Privacy Policy
IMMUNISCAN® GLOBAL PRIVACY POLICY
1. INTRODUCTION & SCOPE
Immuniscan, Inc. (“Immuniscan,” “we,” “us,” or “our”) is committed to protecting privacy, data security, and lawful processing of information while providing authorization infrastructure for animal movement, access, and regulatory compliance.
This Privacy Policy explains how Immuniscan collects, uses, processes, stores, shares, and protects information when individuals or organizations use:
- Immuniscan hardware devices
- Immuniscan software platforms
- Immuniscan authorization services
- Immuniscan websites, portals, and applications
This Privacy Policy applies globally and is intended to comply with applicable data protection and privacy laws, including but not limited to GDPR, UK GDPR, U.S. privacy frameworks, and other regional regulations as detailed in jurisdiction-specific appendices.
2. IMPORTANT DEFINITIONS
- Authorization Event: A policy-based decision determining whether an animal is permitted to move or access a location.
- Device Data: Information generated by Immuniscan hardware devices.
- Operational Data: Data necessary to perform authorization, compliance, and audit functions.
- Customer: An organization or individual authorized to use Immuniscan services.
- End User: A person operating Immuniscan devices on behalf of a Customer.
- Animal Data: Data relating to animal identification and compliance status.
3. DATA CATEGORIES COLLECTED
Immuniscan collects only data necessary to perform authorization, compliance, audit, and operational integrity functions.
3.1 Animal-Related Data
- Microchip identifiers
- Electronic tag identifiers
- Species classification
- Compliance status indicators
- Authorization outcomes
Immuniscan does not collect biometric data from animals beyond identifiers required for verification.
3.2 Authorization & Event Data
- Authorization decision results
- Timestamp and date of scan
- Location metadata (when enabled)
- Device identifier
- Policy version applied
3.3 Device & Technical Data
- Device serial numbers
- Firmware versions
- Connectivity status
- Offline/online state indicators
- Error and diagnostic logs
3.4 Account & Organizational Data
- Organization name
- Account identifiers
- Authorized users
- Billing and procurement metadata
- Contractual references
3.5 Limited Personal Data
- Name
- Business contact information
- Role or title
- Authentication credentials (hashed/encrypted)
Immuniscan does not collect consumer behavioral tracking data and does not engage in targeted advertising practices.
4. PURPOSES OF DATA PROCESSING
Immuniscan processes data strictly for legitimate, defined purposes, including:
- Performing authorization decisions
- Enforcing compliance rules
- Supporting offline authorization workflows
- Maintaining audit logs
- Supporting regulatory reporting
- Ensuring system integrity and security
- Fulfilling contractual obligations
- Supporting customer operations and support
Immuniscan does not process data for unrelated commercial purposes.
5. LEGAL BASES FOR PROCESSING
Depending on jurisdiction, Immuniscan relies on one or more of the following lawful bases:
- Contractual necessity
- Legal obligation
- Legitimate operational interest
- Public interest and regulatory enforcement
- Explicit consent where required
Where consent is required by law, it is obtained in a clear and documented manner.
6. AUTHORIZATION VS. DATA STORAGE
Immuniscan is an authorization platform, not a registry or record-keeping system of origin.
- Authorization decisions are event-based.
- Data retention is limited to operational and regulatory necessity.
- Immuniscan does not independently certify animals or issue legal determinations.
Final acceptance or denial remains with the enforcing authority or organization.
7. OFFLINE OPERATION & SYNCHRONIZATION
Immuniscan devices may operate offline. During offline operation:
- Authorization logic executes locally
- Authorization events are securely stored on-device
- Data is encrypted at rest
- Synchronization occurs when connectivity is restored
Offline operation does not bypass security, audit, or compliance requirements.
8. DATA SHARING & DISCLOSURE
Immuniscan does not sell data.
Data may be shared only with:
- Authorized Customer personnel
- Regulatory or enforcement authorities when required by law
- Service providers under strict contractual controls
- Legal authorities pursuant to valid legal process
All disclosures are limited to what is legally required or contractually authorized.
9. INTERNATIONAL DATA TRANSFERS
Immuniscan operates globally. Data may be processed or stored in multiple jurisdictions depending on deployment.
Where international transfers occur, Immuniscan implements appropriate safeguards, including:
- Standard contractual clauses
- Equivalent legal protections
- Encryption and access controls
- Jurisdiction-specific data residency options (where available)
10. DATA RETENTION
Immuniscan retains data only as long as necessary for:
- Authorization integrity
- Audit and compliance
- Legal obligations
- Contractual requirements
Retention periods may vary by jurisdiction, agreement, and regulatory environment.
11. DATA SECURITY MEASURES
Immuniscan employs industry-standard and enterprise-grade security measures, including:
- Encryption in transit and at rest
- Device-bound security keys
- Role-based access control
- Least-privilege access policies
- Secure firmware and update mechanisms
- Continuous monitoring and logging
Security controls are designed for regulated and enforcement environments.
12. DATA SUBJECT RIGHTS
Subject to applicable law, individuals may have rights to:
- Access personal data
- Correct inaccurate data
- Request deletion where permitted
- Restrict processing
- Object to processing
- Request data portability
Requests may be submitted through designated contact channels and are handled in accordance with applicable law.
13. CHILDREN’S DATA
Immuniscan does not knowingly collect personal data from children. Immuniscan services are intended for professional and organizational use.
14. COOKIES & WEBSITE DATA
Immuniscan websites may use minimal technical cookies necessary for:
- Security
- Authentication
- Session management
Immuniscan does not use behavioral advertising cookies.
15. CHANGES TO THIS POLICY
This Privacy Policy may be updated periodically. Material changes will be communicated through appropriate channels.
16. CONTACT INFORMATION
For privacy-related inquiries, contact:
privacy@immuniscan.com
or via official organizational channels.
17. JURISDICTIONAL APPENDICES
Jurisdiction-specific provisions are incorporated by reference and apply as applicable.
