TELUS Health Wellbeing Privacy Commitment

Last Updated: March 7, 2024

TELUS Health Wellbeing is a digital platform that enables you to better manage your health and wellbeing (the "Service").We are passionate about the protection of your Personal Information and are committed to respecting your privacy. 

You must read this Privacy Policy before using our Services. If you have any questions about our privacy practices, please contact us.

TELUS Health Wellbeing policy to protect your privacy

By accessing or using the TELUS Health Wellbeing platform (web-based portal or mobile app), you understand that your information will be treated in accordance with this TELUS Health Wellbeing Privacy Commitment (“Privacy Commitment”). Our Privacy Commitment and practices are consistent with the 10 Fair Information Principles, applicable data protection laws and we strive to apply the principles of Privacy by Design in the development and review of our products and services.

If you do not want us to collect, use or disclose your Personal Information in the ways identified in this Privacy Commitment, you may choose not to use TELUS Health Wellbeing.‬‬‬‬‬‬‬‬‬‬‬‬‬‬

Definitions

The following definitions apply to this Commitment.

You - An individual who uses, or registers to use, TELUS Health Wellbeing.

Personal Information - Any information about an identifiable individual. The following is a list of the types of information that TELUS Health may collect through its Services. Please note that the types of Personal Information collected about you will depend on the activities in which you participate:

  • Identity Data includes your first name, last name, department or group, unique ID such as your employee ID, or other similar identifiers. 

  • Contact Data includes mailing address, email address and telephone number(s).

  • Profile Data includes profile photo, groups you belong to, events you are attending, challenges you are participating in, badges you have received, rewards you have redeemed.

  • Activity Data includes information collected through devices such as smartwatches that you have chosen to sync with your account and other data about your activities that you may enter manually through the Service.

  • Health and Wellness Data includes height, weight, waist circumference, heart rate, blood pressure, medical history, and family health history. You may also choose to contribute lifestyle habits and interests such as book clubs, meal recipes, parenting tips and financial wellness, as well as your personal wellness goals. 

  • Opinion Data includes any communications with other users through our Services, including our participation forums, message board, streams and/or on leaderboards. 

  • Technical Data includes internet protocol (IP) address, your mobile device’s unique ID number, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access the Services.

  • Usage Data includes information about how you use the Services, such as the buttons, controls, products and ads you click on, pages of our Services that you visit, the time spent on those pages, your search queries, the dates and times of your visits, but also about the webpage you were visiting before you came to our Services and the webpage, app(s) you go to next.

Personal Information does not include anonymized or aggregated information that cannot reasonably be associated with a specific individual.

TELUS Family - In this Privacy Commitment, “TELUS Family” means TELUS Communications Inc. and its subsidiary companies and corporate affiliates, as they may exist from time to time.

TELUS Health Wellbeing - In this TELUS Health Wellbeing Privacy Commitment, the words "we", "us", "our" or "TELUS" refer to TELUS Health (Canada) Ltd.

Accountability

TELUS Health Wellbeing has overall responsibility for protecting the privacy of the Personal Information we collect about you through TELUS Health Wellbeing, and we are directly accountable to you with respect to the handling of that information.

Consent

When you access or use TELUS Health Wellbeing, you consent to our collection, use, disclosure, and storage of your Personal Information as described in this Privacy Commitment.‬‬‬‬‬‬ Your express consent will be sought prior to or at the time of collecting any special category personal information including your personal health information.

You can withdraw your consent at any time, subject to limited restrictions.‬‬

Collection and Use of Personal Information

We collect only the Personal Information required for us to establish and maintain a responsible service relationship with you, to provide our services, and to develop, enhance or market our products and services (including to send you relevant information about products and services that may be of interest to you), and to maintain and improve the security and functionality of our wellness platform.‬  

We collect Personal Information to set up an account for you on the TELUS Health Wellbeing platform so that you can access and use the TELUS Health Wellbeing health-related services. 

We also collect other information from you as you use the TELUS Health Wellbeing Services: 

  • Platform usage information

  • Website and device information

  • Cookies

‬‬‬‬‬We may use Personal Information to send you communication, including newsletters. 

All settings such as notifications and personalization require you to opt-in. If you do not wish to receive notifications or personalize your profile, for example, please adjust your Privacy settings accordingly.

Sharing and Disclosure of Personal Information

We will not disclose your Personal Information for any purpose other than what has been outlined in this Privacy Commitment or as permitted under applicable law, unless we obtain your express consent. We disclose only the limited amount of Personal Information necessary to meet these purposes. 

We do not sell your Personal Information to any third parties.

We may share your Personal Information with our service providers who are contracted to perform services or functions on our behalf where they require the information to assist us in serving you. We use contractual controls to protect this information and limit its use to what is necessary for the service provider to perform the service.

Google Fit API

TELUS Health Wellbeing’s platform use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.

Access, Corrections, and Accuracy of your Personal Information

You can request access to or correction of your Personal Information by contacting us at [email protected].

We rely on you to keep your Personal Information up to date and accurate so that we can serve you.

Storage and Location of your Personal Information

Your Personal Information is stored in the country specified by your employer. The service is managed and supported from Canada.

