EVDS Privacy Notice

Mezzanine Helium Platform for EVDS Back Office

evds.mezzanineware.com

Audience: All EVDS Mezzanine Helium Platform System Users

Users and Roles: These are pre-authorised admin users (who apply through the NDoH SOP002 Application process) that have access to the Helium Platform to view reports, provide support to vaccinees, bulk upload vaccinees and manage facility and booking schedules. This platform is not accessible to the general public and can only be accessed with a valid username and password (as part of the SOP002 application process).

Data Controller

The South African National Department of Health is the controller of the personal data that you (the data subject) provide us. Once you consent to the collection of your personal data through the use of this product ("product") we collect the below-listed types of personal data from you the data subject, in order to fulfil the obligations of your system usage for legitimate business purposes

The use and storage of your data are processed in accordance with this privacy notice.

Data Processing

Purpose of Processing

The NDoH collects this data in order to have a clear audit record of who has access to evds.mezzanineware.com

Legal Basis for Processing

The legal basis for the processing of the personal data of the data subject is:

  • (a) the data subject has given consent (through application SOP002) to the processing of his or her personal data for one or more specific purposes;
  • (b) processing is necessary for the performance of a job role to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

Voluntary or Mandatory Provision of Personal Data

The personal data listed in section "Provision of Personal Data" is mandatory for the fulfilment of the product or service (job role) to which the data subject has or is applying.

Provision of Personal Data 

Once you consent (or due to the legal basis listed above) to the collection of your personal data through the use of this product we collect the below-listed types of personal data from you the data subject.

Where special categories of data are collected the data subject consents to the collection of such information through accepting the privacy notice.

Special category data includes personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation.

  • First name, last name/surname, maiden name
  • Email address
  • Phone number
  • Login username
  • Password
  • National ID number
  • Employer/Organisation 
  • Location data (For specific roles we require: Province, District, Sub-district)

Consequences of failure to provide information

Disqualification from access to the product/service

Data Transfer

Personal Data Recipients

The personal data of the data subject processed by the controller shall not be transferred to any third parties.

Personal Data Storage

The personal data will be stored for as long as the Mezzanine Helium Platform for EVDS Back Office is live and maintained by the NDoH. When a web user's access is removed, their data is still stored in an archived state. 

Automated Decision-Making

The processing activities do not include automated decision-making.

Source of Personal Data

The personal information of the data subject was lawfully obtained from the below-listed sources.

  • First name, last name/surname, maiden name, Mezzanine Access SOP #002
  • Email address, Mezzanine Access SOP #002
  • Phone number, Mezzanine Access SOP #002
  • Login username, Mezzanine Access SOP #002
  • Password, Data Subject
  • National ID number, Mezzanine Access SOP #002
  • Employer/Organisation , Mezzanine Access SOP #002
  • Location data (For specific roles we require: Province, District, Sub-district), Mezzanine Access SOP #002

Data Subject Responsibility

The data subject confirms that they have read and completed the Mezzanine Access Control Form: Mezzanine Access SOP #002:

The completion of the form (Mezzanine Access SOP #002) is required to gain access to the Mezzanine Platform for Reporting and Administration purposes. Where the applicant has access to personal information (PI), a data sharing agreement is required between your organization and NDoH. Failure to prove proof of employment, falsifying information or failure to adhere to the data sharing agreement could result in revoking of Access. All access control is logged, and mis-use of the system could lead to prosecution.

Data Subject Rights

Data subjects have the below-listed rights with regards to the personal data of the data subject.

  • Right of access to information regarding the purposes of the processing, the categories of personal data concerned, the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organizations, where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period
  • Right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing
  • Right to lodge a complaint with a supervisory authority
  • Right to any available information as to their source where the personal data are not collected from the data subject
  • Right to be informed of the existence of automated decision-making, including profiling, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
  • Right to be informed of the appropriate safeguards where personal data are transferred to a third country or to an international organization
  • Right to be provided with a copy of the personal data undergoing processing
  • Right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal
  • Right to object to processing of personal information
  • Right to be informed that and what personal information has been collected when not collected from the data subject
  • Right to be informed that and what personal information has been accessed or acquired by an unauthorized person as well as security compromises

Data Subject Complaints

In the event that you wish to complain about how we have handled your personal data, please contact Data Protection Officer at data-protection-officer@mezzanineware.com or in writing at Suite 173, Private Bag x14, Die Boord, 7613. Our Data Protection Officer will then look into your complaint and work with you to resolve the matter.

If you still feel that your personal data has not been handled appropriately according to the law you can contact the Information Regulator: South Africa (POPIA) or the relevant Supervisory Authority (GDPR) of your region.