Philips InCourage Care Companion Mobile Application Privacy Notice

This Privacy Notice was last updated on 7.30.2019 DATE PENDING FINAL DRAFT APPROVAL.

The Philips InCourage Care Companion mobile application (“App”) provides information related to the use of the Philips InCourage system to help you comply with your prescribed vest therapy regimen. This Privacy Notice is meant to help you understand our privacy practices when you use the App, including what data we collect, why we collect it, and what we do with it, as well as your individual rights.

The App uses personal data collected or processed by the InCourage system device(s) (“Device”) and/or the App (“Services”).

This Privacy Notice applies to personal data collected or processed by the Device and/or the App, which is controlled by or under control of Respiratory Technologies, Inc. d/b/a RespirTech, a Philips company, or its affiliates (”RespirTech”, “our”, “we” or “us”).

What Personal Data are collected and for which purposes

We receive or collect personal data, as described in detail below, when you use our Services, including when you access, download, install the Device or the App, or use the App. We may use this personal data to provide you services requested by you as a contractual necessity, to operate, provide, improve, customize, support, and market our Services based on our legitimate interest, or to comply with a legal obligation to which we may be subject. If you do not want us to collect and process your personal data, you may not be able to use the App.

Account Data

We collect your personal data when you create an account. The personal data we collect to establish your login includes your name, username, email address, phone number, Device serial number and the password you set.

When you invite and permit members to your Care Circle to access the App they will receive an email with an invitation and will also create an account. The data collected includes their first name, last name, email address, phone number(s), user name and password.

If you are a parent or legal guardian of a minor under the age of 18 you may also invite your minor child who is using the Device to access and use the App.

The personal data collected is used to create and manage the account. You can use your account to securely login to the app.

Sensitive Personal Data

Before we collect sensitive personal data, we will inform you and ask your explicit consent. This data includes Device usage data such as the length of the therapy program used, therapy pressure, number of pauses, personal and clinical goal setting, symptom tracking and journaling.

Healthcare Team – The Healthcare team will have access to your Device therapy and usage data to monitor your use of the Device. We will seek your explicit consent for your Healthcare team to create clinical goals for you and to share your goal progress with them. Personal goals set by you are not shared with your Healthcare team. We will also seek your explicit consent to share your symptom data with your Healthcare team. You may withdraw your consent(s) at any time.

Care Circle – The Care Circle will be able to view your Device therapy, usage data, clinical goal setting and symptom tracking. The Care Circle will be able to see personal goals set by you. You enable this access when you invite individuals to join your Care Circle. You can withdraw access to any Care Circle member at any time.

We ask that you and members of your Care Circle not send us and you not disclose any sensitive personal data (e.g., social security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background or trade union membership) on or through the App or otherwise to us.

Data Provided by You

The data you enter into the App includes the personal goals you want to achieve and could include therapy goals from your Healthcare team with your permission. The personal goals you want to achieve, clinical goals from your Healthcare team and the input that you provide will be used to enable the motivational statements used in the App’s goal communications.

You can also document your preferences related to the type of transactional communications that you wish to receive from RespirTech and your preferences for symptom tracking. The symptom data that you provide could be used to provide feedback to/from your Healthcare team.

You can also keep track of important items to review with your Healthcare team or elements of your lung health for self-monitoring by using the journal function.

The data collected is used to provide you with a view of your usage of the InCourage system in order to assist you with complying with your airway clearance therapy goals. You may change any of the settings you set and opt-out of receiving notifications and communication from your Healthcare team as well as reminders you may have set up.

Device Data

You can enable your InCourage system to upload data to the App via Bluetooth® connection. The data collected by the Device includes information related to your use of the Device, such as the time of day you use the Device and the hours of use. The Device also collects information on the pressure settings, number of pauses and program used. If you do not have a connected device you can upload your device data manually into the App.

The data collected is used to provide you, your Care Circle and your Healthcare team with information related to your use and compliance with the InCourage system and your prescribed airway clearance therapy regimen.

Cookies

We use cookies, tags or similar technologies to maintain the user session and your access to the App. They also allow us to recognize your mobile device and collect your personal data including your Device serial number, the IP address of your mobile device, session and usage data, or service-related performance information, which is information about your use of the App. We will ask your consent to enable cookies and de-identify your IP address so RespirTech can review analytics to improve overall App usage and functionality.

The data collected is used to provide you with the App’s functionality and help us analyze overall traffic patterns and identify App usage and performance issues to improve our services.

Customer support

You may provide us with information related to your use of the App, including your interaction with RespirTech, and how to contact you so we can provide you customer support. We operate and provide our Services, including providing customer support, and improving, fixing, and customizing our Services. We also use your information to respond to you when you contact us.

Combined Data

With your consent we may combine and use de-identified and aggregate data to conduct research, help us improve the content, functionality and usability of the App, Device, our products and services and to develop new products and services.

We may combine the information collected from you and share it with RespirTech affiliates and with trusted third parties.

Permissions

The App may request your permission to access your phone or sensors (e.g. camera, Wi-Fi, geo-location, or Bluetooth) or other data (e.g. photos, agenda, or contacts) on your mobile device.

  • We use such data only when it is needed to provide you the Services and only after you provided your explicit consent.
  • Sometimes the permission is a technical precondition of the operating systems of your mobile device. In such case, the App may ask your permission to access such sensors or data, however we will not collect such data, unless when it is required to provide you the App Service and only after you provided consent.

