The Company has a contract with all Data Processors that it uses in compliance with Article 28 & Article 29 of the GDPR and ensures that all Data Processors are compliant with Data Protection Legislation. The policy does not apply to third party services. Where third party services are used, and the third party is not a Data Processor, no Relevant Data (as defined below) is shared with them, or the Relevant Data has been anonymised such that the GDPR does not apply. Information collected by third parties is governed by their privacy practices. We encourage you to learn about the privacy practices of those third parties. In addition, a separate agreement governs delivery, access and use of the Products (the “User Agreement”), This policy applies to Relevant Data received and processed only.
Capitalised terms used in this Policy and not otherwise defined shall have the meanings provided below:
Rajah Blue Family of Companies – the list of the Rajah Blue family of companies is as follows:
Rajah Blue Pte Ltd.
Rajah Blue Risk Map, Rajah Blue Health Rating Tool, Rajah Blue Corporate Suite
Relevant Data – Personal Data and Special Categories of Data are the Relevant Data covered by this policy and as defined in the Data Protection Legislation.
Personal Data – any information relating to an identified or identifiable natural person.
Special Categories of Data – Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data and data concerning health or a person’s sex life or sexual orientation.
Processing/Processed – any operation on personal data, whether automated or not.
Contagious Disease – any infection subject to a specific health alert including epidemics and pandemics including but not limited to: COVID19, MERS, SARS.
Information We Collect and Receive
When you interact with our Sites and Products, we collect information that, alone or in combination with other data, could be used to identify you (Personal Data). Some of the Information we collect is stored in a manner that cannot be linked back to you (Non-Personal Data). Rajah Blue collects, generates and/or receives the following Information:
Certain data about the devices you use to connect with Rajah Blue and your use of the Site and/or Product are automatically logged in our systems, including:
- Сontact details, namely, email.
- Location information. This is the geographic area where you use your computer and mobile devices (as indicated by an Internet Protocol [IP] address or similar identifier) when interacting with our Site and/or Product.
- Log data. As with most websites and technology services delivered over the internet, our servers automatically collect data when you access or use our Site and/or Product and record it in log files. This log data may include the IP address, browser type and settings, the date and time of use, information about browser configuration, language preferences, and cookie data.
- Product and Site-Specific Data. This is information about the Site and/or Product you use and how you use them. We may also obtain data from our third-party partners and service providers to analyze how users use our Site and/or Product. For example, we will know how many users access a specific page on the Site and which links they clicked on. We use this aggregated information to better understand and optimize the Site.
- Device information. These are data from your computer or mobile device, such as the type of hardware and software you are using (for example, your operating system and browser type), as well as unique device identifiers for devices that are using Rajah Blue Product.
Third Party Data
Rajah Blue may receive data about Site visitors, marketing campaigns and other matters related to our business from affiliates and subsidiaries, our partners or others that we use to make our own information better or more useful. This data may be combined with Other Information we collect and might include aggregate level data, such as which IP addresses correspond to zip codes or countries. Or it might be more specific: for example, how well an online marketing or email campaign performed.
Additional Information Provided to Rajah Blue
We receive Other Information when submitted to our Site or if you participate in a focus group, contest, activity or event, apply for a job, request support, interact with our social media accounts or otherwise communicate with Rajah Blue.
Our order process is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record for all our orders. Paddle provides all customer service inquiries and handles returns.
Collection Information from Children
Rajah Blue does not knowingly collect personal information from children under the age of 15. If we determine we have collected personal information from a child younger than 15 years of age, we will take reasonable measures to remove that information from our systems. If you are under the age of 15, please do not submit any personal information through the Site and/or Products. We encourage parents and legal guardians to monitor their children’s Internet usage and to help enforce this Policy by instructing their children never to provide personal information through the Sites and/or Products without their permission.
Use of Your Information by Rajah Blue
We use, process, and store your information as necessary to perform our contract with you and for our legitimate business interests, in operating our Sites, Products, Services, and business including:
- to help us administer our Sites and/or Products, authenticate users for security purposes, provide personalized user features and access, process transactions, conduct research, develop new features, and improve the features, algorithms, and usability of our Sites and/or Products;
- As required by applicable law, legal process or regulation.
