This document explains the collection and usage of personal data in the context of the Accu-Chek® Connect diabetes management app offered by Roche Diabetes Care GmbH. Roche may update this Privacy Notice from time to time. Please check occasionally for any updates.
As long as you use the default settings, your personal data is being locally stored within your Accu-Chek Connect diabetes management app on your mobile device and no such personal data is being transferred to any third party when using the Accu-Chek Connect diabetes management app to (i) connect to and exchange data with compatible blood glucose meters, (ii) manually enter, manage, export and store your own blood glucose and/or insulin data, and the additional health or personal information that is in scope of the Accu-Chek Connect diabetes management app, and (iii) receive computed insulin advice.
The Accu-Chek Connect diabetes management app allows you to configure a data sharing with any addressee you choose e.g. your caregiver or your healthcare providers (together referred to as "Recipient"). Such data sharing is activated once you enter your Recipient's phone number into the respective configuration options of the Accu-Chek Connect diabetes management app. You may modify or de-activate any and all data shares at any time by re-configuring said options. Please refer to the instruction manual for details on how to configure the sharing options of the Accu-Chek Connect diabetes management app.
If data sharing is activated, each of your blood glucose values either measured or manually entered will be transferred to each Recipient configured by you. Optionally, your name and date of birth will be included if configured by you. Do note that Roche has no means of control with regard to the communication path used and your shared data potentially may be read by telecommunication service providers and third parties having access to the data in transit. The SMS technologies used are outside the Accu-Chek Connect diabetes management app and do not allow for an encryption of your shared data in transit. Check your local law to see whether the SMS data is protected by telecommunication secrecy. Also, before enabling any data sharing, check the costs your mobile network operator may charge for sending multiple SMS from your mobile device.
If you would like to share data with your healthcare providers but do not wish to use the SMS based data sharing features explained in this section, please consider the Accu-Chek Connect online account functionality described in section 3.2 below, as the Accu-Chek Connect online account provides for a data transfer that is encrypted end-to-end and does not rely on SMS data exchange.
Your personal data is under your control. When using the Accu-Chek Connect diabetes management app, your personal data will only be collected and used by Roche to the extent when you enable at least one of the following options.
Whenever you connect a compatible blood glucose meter to your mobile device for the first time and start the Accu-Chek Connect diabetes management app, you will be prompted with a product registration screen asking you to register your blood glucose meter with Roche. The registration is of course optional and you may skip it wholly or partly if you wish. If you choose to complete the registration, your personal data that you have filled in will be transferred to Roche together with the model number and serial number of your registered blood glucose meter. Roche will use this meter registration information in order to provide support services to you and to contact you if necessary e.g. in case of product recalls.
As part of the above product registration Roche may ask you for permission to also use your personal data as contained in the registration screen in order to improve the service or for marketing purposes, including contacting you by e-mail – any such use will be subject to your prior consent, which you may revoke at any time as directed in each e-mail sent to you by Roche or by visiting the website listed below in Clause 4.
If you register for an Accu-Chek Connect online account and then use the Accu-Chek Connect diabetes management app to communicate with the online functionality of your Accu-Chek Connect online account, your personal data will be transferred to, collected and stored by Roche – however only upon initiation by you. In this case, all subsequent processing and using of your transferred personal data takes place as specified in the Accu-Chek Connect Online Privacy Notice.
When you set up the Accu-Chek Connect Bolus Insulin Advisor using the code provided by your healthcare provider, your IP-address is transmitted to a third party in order to determine your country of usage. This is required for regulatory purposes.
When installed on an Apple device, the Accu-Chek Connect diabetes management app features an interface that allows you to export data to the Apple Health app. When you enable this Apple Health app link, the Accu-Chek Connect diabetes management app will export the following data to the Apple Health app installed on your mobile device:
a. Your blood glucose values with time and date and together with a manual entry / device measurement indicator; and
b. Your carb values with time and date.
Apple Health app is a product of Apple Inc. Your data potentially may be shared with Apple Inc. and third parties once you enable the interface. Any such transfer and processing is beyond Roche's control. Please refer to the Apple Health app manual and privacy policy or consult with Apple Inc. before enabling the interface.
For the avoidance of doubt, the merely local use of the Accu-Chek Connect diabetes management app without any of the options mentioned under 3.1 to 3.4 above will not transfer your personal data to Roche.
