Biocorp Production (the « Company ») has developed the Biocorp ALiBiDM SDK (the “SDK”), a software development kit designed to be embedded by an integrator (the “Integrator”) into a third-party mobile application (the “Application”), used by end users (the “Users”). The SDK communicates with the Application and Biocorp smart cap device (the “Device”). The Company takes privacy and the protection of personal data very seriously. The Company ensures the confidentiality and security of your personal data and complies with the applicable regulations, namely:

  • The French Data Protection Act n° 7817 of 6th January 1978;
  • EU Regulation 2016/679 on the protection of natural persons with regard to the processing of personal data, and on the free movement of such data, of 27th April 2016, referred to as the GDPR.

Through the SDK, the Company processes certain personal information. This Privacy Policy informs Users and Integrators about how the Company protects the personal data it collects through the use of the SDK and the Company’s commitments to ensuring that such data is respected.

 

What constitutes personal data?

Personal data is any information that identifies, relates to, describes, directly or indirectly, to an individual.

 

Which data will be collected?

Categories of information collected about Users by our SDK

  • A unique and non-incremental number, which uniquely identify an SDK instance (each installation of the Application);
  • Data about the paired Device (serial number, firmware and hardware versions, battery level, error code in case of malfunction) and the Application (version of the Application);
  • Data concerning the smartphone on which the Application is installed (OS version, model, fabricant, time zone);
  • Technical data regarding the use and operation of the Device (priming detection, button actuation duration (start and end date and time), signal duration, number of increments);
  • Usage logs about the use of the Application (generation of reports, pen management) and the pairing with the Device.

 

Why do we collect your personal data and what is the legal basis for this processing?

The data processing is based on Biocorp’s legitimate interest, as defined in Article 6 of the GDPR. This legitimate interest lies in providing patients with medical devices, associated with the SDK, that meet their medical needs. To do so, it is in the interest of Biocorp to collect your usage and technical data for the purpose of analysis, malfunction anticipation and continuous improvement of its products (including connectable medical devices, mobile applications and the SDK itself).


Where are your personal data kept and how long for?

The collected data will be stored on a server under strict conditions of security and confidentiality to ensure the storage of the personal data. Access to this server is restricted to Biocorp.
The data are collected for a maximum period of twelve (12) months, based on the legal basis of the Company’s legitimate interest, in order to fulfill the purposes for which consent was obtained, and the legitimate interest was established.


Who has access to your personal data?

The Company undertakes to comply with current regulations on the protection of collected personal data and ensures that your personal data, whether directly or indirectly identifiable, is only accessible to authorised persons, including the following persons:

  • The Data Protection Officer (DPO) designated by the Company in the event that you contact him (see “How can you exercise your rights” for details of how to contact the DPO), and the Company itself if necessary for the management of right by the DPO;
  • The Company in exercising certain of your rights;
  • The Company and its staff whose participation is necessary to process the data.
    Please note that the Company does not control the information directly collected by the Integrator through the User’s use of the Application that incorporates the SDK. The Company advises Users to consult the Application’s Privacy Policy to learn about how the Integrator handles personal data.

 

Your rights over your personal data.

  • You have several rights regarding the processing of your personal data. These rights include the following:
  • Access: you have the right to request access to your personal data;
  • Correction: you have the right to request the correction of incomplete or inaccurate personal data that we hold about you;
  • Deletion: in certain circumstances, you have the right to ask us to delete or erase your personal data. There are, however, exceptions where we may refuse a request for deletion, such as where said personal data is necessary regarding compliance with French law or if it is relevant to claims;
  • Restriction: you have the right to ask us to suspend the processing of certain personal data about you, in particular if you wish us to establish their accuracy;
  • Objection: you have the right to challenge the fact that we process personal data on the grounds of legitimate interest (or the interest of third parties). However, we may be authorised to continue to process your personal data on the basis of our compelling legitimate interests or where it is justified by legal claims;
  • Use of your personal data after your death: you have the right to determine how your personal data will be used after your death.
    You also have the right to file a complaint with a personal data protection supervisory authority: in France, the Commission Nationale de l’Informatique et des Libertés (CNIL).
 

 

How can you exercise your rights?

 If you have any questions regarding the processing of your personal data or if you wish to exercise any of the rights mentioned above, please contact the Company: the Data Protection Officer (DPO) whose contact details are privacy@biocorp.fr or Biocorp Production, DPO, Service Juridique, La Béchade ZI de Lavaur, 63500 Issoire, France.

In order to verify your identity, Biocorp requires that you provide the SDK instance number available within your Application, as well as the serial number of your device. In case of reasonable doubt, Biocorp may request additional information to confirm your identity beyond a reasonable doubt.

Any future changes to the Privacy Policy will be posted on the Company’s website at https://biocorpsys.com/en/privacy-policy-sdk/. The Company advises each User or Integrator to refer frequently to review any changes or updates to this Privacy Policy.