- to calculate aggregate statistics on the number of unique devices using our Sites and/or Products;
- to send emails and other communications. We may send you alerts messages, service, technical and other administrative emails, messages and other types of communications. We may also contact you to inform you about changes in our Products, our Products offerings, and important Products-related notices, such as security and fraud notices. These communications are considered part of the Products and you may not opt-out of them. In addition, we sometimes send emails about new product features, promotional
communications or other news about Rajah Blue. We will only send you marketing information if you consent to us;
- for billing, account management and other administrative matters. Rajah Blue may need to contact you for invoicing, account management and similar reasons and we use account data to administer accounts and keep track of billing and payments;
- to investigate and help prevent security issues, fraud and abuse;
- If information is aggregated or de-identified so it is no longer reasonably associated with an identified or identifiable natural person, Rajah Blue may use it for any business purpose.
How We Share and Disclose Information
We only disclose Personal Data to third parties when:
- We use service providers who assist us in meeting business operations needs, including hosting, delivering, and improving our Products. We also use service providers for specific services and functions, including email communication, customer support services, and analytics. These service providers may only access, process, or store Personal Data pursuant to our instructions and to perform their duties to us.
- We have your explicit consent to share your Personal Data (if required).
- We believe it is necessary to investigate potential violations of the Terms of Products, to enforce those Terms of Products, or where we believe it is necessary to investigate, prevent, or take action regarding illegal activities, suspected fraud, or potential threats against persons, property, or the systems on which we operate our Site and/or Products.
- We determine that the access, preservation, or disclosure of your Personal Data is required by law to protect the rights, property, or personal safety of Rajah Blue and users of our Site and/or Products, or to respond to lawful requests by public authorities, including national security or law enforcement requests.
- We may disclose Non-Personal Data publicly and to third parties – for example, in public reports about word usage, to partners under agreement with us, or as part of progress reports we may provide to users.
- Rajah Blue does not share your Personal Data with third parties for the purpose of enabling them to deliver their advertisements to you.
- Rajah Blue does not sell or rent your Personal Data.
Third Parties’ Applications and Products
Some third-party applications and services that work with us may ask for permission to access your information. Those applications will provide you with notice and request your consent in order to obtain such access or information. Please consider your selection of such applications and services, and your permissions, carefully.
Some third parties’ embedded content or plugins on our Sites and/or Products, such as Facebook “Like” buttons, may allow their operators to learn that you have visited the Sites, and they may combine this knowledge with other data they have collected about your visits to other websites or online services that can identify you.
Data collected by third parties through these apps and plugins is subject to each parties’ own policies. We encourage you to read those policies and understand how other companies use your data.
E-mailing by Rajah Blue
From time to time, we may want to contact you with information about product announcements, software updates, and special offers. We also may want to contact you with information about products and services from our business partners. We only send marketing communications to users with your prior consent. All Rajah Blue account holders will continue to receive transactional messages related to our Products, even if you unsubscribe from promotional emails.
Data storage, transfer, retention, and deletion
Data Storage and Transfers
Information submitted toRajah Blue will be transferred to, processed, and stored in Australia. When you use the Product on your computing device, user content you save will be stored locally on that device and synced with our servers. Once the data has been stored on our servers, it will no longer be stored on your computing device. To view any of these data on your device, a secure key is used to request upload from our server. Please note that your device will require an internet connection to access the data. If you post or transfer any information to or through our Site and/or Product, you are agreeing to such information, including Personal Data and user content, being hosted and accessed in Australia.
Duration of Information Storage
When you give us personal information, we take steps to make sure that it’s treated securely.
Non-sensitive details (your email address etc.) are sent normally over the Internet, and this can never be guaranteed to be 100% secure. As a result, while we strive to protect your personal information, we cannot guarantee the security of any information you transmit to us, and you do so at your own risk. Once we receive your information, we make our best effort to ensure its security on our systems.
We use industry-standard encryption to protect your data in transit. This is commonly referred to as transport layer security (“TLS”) or secure socket layer (“SSL”) technology. Once we receive your data, we protect it on our servers using a combination of technical, physical, and logical security safeguards. The security of the data stored locally in any of our Product installed on your computing device requires that you make use of the security features of your device. We recommend that you take the appropriate steps to secure all computing devices that you use in connection with our Site and Product.
The Company takes the security of your data very seriously and works to protect your data from loss, misuse and unauthorised access or disclosure.
All staff and officers who handle Relevant Data are aware of this policy and have been given training in how to correctly collect, process, store and delete data. The Company holds a log of when staff training was undertaken and updates it on an annual basis.
