BreatheSmart’s Privacy Policy

Last modified: April 2024

1. Introduction

Aptar Digital Health, LLC and its affiliates Voluntis SAS (hereinafter “ADH,” “our” “we” or “us”) own or control BreatheSmart, a mobile application (the “App”) and a Connect web portal (“the Portal”) that provides healthcare professional (‘Professional’) and their patients with Asthma an aid in recording and monitoring the actuations and related technique of use of prescribed inhaler usage.

Please read this privacy policy carefully as it explains how your personal data are used and how to exercise your rights. This privacy policy supplements any documents or notices that may refer to this privacy policy (i.e Terms of Use which users are required to accept at the time of their first login to the App or Dashboards).

You cannot use BreatheSmart without consenting to the use of your personal information described in this Policy.

A Special Note about Minors: If you are UNDER SIXTEEN (16) YEARS OLD, you are not allowed to use the App.

Should you have any questions, you may directly contact ADH by sending an email to informationgovernance@aptardigitalhealth.com.

2. Who is the Data Controller of your personal data?

ADH is the data controller of your personal data to the extent that it determines the purposes of the processing related to BreatheSmart’s services..

ADH also acts as the data controller of your personal data:

  • when it operates personal data processing in order to comply with its legal and regulatory obligations, in particular regarding the materiovigilance obligations; and
  • when it operates personal data processing in order to improve the App, the Site and/or its services.

3. What does our Privacy Policy include?

This Policy describes how ADH collects, uses and shares information about you through BreatheSmart. Please read this Policy carefully to understand what we do. If you do not understand any aspects of our Privacy Policy, please feel free to contact us as described at the top of this Policy. This Privacy Policy applies only to information we collect through the App and the Site. BreatheSmart also contains links to third party sites that are not owned or controlled by ADH. We are not responsible for the privacy practices of such other sites. ADH does not share Personal Information (defined below) with those sites. We encourage you to be aware when you leave BreatheSmart and to read the privacy statements of each and every website that collects personal information.


4. What information ADH collects?

ADH collects two types of information: (1) information received from you, and (2) information received from others (i.e: Apple Health or Google Health depending on your device and your authorization).

Find below the detailed list of all personal data provided by you via BreatheSmart, or collected from other application, or generated by BreatheSmart (also BreatheSmart automatically collects data via cookies(1) and other trackers):

Type of Data

Examples of Data

Identification data

Fist name, last name, date of birth

Contact details

Email address, phone number,

Health data

Symptoms,
Medication: type, dates, times, inhalation technique when you use your inhaler with an add-on sensor (forced expiratory volume, forced vital capacity, peak expiratory flow rate)

Physical fitness related data

Height, weight, gender, number of steps, active minutes

Exchanges with ADH

Date, hour, and subject of your exchanges with ADH

Electronic network activity information (2)(Traffic data)

Date and time of the visit, viewed pages and files, amount of time spent on particular pages, IP address, device type, browser type and language, operating system, system configuration data, referring URLs, carrier and country location, hardware and processor information.

Information from cookies and trackers

Use of the Platform, compile reports on activity, demographic data, analyze performance metrics, Services usage

Other personal information

environmental conditions, triggers, geolocational information, tagging data, favorites, preferences, session lengths

(1) Cookies are small packets of data that a website stores on your computer’s or mobile device’s hard drive so that your computer will “remember” information about your visit.

(2) These data are necessary for the proper functioning of BreatheSmart, as well as internal analytics purposes.


5. For what purposes does ADH use your personal data?

As data controller, ADH processes your personal data for the following purposes:

Purposes

Examples of use of your Personal Data

Legal Bases

Creating and managing your BreatheSmart’s account

  • to create your patient account
  • to enable you to sign in on BreatheSmart
  • to provide you with the BreatheSmart’s services
  • to enable you to update your patient account

Your Consent to this privacy policy

Providing BreatheSmart’s services

  • to provide symptom management
  • to facilitate Professional use of BreatheSmart in connection with your treatment and care.
  • to receive medication reminders

Your Consent to this privacy policy

Managing after-sales service (call support)

  • to contact you
  • to answer your questions
  • to solve your technical issues

Your Consent to this privacy policy

Compliance with legal and regulatory obligations 

  • to comply with legal and regulatory obligations (i.e for materiovigilance obligations)
  • to process your requests to exercise your rights

Legal and regulatory obligations to which ADH is subject as data processor

Sending monthly newsletterss 

  • Provide regular and updated information on events and/or conferences related to a medical theme, or specific information on new medical advancements.

Legitimate interest of ADH in engaging and maintaining contact with users.

ADH may also process your personal data for legitimate interests as:

  • improving the BreatheSmart’s services or,
  • taking action against any identified breach or,
  • managing any dispute or litigation.

