General information
Your privacy and trust are and have always been a priority for Insulcloud S.L. (hereinafter Insulcloud) We explain in a simple way how we use the personal information you provide us through the Diabetes Control Insulclock® 3600 mobile application. Insulcloud guarantees that we have taken all appropriate measures to provide security and protection to the personal data you provide us through the Diabetes Control Insulclock® 3600 mobile application.
This Privacy Policy is complemented by the contained on the website insulcloud.com This Privacy Policy also applies to the ENDO® Platform, the web Platform designed to be able to view all the information that you, as a user, register and store in the Diabetes Control Insulclock® 3600 mobile application
Read the content of this section carefully and, if you have any doubt regarding the processing that Insulcloud makes of your data or any other aspect of this Privacy Policy, do not hesitate to contact our Data Protection Officer, who will contact you as soon as possible.
Due to legal modifications as well as the own organizational modifications that may occur in Insulcloud, this Privacy Policy may undergo modifications, so we recommend that you review it periodically. However, in case we consider that the changes introduced are important, we will contact you through the contact details you have provided us, if applicable.
If you do not agree with something, in whole or in part, of what we detail here and do not accept the provisions in this document, we ask you not to use any of our services or products.
Who will be responsible for the processing of personal information?
The information you provide us through the mobile application will be the responsibility of Insulcloud. To help you identify us better and, if you wish, contact us, we provide you with our data:
- Owner: Insulcloud, S.L.
- Trade Name: Insulcloud
- Registration Data: Mercantile Registry of Bizkaia sheet BI-73144, Volume 5838, Folio 198.
- Tax ID (NIF): B-87131454
- Registered office: Calle Alameda de Mazarredo 25, 1º, 48009 Bilbao, Bizkaia (Spain)
- Headquarters: Calle Bravo Murillo 101, 2ª, 28020 Madrid (Spain)
- Email: info@insulcloud.com
- Data protection officer: legal@insulcloud.com
What is Personal Information?
It is any information that relates to an identified or identifiable natural person. An identified or identifiable natural person is considered to be one whose identity can be determined, directly or indirectly, in particular by means of an identifier (for example: name, email or an identification number).
We collect, store and use your personal information when necessary to provide you with any of our services and for the development of our business, as described in this Privacy Policy. Our intention is that you are permanently informed of the processing that in Insulcloud we do of the personal information that we process about you, so we ask you to get in contact us whenever a doubt arises in this regard.
What personal information do we collect and how do we collect it?
To use the Diabetes Control Insulclock® 3600 mobile application, it is necessary for you to register and provide us with a valid email. If you are a healthcare professional user of the ENDO® Platform, you will be able to access it with your user account, which will be provided to you by Insulcloud if you request it.
Because the Diabetes Control Insulclock® 3600 mobile application and the ENDO® Platform will manage personal medical data among others, to guarantee correct protection of your personal data, you must register as a user to be able to use this application, with a valid email address and a password.
Do not reveal your access password to any third party and change it periodically. In the event that you forget your password, we provide you with a recovery mechanism through the Diabetes Control Insulclock® 3600 mobile application and the ENDO® Platform, through which we will send a link to the email you provide us so that you can modify your password. Make sure that the email address you provide us is written correctly. Once you have logged into your account with the password we have provided, we recommend that you set a new one that is easy for you to remember.
We offer you certain services that require you to provide us with some additional personal data to be able to provide the service:
- Your User Profile. We give you the opportunity to register your personal data referring to: photo (optional), name, email, phone number, weight, height, BMI (automatically generated once we know your weight and height), ID, sex, date of birth, your type of diabetes, type of treatment and your start year in diabetes (debut year). This information is provided by yourself as a user (or parent or legal guardian of the minor user) of the Diabetes Control Insulclock® 3600 mobile application to provide you with our services.
- Your Diabetic Diary. In this section, we collect data on the insulin injected (type and amount) and the moment in which it is injected, either receiving the data automatically (if you use the Insulclock® device) or manually if you introduce these data manually.
