Physio.me Privacy Notice and Consent - Patient
Introduction
Biogen MA, Inc. of 225 Binney Street, Cambridge, MA 02142, USA (“Biogen”) has developed the platform Physio.me (the “Platform”), a digital physiotherapy companion that offers users the ability to perform tailored, secure exercises at home, so patients can achieve their goals, measure progress, and share progress with their physiotherapists. The Platform consists of a mobile app where patients can access information about their assigned exercises and track their progress; and a web solution where their physiotherapist can assign exercises and track their patient’s progress.
This privacy notice explains how Biogen would like to process your personal data (meaning any data relating to you as a person and your personal circumstances) on the Platform and how you may give your consent to this processing.
The granting of your consent is entirely voluntary and may be withdrawn at any time. You will not suffer any negative consequence if you choose not to give your consent, however we will not be able to register you if you do not. If you wish to continue, please read the following information carefully and provide your consent by ticking the relevant tick box during registration.
What data we collect about you?
Biogen will collect and process the following data about you when you use the Platform:
- first name
- last name
- e-mail address
- username and password
- gender
- date of birth
- place of birth
- phone number
- disease and level of progression
- information about your exercise plan
- data related to your health and wellbeing (fatigue, mood, level of pain, etc.)
How we use your personal data
The Platform needs certain personal data such as first & last name, e-mail address and password to create a profile for you, for you to log in and out and for you to use its features. Further personal data which you input is required for the Platform’s features to function. Your profile will be accessed by your physiotherapist who will be able to track your progress and to assign different exercises to you as part of your treatment programme.
Additionally, we may use aggregated anonymous data to optimise user experiences with the Platform and to enhance and improve the Platform’s functionality. We may use aggregated anonymous data about usage of the Platform in external communications such as publications or conferences.
Marketing communicationsYou also have the choice to consent to receive communications from Biogen by e-mail, SMS or other channels to keep you informed. It is your decision whether you provide your consent. If you do not consent you may still use the app, but this means you will not be able to receive such communications. You may withdraw your consent to this in the app settings. Withdrawing your consent means we will no longer send you such communications.
How we share your information and international transfers
Biogen engages service providers to assist it in the administration of its data processing activities in relation to the Platform (known as “data processors”). These include the companies which: (a) host the Platform and your personal data in the cloud and provide Biogen with data storage facilities; (b) provide application development services for the purposes of the Platform; (c) provide support centre solutions; and (d) provide direct mailing services.
Biogen may also share your personal data with other companies in the Biogen group including Biogen International GmbH, Neuhofstrasse 30, 6340 Baar, Switzerland and Biogen France SAS of 1 Passerelle des Reflets, 92400 Courbevoie, France. If a third party acquires all or part of Biogen's business or assets, then your personal data may be disclosed in connection with that sale.
Ensuring protection of your data
The transfers mentioned above may include transfers outside of your country to countries outside the European Economic Area (EEA). Biogen takes appropriate steps to ensure your data is adequately protected if transferred to such countries. For example, Switzerland is a country deemed to provide an adequate level of data protection under its data protection laws by the European Commission. Biogen otherwise has Standard Contractual Clauses, or equivalent measures, in place where necessary to provide an adequate level of data protection. Upon your request, Biogen will provide you with a list of all recipients of your personal data and/or further information on any data transfer agreements with recipients outside the EEA.
How we store your personal data
We will only retain your personal data for as long as it is necessary for the purpose for which that data was collected and to the extent permitted by applicable laws. When we no longer need to use your personal data, we will remove it from our systems and records and/or take steps to anonymise it so that you can no longer be identified from it (unless we need to keep your personal data to comply with legal or regulatory obligations to which we are subject).
Giving and withdrawing your consent
Because Physio.me is designed for patients, we process your health-data from the moment you register and begin to use it. We therefore require your explicit consent for this data processing under data protection law, as set out in detail under this privacy notice. You give your consent by ticking the box in the registration process. You may withdraw your consent by deleting the account under “personal details” within the “profile” section in the app. Your account will then be deleted and you will no longer be able to use the Platform. If you decide to withdraw your consent, this does not affect the lawfulness of the processing before the withdrawal of consent.
Your rights
You may contact Biogen at any time to exercise the following rights under data protection law:
- access and receive your personal data or require information about the personal data that we hold about you;
- ask us to restrict our processing of your personal data;
- ask for your personal data to be provided on a portable basis; and
- ask us to correct or erase information we hold about you.
Please note that some of these rights are limited by applicable data protection law and we have the right to collect, process and hold your personal data to perform our legal obligations. You may, should you feel it necessary, lodge a complaint with your local data protection authority if you feel your privacy rights have been infringed.
Contact Biogen
Under European data protection law, a “controller” is the legal entity that is responsible for protecting your personal data and helping you to exercise your data protection rights. Biogen and your physiotherapist will each act as separate controllers. Biogen will be controller for the purposes of providing the services of the Platform while your physiotherapist will be controller for the purposes related to your standard care and treatment as a healthcare professional.
Biogen’s EU data protection representative is its affiliated company Biogen GmbH of Carl-Zeiss-Ring 6, 85737 Ismaning, Germany. If, at any time, you have questions or concerns about this Privacy Notice or the processing of your personal data, you can contact Biogen’s Data Protection Officer at privacy@biogen.com.