Privacy Policy
« EkiYou »
TABLE OF CONTENTS :
- Identity and contact details of the controller
- Data Protection Officer (DPO)
- Data processing and purposes
- Social Networks
- Data recipients
- Storage and transfer of data outside the European Union
- Security of personal data
- Use of data for statistical purposes and in the context of clinical studies
- Your rights
The company DIAPPYMED (hereinafter “the Controller”) wishes by this Privacy Policy, to inform users of the application (hereinafter “Users”) of the processing of personal data collected via the application EkiYou (hereinafter “the Application”).
The collection of personal data is carried out in compliance with the provisions of REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (GDPR).
The User is hereby informed that the personal data indicated as mandatory on the forms and collected as part of the service described herein are necessary for the use of the EkiYou application.
- Identity and contact details of the data controller
The processing of Users’ personal data is carried out under the responsibility of the following controller :
DIAPPYMED
Cap Alpha,
3 avenue de l’Europe,
34830, Clapiers
represented by Mr. Omar DIOURI.
- Data Protection Officer (DPO)
Our Data Protection Officer has been registered with the data protection authorities in an EU member state. If you have any questions or requests regarding this privacy statement or for the data protection officer, you can contact the DPO via the following email address : dpo@diappymed.com
- Data processing and purposes
Management of the User’s account and authentication on the application
Sub-purposes:
- Creation and modification of the account on the Application by the User;
- Authentication of the User on the Application
Personal data of the User that are collected:
- Identification and contact data of the User (name, first name, birth date, e-mail, phone number, username, identification number for the User in the Controller’s systems, sex, country, optional postcode);
- Data related to the User’s identifiers (such as login, password, IP address)
|
Data Controller |
Legal Basis |
Retention period |
Recipient |
Data Transfer |
|
Diappymed |
Art. 6§1.b. – Necessary for the performance of a contract or precontract |
Erasure 30 days from the deletion of the account.
Retention of technical logs and authentication history logs for 1 year from their collection. |
The data controller and any authority legally authorized to access the data |
Google Cloud Platform (GCP) (see Section 6 of this Privacy Policy) |
Management of the access
Sub-purposes:
- Enable the User to access the App: taking out a subscription, making an in-app purchase where applicable, generating an access code at the request of the User or a healthcare professional, and activating access based on a prescription (prescription provided by the User or by a healthcare professional);
- Receive and administratively process the prescription required to activate access (verification of the required elements, activation traceability);
- Collect, record and use access-related information (creation, activation, renewal, suspension) and maintain the access history;
- Check and manage access status related to purchases/subscriptions made via the app stores (e.g., confirmation of activation/renewal), without processing payment data;
- Handle requests, complaints and disputes (including the prevention and handling of fraud/abuse where applicable);
- Record and manage information relating to healthcare professionals identified on the received prescription and/or who submitted the prescription to the Controller, in order to administratively process the prescription and activate access to the App.
Personal data of the User that are collected:
- Identification and contact data (last name, first name, date of birth, sex, email, phone number, internal user ID in our systems);
- Authentication and technical data (login, password, IP address);
- Access-related data (access type: subscription / in-app purchase / code / prescription, access status, activation/renewal/suspension dates, access history);
- App store purchase/subscription data, without payment data (e.g., transaction identifiers/tokens or technical receipts provided by the stores to verify activation/renewal);
- Prescription data (information required for activation, including any health data contained in the prescription);
- National Social Security number (where applicable, when required for prescription-based access).
Personal data of the healthcare provider that are collected (only for the 6th purpose):
- Identification and contact data of the healthcare provider (name, first name, e-mail, phone number) ;
- RPPS / finess number
|
Data Controller |
Legal Basis |
Retention period |
Recipient |
Data Transfer |
|
Diappymed |
Art. 6§1.b. – Necessary for the performance of a contract or precontract |
Archiving accounting supporting documents: 10 years from the end of the financial year.