In the Diabetes Control Insulclock® 3600 mobile application, you can add other data:
- Glucose doses: You can add your glucose levels, as well as the day and time in which those glucose levels occur. You can add them manually or automatically if you have a glucometer or continuous glucose monitor compatible with the system, depending on the version you have of the Diabetes Control Insulclock® 3600 mobile application. We recommend that you consult the Privacy Policy of these services offered by third parties.
- You can add notes and photos as you wish, although we have designed this section to add photos of meals, for example. We will need your authorization to access your photos and images stored on your smartphone as well as your smartphone's camera.
- Your Tutors. You can appoint a tutor or tutors to help you with the management of your diabetes treatment. This person could be a family member, a friend, a doctor, a nurse… We will need your authorization to be able to send the data that you store in the Diabetes Control Insulclock® 3600 mobile application to the designated person.
- Your Insulclock® device. If you have an Insulclock device attached to your insulin pen, we will receive information about what type of insulin has been injected (brand and type), how much insulin has been injected (dose), and at what time the insulin was injected. All these data will be collected automatically every time you use your Insulclock® device and synchronize it with the Diabetes Control Insulclock® 3600 mobile application. The Diabetes Control Insulclock® 3600 mobile application will request authorization so that we can access your location data. These data will be used to know where your Insulclock® device is, which is very useful in case you have lost it or it has been stolen. In addition, the location data will serve us to contact your assigned tutor in case you may have suffered an accident that could place you in a serious health situation (hyperglycemia or hypoglycemia).
If you wish, you can automatically store your data stored in Healthkit® (for the iOS® version of the Diabetes Control Insulclock® 3600 mobile application) or in Google Fit® (for the Android® version of the Diabetes Control Insulclock® 3600 mobile application). We recommend that you consult the Privacy Policy of these services offered by third parties. In addition, we offer the possibility of linking activity bracelets such as Fitbit®, Polar® and Garmin® through the provider Terra.
When you provide us with any personal information, you guarantee us that the information is true, accurate, without limitations or reservations, and that you provide it freely and give your consent for its processing in accordance with what is established in this Privacy Policy. Please, if there is any variation in the data you have provided us, communicate it to legal@insulcloud.com.
Data of minors
We want to let you know that this Diabetes Control Insulclock® 3600 mobile application is aimed at all people with diabetes, their caregivers, professionals or not, as well as the physicians who treat them. Minors who intend to make use of the services contained in the Diabetes Control Insulclock® 3600 mobile application must have the prior consent of their parents, tutors or legal representatives, these being solely responsible for the acts carried out by the minors in their charge. If we detect that a minor is making use of this mobile application, we will request an authorization from their parents or legal guardians. Once consent is obtained, the parents or legal guardians of the minor will be able to obtain access to the minor's data and to the account that the minor may eventually create.
The parents or legal guardians of the minor may express their desire for the processing of the minor's data to end at any time, through a request to Insulcloud for the minor's account to be deleted, sending an email to legal@insulcloud.com or by sending a letter to Insulcloud S.L., Calle Bravo Murillo 101, 2ª, 28020 Madrid (Spain), accompanied by a photocopy of the ID and a photocopy/document of the Family Book. We will delete the minor's account, but we will retain non-identified or non-identifiable general information for research purposes and that which we are forced to retain to comply with current legislation.
How can you modify your personal data?
You can correct your profile information through your account settings in the Diabetes Control Insulclock® 3600 mobile application. At the moment you modify your personal information, it will likewise be modified in our databases automatically.
To what aspects does this Privacy Policy apply?
This Privacy Policy applies only to the personal information you send when creating an account in the Diabetes Control Insulclock® 3600 mobile application, also shown on the ENDO® platform, and to the personal information, including that of a medical nature, that we may receive from you or your healthcare providers or others, as established in this document and as stored within the Diabetes Control Insulclock® 3600 mobile application and ENDO® web platform.
