Privacy Policy

Introduction

Blue Oak Health Pte. Ltd. (“Blue Oak”) provides this Privacy Policy to inform you of our policies and procedures regarding the collection, use and disclosure of personal information we receive from members of Blue Oak’s programs and services, which we make available via our website, accessible at www.blueoakhealth.com (the “Site”). This Privacy Policy governs your access to and use of Blue Oak’s programs and services online, and by using Blue Oak’s programs and services, you consent to the collection, transfer, processing, storage, disclosure and other uses described in this Privacy Policy. This Privacy Policy may be updated from time to time. We will notify you of any material changes by posting the new Privacy Policy on the Site. You are advised to consult this policy regularly for any changes. Unless otherwise defined in this Privacy Policy, terms used in this Privacy Policy have the same meanings as in our Blue Oak Terms and Conditions of Use.

As used in this policy, the terms “using” and “processing” information include using cookies on a computer, subjecting the information to statistical or other analysis and using or handling information in any way, including, but not limited to collecting, storing, evaluating, modifying, deleting, using, combining, disclosing and transferring information within our organization or among our affiliates within Singapore or internationally.

How we use your information

When using this site and related online services (including Blue Oak Care Diary), we may require you to provide us your personal information.

You may wish to know that:

  • We use your information only to provide the services that you request us to perform
  • We do not sell or share identifiable customer information with anyone outside Blue Oak
  • We have established safeguards (these are physical, electronic and procedural) to protect this information.

If you are giving personal information about someone else, we rely on you to inform the parties concerned that:

  • You are providing the information to us
  • The purpose you are disclosing the information to us.

We rely solely on you to obtain the necessary consent before providing us the personal information of someone else.

The full version of our Personal Data Protection Policy Statement is in the following section.

Personal Data Protection Policy Statement

We at Blue Oak Health Pte. Ltd. (hereafter referred to as the "Blue Oak") take our responsibilities under Singapore’s Personal Data Protection Act 2012 (the "PDPA") seriously. We also recognise the importance of the personal data you have entrusted to us and believe that it is our responsibility to properly manage, protect and process your personal data.

This Data Protection Policy is designed to assist you in understanding how we collect, use, disclose and/or process the personal data you have provided to us, as well as to assist you in making an informed decision before providing us with any of your personal data.

If you, at any time, have any queries and/or feedback on this policy or any other queries in relation to how we may manage, protect and/or process your personal data, please do not hesitate to contact our Data Protection Officer (the "DPO") at:

Attention to: Data Protection Officer
Via Email: dpo@blueoakhealth.com
Via Post: 1 Gateway Drive, #07-01, Westgate Tower, Singapore 608531

Our Data Protection Officer will get in touch with you if further information or clarifications are required.

1     Introduction to the PDPA

1.1     "Personal Data" is defined under the PDPA to mean data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which an organisation has or is likely to have access. Common examples of personal data could include names, identification numbers, contact information, medical records, photographs and video images.

2     Collection of Personal Data

2.1     We will only collect, use or disclose Personal Data in accordance with the PDPA. Generally, we may collect Personal Data through various means including but not limited to the following:

  1. when you register for any services through our website(s);
  2. when you submit an application form and/or consent form or other forms relating to any of the services provided by us;
  3. when you submit an application form and/or consent form or other forms relating to any of the services provided by us;
  4. when you participate in any of our research programs;
  5. when you are attended to and/or served by one of our consultants who carry out the services you have requested for;
  6. when you provide us with feedback;
  7. when you request that we contact you for any reasons; or
  8. when you submit your Personal Data to us for any other reasons.

2.2     The type of Personal Data collected that we may collect may include the following:

  1. name, gender, race, marital status and contact particulars, including telephone number(s), residential/mailing address(es) and email address;
  2. details of identification documents such as NRIC or passport numbers;
  3. the name and contact particulars of next-of-kin;
  4. health / medical information including height and weight;
  5. photographs and video;
  6. any other information which you may voluntarily provide to us from time to time in the course of your interaction with us.

3     Purposes for Collection, Use, Disclosure and Processing of Personal Data

3.1     The personal data which we collect from you may be collected, used, disclosed and/or processed for various purposes, depending on the circumstances for which we may/will need to process your personal data. Such purposes include but are not limited to the following:

