Privacy statement on data processing and data protection within the framework of the EU digital COVID certificate

 

COVIDSAFE APP

 

v.1 – 16th June 2021

 

CovidSafe is an application specifically designed in the context of controlling the COVID-19 pandemic. This app uses your personal and confidential data exclusively for the purpose of controlling the COVID-19 pandemic.

In this privacy statement, you will find all the information concerning the processing of your personal data by this app within the framework of the EU digital COVID Certificate.  In particular, it will clarify how your data are collected, processed and used.  This document is divided into two parts:

 

General

What is a processing of personal data ? Concepts.

 

Personal data”: any information relating to an identified or identifiable natural person (‘data subject’, i.e. not a company for instance); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Processing”: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Controller”: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

“Processor”: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

 

What are your rights regarding the processing of personal data?

 

You can always verify which data relating to you are processed and, if necessary, have them corrected.  You also have the right to object to any processing that is based on the public interest.  If you believe that your data are no longer relevant and should therefore be deleted, you also have the right to request this.  Finally, if a processing operation is based on your consent, you have the right to withdraw your consent at any time.

If you have any questions regarding the processing of your personal data or if you wish to exercise any of the above rights, you may contact the data protection officer of the controller, whose contact details are provided below.

You can also contact the data protection officer if you do not agree with the way your data are being processed.  In addition, you can always lodge a complaint with the supervisory authority concerned.

EU digital COVID certificate

 

EU digital COVID certificate controller

 

This app is provided to the user by eHealth platform. The app is only available to persons whose certificates are managed by the institutions responsible for creating the vaccination certificate, test certificate or recovery certificate.

The controller for the processing performed by the app is the user who has installed the app on his device.

Purpose and legal basis of the processing

 

The EU Digital COVID Certificate will facilitate safe free movement of citizens in the EU during the COVID-19 pandemic. The certificate will allow you to prove that you have been vaccinated against COVID-19, that you have received a negative test result or that you have recovered from COVID-19. The certificate can be used in all EU Member States and in Iceland, Liechtenstein and Norway. Discussions are underway with Switzerland to ensure that this certificate can also be used in that country.

The purpose of this app is to retrieve the EU digital COVID certificate of the user and of the persons for whom the user is empowered to process the data, and to store these certificates on the user's device.

The use of this app is completely voluntary. This means there is no obligation to install it. By installing the app and entering his identification data, the user consents to the processing of his data by the app.

 

Type of personal data

 

To obtain a EU digital COVID certificate, the following data are processed:

Where do these personal data come from?

 

The EU digital COVID certificate includes three different types of certificates:

The vaccination certificate is issued by the controllers below, each for his own area of responsibility, and can be retrieved by the app:

The EU digital COVID test and recovery certificates are issued by Sciensano, registered at the Crossroads Bank for Enterprises under the number 0693.876.830, whose offices are located at Juliette Wytsmanstraat 14, 1050 Elsene. These certificates can also be retrieved by the app.

 

Transfer

 

The user can decide to show the QR code of the application to third parties. By doing this, the user will communicate identity and content data of the certificates to this third party.

The app may transfer data relating to the use of the app and the device to Firebase (to detect problems in the app) with the user's consent. The transfer is subject to the following privacy policy : https://firebase.google.com/support/privacy. No data related to the content of the certificates will be transmitted.

Use of the camera:

 

The CovidSafe app does not use the camera of your device.

 

Retention period

 

The certificates are stored on the user’s device as long as they are valid and are deleted when the user deletes the app from his device.