Privacy Statement

The myBETAapp™ is an application offered by Bayer AG, Leverkusen, Germany ("we" or "us"), providing support to patients of Multiple Sclerosis by supporting the responsible use of Betaseron® (interferon beta-1b), tracking the injection history and offering multiple sclerosis related educational information. With this Privacy Statement, we would like to inform you about how we handle your personal data.

Which personal data is being handled?
When you use myBETAapp™ and subject to your prior explicit consent, the following personal data will be collected, processed and used:

Please note that the fact that you are using Betaseron® and myBETAapp™ also reveals information about your health status.

How and where is my personal data stored and transferred to?
The myBETAapp™ is a cloud-based system. Hence, subject to your prior explicit consent, the above described personal data will be transmitted to and stored on a database located in Germany.

In case you make use of our call center services, the information you give to the operator will be transferred to our service provider located in the USA. In case you inquire information about your personal data stored on the database in Germany, the call center provider will receive respective information from our hosting service provider. However, we have taken appropriate safeguards designed to protect your personal data by having concluded the standard data protection clauses adopted by the EU Commission with our call center provider.

Who has access to my personal data?
Neither we as the sponsor of the BETACONNECT™ products, nor Medicom Innovation Partner a/s ("Medicom") - who has developed the BETACONNECT™ auto-injector, the myBETAapp™ and the BETACONNECT™ Navigator for us and who is responsible for these medical devices as legal manufacturer - wish to have access to your personal data.

Therefore, we have contracted the following service providers who handle your personal data on our behalf and who are either contractually or by law prohibited to provide us or Medicom with any access to your personal data:

For which purpose is my personal data handled?
Our service providers collect, process and use your personal data exclusively in order to be able to provide to you the functionalities of myBETAapp™ or for technical support reasons.

Furthermore, TWT Digital Health generates and shares with us and other companies of the Bayer Group aggregated data of at least 25 Betaseron® patients for statistical purposes (e.g. usage statistics). However, due to the aggregation process, the data we are using is anonymous and can thus not be used to identify any specific individual.

Beta Nurses and your HCP may access your personal data for the sole purposes of treatment and healthcare operations. This access may be in the form of exporting the data and printing the data for the Beta Nurse or HCP to use the data for treatment purposes.

Finally, in case you report any untoward medical occurrence ("adverse event"), we are by law obliged to process and report the respective adverse event information to the competent regulatory authorities. However, these reports only contain your information in a pseudonymized form and thus no information that allows someone to directly identify you.

How long is my personal data stored and when will it be deleted?
Injection data older than 7 years will be deleted automatically. All other personal data will not be deleted automatically, but you can irrevocably delete your account including all data at any time by using the "Delete Account" functionality in the Settings.

What are my rights?
You have the right to

Who can I contact in case I have a data privacy related question or want to exercise my rights?
Since we have limited the access to your personal data to our service providers, we are not able to handle your data privacy related requests ourselves. Thus, please address any data privacy related request to our call center, who will process your requests on our behalf, using the following contact information:

Telephone: 1-844-351-5696 (Toll-free phone number)

You can reach the data protection officer of Bayer AG using the following address:
Data Protection Officer
Bayer AG
51373 Leverkusen, Germany

Changes to this Privacy Statement
We will update this Privacy Statement from time to time to reflect changes to our practices, technology, legal requirements and other factors. Please check the "Last Updated" legend at the bottom of this page to see when this Privacy Statement was last revised.

Last Updated: October 1st, 2018