Through the Diabetes Control Insulclock® 3600 mobile application we give you the possibility to access our website insulcloud.com , however, the use of the Insulclock® website will be subject to an additional Privacy Policy. This Privacy Policy will not be applicable to other personal information that you provide to Insulcloud or that Insulcloud collects about you.
What do we use your personal information for?
At Insulcloud we use your personal information with the utmost caution to ensure adequate protection of your personal information, adjusting to the legislation in force at all times, and we will do so as explained below:
- To provide you with a user account in the Diabetes Control Insulclock® 3600 mobile application and/or in the ENDO® platform, to improve your user experience, allowing you to access your information and present it in an effective and easy-to-use way. We use this information to set up and manage your account and offer you technical and usage assistance, verify your identity and send important information related to your account and the service we provide you.
- To respond to your doubts or technical support questions, including operation problems, resolution of incidents or to resolve any other type of doubt or to receive and respond to any type of comment you want to send us.
- To send you updated information about your treatment, diabetic training, healthy life, exercise and nutrition through the chat of the Diabetes Control Insulclock® 3600 mobile application.
- To send you personalized marketing information based on the information associated with your user account. Do not worry, you will always have the option to refuse to receive this type of communications.
- To better understand the way you use and interact with the INSULCLOUD® 3600 SYSTEM (including its functions and features), including its operation and its influence on users (including basic demographic data of users, such as their geographical location) in order to validate updates and guarantee at all times the security and protection of the INSULCLOUD® 3600 SYSTEM.
- To create, register, use or disclose such information (or facilitate access to it) to our affiliated companies and to healthcare professionals, researchers and third-party centers for research and analysis purposes.
- For product development or data analysis, surveys or statistical studies.
- To research, develop (including functionalities and features), test and improve the INSULCLOUD® 3600 SYSTEM.
- It is possible that for legal reasons we may be forced to use and retain personal information, as can happen, for example, for the prevention, detection or investigation of a crime or fraud, possible threats to the safety of people, violations of this privacy policy or as a means of proof in litigation in which we are a party. It is possible that your personal information is subject to the legislation of other countries and is accessible to the government, courts, law enforcement forces and regulatory entities of other countries. Likewise, it is likely that we use your personal information to comply with the requirements of internal audits on security for the protection of your data or any other matter that we consider necessary. These uses will always be based on:
- current laws, including those applicable outside your country of residence;
- a request from a court or tribunal, a security or regulatory body, as well as other public authorities, including those that come from outside your country of residence;
- compliance with these General Conditions of Use and, in particular, the Privacy Policy;
- protection of our rights, privacy, safety or property, or those of other people.
Do we share your personal information?
We share your personal information with our providers, to the extent that this is necessary to facilitate, maintain and host the INSULCLOUD® 3600 SYSTEM or offer technical support for its use.
When you decide to use the tutor service that we offer you through our Diabetes Control Insulclock® 3600 mobile application, we will only send your information to the person you designate as such through the email address you provide us. We also offer you the possibility of sharing your personal information with your endocrinologist and/or diabetes educator, for which we will ask you to grant your express consent.
Likewise, if the Endocrinology Service/Unit or Primary Care Physician who treats your disease uses the INSULCLOUD® 3600 SYSTEM as a consultation and management tool for the parameters and values related to your diabetes, you may authorize the sending of your data to the ENDO® platform of your doctor, who will receive them in real time. To do this, it will also be necessary for you to provide us with your express consent.
In the event that we provide personal information of yours to our providers for the purpose of providing us with assistance to create your INSULCLOUD® 3600 SYSTEM account, such third parties are obligated to maintain and protect the confidentiality of your personal information and use it only to the extent strictly necessary.
We may share your personal information with third parties (including affiliated companies of Insulcloud) with whom we market a product or service or perform a joint activity or program, including but not limited to research and/or development programs, statistical analysis or clinical trials. We may also share your personal information with other providers if you expressly request it.
We will not transfer your personal information to third parties, except in connection with the sale, merger or transfer of a line or division of our products or Insulcloud, so that the buyer can continue providing you with the information and services that Insulcloud has been providing. For the avoidance of doubt, we will not sell your personal information to third parties for commercial purposes and will only share your personal data with third parties to the extent that you have provided your consent or as permitted by applicable law.
