Lyra International
Global Privacy Policy
Last Updated: 25/04/24
Here are a few highlights of the changes to help you understand how this may impact your data.
- We’ve updated our Global Privacy Statement to address requirements in the UK and countries outlined in the addendums which can be found at the bottom of this policy under the ‘Jurisdiction Specific Terms’ tab.
- We’ve updated country and state requirements related to data collection, usage practices and disclosures.
Review our full statement below for complete details about the changes to our policy and to learn more about how we process personal information.
Introduction
Lyra International Holdings Ltd and its subsidiary companies and branches (referred to as Lyra International going forward) is a wholly owned subsidiary of Lyra Health Inc. Lyra International support organisations through the promotion of the health and wellbeing of their employees, while at the same time improving productivity and reducing absence. We have been an Employee Assistance Programme (“EAP”) provider since 1987 and today, we are one of the major global players in the sector. We are committed to ensuring your privacy and personal information is protected.
What is Data Protection Law?
Data protection law gives individuals certain rights about the way in which their personal data is processed. If organisations do not comply with data protection law, they may be subject to penalties imposed by the national data protection authorities and the courts. When Lyra International processes personal data, this activity and the personal data in question are covered and regulated by applicable data protection law, specifically the UK Data Protection Act 2018 and the UK GDPR – as the principal regulations in the policy – and the EU’s General Data Protection Regulation (GDPR) which covers all EU countries plus Norway, Iceland, and Lichtenstein. For countries outside these regions (e.g. Switzerland) where we – or our subsidiaries – gather and process data, additional conditions may apply, where this is the case, you will find these in our ‘Jurisdictional Clauses‘ at the bottom of this policy.
Data Privacy Policy
This Data Privacy Policy (Global) (“Policy”) establishes Lyra International’s approach to global compliance and the lawful processing of personal data. As a UK company, the UK Data Protection Act 2018, the UK e-Privacy Regulations (‘PECR’), and the UK-adopted version of the EU GDPR (‘UK GDPR’) apply directly to all our UK processing, as such, for the purposes of this policy, we use ‘GDPR’ to refer to both the UK and EU versions due to their similarities, except when we refer to International Data Transfers for example.
We always seek to comply with the applicable data protection laws relevant to our processing of personal data, as such where local laws and regulations mandate additional restrictions on the collection, use and disclosure of personal data that exceed those contained in this Policy, the local laws and regulations will prevail. These addendums can be found at the bottom of this policy under ‘Jurisdiction Specific Terms’ tab.
This Policy describes how personal data must be processed to meet Lyra International’s data protection standards and to comply with privacy laws and regulations. Additional instructions and / or guidelines regarding personal data processing activities at Lyra International are provided to employees in internal policies.
What does this mean for Lyra International?
Lyra International must take proper steps to ensure that it processes personal data on an international basis in a safe and lawful manner. Lyra International has therefore developed policies and procedures to ensure appropriate governance and compliance with such data privacy laws. This framework will apply to all personal data processing activities conducted by Lyra International globally subject to our jurisdictional legal requirements.
Data Protection Principles
Below is the summary of basic data protection principles that Lyra International must observe when it processes personal data.
Principle 1 – lawfulness of processing, fairness and transparency
- Lyra International will ensure that all processing is carried out in accordance with applicable laws.
- Lyra International will inform and explain to individuals, at the time when their personal data is collected, how their personal data will be processed.
nen Daten verarbeitet werden.
Principle 2 – purpose limitation
- Lyra International will only obtain and process personal data for those purposes which are known to the individual or which are within their expectations and are relevant to Lyra International.
- Lyra International will only process your data for the express purposes for which it was given, for example out of contractual obligation, because you’ve given your express consent, or where there is a legal basis for doing so. Where we consider ‘Legitimate Interest’ a legal basis, we will balance this against the potential risks to the rights and freedoms of the individual — for example, limiting what we keep, who we send your data to, how long we keep it for, what we do with it and the technical measures we use to protect your information.
How do we collect your personal information? | We collect personal information directly from you: • using our EAP services generally and which may be telephonically, via e-mail through the web, mobile or web applications, any other internet-based application or in person; • when you contract with Lyra International to provide services on our behalf or where we agree to provide services on your behalf. • via cookies. You can find out more about this in our Cookie Policy • through feedback forms; • when you provide your details to us either online or offline; • when you respond to any job advertisement or are employed by Lyra International We also collect your personal information from many different sources including third parties such as: • your employer • medical professionals |
---|
Principle 3 – data minimisation
- Lyra International will ensure that data collected and processed is adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.