  1. during provision of our health coaching program;
  2. processing your healthcare biometrics for risk profiling, health coaching and care coordination. It includes on-going collation and monitoring of your healthcare biometrics so we can understand your condition to the best possible extent.
  3. administering, servicing (including pre- and post- sales support), managing and maintaining your relationship and healthcare programs with the us (including the mailing of correspondences to you involving the disclosure of your personal data printed on the external envelopes);
  4. carrying out the operations and transactions under your health coaching programs with us including making and obtaining payments;
  5. carrying out your instructions or responding to your enquiries;
  6. storing, hosting, backing up (whether for disaster recover or otherwise) of the personal data whether within or outside Singapore;
  7. complying with applicable legal and regulatory obligations in managing your relationship and health coaching programs with Blue Oak.
  8. carrying out research, survey, post-program follow-up or impact assessment and statistical analysis;
  9. employees training and quality assurance program;
  10. informing or engaging you for the Blue Oak’s events, talks or workshops; and
  11. if you have so consented, sending you marketing, advertising and promotional information about other health coaching programs or technologies and/or services that we may be selling or marketing, whether now or in the future, and which we believe may be of interest or benefit to you (the “Marketing Purpose”), by way of the modes of communication as consented by you;
  12. business operation purposes including safety and security, record-keeping, facilitating the completion of transactions, and accounting or auditing;
  13. compliance with laws, regulations, codes or guidelines binding upon us, including disclosures to regulatory authorities or other public bodies; and
  14. any other purpose reasonably related and/or ancillary to any of the abovementioned purposes including any other purposes where consent was specifically given or obtained.

(collectively, the “Purposes”).

3.2     In order to conduct our business operations more smoothly, we may also be disclosing the personal data you have provided to us to our third party service providers, agents and/or our affiliates or related corporations, and/or other third parties whether sited in Singapore or outside of Singapore, for one or more of the above-stated Purposes. Such third party service providers, agents and/or affiliates or related corporations and/or other third parties would be processing your personal data either on our behalf or otherwise, for one or more of the above-stated Purposes.

3.3     If you have provided us with any contact particulars and have indicated your consent to being contacted for the purpose of follow-ups or impact assessment after completion of our health coaching programs, then from time to time, we may contact you using such contact particulars (including via voice calls, SMS or other means).

3.4     You may withdraw your consent for receiving communication related to follow-ups or impact assessment after completion of our health coaching programs at any time. Please contact our DPO with your request. It may take up to 30 days for your withdrawal to be processed. Therefore, you may still receive communication related to follow-ups or impact assessment during this time. Please note that even after your withdrawal of consent to be contact for follow-ups or impact assessment, we may still contact you for other purposes in relation to the services we provide you.

3.5     In some cases, we may encrypt, anonymise and/or aggregate the information before disclosing it to third parties.

3.6     We will also ensure that any overseas organisation or third party we work with observe strict confidentiality and data protection obligations.

4     Specific Issues for the Disclosure of Personal Data to Third Parties

4.1     We will not disclose your personal data to third parties without first obtaining your consent permitting us to do so. However, please note that we may disclose your personal data to third parties without first obtaining your consent in certain situations, including, without limitation, the following:

  1. cases in which the disclosure is required or authorised based on the applicable laws and/or regulations;
  2. cases in which the purpose of such disclosure is clearly in your interests, and if consent cannot be obtained in a timely way;
  3. cases in which the disclosure is necessary to respond to an emergency that threatens the life, health or safety of yourself or another individual;
  4. cases in which the disclosure is necessary for any investigation or proceedings;
  5. cases in which the personal data is disclosed to any officer of a prescribed law enforcement agency, upon production of written authorisation signed by the head or director of that law enforcement agency or a person of a similar rank, certifying that the personal data is necessary for the purposes of the functions or duties of the officer;
  6. cases in which the disclosure is to a public agency and such disclosure is necessary in the public interest; and/or
  7. where such disclosure without your consent is permitted by the PDPA or by law.

4.2     The instances listed above at paragraph [4.1] are not intended to be exhaustive. For more information on the exceptions, you are encouraged to peruse the Second, Third and Fourth Schedules of the PDPA which is publicly available at http://statutes.agc.gov.sg.

5     Consent

5.1     Unless otherwise authorised under the PDPA or under any other applicable law, we will not collect, use and/or disclose your Personal Data without prior consent.

5.2     We will take reasonable steps to highlight the purposes of such collection, use and/or disclosure of Personal Data by way of various means, including but not limited to the following:

  1. by way of express provisions in contracts, applicable forms and/or consent forms to be signed and submitted to us;
  2. by notification on our website; or
  3. our communications with you.

5.3     In the event that you provide us with any Personal Data relating to a third party including a reference to us for the purposes of us providing our services to that third party, the submission of such information to us is a representation to us that you have obtained the consent of the third party to provide us with their Personal Data.

6     Request for Access and/or Correction of Personal Data

6.1     You may request to access and/or correct the personal data currently in our possession or control by submitting a written request to us. To facilitate such a request, please submit your written request to our DPO at this email address: dpo@blueoakhealth.com, including the following data: full name, contact number, IC number, residential address, your request and purpose of your request and a letter of authority where applicable.

