§1. Introduction
The purpose of this iWi Corporation Privacy Policy (this “Policy”) is to establish the uniform standards for the protection and handling of Personal Data in iWi Corporation. iWi Corporation recognizes the importance of having effective personal data protections in place and is committed to compliance with applicable data privacy laws, regulations, internal policies and procedures. These protections form the foundation of a trustworthy company and are necessary to maintain the confidence of patients, healthcare professionals, business partners and Executives and Employees and ensure the company’s own compliance with such applicable laws and regulations. This Policy is based on globally accepted, basic principles on personal data protection.
This Policy applies worldwide to all Executives and Employees and companies of iWi Corporation. Data that has been anonymized in accordance with standards under applicable laws or regulations does not constitute Personal Data under this Policy.
iWi Corporation is responsible for compliance with this Policy. Where this Policy conflicts with applicable laws, regulations, industry codes and/or regional/local policies and procedures (to the extent that these exist), the most restrictive requirements shall prevail.
§2. Definitions
Executives, directors, officers, employees, temporary workers (whether full-time or part-time), and any individual hired or contracted by iWi Corporation
Any information that can directly or indirectly identify a specific individual. Examples of Personal Data include, without limitation, both directly identifiable information such as a name, identification number or unique job title, and indirectly identifiable information such as date of birth, unique mobile or wearable device identifier, telephone number, key-coded data or online identifiers (e.g. IP addresses) linked to a specific individual.
Any operation performed on Personal Data, with or without the use of automated systems, including, without limitation, collection, recording, organization, storage, adaptation, alteration, retrieval, consultation, use, evaluation, analysis, reporting, sharing, disclosure, dissemination, transmission, making available, alignment, combination, blocking, deleting, erasure or destruction.
Under various laws, Sensitive Personal Data is a specific category of Personal Data that, if lost, misused or accessed without authorization, has the potential to cause harm or embarrassment to an individual. Processing of Sensitive Personal Data requires enhanced protection measures. Categories of Sensitive Personal Data depends on applicable laws or regulations. The following is a non-exhaustive list of categories that may be considered to be Sensitive Personal Data under applicable laws or regulations: government issued ID numbers; financial data; payment card and account numbers; passwords; salary information; medical/health information; race, ethnicity and national origin; sexual orientation or activity; disability status; and religious or political beliefs; genetic or biometric data.
§4. Expectations for Handling Personal Data
Executives and Employees are expected to process and safeguard Personal Data as confidential information and to safeguard it against loss, misuse, and unauthorized access. Executives and Employees will only be permitted to access Personal Data as necessary to meet legitimate business needs within the scope of their role and assigned tasks. Executives and Employees are prohibited from using or accessing Personal Data outside of the scope of their employment at iWi Corporation, from disclosing it to unauthorized persons inside or outside the company, and from otherwise processing Personal Data in a manner inconsistent with this Policy.
Executives and Employees that process Personal Data are expected to follow applicable regional/local procedures to report suspicious activity or potential unauthorized access (such as a cyberattack or accidental is closure) related to Personal Data to the appropriate department.
iWi Corporation prohibits any form of retaliation for good faith reporting of any suspected violation of this Policy.