What personal information do we collect? | As the data controller , joint data controller and/or data processor Lyra International may collect and process the following information about you: • Personal information o contact, gender, details such as name, email address, postal address, and telephone number o factors specific to physical, physiological, economic, cultural, or social identity o information obtained through our use of cookies. You can find out more about this in our Cookie Policy • Sensitive personal information |
---|
Principle 4 – accuracy
- Lyra International will keep personal data accurate and, where necessary, kept up to date.
- Every reasonable step taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’).
Principle 5 – limited retention of personal data
- Lyra International will only keep personal data for as long as is necessary for the purposes for which it is collected and further processed and to comply with our legal and regulatory obligations. The time we retain your personal information for, will differ depending on the nature of the personal information and what we do with it. In some cases, such as if there is a dispute or a legal action, we may be required to keep personal information for longer.
- However, please note that certain local or national laws may require us to keep your data for a longer period. In such cases, we will hold your information in accordance with those legal requirements. Rest assured, all data is kept secure and will only be used for the purposes for which it was collected and will be deleted when it is no longer necessary for those purposes or as otherwise required by applicable laws.
- Your personal data will be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures required by data protection law in order to safeguard the rights and freedoms of individuals.
Principle 6 – integrity and confidentiality (security)
Lyra International has a dedicated security team who maintain stringent controls over the personal data we collect, maintaining it in firewalled and secured systems and databases with strictly limited and controlled access rights, to ensure it is secure. If you would like to know more about how we secure your data you can contact us by emailing globaldpo@lyrahealth.com.
- Where processing is necessary for us to provide you with the services you require, such as assessing your needs, setting you up as a user, communicating with you, and assisting you with technical support, for example on our Lyra Hub App, your data will be processed and stored within the European Union. Please be aware that if you reside outside of the EEA, your data may also be processed at one of our regional servers, depending on the technical and operational requirements of the service provided. All processing will be in line with the relevant data protection regulations. You can find further information in the Jurisdictional Clauses at the bottom of this policy.
- Lyra International will implement appropriate technical and organisational measures to ensure a level of security of personal data that is appropriate to the risk for the rights and freedoms of the individuals.
- Lyra International will ensure that providers of services to Lyra International also adopt appropriate and equivalent security measures.
- Lyra International will comply with data security breach notification requirements as required under applicable law.
- Lyra International will ensure that information is processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organisational measures.
How do we use your personal information? | We use your personal information to provide you with the services you require based on your situation. So, if you have a problem, we make sure the right network of providers and specialists are in place. However, there are many other reasons why we use your personal information.
Under UK and EU data protection laws we need a reason to use and process your personal information and this is called a legal basis. Generally speaking, most countries we operate in require a legal basis for us to process user data, where this is the case, you can view our Jurisdictionally specific sections at the bottom of this policy however as the GDPR sets such a high bar, we refer to this as a reliable benchmark. We have set out below the main reasons why we process your personal information and the applicable circumstances when we will do so. When the personal information we process about you is classed as sensitive personal information (such as details about your health, sexual orientation, or criminal offences) we must have an additional legal ground for such processing. Legal grounds are as follows. We need to use your sensitive personal information such as health data because it is necessary for your vital interests, this being a life-or-death matter. |
---|
Principle 7 – rights of individuals
- Lyra International will adhere to the data subject rights procedure under GDPR, where we operate in a country outside of the EU, UK or the broader EEA, your rights will be based on our obligations in that country, as such, we will respond to any requests from individuals to access their personal data in accordance with applicable law.
- Lyra International will also deal with requests to rectify or erase inaccurate or incomplete personal data, or to cease processing personal data in accordance with the data subject rights procedure. Please see below the contact details for each of our regional offices where you can exercise these rights.