Technical access management: deletion 30 days after account deletion. |
The data controller and any authority legally authorized to access the data |
Google Cloud Platform (GCP) (see Section 6 of this Privacy Policy) |
Management of the requests via the dedicated form on the Application
Sub-purposes:
- The answer to requests from the User regarding the services offered by the Controller via the dedicated form on the Application;
- Maintain and manage the correspondence and, where applicable, handle complaints and disputes;
- Receive, record, assess and handle reports submitted via the contact form (product complaints, malfunctions, incidents, adverse events, risks, quality issues) as part of Post-Market Surveillance (PMS) and vigilance activities;
Personal data of the User that are collected:
- Identification and contact data of the User (last name, first name, date of birth, email, optional phone number, username, identification number for the User in the Controller’s systems, sex, country, optional postcode);
- Data related to the User’s identifiers (such as login, password, IP address)
|
Data Controller |
Legal Basis |
Retention period |
Recipient |
Data Transfer |
|
Diappymed |
Art. 6§1.c. – Necessary for compliance with a legal obligation |
5 years starting from the request or solicitation |
The data controller and any authority legally authorized to access the data |
Google Cloud Platform (GCP) (see Section 6 of this Privacy Policy) |
Management of the exercise of data subjects’ rights
Sub-purposes:
- The management of the exercise of data subjects’ rights and the answer to data subject via e-mail or by post
- The management of disputes
Personal data of the User that are collected:
- Identification and contact data of the User (last name, first name, date of birth, email, optional phone number, username, identification number for the User in the Controller’s systems, sex, country, optional postcode, proof of identity where applicable);
- Data related to the User’s identifiers (such as login, password, IP address)
|
Data Controller |
Legal Basis |
Retention period |
Recipient |
Data Transfer |
|
Diappymed |
Art. 6§1.c. – Necessary for compliance with a legal obligation |
5 years starting from the exercise of the data subject’s right |
The data controller and any authority legally authorized to access the data |
Google Cloud Platform (GCP) (see Section 6 of this Privacy Policy) |
Management of opinion polls, studies and customer satisfaction surveys
Sub-purposes:
- The improvement of the Application by inviting Users to participate in opinions, studies and customer satisfaction surveys
- The justification of the interests the Application represents for the medical follow-up of diabetes of Users when asked by the appropriate authorities
Personal data of the User that are collected:
- Identification and contact data of the User (last name, first name, date of birth, email, optional phone number, username, identification number for the User in the Controller’s systems, sex, country, optional postcode);
- Data related to the User’s identifiers (such as login, password, IP address)
|
Data Controller |
Legal Basis |
Retention period |
Recipient |
Data Transfer |
|
Diappymed |
Art. 6§1.f – Legitimate interest of the Controller |
5 years starting from the opinion poll, study of customer satisfaction study |
The data controller and any authority legally authorized to access the data |
Google Cloud Platform (GCP) (see Section 6 of this Privacy Policy) |
Management the follow-up of diabetes
Sub-purposes:
- Account setup and personalization: allow the User to enter and update information and settings relating to personal characteristics and health.
- Logbook and history: allow the User to record, view and retrieve the history of their data (logbook).
- Reminders and treatment tracking: allow the User to set reminders (e.g., basal insulin time) and record injections and/or blood glucose measurements.
- Dose recommendations (meal bolus and correction): enable the User to obtain insulin dose recommendations for a meal and/or a correction, calculated from the data and settings provided (e.g., carbohydrates, glucose value, physical activity, physiological ratios ICR and CF, insulin on board/active insulin where applicable).
- Optional – Parameter adjustment recommendations (if the feature is offered): enable the User, if they activate this option, to receive recommendations to adjust basal dose and/or ICR and CF settings, based on the history and data recorded.
- Access to informational content: allow the User to access educational content about diabetes (nutrition, physical activity, mental health, travel, testimonials, etc.).
- Food data search: allow the User to search for foods and related data within the App.
- Algorithm operation: enable the App’s algorithms to run based on the User’s consent, where required.
- Third-party technical services: integrate technical services operated by processors acting on behalf of the Controller (e.g., hosting, authentication, notifications).