With whom are Personal Data shared

RespirTech may disclose your personal data to third party service providers, business partners, or other third parties in accordance with this Privacy Notice and/or applicable law.

Service Providers

We work with third-party service providers to help us operate, provide, improve, understand, customize, support, and market our Services.

We may share your personal data with the following service providers:

IT and Cloud Providers

These service providers deliver the necessary hardware, software, networking, storage, transactional services and/or related technology required to run the App or provide the Services.

RespirTech requires its service providers to provide an adequate level of protection to your personal data similar to the level that we provide. We require our service providers to process your personal data only in accordance with our instructions and only for the specific purposes mentioned above, to have access to the minimum amount of data they need to deliver a specific service, and to protect the security of your personal data.

Other third parties

RespirTech, as a Philips company, may be subject to transfers of ownership. Such a transfer of ownership could include the transfer of your personal data directly related to that business, to the purchasing company. All of our rights and obligations under our Privacy Notice are freely assignable by RespirTech to any of our affiliates, in connection with a merger, acquisition, restructuring, or sale of assets, or by operation of law or otherwise, and we may transfer your personal data to any of our affiliates, successor entities, or new owner.

Cross-border transfer

Your personal data is stored and processed in the United States and is not subject to any cross-border transfer.

How long do we keep your Personal Data

We will retain your personal data for as long as needed or permitted in light of the purpose(s) for which the data is collected. The criteria we use to determine our retention periods include: (i) the length of time you use the App and Services; (ii) whether there is a legal obligation to which we are subject; or (iii) whether retention is advisable in light of our legal position (such as in regard to applicable statutes of limitations, litigation or regulatory investigations).

Your choices and rights including data subject to the Health Insurance Portability and Accountability Act of 1996 (‘HIPAA”)

You may access, inspect and receive a copy of your sensitive personal data (in hard copy or electronically) contained in our records. You need to make your request in writing as per the instructions below. We may charge a reasonable fee for copies. There are limited situations in which we may deny your request for access. In these situations, we will let you know why we cannot grant your request and how you may ask for a review of our denial.

You may request that we amend your sensitive personal data. You need to make your request in writing and explain your reason for the amendment as per the instructions below. Under limited circumstances, we may deny your request. If we do so, you may file a statement of disagreement with us. You may also ask that any future disclosures of your sensitive personal data, include your requested amendment and our denial of your request.

You may request that we restrict our use or disclosure of your sensitive personal data for payment or health care operations. You need to make your request in writing as per the instructions below. We are not required to agree to your request for a restriction. However, if we do agree, we will comply with our agreement, unless there is an emergency or we are otherwise required to use or disclose the data. If we decide to end our agreement to the restrictions, we will tell you.

You may request that we communicate with you in a specific way or at a specific location as per the instructions below. For example, you may request that we contact you at an address other than your home address. We will agree to your request if we determine that your request is reasonable. You need to make your request in writing.

You may request a listing of certain disclosures we have made of your sensitive personal data. You need to make your request in writing as per the instructions below. You may ask for disclosures made up to six (6) years before the date of your request. We will provide you one accounting in any 12 month period free of charge.

You have the right to receive a paper copy of this Notice at any time.

To exercise any of these individual privacy rights, contact our Privacy Office at the telephone number or address listed below. You must submit the request in writing to RespirTech_Compliance@philips.com. We will respond to your request consistent with applicable law.

In your request, please make clear which individual privacy right you wish to exercise. For your protection, we may only implement requests with respect to the personal data associated with your account, your email address or other account information, that you use to send us your request, and we may need to verify your identity before implementing your request. We will try to comply with your request as soon as reasonably practicable.

Please note that if you make use of (some of) your choices and rights, you may not be able to use, in whole or in part, of the App anymore.

We protect your personal data

We take seriously our duty to protect the data you entrust to RespirTech against accidental or unauthorized alteration, loss, misuse, disclosure or access. RespirTech uses a variety of security technologies, technical and organizational measures to help protect your data. For this purpose we implement, among others, access controls, use firewalls and secure protocols.

Special information for parents

While the Services are not directed to children under the age of 18, it is RespirTech policy to comply with the law when it requires parent or guardian permission before collecting, using or disclosing personal data of children. We are committed to protecting the privacy needs of children and we strongly encourage parents and guardians to take an active role in their children’s online activities and interests.

If a parent or guardian becomes aware that his or her minor child has provided us with his or her personal data without their consent, please contact us at RespirTech_Compliance@philips.com.

If we become aware that a minor child has provided us with personal data, we will delete his/her data from our files.

Changes to this Privacy Notice

Our Services may change from time to time without prior notice to you. For this reason, we reserve the right to amend or update this Privacy Notice from time to time. When we update this Privacy Notice, we will also update the date at the top of this Privacy Notice.

We encourage you to review regularly the latest version of this Privacy Notice.

The new Privacy Notice will become effective immediately upon publication. If you do not agree to the revised notice, you should alter your preferences, or consider stop using our Services. By continuing to access or make use of our Services after those changes become effective, you acknowledge that you have been informed and agree to the Privacy Notice as amended.

Contact Us

If you have any question about this Privacy Notice or about the way in which RespirTech uses your personal data, please contact us at the below email address. RespirTech_Compliance@philips.com

RespirTech
5905 Nathan Lane N, Suite 200
Plymouth, MN 55442
800.793.1261 or 651.379.8999