6.2     In respect of a request to access personal data, once we have obtained the relevant information from you to deal with the request, we will seek to provide you with the relevant personal data within 30 days. Where we are unable to respond to you within the said 30 days, we will notify you of the soonest possible time within which we can provide you with the information requested. Please note that the PDPA exempts certain types of personal data from being subject to your access request. In this regard, we would advise that you take note of sections 21(2) to (4) and the Fifth Schedule of the PDPA.

6.3     In respect of a request to correct personal data, once we have obtained the relevant information from you to deal with the request, we will:

  1. correct your personal data within 30 days. Where we are unable to do so within the said 30 days, we will notify you of the soonest practicable time within which we can make the correction. Note that the PDPA exempts certain types of personal data from being subject to your correction request as well as provides for situation(s) when correction need not be made by us despite your request.; and
  2. subject to your direction, we will send the corrected personal data to the relevant organisations which the personal data was disclosed by us within a year before the date the correction was made, unless that other organisation does not need the corrected personal data for any legal or business purpose.

6.4     We may also need to charge a fee for the handling and processing of your requests to access your personal data. We will provide you with a written estimate of the fee prior to charging.

7     Request to Withdraw Consent

7.1     You may withdraw your consent for the collection, use and/or disclosure of your personal data in our possession or under our control by submitting a written request to us. In this regard, kindly contact our DPO by way of the contact details set out herein.

7.2     We will process your request within 30 days from such a request for withdrawal of consent being made, and will thereafter not collect, use and/or disclose your personal data in the manner stated in your request.

7.3     However, your withdrawal of consent could result in legal and practical consequences arising from such withdrawal. In this regard, depending on the extent of your withdrawal of consent for us to process your personal data, we may be unable to continue with your existing relationship with us and/or the health coaching programs you have with us may have to be terminated.

8     Administration and Management of Personal Data

8.1     We will take reasonable efforts to ensure that your personal data is accurate and complete, if your personal data is likely to be used by us to make a decision that affects you, or disclosed to another organisation. In this regard, we would appreciate if you could update us of any changes in your personal data. We will not be held liable or responsible for relying on inaccurate or incomplete personal data arising from your failure to update us of any changes in your personal data that you had initially provided us with.

8.2     We will put in place reasonable security arrangements to ensure that your personal data is adequately protected and secured. Appropriate security arrangements will be taken to prevent any unauthorised access, collection, use, disclosure, copying, modification, leakage, loss, damage and/or alteration of your personal data in our possession. However, we cannot assume responsibility for any unauthorised use of your personal data by third parties which are wholly attributable to factors beyond our control.

8.3     We will take reasonable steps to ensure that third parties who receive personal data from us adopt measures in compliance with the PDPA or to a standard comparable to the protection received under the PDPA in the case of a recipient outside Singapore. In such cases, we may incorporate appropriate contractual terms in our written agreements with such third parties.

8.4     We will also put in place measures such that your personal data in our possession or under our control is destroyed and/or anonymised as soon as it is reasonable to assume that (i) the purpose for which that personal data was collected is no longer being served by the retention of such personal data; and (ii) retention is no longer necessary for any other legal or business purposes.

9     Feedback Process

9.1     If you have any complaint or grievance regarding about how we are handling your personal data or about how we are complying with the PDPA, we welcome you to contact us with your complaint or grievance.

9.2     Please contact us through one of the following methods with your complaint or grievance:

  1. E-mail: dpo@blueoakhealth.com. Attention it to the ‘Data Protection Officer’
  2. Office address: 1 Gateway Drive, #07-01, Westgate Tower, Singapore 608531. Attention it to the ‘Data Protection Officer’

Where it is an email or a letter through which you are submitting a complaint, your indication at the subject header that it is a PDPA complaint would assist us in attending to your complaint speedily by passing it on to the relevant staff in our organisation to handle. For example, you could insert the subject header as “PDPA Complaint”.

9.3     We will certainly strive to deal with any complaint or grievance that you may have speedily and fairly.

10     Updates On Data Protection Policy

10.1     As part of our efforts to ensure that we properly manage, protect and process your personal data, we will be reviewing our policies, procedures and processes from time to time.

10.2     We reserve the right to amend the terms of this Data Protection Policy at our absolute discretion. Any amended Data Protection Policy will be posted on our website and can be viewed at www.blueoakhealth.com/privacy.html.

10.3     You are encouraged to visit the above website from time to time to ensure that you are well informed of our latest policies in relation to personal data protection.

11     Governing Law

11.1     This Data Protection Policy and your use of this website shall be governed by and construed in accordance with the laws of Singapore. For the avoidance of doubt, any dispute that might arise between you and us will be governed by the laws of Singapore.

Effective Date: 22 September 2014