The right to access your personal information | You are entitled to a copy of the personal information we hold about you and certain details of how we use it. In Europe, there will not usually be a charge for dealing with these requests. Your personal information will usually be provided to you in writing, unless otherwise requested, or where you have made the request by electronic means, in which case the information will be provided to you by electronic means where possible. For requests to access medical records, we will provide a summary of clinical interactions. |
---|---|
The right to rectification | We take reasonable steps to ensure that the personal information we hold about you is accurate and complete. However, if you do not believe this is the case, please contact us and you can ask us to update or amend it. |
The right to erasure | In certain circumstances, you have the right to ask us to erase your personal information, for example where the personal information we collected is no longer necessary for the original purpose or where you withdraw your consent. However, this will need to be balanced against other factors, for example according to the type of personal information we hold about you and why we have collected it, there may be some legal and regulatory obligations which mean we cannot comply with your request. Please note that if you withdraw your consent, we may not be able to provide you with the services you have requested. |
Right to restriction of processing | In certain circumstances, you are entitled to ask us to stop using your personal information, for example where you think that the personal information, we hold about you may be inaccurate or where you think that we no longer need to process your personal information. |
Right to data portability | In certain circumstances, you have the right to ask that we transfer any personal information that you have provided to us to another third party of your choice. Once transferred, the other party will be responsible for looking after your personal information. |
Right to object to direct marketing | You can ask us to stop sending you marketing messages at any time. |
Right not to be subject to automated decision making | Some of our decisions are made automatically by inputting your personal information into a system or computer and the decision is calculated using certain automatic processes rather than our employees making those decisions. |
The right to withdraw consent | For certain uses of your personal information, we will ask for your consent. Where we do this, you have the right to withdraw your consent to further use of your personal information. Please note in some cases we may not be able to deliver the services you require if you withdraw your consent. |
The right to make a complaint | You have a right to complain to the relevant regulator at any time if you object to the way in which we use your personal information. More information can be found below on the appropriate regulator for the regions covered. |
Principle 8 – ensuring adequate protection for trans-border
- Lyra International is a global business. To offer our services, we may need to transfer your personal data to companies within the Lyra Group of companies and with third parties in other countries.
Lyra International will not transfer personal data that is subject to GDPR to third parties outside the UK or the European Economic Area (“EEA”) without ensuring adequate protection.
With the exception of those countries with Adequacy under GDPR, where data is transferred outside the United Kingdom, EEA or Switzerland, for example to the US where ICAS’s parent company, Lyra Health is registered the EU Standard Contractual Clauses, and the associated UK Addendum will apply to personal data that is transferred. This will also apply where either directly or via onward transfer and to any country or recipient outside the UK, EEA or Switzerland that is not recognised by the European Commission (or, in the case of transfers from Switzerland, the competent authority for Switzerland). - We use “cookies” and other web technologies to collect information and to support certain features of our websites, this will include the transfer of identifiable cookie data to countries outside the UK and EEA that have different privacy laws and requirements, and some provide less legal protection for your personal information than others. For more information see our Cookie Policy.
Who do we share your personal information with? | We might share your personal information with two types of organisations – companies within the Lyra group of companies, i.e. parent companies, subsidiary and affiliated (sister companies) (“Group”), and other third parties outside the Group. We won’t share any of your personal information other than for the purposes described in this Privacy Policy and if we share anything outside the Group, it will be kept strictly confidential and will only be used for reasons that we have agreed in advance. |
---|
Principle 9 – safeguarding the use of sensitive personal data
- Owing to the services that we offer, Lyra International sometimes needs to process sensitive personal information (known as special category data) about you, in order to fulfil our contractual requirements – referred to as a ‘Legal Basis’. Where we collect such information, we will only request and process the minimum necessary for the specified purpose and identify a compliant legal basis for doing so based on your jurisdiction.
- Where we rely on your consent for processing special category data, we will obtain your informed and explicit consent. You can modify or withdraw consent at any time, which we will act on immediately, unless there is a legitimate or legal reason for not doing so.
- Additional security measures and safeguards will be implemented to ensure that this sensitive personal data remains confidential and that it is deleted as soon as is reasonably possible.
Principle 10 – accountability
- Lyra International takes responsibility for compliance with the other data protection principles.
- Lyra International implements appropriate technical and organisational measures, including record keeping, in order to be able to demonstrate compliance.
Legally Binding Effect of This Policy
Lyra International and its employees (including new hires, individual contractors, and temporary staff) that process personal data worldwide must comply with, and respect, this Policy when processing personal data as a controller and / or processor, irrespective of the country in which they are located.
Lyra International reserves the right to change, modify or update this Policy, including changes to the Jurisdictional specific sections below at any time. Please review it frequently for any updates.
Contact Details and Your Rights to Complain
If you have any questions regarding the provisions of this Policy, your rights under this Policy or any other data protection issues, you can contact the Lyra International Data Privacy Office at the address below who will either deal with the matter or forward it to the appropriate person or department within ICAS.
