information relating to an identified or identifiable natural person.
Special Categories of Data – Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data and data concerning health or a person’s sex life or sexual orientation.
Processing/Processed – any operation on personal data, whether automated or not.
Contagious Disease – any infection subject to a specific health alert including epidemics and pandemics including but not limited to: COVID19, MERS, SARS.

Information We Collect and Receive

When you interact with our Sites and Products, we collect information that, alone or in combination with other data, could be used to identify you (Personal Data). Some of the Information we collect is stored in a manner that cannot be linked back to you (Non-Personal Data). Gopass Global collects, generates and/or receives the following Information:

Usage Information

Certain data about the devices you use to connect with Gopass Global and your use of the Site and/or Product are automatically logged in our systems, including:

  • Сontact details, namely, email.
  • Location information. This is the geographic area where you use your computer and mobile devices (as indicated by an Internet Protocol [IP] address or similar identifier) when interacting with our Site and/or Product.
  • Log data. As with most websites and technology services delivered over the internet, our servers automatically collect data when you access or use our Site and/or Product and record it in log files. This log data may include the IP address, browser type and settings, the date and time of use, information about browser configuration, language preferences, and cookie data.
  • Product and Site-Specific Data. This is information about the Site and/or Product you use and how you use them. We may also obtain data from our third-party partners and service providers to analyze how users use our Site and/or Product. For example, we will know how many users access a specific page on the Site and which links they clicked on. We use this aggregated information to better understand and optimize the Site.
  • Device information. These are data from your computer or mobile device, such as the type of hardware and software you are using (for example, your operating system and browser type), as well as unique device identifiers for devices that are using Gopass Global Product.
The detailed information on the basis for the collection, storage and processing of each type of personal information is provided in Lawful Basis for Personal Data Processing section of Privacy Policy.

Cookies

Gopass Global uses cookies and similar technologies in our Site and Services that help us collect Other Information. The Site and Services may also include cookies and similar tracking technologies of third parties, which may collect Other Information about you via the Site and Services and across other websites and online services. For more details about how we use these technologies, please see our Cookie Policy.

Third Party Data

Gopass Global may receive data about Site visitors, marketing campaigns and other matters related to our business from affiliates and subsidiaries, our partners or others that we use to make our own information better or more useful. This data may be combined with Other Information we collect and might include aggregate level data, such as which IP addresses correspond to zip codes or countries. Or it might be more specific: for example, how well an online marketing or email campaign performed.

Additional Information Provided to Gopass Global

We receive Other Information when submitted to our Site or if you participate in a focus group, contest, activity or event, apply for a job, request support, interact with our social media accounts or otherwise communicate with Gopass Global.

Payment Information

Our order process is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record for all our orders. Paddle provides all customer service inquiries and handles returns.
Payments information (these include name, location, contact details, and billing information) provided by you will be stored and processed by ChargeBee.com and Stripe. All such information is subject to the privacy policy of ChargeBee and Stripe (available here https://www.chargebee.com/privacy/ and https://stripe.com/privacy-center/legal ).
ChargeBee, Stripe and Gopass Global have a legitimate interest to use provided data for product fulfilment, order processing, fraud prevention, and product support.

Collection Information from Children

Gopass Global does not knowingly collect personal information from children under the age of 15. If we determine we have collected personal information from a child younger than 15 years of age, we will take reasonable measures to remove that information from our systems. If you are under the age of 15, please do not submit any personal information through the Site and/or Products. We encourage parents and legal guardians to monitor their children’s Internet usage and to help enforce this Policy by instructing their children never to provide personal information through the Sites and/or Products without their permission.

Use of Your Information by Gopass Global

We use, process, and store your information as necessary to perform our contract with you and for our legitimate business interests, in operating our Sites, Products, Services, and business including:

  • to help us administer our Sites and/or Products, authenticate users for security purposes, provide personalized user features and access, process transactions, conduct research, develop new features, and improve the features, algorithms, and usability of our Sites and/or Products;
  • As required by applicable law, legal process or regulation.
  • to calculate aggregate statistics on the number of unique devices using our Sites and/or Products;
  • to send emails and other communications. We may send you alerts messages, service, technical and other administrative emails, messages and other types of communications. We may also contact you to inform you about changes in our Products, our Products offerings, and important Products-related notices, such as security and fraud notices. These communications are considered part of the Products and you may not opt-out of them. In addition, we sometimes send emails about new product features, promotional communications or other news about Gopass Global. We will only send you marketing information if you consent to us;
  • for billing, account management and other administrative matters. Gopass Global may need to contact you for invoicing, account management and similar reasons and we use account data to administer accounts and keep track of billing and payments.
  • to investigate and help prevent security issues, fraud and abuse.
  • If information is aggregated or de-identified so it is no longer reasonably associated with an identified or identifiable natural person, Gopass Global may use it for any business purpose.