When you use the online functionality of an Accu-Chek Connect online account and the Accu-Chek Connect diabetes management app, you will see your personal data that Roche has stored and the recipients to whom Roche transmits such data, i.e. your invited caregivers. Unless otherwise agreed with Roche, the purpose of Roche's storage and processing of personal data is limited to the provision of the online functionality pursuant to the Terms of Use for Accu-Chek Connect online account and license for software. When logged in, you may also delete your personal data or exclude invited caregivers from access to your personal data.
When you complete the blood glucose meter registration, only the data you provide and the serial number of the registered blood glucose meter will be transferred to Roche. You may at any time revoke consents granted in the initial blood glucose meter registration by returning to the meter registration feature, deselecting the option to receive information on new Accu-Chek products, and resending the meter registration.
If you have difficulty assessing Roche's processing of your personal data, including the purposes of such processing, third party access or deletion, you may also request the relevant information from Roche. In order to do so, please contact Roche as described below.
Should your personal data be incorrect and if you cannot correct it yourself when logged in, Roche will correct it upon your request. In order to do so, please contact Roche as described below.
Roche will erase your personal data should its storage no longer be necessary for the aforementioned purposes. There will be a need to store your personal data for regulatory reasons, but it will be blocked and hence be made unavailable for further productive use.
Your data is stored on your device. If you have shared your data with the Apple Health app, you can also port it via the Apple Health app also. You can also port your data by sharing it with another account you may have. If you have difficulty, contact Roche as described below.
When you use Accu-Chek Connect diabetes management app, Roche collects information sent to Roche by your smartphone that tells us how you are using the Accu-Chek Connect diabetes management app ("usage information"). Usage information is not attributed to you personally.
Roche uses aggregate information about our users and non-personal information to analyze Accu-Chek Connect diabetes management app and user behavior and prepares aggregated reports through Google Analytics provided by Google, Inc. ("Google") to help us identify the features which have the greatest interest by users in general. Google is certified under the US-EU and US-CH Privacy Shield and we have agreed with Google a data processing agreement to ensure they operate Google Analytics on our behalf. IP-anonymization is active. If you use the Accu-Chek Connect diabetes management app from within states that form part of the European Economic Area, your IP address will be truncated within the area of Member States of the European Union or other parties to the Agreement on the European Economic Area before transfer to a Google server. Only in exceptional cases the whole IP address will be first transferred to a Google server in the USA and truncated there.
Google will process this usage information on our behalf for the purpose of evaluating your use of the Accu-Chek Connect diabetes management app. To do this, we collect information about your interactions with the Accu-Chek Connect diabetes management app such as button or feature activation and send it to Google periodically. We do not analyze any of the data you enter such as measurements. Google compiles reports on app usage activity for us. The data analyzed in Google Analytics will not be associated with any other data held by Google.
You may opt-out of this data use in the settings of the Accu-Chek Connect diabetes management app.
The Accu-Chek Connect diabetes management app is only intended for use by individuals meeting, at minimum, age restrictions based upon individual country laws and regulations. Roche does not knowingly collect personal information via our websites, applications, services, or tools from children. As a parent or legal guardian, please do not allow your children to submit personal information without your permission.
The Accu-Chek Connect diabetes management app stores its data on your device and in encrypted form. It is your responsibility to make sure that your personal information is accurate and that your password is kept in a private and secure manner and not shared with others.
To the extent your data is processed by Roche remotely, Roche processes your personal information in ISO27001 certified data centers in Germany and uses certified encrypted storage mechanisms to separate your personal information from that of other users as well as to protect your personal information from unauthorized access. Your data may be accessed, with your permission as set forth in this Privacy Notice, by Roche Diabetes Care employees and healthcare providers.
Roche Diabetes Care GmbH is the data controller. See below, or visit www.roche.de/service/impressum.htm for all relevant contact information.
Roche Diabetes Care GmbH
Sandhofer Strasse 116
68305 Mannheim, Germany
Tel: +49 (0) 621 / 759- 0
www.accu-chek.com
e-Mail: mannheim.allgemein@roche.com
Registered Office: Mannheim
Register court: AG Mannheim HRB 720251
Managing Director: Michael Wöhler
Chairman of the Board: Dr. Severin Schwan
Regulatory Authority: Regional Council Karlsruhe VAT Reg. (ID): DE 297138554
If you have questions or are not satisfied with the way Roche handles your data or responds to your requests, you may contact the data protection officer of Roche Diabetes Care GmbH at global.rdc-dpo@roche.com
You also have the right to lodge a complaint with the competent data protection authority for Roche, the Baden Wurttemberg Data Protection Authority (LfDI). The contact details for the LfDI can be found on their website (https://www.baden-wuerttemberg.datenschutz.de). Alternatively, you may also contact the data protection authority in the country of your habitual residence.
07250436008