Our Data Protection Officer is available to facilitate requests for access or correction to users own personal information and to describe how you can file a complaint with the applicable regulator regarding our handling of your personal information where required by law:
To log a Data Subject Access Request, e-mail globaldpo@lyrahealth.com
If you wish to comment, or make a complaint about the way we process your data or to find out more about your rights, you can contact our Data Protection Officer using the details below:
Attention: Ayjan Cunningham – Data Privacy Officer
Email: globaldpo@lyrahealth.com
Address: Lyra International Holdings Ltd, 85 Gresham Street, London, EC2V 7NQ
Please note that in some cases we may not be able to comply with a request relating to your rights under this policy for reasons such as our own obligations to comply with other legal or regulatory requirements. However, we will always respond to any request you make within one month or whatever the requirement is under your regional legislation and if we can’t comply with your request, we will tell you why. In some circumstances exercising some of these rights (including the right to erasure, the right to restriction of processing and the right to withdraw consent) will mean we are unable to continue providing you the services you have selected and may therefore result in the cancellation thereof.
Regional enquiries
Lyra International operate in over 150 territories worldwide, some regions of which are independent ‘non-Lyra’ subsidiaries who will process, maintain, and store service user data locally, and as such, will be solely responsible, and wholly accountable, under their own state or countries laws for how they manage this data. Where this is not the case, and where data is potentially processed outside of its borders by Lyra International or its Parent company, we provide a non-exhaustive list of regional offices below who you can contact for data related queries. If you do not see your country listed below, please contact globaldpo@lyrahealth.com.
Group Entity | Jurisdictions covered | Lyra contact for data related enquires, including Access Requests | The regulatory authority |
---|---|---|---|
Lyra UK & Ireland Ltd | United Kingdom Ireland | globaldpo@lyrahealth.com | Information Commissioner’s Office (ICO) |
Lyra Schweiz GmbH | Switzerland | dataprotection.officer@icas.ch | Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB) |
ICAS France SASU | France | dataprotection.officer@icas-eap.com | Commission Nationale de l’Informatique et des Libertés (CNIL) |
ICAS Deutschland GmbH | Germany | dataprotection.officer@icas-eap.com | Bundesbeauftragter für Datenschutz und Informationsfreiheit (BfDI) |
ICAS Italia soc. unipersonale | Italy | dataprotection.officer@icas-eap.com | Garante per la protezione dei dati personali (GPDP) |
ICAS Luxembourg S.à.r.l. | Luxemburg | dataprotection.officer@icas-eap.com | Commission Nationale pour la Protection des Données (CNPD) |
ICAS Austria GmbH | Austria | dataprotection.officer@icas-eap.com | Österreichische Datenschutzbehörde |
Lyra Health Hungary Kft | Hungary | info@icashungary.com | Hungarian National Authority for Data Protection and Freedom of Information |
ICAS Netherlands | The Netherlands | info@icas.nl | Dutch Data Protection Authority |
ICAS Spain | Spain | globaldpo@lyrahealth.com | Agencia Española de Protección de Datos (AEPD) |
ICAS Belgium | Belgium | globaldpo@lyrahealth.com | Data Protection Authority |
Turning Point | Malaysia | consult@turningpoint.org.my | Department of Protection of Personal Data |
SACAC | Singapore | admin@sacac.sg | Personal Data Protection Commission (PDPC) |
Lyra Southern Africa Pty Ltd | South Africa | paia@icas.co.za | Information Regulator |
Lyra Canada | Canada | globaldpo@lyrahealth.com | Office of the Privacy Commissioner of Canada (PIPEDA) Office of the Information and Privacy Commissioner of Alberta (PIPA Alberta) Office of the Information and Privacy Commissioner for British Columbia (PIPA BC) Commission d’accès à l’information du Québec (CAI; Quebec Privacy Act) |
ICAS MENA (office in Dubai) | Algeria Bahrain Egypt Iraq Jordan Kuwait Lebanon Libya Mauretania Morocco Oman Pakistan Palestine Qatar Saudi Arabia Senegal Tunesia UAE Yemen | globaldpo@lyrahealth.com | Commissioner of Data Protection Dubai International Financial Centre Authority (DIFC) |
Switzerland
This Swiss Jurisdictional Addendum (“Addendum”) is incorporated into and forms an integral part of the Privacy Policy of Lyra International and is applicable to all personal data collected or processed by the us from data subjects located in Switzerland. If there is any conflict between this Addendum and the rest of the Privacy Policy, the provisions of this Addendum will prevail for the protection of personal information of data subjects residing in Switzerland.
Applicable Law and Jurisdiction
This Addendum is governed by the Swiss Federal Act on Data Protection (“FADP”) and any applicable regulations or decisions issued by the Swiss Federal Data Protection and Information Commissioner (FDPIC). Any disputes arising from or in connection with this Addendum shall be subject to the exclusive jurisdiction of the competent courts in Switzerland.