How We Share and Disclose Information

We only disclose Personal Data to third parties when:

  • We use service providers who assist us in meeting business operations needs, including hosting, delivering, and improving our Products. We also use service providers for specific services and functions, including email communication, customer support services, and analytics. These service providers may only access, process, or store Personal Data pursuant to our instructions and to perform their duties to us.
  • We have your explicit consent to share your Personal Data (if required).
  • We believe it is necessary to investigate potential violations of the Terms of Products, to enforce those Terms of Products, or where we believe it is necessary to investigate, prevent, or take action regarding illegal activities, suspected fraud, or potential threats against persons, property, or the systems on which we operate our Site and/or Products.
  • We determine that the access, preservation, or disclosure of your Personal Data is required by law to protect the rights, property, or personal safety of Gopass Global and users of our Site and/or Products, or to respond to lawful requests by public authorities, including national security or law enforcement requests.
  • We need to do so in connection with a merger, acquisition, bankruptcy, reorganisation, sale of some or all of our assets or stock, public offering of securities, or steps in consideration of such activities (e.g., due diligence). In these cases, some or all of your Personal Data may be shared with or transferred to another entity, subject to this Privacy Policy.
  • We may disclose Non-Personal Data publicly and to third parties – for example, in public reports about word usage, to partners under agreement with us, or as part of progress reports we may provide to users.
  • Gopass Global does not share your Personal Data with third parties for the purpose of enabling them to deliver their advertisements to you.
  • Gopass Global does not sell or rent your Personal Data.

Third Parties’ Applications and Products

Some third-party applications and services that work with us may ask for permission to access your information. Those applications will provide you with notice and request your consent in order to obtain such access or information. Please consider your selection of such applications and services, and your permissions, carefully.
Some third parties’ embedded content or plugins on our Sites and/or Products, such as Facebook “Like” buttons, may allow their operators to learn that you have visited the Sites, and they may combine this knowledge with other data they have collected about your visits to other websites or online services that can identify you.
Data collected by third parties through these apps and plugins is subject to each parties’ own policies. We encourage you to read those policies and understand how other companies use your data.

E-mailing by Gopass Global

From time to time, we may want to contact you with information about product announcements, software updates, and special offers. We also may want to contact you with information about products and services from our business partners. We only send marketing communications to users with your prior consent. All Gopass Global account holders will continue to receive transactional messages related to our Products, even if you unsubscribe from promotional emails.

Data storage, transfer, retention, and deletion

Data Storage and Transfers

Information submitted to Gopass Global will be transferred to, processed, and stored in Australia. When you use the Product on your computing device, user content you save will be stored locally on that device and synced with our servers. Once the data has been stored on our servers, it will no longer be stored on your computing device. To view any of these data on your device, a secure key is used to request upload from our server. Please note that your device will require an internet connection to access the data. If you post or transfer any information to or through our Site and/or Product, you are agreeing to such information, including Personal Data and user content, being hosted and accessed in Australia.

Duration of Information Storage

As the general rule, we retain your data while you are a customer (some types of data are automatically deleted every 30 days) and will delete your information within 30 days of either party’s termination of the Terms of Use or upon written request. You can remove your Personal Data from Gopass Global at any time by emailing us with the respective request: enquiries@gopassglobal.com . However, we may keep some of your Personal Data for as long as reasonably necessary for our legitimate business interests, including fraud detection and prevention and to comply with our legal obligations including tax, legal reporting, and auditing obligations. In any case, if you are required by law to maintain Gopass Global services during your visit to Australia, your request to delete your Personal Data will only be actioned after your depart Australia.

Safeguards

When you give us personal information, we take steps to make sure that it’s treated securely.
Non-sensitive details (your email address etc.) are sent normally over the Internet, and this can never be guaranteed to be 100% secure. As a result, while we strive to protect your personal information, we cannot guarantee the security of any information you transmit to us, and you do so at your own risk. Once we receive your information, we make our best effort to ensure its security on our systems.
We use industry-standard encryption to protect your data in transit. This is commonly referred to as transport layer security (“TLS”) or secure socket layer (“SSL”) technology.
Once we receive your data, we protect it on our servers using a combination of technical, physical, and logical security safeguards. The security of the data stored locally in any of our Product installed on your computing device requires that you make use of the security features of your device. We recommend that you take the appropriate steps to secure all computing devices that you use in connection with our Site and Product.
The Company takes the security of your data very seriously and works to protect your data from loss, misuse and unauthorised access or disclosure.
All staff and officers who handle Relevant Data are aware of this policy and have been given training in how to correctly collect, process, store and delete data. The Company holds a log of when staff training was undertaken and updates it on an annual basis.
All access or attempts to access your personal information are automatically monitored by the Gopass Global security systems and any Gopass Global officer who breaches our privacy and data protection rules will have their access suspended and may face disciplinary action and/or prosecution.