All access or attempts to access your personal information are automatically monitored by the Rajah Blue security systems and any Rajah Blue officer who breaches our privacy and data protection rules will have their access suspended and may face disciplinary action and/or prosecution.
All breaches will be reported to the relevant supervisory authority within 72 hours, unless the data was anonymised or encrypted or if it has a particularly high risk. Breaches of this policy by staff, contractors, officers of the Company will be dealt with under the Company’s grievance and disciplinary policy and may lead to a disciplinary sanction.
If Rajah Blue learns of a security system breach, we will attempt to notify you and provide information on protective steps, if available, through the email address that you have provided to us or by posting a notice on the Site. Depending on where you live, you may have a legal right to receive such notices in writing.
Lawful Basis for Personal Data Processing
Rajah Blue uses, processes, and stores Personal Data, as necessary to perform our contract with you, and based on our legitimate interests in order to provide the services in connection with the Product and maintaining Product’s functionality, namely:
- Log data (crash data and other diagnostic reports; cleanup logs: files path and size, system libraries versions, scan/removal duration, device information) – for identifying and fixing defects in Product’s functionality. Logs and entire reports are important to analyse user problems, application misfunctions and crashes. Data is mandatory and is frequently the main source, which helps to understand and resolve application issues.
- Device information: Operating System (OS) running on your device, Internet Protocol (IP) address, access times, browser type, and language, OS localization, CMM bundle IDs, CMM version, screen resolution, cid, battery info, RAM usage info, drive info, processor info, GPU info, disk info (type, total, free, backups), files metadata, applications preferences data, installed applications, network names and preferences, computer uptime in hours – to identify and localise user issues (bugs) and to understand and localise user problems, for the Product correct scanning and cleaning logic, actually, Product functioning.
- We are collecting your data when you are contacting our customer support team via call, email or another communication tool. The purpose of collecting is for helping you to solve any issue you have with our services. The legal basis of collecting is the fulfilment of our contractual or pre-contractual obligations to you. Additionally, we may record the calls. The purpose of call recording is quality control of our customer support services and personnel training. The legal basis of call recording is our legitimate interests in retaining you as a customer and providing you with first-class customer support services.
- We rely on your consent to process Personal Data:
- to send promotional emails,
- to place cookies on your devices and
- for in-app analytics events and actions, used by us to understand user behaviour, analyse and optimise it.
In some cases, Rajah Blue may process Personal Data pursuant to legal obligation or to protect your vital interests or those of another person.
Rajah Blue Information Collection Details
What personal information will be collected, and why is it being collected?
When you register:
We will ask you to consent to the collection of your:
- mobile phone number — so that you can be contacted if needed for contact tracing
- Emergency contact number, contact name and contact email – so that we can contact relatives/friends on your behalf if you are unable to do so yourself
- Email – so that we can contact you if your phone is not working, has been lost or become damaged and to assist you with your login should you need a new password or login identity
- name — so the relevant health officials can confirm they are speaking to the right person when performing contact tracing. This will be easiest if you provide your full name, but you can use a pseudonym or fake name if you prefer
- age range — so health officials can prioritise cases for contact tracing if needed.
If you are under 15 years of age, your parent or guardian will need to consent to the collection of your registration information and contact data.
When you use Rajah Blue:
You or your travel agent will be asked to upload your current travel itinerary – so that we can automatically upload your travel itinerary and alert you if any part of your itinerary is likely to be a threat to your health.
Your health score is calculated for the purposes of providing a risk score to add to the Rajah Blue travel score. No personal data is ever kept by Rajah Blue, without the direct consent of the user for reuse purposes, and not for any further data accumulation or use.
How will personal information be stored?
We will store all registration information and other data encrypted in the Singapore data store. It is a cloud-based facility, using infrastructure located in Singapore, which has been classified as appropriate for storage of data.
We will delete all personal data in the data store if you request this through theRajah Blue application
How will personal information be used and disclosed?
We will use or disclose your personal information to enable contact tracing by health officials. This includes:
- using your mobile number to send you an SMS to send you alerts and notifications
- using your device identity number to send you messages and alerts
Further information about privacy
the Australian Privacy Principles (APP)
- a registered APP code that binds us, and
- how we will deal with such a complaint.
- Will people’s identification, health and work details be on-sold by Rajah Blue?