Personal data of the User that are collected:
- Identification and contact data of the User (last name, first name, date of birth, email, optional phone number, username, identification number for the User in the Controller’s systems, sex, country, optional postcode);
- Data related to the User’s identifiers (such as login, password, IP address)
- Personal characteristics (sex, gender, height and weight of the User, physical activity, eating habits);
- Health data (such as diabetes type, injection system, bolus and rapid insulin pen, basal and lente insulin pen, pump and rapid insulin, carbohydrate ratio and correction factors, total basal daily dose, total bolus daily dose, time of lente insulin injection, injection data, blood glucose data);
|
Data Controller |
Legal Basis |
Retention period |
Recipient |
Data Transfer |
|
Diappymed |
Art. 6§1.a – Consent of the data subject
and Art. 6§1.f – Legitimate interest of the Controller regarding sub-purpose no. 8 |
Erasure 30 days from the deletion of the account |
The data controller and any authority legally authorized to access the data |
Google Cloud Platform (GCP) (see Section 6 of this Privacy Policy) |
Post-market surveillance
Sub-purposes:
- Ensuring the safety and performance of the medical device, with the surveillance of the performances of the Application, the detection and correction of the technical anomalies and the compliance upgrade with the applicable law;
- Managing complaints, claims and reports (quality, safety, cybersecurity, malfunctions), including assessment, traceability, corrective/preventive actions and follow-up;
- Vigilance: detecting, assessing and handling potential incidents and adverse events and, where applicable, making the required notifications/communications to competent authorities and relevant bodies in accordance with regulations;
- Providing application support for Users, with technical support and a resolution of problems linked to the Application, the answers to requests from the Users and the improvement of the User’s experience;
- Measuring the usage of the Controller’s products, with an analysis of the uses and a follow-up of the habits in order to optimize the functionalities and the identification of the User’s needs;
- The improvement of the medical devices products, including the collection of Users’ feedback, the integration of new medical and technological requirements, and the continuous optimization of functionalities and reliability;
- The management of complaints and vigilance issues
- The supply by third parties of technical functions on behalf of the Controller
Personal data of the User that are collected:
- Identification and contact data of the User (last name, first name, date of birth, email, optional phone number, username, identification number for the User in the Controller’s systems, sex, country, optional postcode);
- Data related to the User’s identifiers (such as login, password, IP address)
- Personal characteristics (sex, gender, height and weight of the User, physical activity, eating habits);
- Health data (such as diabetes type, injection system, bolus and rapid insulin pen, basal and lente insulin pen, pump and rapid insulin, carbohydrate ratio and correction factors, total basal daily dose, total bolus daily dose, time of lente insulin injection, injection data, blood glucose data);
|
Data Controller |
Legal Basis |
Retention period |
Recipient |
Data Transfer |
|
Diappymed |
Art. 6§1.f – Legitimate interest of the Controller |
10 years starting from the end of the commercialization of the Application (MDR 2017-745) |
The data controller and any authority legally authorized to access the data |
Google Cloud Platform (GCP) (see Section 6 of this Privacy Policy) |
Studies, assessments and research as part of post-market clinical follow-up (PMCF)
Sub-purposes:
- Conduct post-market clinical studies, assessments and analyses (PMCF) in order to document and monitor the safety, performance and benefit–risk profile of the medical device, in accordance with applicable obligations;
- Produce clinical evaluation indicators and reports (e.g., usage and outcome analyses) based on data already collected via the Application, without any additional act or procedure being imposed on the User as part of these analyses;
- Produce results in aggregated and/or pseudonymised form and, where applicable, scientific or regulatory communications.
Personal data of the User that are collected:
- Indirect identification data (the User’s pseudonymised identification number);
- Personal characteristics (sex, gender, height and weight of the User, physical activity, eating habits);
- Health data (such as diabetes type, injection system, bolus and rapid insulin pen, basal and lente insulin pen, pump and rapid insulin, carbohydrate ratio and correction factors, total basal daily dose, total bolus daily dose, time of lente insulin injection, injection data, blood glucose data);
|
Data Controller |
Legal Basis |
Retention period |
Recipient |
Data Transfer |
|
Diappymed |
Art. 6§1.f – Legitimate interest of the Controller
Article 9 (health data): Art. 9(2)[i/j] (processing necessary for reasons of substantial public interest in the area of public health and/or for research purposes, subject to appropriate safeguards). |
PMCF working data / analysis datasets: 2 years from the last publication of the research results or, if there is no publication, until the signing of the final research report. Aggregated results: 10 years from the end of the marketing of the Application (MDR 2017/745). |
The data controller and any authority legally authorized to access the data |
Google Cloud Platform (GCP) (see Section 6 of this Privacy Policy) |
Management of partnerships with other apps or diabetes monitoring applications
Sub-purposes:
- Improve the User’s diabetes monitoring by enabling them to connect their EkiYou account to partner third-party diabetes monitoring services (including applications, continuous glucose monitoring (CGM) systems, connected insulin pens and/or telemonitoring/remote patient monitoring platforms), provided that such services are covered by a partnership with the Controller;
- Enable, with the User’s consent, EkiYou to share/transmit certain health data to a partner third-party application/platform (in particular for telemonitoring), in line with the settings chosen by the User;
- Enable EkiYou to collect, synchronize and record data from connected third-party devices/services (including CGM glucose data and/or injection data from a connected insulin pen) when linked to the User’s EkiYou account;
- Enable the receipt, recording and administrative processing of prescriptions transmitted by a partner third-party application/platform (where applicable with the User’s consent), in order to activate access rights to the App when a prescription is received.
