Jurisdiction-Specific Appendices
(Applies in addition to the Global Privacy Policy and Terms of Service)
APPENDIX A — UNITED STATES
A.1 Applicable Frameworks
Immuniscan operates within the United States in accordance with applicable federal, state, and local laws, including but not limited to:
- State privacy statutes (e.g., California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA))
- Sector-specific animal health, transport, and biosecurity regulations
- Contractual obligations with federal, state, and municipal agencies
A.2 U.S. Data Subject Rights
Where applicable, U.S. residents may have rights to:
- Request disclosure of categories of personal data collected
- Request correction of inaccurate personal data
- Request deletion of personal data, subject to legal exceptions
- Opt out of certain data disclosures where applicable
Immuniscan does not sell personal data as defined under applicable U.S. privacy laws.
A.3 Law Enforcement & Regulatory Disclosure
Immuniscan may disclose data to U.S. governmental authorities, including animal health, border, customs, or public health agencies, when required by law or pursuant to valid legal process.
APPENDIX B — EUROPEAN UNION (GDPR)
B.1 GDPR Applicability
For users located in the European Economic Area (EEA), Immuniscan acts as:
- A Data Processor when processing data on behalf of Customers
- A Data Controller for limited operational and account-related data
B.2 Lawful Bases Under GDPR
Processing is conducted pursuant to Article 6 of the GDPR, including:
- Performance of a contract
- Compliance with legal obligations
- Legitimate interests related to biosecurity, compliance, and enforcement
- Public interest where applicable
B.3 Data Subject Rights (EEA)
EEA data subjects may exercise rights to:
- Access
- Rectification
- Erasure (right to be forgotten)
- Restriction of processing
- Data portability
- Objection to processing
Requests are handled in accordance with GDPR timelines and requirements.
B.4 International Transfers
Where data is transferred outside the EEA, Immuniscan relies on:
- Standard Contractual Clauses (SCCs)
- Equivalent safeguards recognized under GDPR
APPENDIX C — UNITED KINGDOM (UK GDPR)
C.1 UK GDPR Alignment
For UK-based users, Immuniscan processes data in accordance with the UK GDPR and the Data Protection Act 2018.
C.2 UK Data Rights
UK residents retain rights equivalent to those under the GDPR, including rights to access, correction, deletion, and objection.
C.3 Supervisory Authority
Complaints may be raised with the UK Information Commissioner’s Office (ICO), without prejudice to other legal remedies.
APPENDIX D — CANADA
D.1 PIPEDA Compliance
Immuniscan processes personal information in accordance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.
D.2 Purpose Limitation
Personal information is collected solely for purposes related to authorization, compliance, and operational integrity.
D.3 Access & Correction
Individuals may request access to or correction of personal information, subject to legal limitations.
APPENDIX E — AUSTRALIA
E.1 Australian Privacy Principles (APPs)
Immuniscan complies with the Australian Privacy Act 1988 and the Australian Privacy Principles.
E.2 Cross-Border Disclosure
Where personal information is disclosed outside Australia, Immuniscan takes reasonable steps to ensure recipients comply with equivalent privacy protections.
APPENDIX F — ASIA-PACIFIC (GENERAL)
F.1 Regional Applicability
Immuniscan’s operations across the Asia-Pacific region are governed by applicable national data protection and privacy laws, including but not limited to:
- Singapore Personal Data Protection Act (PDPA)
- Japan Act on the Protection of Personal Information (APPI)
- South Korea Personal Information Protection Act (PIPA)
F.2 Regulatory Cooperation
Immuniscan cooperates with lawful requests from competent authorities related to animal health, border control, and public safety, consistent with applicable law.
APPENDIX G — DATA RESIDENCY & GOVERNMENT DEPLOYMENTS
G.1 Data Localization
Certain government or enterprise deployments may require data residency within a specific jurisdiction. Immuniscan supports jurisdiction-specific hosting and processing options where contractually agreed.
G.2 Sovereign & Restricted Deployments
For sovereign, defense, or high-security environments, Immuniscan may offer:
- Isolated deployments
- Restricted access controls
- Enhanced audit and logging requirements
APPENDIX H — CONFLICTS & PRECEDENCE
In the event of a conflict between:
- The Global Privacy Policy
- These Jurisdiction-Specific Appendices
- A Customer-specific agreement or order form
The following order of precedence applies:
- Customer-specific agreement
- Jurisdiction-Specific Appendix
- Global Privacy Policy
- Terms of Service
APPENDIX I — CONTACT & REGULATORY INQUIRIES
Jurisdiction-specific privacy or legal inquiries may be directed to:
