Privacy Policy

At InstaBlood we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use InstaBlood application.

1. Information We Collect

Personal Information: We may collect personal information, such as your name, email address, and phone number, when you register an account or voluntarily provide it to us through the App.

Health Information: To facilitate blood donation, the App may collect health-related information, such as your blood type, last blood donation date with your explicit consent.

Device Information: We may automatically collect certain information about your device, including its model, operating system, the current location, and unique device identifier when you use the App.

Usage Data: The App may collect information about how you use it, such as the features you access, the pages you visit, and the actions you take while using the App.

2. How We Use Your Information

Blood Donation Facilitation: We use the information you provide to facilitate blood donation activities and connect you with potential recipients or blood banks.

Communication: We may use your contact information to send you important updates, announcements, or information related to your blood donation activities and account.

Improvement and Personalization: The data collected allows us to improve the App’s functionality, personalize your user experience, and enhance our services.

3. Data Sharing and Disclosure

Service Providers: We may share your information with trusted third-party service providers who assist us in delivering our services, such as cloud hosting providers, data analytics companies, and customer support platforms. These service providers are contractually obligated to maintain the confidentiality and security of your data and are prohibited from using your information for any purpose other than providing services to us.

Legal Requirements: We may disclose your information if required by law, court order, or government regulation, or if we believe that such disclosure is necessary to comply with a legal obligation, protect our rights or property, or ensure the safety of our users or others.

4. Data Security

We employ industry-standard security measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction. These measures include encryption, access controls, regular security assessments, and staff training on data protection best practices. However, please be aware that no method of transmission over the internet or electronic storage is entirely secure, and we cannot guarantee absolute security.

Access Control:
  • Implementing role-based access control (RBAC) to restrict access to sensitive systems and data based on users' roles and responsibilities.
  • Enforcing strong authentication methods such as multi-factor authentication (MFA) to verify users' identities before granting access.
  • Monitoring and auditing user activities to detect and respond to unauthorized access attempts or suspicious behavior.
Encryption:
  • Encrypting sensitive data at rest and in transit using strong encryption algorithms to prevent unauthorized access or interception.
  • Implementing end-to-end encryption for communication channels and storage systems to ensure data confidentiality and integrity.
Network Security:
  • Deploying firewalls, intrusion detection/prevention systems (IDS/IPS), and network segmentation to protect against unauthorized access, malware, and network-based attacks.
  • Conducting regular vulnerability assessments and penetration testing to identify and remediate security weaknesses in network infrastructure and applications.
Endpoint Security:
  • Installing and updating anti-malware software, endpoint protection platforms (EPP), and host-based intrusion detection systems (HIDS) to defend against malware, ransomware, and other threats.
  • Enforcing device encryption, endpoint management policies, and secure configuration standards to protect endpoints such as desktops, laptops, and mobile devices.
Security Awareness Training:
  • Providing ongoing cybersecurity awareness training and education for employees to promote good security practices and behavior.
  • Conducting simulated phishing exercises to test employees' awareness and responsiveness to phishing attacks and social engineering tactics.
Incident Response and Management:
  • Developing incident response plans and procedures to effectively detect, contain, and mitigate security incidents and data breaches.
  • Establishing a dedicated incident response team and coordinating with internal stakeholders and external partners (e.g., law enforcement, regulatory agencies) to manage security incidents and minimize impact.
Security Policy and Governance:
  • Developing and enforcing security policies, standards, and guidelines that outline organizational security requirements, responsibilities, and acceptable use of IT resources.
  • Establishing governance structures and compliance frameworks (e.g., ISO 27001, NIST Cybersecurity Framework) to manage risks, ensure regulatory compliance, and continuously improve security posture.

5. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy and as required by applicable laws and regulations. The specific retention period for different types of data may vary depending on the purpose for which it was collected and the legal requirements applicable to us. Once your data is no longer needed for the purposes stated herein, we will securely delete or anonymize it in accordance with our data retention policies and procedures.

6. Your Choices

You can review and update your personal information within the App’s settings. If you wish to delete your account or any specific data, please contact us at support@instablood.org.

7. Withdrawal, Access and Correction of Your Personal Data

7.1 Should you wish to withdraw from Instablood Platform, please follow the instructions below:
  • Navigate to the Profile section in the Instablood mobile app.
  • Click on the Delete Account button.
  • Your account and all data will be removed from our Instablood platform and you will receive a confirmation email upon successful removal.

If you faced any issues, please contact our Support at info@instablood.org.

7.2 Please note that if your Personal Data has been provided to us by a third party, you should contact such party directly to make any queries, feedback, and access and correction requests to Instablood on your behalf.
7.3 Please note that if you withdraw your consent to any or all use of your Personal Data, depending on the nature of your request, Instablood may not be in a position to continue to provide its services to you or administer any contractual relationship in place.

8. Children’s Privacy

The App is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18 years of age.

9. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted within the App, and the revised date at the top of this policy will be updated accordingly.

10. Contact Us

If you have any questions, concerns, or suggestions regarding our Privacy Policy, please contact us at support@instablood.org.

Download InstaBlood: Donate Blood, Inspire Hope.

Our mission is to connect blood donors and recipients, saving lives through one donation at a time.

Image