Where do we store your personal information?
The personal information that you provide us for the creation of a user account and the data generated by the use you make of the INSULCLOUD® 3600 SYSTEM is hosted in the cloud, securely, by Google Cloud Platform , a digital tool developed by Google Inc.
We take measures to ensure that the information we collect is processed in accordance with this Privacy Policy and according to the requirements of applicable law, regardless of the location of the data, and the agreement that Insulcloud has signed with Google.
We also store personal information that you provide us in IBM Cloud , securely, a digital tool developed by IBM .
We take measures to ensure that the information we collect is processed in accordance with this Privacy Policy and according to the requirements of applicable law, regardless of the location of the data, and the agreement that Insulcloud has signed with IBM.
We guarantee that in the event that we are forced to provide personal information of yours to our providers, current or future, for the purpose of providing us with support for possible incidents of the INSULCLOUD® 3600 SYSTEM, such third parties are obligated to maintain and protect the confidentiality of your personal information and use it only to the extent that it is absolutely and strictly necessary.
How do we protect your personal information?
Given the "core" of Insulcloud, the protection of your personal information has always been, is, and will be a maxim of our company. That is why we use and have implemented all legal, administrative, and technical mechanisms to guarantee the protection of your personal data.
Your personal data is protected. At Insulcloud we restrict our employees' access to your personal information only in those cases or situations in which such access is strictly necessary to provide you with good service or to guarantee its security, and they will only access those personal data necessary to provide the specific service.
On the other hand, your personal identification data (first name, last name, and email) are stored pseudonymized and dissociated from other data you provide us through the INSULCLOUD® 3600 SYSTEM, in such a way that they can no longer be attributed to you.
It is important to keep in mind that no data transmission over the Internet is perfectly secure, so we advise you to take extreme precautions whenever you share personal information over the network. Also keep in mind that only you are responsible for protecting the access data to the account you have created in the INSULCLOUD® 3600 SYSTEM, so we recommend that you pay extreme attention not to leave user sessions open, create a password that only you know and that cannot be easily guessed, as well as not share the keys or access data to your account with anyone.
We are not responsible in case of loss or theft of your access password, or for the activities that unauthorized users may carry out with your user account, in the event that you are responsible for the unauthorized accesses. However, at Insulcloud we are here to help you, always and at all times, so if you have proof or suspicions that your account may have suffered unauthorized access or that your personal information may be compromised, please contact our Data Protection Officer as soon as possible.
For how long do we store your personal information?
We will safeguard and retain your personal information for as long as necessary and reasonable in accordance with current legislation and commercial matters. To determine these times or conservation time periods, at Insulcloud we will observe the provisions of local laws and contractual obligations. When we no longer need personal information, we will delete it from our records and databases securely.
We retain your personal data to provide you with the INSULCLOUD® 3600 SYSTEM service and for legitimate and essential business purposes, such as maintaining the performance of the INSULCLOUD® 3600 SYSTEM, making data-based business decisions about new features and offers, complying with our legal obligations and resolving disputes. We retain some of your personal data while you are a user of the INSULCLOUD® 3600 SYSTEM (your account information, your diabetic diary information, your tutors' information).
If you request it, we may delete or anonymize your personal data so that you are not identified, unless, legally, we can or are required to retain certain personal data, including the following cases:
- If there is an unresolved problem related to your account or an unresolved claim or dispute, we will retain the necessary personal data until said problem is resolved;
- When we are obligated to retain the personal data to comply with our legal, fiscal, accounting and auditing obligations, we will retain the necessary personal data for the period required by applicable law; and/or,
- When necessary for our legitimate business interests, such as fraud prevention or maintaining the security of our users.
Will we send you advertising information?
You may receive advertising information if you are using the Diabetes Control Insulclock® 3600 mobile application, both for iOS and Android. You will receive advertising regarding offers of Insulcloud services, but in no case will you receive third-party advertising through said mobile application. These communications will be made only through the application chat or via email.