Data Breaches

All breaches will be reported to the relevant supervisory authority within 72 hours, unless the data was anonymised or encrypted or if it has a particularly high risk. Breaches of this policy by staff, contractors, officers of the Company will be dealt with under the Company’s grievance and disciplinary policy and may lead to a disciplinary sanction.
If Gopass Global learns of a security system breach, we will attempt to notify you and provide information on protective steps, if available, through the email address that you have provided to us or by posting a notice on the Site. Depending on where you live, you may have a legal right to receive such notices in writing.

Lawful Basis for Personal Data Processing

Gopass Global uses, processes, and stores Personal Data, as necessary to perform our contract with you, and based on our legitimate interests in order to provide the services in connection with the Product and maintaining Product’s functionality, namely:

  • Log data (crash data and other diagnostic reports; cleanup logs: files path and size, system libraries versions, scan/removal duration, device information) – for identifying and fixing defects in Product’s functionality. Logs and entire reports are important to analyse user problems, application misfunctions and crashes. Data is mandatory and is frequently the main source, which helps to understand and resolve application issues.
  • Device information: Operating System (OS) running on your device, Internet Protocol (IP) address, access times, browser type, and language, OS localization, CMM bundle IDs,  CMM version, screen resolution, cid, battery info, RAM usage info, drive info, processor info, GPU info, disk info (type, total, free, backups), files metadata, applications preferences data, installed applications, network names and preferences,
  • computer uptime in hours. – to identify and localise user issues (bugs) and to understand and localise user problems, for the Product correct scanning and cleaning logic, actually, Product functioning.
  • We are collecting your data when you are contacting our customer support team via call, email or another communication tool. The purpose of collecting is for helping you to solve any issue you have with our services. The legal basis of collecting is the fulfilment of our contractual or pre-contractual obligations to you. Additionally, we may record the calls. The purpose of call recording is quality control of our customer support services and personnel training. The legal basis of call recording is our legitimate interests in retaining you as a customer and providing you with first-class customer support services.
  • We rely on your consent to process Personal Data:
    • to send promotional emails,
    • to place cookies on your devices and
    • for in-app analytics events and actions, used by us to understand user behaviour, analyse and optimise it.
In some cases, GGopass Global may process Personal Data pursuant to legal obligation or to protect your vital interests or those of another person.

Gopass Global Information Collection Details

What personal information will be collected, and why is it being collected?

When you register:

We will ask you to consent to the collection of your:

  • mobile phone number — so that you can be contacted if needed for
  • contact tracing
  • Emergency contact number, contact name and contact email – so that
  • we can contact relatives/friends on your behalf if you are unable to do so
  • yourself
  • Email – so that we can contact you if your phone is not working, has been
  • lost or become damaged and to assist you with your login should you need
  • a new password of login identity
  • name — so the relevant health officials can confirm they are speaking to
  • the right person when performing contact tracing. This will be easiest if you provide your full name, but you can use a pseudonym or fake name if you prefer
  • age range — so health officials can prioritise cases for contact tracing if needed
If you are under 15 years of age, your parent or guardian will need to consent to the collection of your registration information and contact data.

When you use Gopass Global:

Travel data:
You or your travel agent will be asked to upload your current travel itinerary – so that we can automatically upload your travel itinerary and alert you if any part of your itinerary is likely to be a threat to your health.
Health data:
Your health score is calculated for the purposes of providing a risk score to add to the Gopass Global travel score. No personal data is ever kept by Gopass Global, without the direct consent of the user for reuse purposes, and not for any further data accumulation or use.

How will personal information be stored?

We will store all registration information and other data encrypted in the Singapore data store. It is a cloud-based facility, using infrastructure located in Singapore, which has been classified as appropriate for storage of data.  We will delete all personal data in the data store if you request this through the Gopass Global application

How will personal information be used and disclosed?

We will use or disclose your personal information to enable contact tracing by health officials. This includes:

  • using your mobile number to send you an SMS to send you alerts and notifications
  • using your device identity number to send you messages and alerts

Further information about privacy

the Australian Privacy Principles (APP)

  • a registered APP code that binds us, and
  • how we will deal with such a complaint.

Common Questions

  1. Will people’s identification, health and work details be on-sold by Gopass Global?
    No
  2. Will personal information be used for any form of research (medical, market, etc) other than to support contact tracing?
    No. Once all personal information has been deleted, aggregated data, location data, infection data and other non-personal information will be made available to support research.
  3. Will personal data be made available to police and other law enforcement agencies?