Retention

We retain Personal Information only for as long as necessary to fulfill the purposes described in this Privacy Commitment or as required to meet legal or regulatory requirements.

Safeguards

We have implemented a comprehensive information security program.

Changes to this Privacy Statement

We may make changes to this notice and we will notify you of the changes to our information practices.

Questions, Complaints, and Contact

You can always reach our Data Protection Officer at [email protected] if you have privacy questions, concerns or complaints.

Privacy Addendum for Europe

This Privacy Policy Addendum for Europe is for users of TELUS Health Wellbeing services who are located in the European Economic Area (EEA) and Switzerland. If you’re located in the EEA or Switzerland, you should read both the TELUS Health Wellbeing Privacy Commitment and this Privacy Addendum for Europe to understand your rights and options.

Basis of Lawful Processing 

European data protection laws require us to be specific about our reasons or grounds for using your personal information. TELUS Health Wellbeing processes the personal information of users in the EEA or Switzerland on these grounds:

Identity Data: We collect and process your Identity Data for the purpose of registering and maintaining your account with our Services and with the Program Provider. We also collect and process this data to prevent, detect, and investigate fraud or security incidents. The legal basis for processing your Identity Data is to perform a contract with you.

Contact Data: We collect and process your Contact Data for the purpose of verifying your account details, contacting you with account information, and sending you relevant materials about our Services according to your preferences. We may also use the region that you have identified in our aggregated research and analytics and for quality improvement purposes. The legal basis for processing your Contact Data is to perform our contract with you. We also rely on our legitimate interest to use anonymized and aggregated data for the purpose of quality improvement and product development for our Services. 

Profile Data: We collect and process your Profile Data for the purpose of allowing you to personalize your profile, help your colleagues identify you in the Service, including the Program Provider, if you choose to be identified, help us verify your account, showcase your achievements on the Leaderboard, if applicable, and to resolve any inquiries or complaints. The legal basis for processing your Profile Data is to perform a contract with you.

Health and Wellness Data: We collect and process your Health and Wellness Data for the purpose of helping you organize and assess your health and wellness statistics, manage rewards and benefits to you through the Services, to offer you personalized recommendations for wellness content in our online newsletters, and to recommend programs you may wish to join through our Services. We also use anonymized information to train our machine learning algorithms and processes. We use any Health and Wellness Data that you contribute to our Wellness Survey for the purpose of determining and sharing a Wellbeing Score. The purpose of this data processing is to provide you with more personalized and relevant services, and to help you assess and track your wellbeing metrics. The legal basis for processing your Health and Wellness Data is consent.

Activity Data: We collect and process your Activity Data for the purpose of helping you organize and store your activity achievements, tracking your achievements on the Leaderboard for your organization (if applicable), and to provide rewards and activity incentives. The legal basis for processing your Activity Data is performance of a contract with you. We rely on our legitimate interest to process Activity data for the purpose of internal quality improvement including training our algorithms to better calibrate incentives to activities. 

Opinion Data: We collect and process Opinion Data for the purpose of enabling community-building through our Services and to stimulate positive incentives for health and wellness. Where we enable the sharing of Opinion Data, you may control the extent of your engagement and opt-in or opt-out of certain forms of engagement through our Services, either through your “Privacy Settings” in your account or through some similar mechanism. We may record and store archives of these communications on TELUS Health controlled servers to protect the safety and wellbeing of our users. The legal basis for processing your Opinion Data is your consent. We also rely on our legitimate interest to process your Opinion Data for the purpose of ensuring safe and respectful communications in our Services. 

Technical Data: We collect and process your Technical Data for the purpose of understanding your use of the Services and to troubleshoot technical issues when using the Services. We also process this data for quality improvement purposes to create a better user experience. The legal basis for processing your Technical Data is our legitimate interest to administer a high quality, easy to navigate, engaging and well-functioning wellness platform, and to provide timely and appropriate technical support to our users as needed.   

Usage Data: We collect and process your Usage Data for training and quality assurance purposes, to understand how you use our Service, to identify and resolve technical issues with our Service and to improve user experience on our platform. The legal basis for processing your Usage Data is our legitimate interest in quality improvement of our Services and technical assistance. 

Your Legal Rights in the EEA and Switzerland

Under certain circumstances, you have rights under data protection laws in relation to your personal information. You may have the right to:

Object to processing of your Personal Information: where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal information for direct marketing purposes. In some cases, we may have compelling legitimate grounds to process your information and will communicate that to you.

Request restriction of processing of your Personal Information: This enables you to ask us to suspend the processing of your Personal Information in the following scenarios: (a) if you want us to establish the information's accuracy; (b) where our use of the information is unlawful but you do not want us to erase it; (c) where you need us to hold the information even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your information but we need to verify whether we have overriding legitimate grounds to use it.

Request the transfer of your Personal Information to you or to a third party: We will provide to you, or a third party you have chosen, your Personal Information in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

Withdraw consent at any time where we are relying on consent to process your Personal Information: However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain services to you. We will advise you if this is the case at the time you withdraw your consent.

If you wish to exercise any of the rights set out above, please contact us using the details set out under Questions, Complaints, and Contact.