- Will personal information be used for any form of research (medical, market, etc) other than to support contact tracing?
No. Once all personal information has been deleted, aggregated data, location data, infection data and other non-personal information will be made available to support research.
- Will personal data be made available to police and other law enforcement agencies?
Yes, but only if a warrant is issued for a specific record associated with an offence and only for specified records shown on a warrant. In general, the provisions of section 3E of the Crimes Act 1914 (or State/Territory equivalent) must be met.If you request, Rajah Blue will delete all of your personal information following the end of your trip and will not be able to support law enforcement requests for personal information.
- Will my information be available to the US authorities under the American Cloud Act?
Yes, while your data is stored in Australia on a Microsoft Azure platform. The Clarifying Lawful Overseas Use of Data (CLOUD) Act enables US authorities to issue a warrant to obtain data.If you request, Rajah Blue will delete all of your personal information following the end of your trip and will not be able to support law enforcement requests for personal information.
- Is my data safe from hacking?
Yes. All personal information is encrypted on our servers, in our portals, in transit and on your mobile device. Even if data is stolen from any part of our system, it will be encrypted. All Rajah Blue staff require authorisation to access any data (for example our customer service staff) and all of our systems are protected by two- factor authentication (and other security measures). This does not protect your data if you provide deliberate or accidental access to your data and/or account. The mobile application is password protected and two-factor authentication is required to access critical personal information. You should always lock your mobile device when not in use and protect passwords to prevent unauthorised access to your information.
- If I believe that information about me in Rajah Blue is incorrect, can that be corrected?
Contact to find out more about privacy within the department, or to make a privacy enquiry or complaint
Email: [email protected]
100C Pasir Panjang Road
#04-03 SLC House
Phone: +65 98378813
Email: [email protected]
We may need to update this Policy to keep pace with changes in our Sites, Products, and Services, our business, and laws applicable to us and you. We will, however, always maintain our commitment to respect your privacy. We will notify you of any material changes that impact your rights under this Policy by email (to your most recently provided email address) or post any other revisions to this Policy, along with their effective date, in an easy-to-find area of the Sites, so we recommend that you periodically check back here to stay informed of any changes. Please note that your continued use of Rajah Blue after any change means that you agree with, and consent to be bound by, the new Policy. If you disagree with any changes in this Policy and do not wish your information to be subject to it, you will need to stop using the Sites and/or Products.
Individuals located in the European Economic Area (EEA) have certain rights in respect to their personal information, including the right to access, correct, or delete Personal Data we process through your use of the Site and/or Product. Rajah Blue applies the following to any Rajah Blue user, regardless of their location.
- Have your Personal Data corrected or deleted. You may ask us to correct information you think is inaccurate or completely delete all information that we hold about you by emailing: [email protected].
- Access your Personal Data report by submitting a request at [email protected]. This report will include the Personal Data we have about you, provided to you in a structured, commonly used, and portable format.
- Object to us processing your Personal Data. It is your right to lodge an objection to the processing of your personal data by emailing: [email protected] if you feel the “ground relating to your particular situation” apply. The only reasons we will be able to
deny your request is if we can show compelling legitimate grounds for the processing, including your and our obligations under Australian law, which limit your interest, rights and freedoms, or the processing is for the establishment, exercise or defence of legal claims.
- You can ask us to stop using your Personal Data, including when we use your Personal Data to send you marketing emails. We only send marketing communications to users with your prior consent, and you may withdraw your consent at any time by clicking the “unsubscribe” link found within Rajah Blue emails and changing your contact preferences. Please note you will continue to receive transactional messages related to our Product, even if you unsubscribe from marketing emails.
- Complain to a regulator. If you think that we haven’t complied with data protection laws, you have a right to lodge a complaint with your local supervisory authority.
Data Protection Officer
To communicate with our Data Protection Officer, please email [email protected]
The Company is not established in the EU and therefore VeraSafe has been appointed as Rajah Blues representative in the EEA for data protection matters, pursuant to Article 27 of the General Data Protection Regulation of the European Union.
To make such an inquiry, please contact VeraSafe using this contact form: https://www.verasafe.com/privacy-services/contact-article-27-representative. Alternatively, VeraSafe can be contacted at:
VeraSafe Czech Republic s.r.o
Prague 1, 11002
Contact form: https://www.verasafe.com/privacy-services/contact-article-27-representative