    Yes, but only if a warrant is issued for a specific record associated with an offence and only for specified records shown on a warrant. In general, the provisions of section 3E of the Crimes Act 1914 (or State/Territory equivalent) must be met.

    If you request, Gopass Global will delete all of your personal information following the end of your trip and will not be able to support law enforcement requests for personal information.

  4. Will my information be available to the US authorities under the American Cloud Act?

    Yes, while your data is stored in Australia on a Microsoft Azure platform. The Clarifying Lawful Overseas Use of Data (CLOUD) Act enables US authorities to issue a warrant to obtain data.

    If you request, Gopass Global will delete all of your personal information following the end of your trip and will not be able to support law enforcement requests for personal information.

  5. Is my data safe from hacking?

    Yes. All personal information is encrypted on our servers, in our portals, in transit and on your mobile device. Even if data is stolen from any part of our system, it will be encrypted. All Gopass Global staff require authorisation to access any data (for example our customer service staff) and all of our systems are protected by two- factor authentication (and other security measures).

    This does not protect your data if you provide deliberate or accidental access to your data and/or account. The mobile application is password protected and two-factor authentication is required to access critical personal information. You should always lock your mobile device when not in use and protect passwords to prevent unauthorised access to your information.

  6. If I believe that information about me in Gopass Global is incorrect, can that be corrected?

    Yes. Gopass Global can provide you with all your personal data to enable the correction of information on request. See details in our Privacy Policy statement (below).

Privacy enquiries

Contact to find out more about privacy within the department, or to make a privacy enquiry or complaint


Privacy Officer:
Email: enquire@GopassGlobal.com

Postal address:
100C Pasir Panjang Road
#04-03 SLC House
Singapore 118519
Enquiries:
Phone: +65 98378813
Email: enquire@gopassglobal.com
Web: https://www.GopassGlobal.com

Changes to our Privacy Policy

This privacy policy was last updated on 1 August 2020 and this version is in line with the Australian Privacy Principles and GDPR guidelines.
We may need to update this Policy to keep pace with changes in our Sites, Products, and Services, our business, and laws applicable to us and you. We will, however, always maintain our commitment to respect your privacy. We will notify you of any material changes that impact your rights under this Policy by email (to your most recently provided email address) or post any other revisions to this Policy, along with their effective date, in an easy-to-find area of the Sites, so we recommend that you periodically check back here to stay informed of any changes. Please note that your continued use of Gopass Global after any change means that you agree with, and consent to be bound by, the new Policy. If you disagree with any changes in this Policy and do not wish your information to be subject to it, you will need to stop using the Sites and/or Products.

Contact us

You may contact us with any questions relating to this Privacy Policy by e- mailing: enquire@Gopassglobal.com

Your Rights

Individuals located in the European Economic Area (EEA) have certain rights in respect to their personal information, including the right to access, correct, or delete Personal Data we process through your use of the Site and/or Product. Gopass Global applies the following to any Gopass Global user, regardless of their location. You can:

  • Have your Personal Data corrected or deleted. You may ask us to correct information you think is inaccurate or completely delete all information that we hold about you by emailing: enquire@Gopassglobal.com.
  • Access your Personal Data report by submitting a request at enquire@Gopassglobal.com. This report will include the Personal Data we have about you, provided to you in a structured, commonly used, and portable format.
  • Object to us processing your Personal Data. It is your right to lodge an objection to the processing of your personal data by emailing: enquire@Gopassglobal.com if you feel the “ground relating to your particular situation” apply. The only reasons we will be able to deny your request is if we can show compelling legitimate grounds for the processing, including your and our obligations under Australian law, which limit your interest, rights and freedoms, or the processing is for the establishment, exercise or defence of legal claims.
  • You can ask us to stop using your Personal Data, including when we use your Personal Data to send you marketing emails. We only send marketing communications to users with your prior consent, and you may withdraw your consent at any time by clicking the “unsubscribe” link found within Gopass Global emails and changing your contact preferences. Please note you will continue to receive transactional messages related to our Product, even if you unsubscribe from marketing emails.
  • Complain to a regulator. If you think that we haven’t complied with data protection laws, you have a right to lodge a complaint with your local supervisory authority.

Data Protection Officer

To communicate with our Data Protection Officer, please
email enquire@Gopassglobal.com

EEA Representative

The Company is not established in the EU and therefore VeraSafe has been appointed as Gopass Global’s representative in the EEA for data protection matters, pursuant to Article 27 of the General Data Protection Regulation of the European Union.
To make such an inquiry, please contact VeraSafe using this contact form: https://www.verasafe.com/privacy-services/contact-article-27- representative. Alternatively, VeraSafe can be contacted at: VeraSafe Czech Republic s.r.o Klimentská 46 Prague 1, 11002 Czech Republic Contact form: https://www.verasafe.com/privacy-services/contact-article-27-representative