Definition of Terms
For the purpose of this Addendum, the terms “personal data,” “data subject,” “controller,” “processor,” and “processing” shall have the same meaning as provided under the General Data Protection Regulation (GDPR).
Principle 1 – lawfulness of processing, fairness, and transparency
- Lyra Schweiz GmbH shall process personal data of data subjects located in Switzerland only on a lawful basis as provided under the FADP. The legal basis for processing may include the data subject’s consent, the necessity of processing for the performance of a contract with the data subject, compliance with a legal obligation, protection of vital interests, the performance of a task carried out in the public interest or in the exercise of official authority, or the legitimate interests pursued by Lyra Schweiz GmbH or a third party. .
Principal 7 – Rights of Individuals:
Data subjects located in Switzerland have the following rights regarding their personal data:
- Right to Information: Data subjects have the right to obtain information about the processing of their personal data, including the purposes, categories of personal data processed, recipients or categories of recipients to whom the personal data is disclosed, and the retention period for the personal data.
- Right of Access: Data subjects have the right to access their personal data held by the Lyra Schweiz GmbH and receive a copy thereof.
- Right to Rectification: Data subjects have the right to request the rectification of inaccurate personal data concerning them and the completion of incomplete personal data.
- Right to Erasure: Data subjects have the right to request the erasure of their personal data under certain circumstances, such as when the personal data is no longer necessary for the purposes for which it was collected or processed.
- Right to Restriction of Processing: Data subjects have the right to request the restriction of the processing of their personal data under certain circumstances, such as when the accuracy of the personal data is contested, or the processing is unlawful.
- Right to Data Portability: Data subjects have the right to receive their personal data in a structured, commonly used, and machine-readable format, and have the right to transmit such data to another controller without obstruction.
- Right to Object: Data subjects have the right to object to the processing of their personal data, including for direct marketing purposes or when the processing is based on the legitimate interests pursued by Lyra Schweiz GmbH.
- Right to withdraw consent: If consent has been given for data processing and there is no other legal basis for data processing, data subjects have the right to withdraw their consent at any time.
Automated decision making: We are committed to protecting your privacy and ensuring compliance with data protection regulations, including the Federal Act on Data Protection (FADP). In accordance with our data processing practices, we would like to inform you that we do not carry out any automated decision-making processes in relation to your personal data.
Automated decision-making refers to processes in which algorithms, artificial intelligence or machine learning are used to make decisions about individuals without human intervention. These decisions can have a significant impact on your rights and interests. However, we would like to assure you that all decisions made in relation to your data will be subject to human review and consideration where appropriate to ensure fairness, transparency and compliance with the DPA.
Principle 8 – ensuring adequate protection for trans-border transfers
- Lyra International only transfers anonymised data from Switzerland to locations within the European Economic Area (EEA), so that this is not considered personal data under Swiss law.
- Swiss legislation permits the transfer of personal data to countries with adequate data protection. Therefore, in cases where a service user’s data is not processed in Switzerland, e.g. when using the chat outside working hours, Lyra International will only transfer personal data from Switzerland to a country within the European Economic Area (EEA). This ensures that personal data is protected in accordance with the strict Swiss data protection standards.
Complaints and Inquiries:
Our Data Protection Officer is available to facilitate requests for access or correction to users own personal information and to describe how you can file a complaint with the applicable regulator regarding our handling of your personal information where required by law. Please see contact details for both the Data Protection team, and applicable regulator in the table above.
- “ICAS” includes but is not limited to ICAS International Holdings including ICAS Gulf (branch), ICAS Spain, ICAS Southern Africa, ICAS Hungary, ICAS Netherlands, ICAS Belgium, ICAS France, ICAS Deutschland, ICAS Italia, ICAS Luxembourg, ICAS Austria, Turning Point (MY), SACAC (SING) and designated third parties (“Group Members”).
- “Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- “Personal data” / “Personal information” means any information relating to an identified or identifiable natural person (“Data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- “Sensitive personal data” means “special categories of personal data” as set out in GDPR as well as Article 6 in the UK GDPR, which must be treated with extra security. These categories include health information and also genetic data and biometric data where processed to uniquely identify an individual. Personal data relating to criminal convictions and offences are not included, but similar extra safeguards apply to its processing.
- For the purpose of this Policy, reference to Europe means the EEA which incorporates Norway, Iceland, Lichtenstein as well as Switzerland.