Personal data of the User that are collected:
- Identification and contact data of the User (last name, first name, date of birth, email, optional phone number, username, identification number for the User in the Controller’s systems, sex, country, optional postcode);
- Data related to the User’s identifiers (such as login, password, IP address)
- Personal characteristics (sex, gender, height and weight of the User, physical activity, eating habits);
- Health data (such as diabetes type, injection system, bolus and rapid insulin pen, basal and lente insulin pen, pump and rapid insulin, carbohydrate ratio and correction factors, total basal daily dose, total bolus daily dose, time of lente insulin injection, injection data, blood glucose data);
- Social security number
Personal data of the healthcare provider that are collected (only for the 4th purpose):
- Identification and contact data of the healthcare provider (name, first name, e-mail, phone number) ;
- RPPS / finess number
|
Data Controller |
Legal Basis |
Retention period |
Recipient |
Data Transfer |
|
Diappymed |
Art. 6§1.a – Consent of the data subject |
10 years starting from the end of the commercialization of the Application (MDR 2017-745) |
The data controller and any authority legally authorized to access the data, as well as the partner diabetes monitoring applications covered by the User’s consent. |
Google Cloud Platform (GCP) (see Section 6 of this Privacy Policy) |
The mandatory or optional nature of the data to be provided is indicated to the User at the time of collection by an asterisk (*).
The requirement to provide mandatory data is of a regulatory or contractual nature or it conditions access to the functionalities of the Controller’s Application.
Access to the functionalities of the Controller’s Application cannot be granted if this information is not provided.
By voluntarily providing optional data, the User expressly accepts that they will be processed under the conditions and for all the above purposes.
- Social Networks
The Data Controller is present on various social networks, including Facebook, Instagram, LinkedIn, Youtube. As such, the Data Processor is likely to process the public data of the profiles of social network users who share, subscribe, follow or contact the Data Processor on these platforms.
The Data Processor shall not be responsible for the User’s public data accessible on these networks and platforms. The User is therefore advised to read the privacy policies applicable to each of these platforms in order to configure his or her privacy settings.
- Data Recipients
The Data Controller may share some of your data with its service providers (see section 3.).
This transmission of data by the Data Controller is carried out within the strict limits necessary for the accomplishment of the tasks conferred on these service providers.
These recipients may be required to contact the User directly using the contact details that they have provided.
The Data Controller requires these recipients to use the User’s personal data only to manage the services for which they are responsible and in accordance with the applicable laws and regulations on the protection of personal data.
Where applicable, the User’s personal data may be communicated to third parties authorized by law (in particular in the context of an express and motivated request from the judicial authorities).
Similarly, if the Data Controller is involved in a merger, acquisition, transfer of assets or receivership procedure, it may be required to transfer or share all or part of its assets, including the User’s personal data. In this case, the User will be informed and will be able to give his informed consent, before any transfer of his personal data to a third party.
- Storage and transfer of data outside the European Union
Personal data processed through the App are hosted within the European Union, in data centers located in Frankfurt, Germany, by our processor Google. Data processed through Google may be transferred to Google LLC in the United States. Where applicable, such transfers are governed by a GDPR-compliant mechanism, including the EU–U.S. Data Privacy Framework adequacy decision where applicable and/or the European Commission’s Standard Contractual Clauses, supplemented where necessary by additional safeguards.
