Biocorp Production (the « Company ») has developed and is the publisher of the Biocorp’s Application for Pen (the “BAP Application”) and takes privacy and the protection of personal data very seriously. The Company ensures the confidentiality and security of your personal data and complies with the applicable regulations, namely:
- The French Data Protection Act n° 7817 of 6th January 1978;
- EU Regulation 2016/679 on the protection of natural persons with regard to the processing of personal data, and on the free movement of such data, of 27th April 2016, referred to as the GDPR.
The purpose of this Privacy Policy is to inform Users of the BAP Application as well as possible of the way in which the Company protects the personal data it collects in the context of the use of the BAP Application and of the commitments made by the Company to ensure that Users’ personal data is respected.
By continuing to use the BAP Application, the User acknowledges that they have read the terms of this Privacy Policy.
The processing of personal data carried out by the Company through the BAP Application is based on the consent of the Users, which the User can give or withdraw at any time from the BAP Application. Therefore:
1. If you have not consented to the Company’s collection of your data:
In this case, no data is transmitted to the Company, as all data is only stored locally by the BAP Application.
Therefore, in accordance with the recommendations of the French Commission Nationale de l’Informatique et des Libertés (CNIL) concerning mobile applications, this data is not subject to the GDPR.
The User understands that certain technical usage information of the BAP Application, related to crashes, may be transmitted anonymously to the Company by Crashlytics. This information is used to track, prioritise, and fix stability issues that erode the BAP Application quality in order to enable technical monitoring and correction of any errors/bugs in the BAP Application.
2. If you have consented to the Company’s collection of data:
- What constitutes personal data?
Personal data is any information relating to yourself that can be used to identify or re-identify you, directly or indirectly.
- Which data will be collected?
The following data will be collected during your use of the BAP Application associated with a connected device of the Company (the “Device”) are as follows:
- Your email address;
- Data about the paired Device(s) (serial number, firmware and hardware versions, battery level, error code in case of malfunction);
- Data about the recorded injections (date and time, status between priming or injected dose, chosen pen and ratio);
- Data concerning the smartphone on which the BAP Application is installed (OS version, model, language) and the activation code (or “token”);
- Usage logs about the pairing with the Device, the pen management, the recording of an injection and the generation of reports.
If you participate in a study, you must consult the documentation relating to your participation, as it is for this reason that you use the BAP Application.
When the BAP Application is used collaboratively by several people successively on the same instance of the BAP Application or when the registered email address is said to be “generic”, the data collected is not linked to a specific user (i.e. several employees can operate the same instance of the BAP Application or the same email address), and the data is not individually traceable. As a result, the Company may consider that these data do not qualify as personal data.
Certain technical usage information of the BAP Application, related to crashes, may be transmitted anonymously to the Company by Crashlytics. This information is used to track, prioritise, and fix stability issues that erode the BAP Application quality in order to enable technical monitoring and correction of any errors/bugs in the BAP Application.
- Why do we collect your personal data and what is the legal basis for this processing?
On the legal basis of your consent, the Company collects your personal data for research and development purposes, tests, studies, demonstrations, calls for tenders to mobile application publishers or for any other purpose that would lead to the improvement of its products (connected devices, mobile applications, SDKs, etc.).
- Where are your personal data kept and how long for?
The data is stored on a secure server, located in the European Union, in France. It is stored for a maximum period of twelve (12) months so that the Company can process it in accordance with the determined purpose.
- Who has access to your personal data?
The Company undertakes to comply with the regulations in force regarding the protection of personal data collected and undertakes to ensure that your personal data is only accessible to authorised persons, including the following persons:
- Company personnel whose participation is necessary for data processing, including in the context of a study;
- The people in charge of analyzing the data collected;
- The Data Protection Officer (DPO) appointed by the Company;
- The Company in exercising certain of your rights.
In this context, you undertake to take all necessary precautions, in particular in terms of security of access to your equipment, so that said data is not made accessible to unauthorised third parties. The Company shall not be liable for such third party’s access to the data entered into the BAP Application in the event of negligence.
- Your rights over your personal data
You have several rights regarding the processing of your personal data. These rights include the following:
- Access: you have the right to request access to your personal data;
- Correction: you have the right to request the correction of incomplete or inaccurate personal data that we hold about you;
- Deletion: in certain circumstances, you have the right to ask us to delete or erase your personal data. There are, however, exceptions where we may refuse a request for deletion, such as where said personal data is necessary regarding compliance with French law or if it is relevant to claims;
- Restriction: you have the right to ask us to suspend the processing of certain personal data about you, in particular if you wish us to establish their accuracy;
- Withdrawal: you have the right to withdraw your consent at any time directly from the settings of the BAP Application;
- Use of your personal data after your death: you have the right to determine how your personal data will be used after your death.
You also have the right to file a complaint with a personal data protection supervisory authority: in France, the Commission Nationale de l’Informatique et des Libertés (CNIL).
- How can you exercise your rights?
If you have any questions regarding the processing of your personal data or if you wish to exercise any of the rights mentioned above, please contact the Company: the Data Protection Officer (DPO) whose contact details are privacy@biocorp.fr or Biocorp Production, DPO, Legal Department, La Béchade ZI La Lavaur, 63500 Issoire, France. You can withdraw your consent at any time directly from the BAP Application.
In order to verify your identity in exercising your data protection rights, you may be asked to provide information that will allow the controller to confirm your identity beyond a reasonable doubt.
The Company reserves the right to change the Privacy Policy at any time. You will be notified of this update within the App with a way to access the new version, which can be accessed at https://biocorpsys.com/en/privacy-policy-bap/