What rights do you have regarding your personal information?
Current legislation on Data Protection grants you rights whose respect we ensure at Insulcloud and we guarantee that you can always exercise them.
You have the RIGHT OF ACCESS to know if at Insulcloud we are processing personal data of yours or of the person you legally represent, as well as to have control over them, know the purposes for which we process your data, how we process your personal information at Insulcloud and whatever other information you may request from us in this regard. You have the right to access the personal information we have in our possession about you free of charge. To do so, please get in contact us. We will ask you to identify yourself properly, through proof of identity, as we must verify your identity before supplying your personal data. Once the identity verification procedures have been completed, we will provide you with this information as soon as possible, which will never exceed one month (30 days) from the date on which you placed your request.
You also have the RIGHT OF RECTIFICATION of your personal data, that is, you have the right to modify or request that we modify your personal data that is inaccurate or incomplete. You can request this rectification by getting in contact us, indicating which data it refers to, as well as the correction to be made, and it must be accompanied by the supporting documentation of what is requested, since in this case we must also verify your identity. Once your request is received, we will proceed to the rectification of your data within a period not exceeding 10 days.
You are also assisted by the RIGHT OF ERASURE, which implies the request for deletion of a data item of yours or any record in our possession that is unnecessary or not relevant for the purpose for which it was collected and/or that may allow your identification by Insulcloud. The data or record will be blocked, that is, it will be identified and reserved in order to prevent its processing. We will proceed to agree on the deletion of the personal data over which the right is exercised, and we will carry it out within 10 days from the collection of your request, and we will notify you in writing of the result of the cancellation carried out. You can request this deletion by getting in contact us, indicating which data it refers to.
You also have the RIGHT TO LIMITATION. The exercise of this right of limitation means that, if you request it, the processing operations that would correspond in each case will not be applied to your personal data, that is, we will not delete your data, but we will stop processing it as we have been doing until now. You can request this limitation of processing by getting in contact us, indicating which data it refers to. We will proceed to agree on the limitation of processing of the personal data over which the right is exercised, and we will do so within 10 days from the collection of your request, and we will notify you in writing of the result of the limitation of processing carried out.
You also have the RIGHT TO OBJECT, at any time, which implies that you can object to Insulcloud continuing to process your personal data by getting in contact us, for which you must also identify yourself properly, in the same terms as for the exercise of the previous rights. In a period not exceeding 10 days we will stop processing your data unless there are legitimate and legal reasons that make the processing we do of your data prevail over your interests, rights and freedoms, or for the formulation, exercise or defense of claims.
The GDPR also grants you the RIGHT TO PORTABILITY of data by which you can request a copy of your personal data in electronic format so that you can transmit said data for use in the service of a third party. We will comply with the exercise of this right without undue delay and as soon as possible, in view of technical needs. You can request the portability of your data by getting in contact us.
You also have the RIGHT NOT TO BE SUBJECT TO AUTOMATED DECISION-MAKING, which means that you are protected by the right not to be subject to decisions based solely on automated decision-making, which includes profiling, when the decision may have a legal effect on you or produce a similar important effect.
In the event that these rights are to be exercised regarding the personal data of a minor, in addition to the previous identity proofs, your request must be accompanied by a photocopy of the family book or document proving that you are the legal representative of the minor, their parents or legal guardians.
We also inform you that if for any reason you are not satisfied with the way in which at Insulcloud we process the information we have under our responsibility with your personal data or we have not conveniently satisfied the exercise of any of the rights described above, you have the right to claim before the National Supervisory Authorities: Germany, Austria, Belgium, Bulgaria, Cyprus, Croatia, Denmark, Slovakia, Slovenia, Spain, Estonia, Finland, France, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, United Kingdom, Czech Republic, Romania, Sweden, Iceland, Liechtenstein, Norway, Switzerland.
If you wish to submit any type of request regarding the personal information that Insulcloud has about you, do not hesitate to contact our Data Protection Officer, who will contact you as soon as possible.