The Data Privacy Framework (DPF) is a self-certification mechanism for U.S. companies. The European Commission has considered that transfers of personal data from the EEA to U.S. companies certified under the DPF benefit from an adequate level of protection. For more information about the DPF, you may consult the following resource: https://www.dataprivacyframework.gov/
- Security of personal data
The Data Controller implements organizational, technical, software and physical measures for digital security to protect the User’s personal data from alteration, destruction and unauthorized access. However, it should be noted that the Internet is not a completely secure environment and that the Data Controller cannot guarantee the security of the transmission or storage of the User’s data on the Internet.
- Use of data for statistical purposes and for clinical studies
As part of its commitment to the continuous improvement of its service, the Data Controller may use anonymized data for statistical purposes.
This data allows the Data Controller to perform analyses and find correlations between different variables, which helps it to better understand the needs of Users and to improve the quality of its services.
In the context of the continuous improvement of the Application and the monitoring of its quality, DIAPPYMED carries out statistical analyses and measures key indicators (e.g., usage, stability, performance, safety).
Depending on the case, these analyses may rely on:
- Aggregated and/or anonymised data: where anonymisation is possible, the data are processed in such a way that Users can no longer be identified.
- Pseudonymised data: where anonymisation is not possible without a loss of relevance, DIAPPYMED uses technical identifiers replacing directly identifying elements and applies appropriate security and access restriction measures.
These analyses are used in particular to:
- Understand usage trends and improve ergonomics and functionalities;
- Monitor the quality, safety and performance of the device;
- Produce monitoring indicators.
DIAPPYMED may reuse certain data collected via the Application in order to conduct studies/assessments as part of post-market clinical follow-up (PMCF) and MR-004, based on existing data, without any additional act or procedure being imposed on the User as part of these analyses.
For each PMCF study, dedicated information (objective, categories of data used, period, recipients, retention period, protection measures, contact details) is kept up to date and is accessible at the following address: [www.diappymed.com, section “Data reuse”].
You may object to the use of your data for PMCF studies at any time by contacting : dpo@diappymed.com
- Your rights
In accordance with the provisions of Regulation No. 2016/679 of April 27, 2016 and Law No. 78-17 of January 6, 1978 as amended, the User is fully informed of his rights.
The User has :
- a right of access to his data : the User has the right to obtain confirmation as to whether or not his data is being processed, as well as the communication of a copy of his data and information relating to the characteristics of the processing carried out by the Data Controller on such data ;
- a right to rectification of inaccurate information and incomplete data ;
- a right to the deletion of data that are no longer necessary for the processing, a right to withdraw consent to the processing, a right to object to the processing of his data when there are no legitimate and compelling reasons justifying the processing, a right to object to commercial prospecting ;
- a right to limit the processing in case of inaccuracy of the data during the time of their verification, or when they are no longer necessary for the exercise of a legal right ;
- a right to data portability, in order to request the transmission to another person in charge of the data provided with his consent or on the occasion of the conclusion of the contract ;
- a right not to be subject to a decision based exclusively on automated processing that produces significant legal effects concerning him ;
- a right to define directives concerning the fate of his data after his death.
The User may exercise his rights at any time :
- By mail to the address :
DIAPPYMED
Cap Alpha,
3 avenue de l’Europe,
34830, Clapiers
- By email to the address : dpo@diappymed.com // ekiyou@diappymed.com
The User must specify in their request their full name, e-mail address or postal address to which they wish the reply from the Data Controller they have contacted to be sent.
For security reasons and to avoid fraudulent requests, DiappyMed reserves the right to request proof of identity if there is reasonable doubt as to the applicant’s identity. Once the request has been processed, this proof will be destroyed.
In accordance with the law, this request will be answered within one month of its receipt.
Finally, the User has the right to lodge a complaint with the French Supervisory Authority, i.e., the “Commission Nationale de l’Informatique et des Libertés” (hereinafter : “CNIL”) or any other competent supervisory authority in his State of residence.
The User may make this complaint to the French CNIL :
- By mail to the following address :
3 Place de Fontenoy
TSA 80715
75334 PARIS CEDEX 07
- By phone at 01 53 73 22 22 (Monday to Thursday from 9am to 6:30pm / Friday from 9am to 6pm) ;
- By fax at 01 53 73 22 00 ;
- Via the CNIL website at the following address: https://www.cnil.fr/fr/plaintes