6. Who can access your Personal Data ?

ADH will not sell or rent your Personal Data. Your personal data may be transmitted to the following recipients when you use BreatheSmart and the services it provides:

Recipients

Purposes

ADH and its duly authorized employees Exclusively for the purposes detailed in the Section 5 of this privacy policy
Your healthcare provider and its duly authorized employees Exclusively for the purposes detailed in the Section 5 of this privacy policy
Companies of the ADH Group and their duly authorized employees Exclusively for administrative, operational and technical purposes related to the management of BreatheSmart and its services
ADH' service providers(hosting provider, IT service providers, etc.) Exclusively for operational and technical purposes related to the management of BreatheSmart and its services
Administrative or judiciary authorities Exclusively in the case of an express and justified request or in case of an alleged violation of legal or regulatory provisions
Lawyers and all interested parties Exclusively in the case of the management of possible disputes and other legal matters where appropriate
Other third parties Following or during a restructuring, reconstitution, acquisition, debt financing, merger, sale of assets of ADH or a similar transaction, as well as in case of insolvency, bankruptcy or receivership where personal data are transferred to one or more third parties as assets of ADH


7. What are your rights regarding your Personal Data ?

If you have any questions or wish to exercise your rights, you may directly contact ADH by sending an email to informationgovernance@aptardigitalhealth.com.

  • you can request the access to your personal data in order to obtain clear, transparent and understandable information on how ADH processes your personal data and on your rights (as provided in this policy), as well as a copy of your personal data (you can access certain information relating to your account (name, contact information and preferences) by signing into your account and going to the “PROFILE” section of our mobile or web application).
  • you can request the rectification of your personal data in order to obtain the modification of your personal data if they are obsolete, inaccurate or incomplete.
  • you can request the closure of your online account. If you close your account, we will no longer use your online Personal Information or share it with third parties. ADH may, however, retain a copy of the information for legal purposes and to avoid identity theft or fraud.
  • you have a right to ask to get an Accounting of Disclosures of when and why your health information was shared.
  • you may decide if you want to give your authorization before your health information may be used or shared for certain purposes, such as for marketing.
  • you have the right to receive your information in a confidential manner.
  • you have a right to restrict who receives your information.

Under certain circumstances, ADH may ask you for specific information in order to confirm your identity and ensure the exercise of your rights. This is another appropriate security measure to ensure that personal data is not disclosed to an individual who does not have the right to receive it.


If needed (fraud, scams, rip-off, bogus product, etc.), you may also report a complaint to your national data protection agency,the Federal Trade Commission ‘FTC’.

To do so you may:

  • directly use the FTC complaint form available on their website : ftc.gov/complaint
  • or call 1-877-FTC-HELP


8. How is your Personal Data protected?

ADH has implemented technical and organizational measures in order to protect your personal data, in particular against potential data breaches likely to cause, either by accident or unlawfully, the destruction, loss, modification, unauthorized access or divulgation of your personal data. These measures will guarantee a level of security adapted to the data and will take into account the state of the art and the cost of implementation in relation to the risks and nature of the data to be protected.

In particular, your health data are stored on servers operated by duly certified hosting providers (“HDS”). This is a French-specific certification standard mainly based on the ISO 27001 standard on the management of information security systems.

ADH also guarantees that all members of its personnel and any other person processing your personal data will respect the internal rules and procedures related to the processing of personal data, including the technical and organizational security measures put in place to protect your personal data. In this context, ADH reviews and updates its practices regularly to enhance your privacy and ensure that its internal policies are followed.

However, even with these safeguards, ADH cannot guarantee, ensure, or warrant the security of any information you transmit to us. There is no guarantee that information may not be accessed, disclosed, altered, or destroyed by breach of any of our physical, technical, or managerial safeguards. It is your responsibility to protect the security of your login information. Please note that e-mails and other communications you send to voluntis-privacy.glo@aptar.com are not encrypted, and we strongly advise you not to communicate any confidential information through these means.

If you have found a vulnerability or would like to report a security incident, you may send an email to informationgovernance@aptardigitalhealth.com or use the dedicated message service available through the App or contact your national data protection agency FTC (as described in section 7).


9. Where and how long will your Personal Data be maintained?

BreatheSmart mobile and Dashboards are hosted and managed on servers located within the United States. By using and accessing BreatheSmart, you agree and consent to the transfer to and processing of Personal Information on servers located in the United States, even when you travel outside the United States, and you recognize that the protection of such information may be different than required under the laws of any location that you visit.

As a general rule, your personal data will only be retained for ten (10) years following your last use of the services, or as necessary to fulfill legal or regulatory obligations.

In the absence of applicable exceptions, your traffic data will be kept for a period of thirteen (13) months from the connection date.


10. How will you know if this Policy changes?

This Privacy Policy may be amended from time to time, in particular to reflect the changes in the services provided by BreatheSmart or the applicable regulations. Any revised version of the Privacy Policy will be posted on this page and at other places deemed appropriate.


11. How can you contact ADH if you have questions?

If you have any questions, concerns, complaints or suggestions regarding our Privacy Policy or otherwise need to contact us, please email our Data Protection Officer at informationgovernance@aptardigitalhealth.com or use the dedicated message service available through the App.

In the event of any fraud or scams, you may report a complaint to your national data protection agency (the FTC) as described in section 7.