Privacy Policy
Privacy Policy for the Impella Mobile Application ("Privacy Notice")
Status: February 2023
Background
This service (hereinafter "App") is provided by
Abiomed, Inc.
22 Cherry Hill Drive
Danvers, MA 01923
United States
+1 (978) 646-1400
(hereinafter "we" or "us").
If you have any questions, requests or concerns about your privacy, the protection of your data, or the terms of this Policy, please contact us via the "Contact" section below or through Abiomed's privacy web form.
Within the App, we enable you to retrieve important information about the Impella® family of heart pumps for healthcare professionals.
When you use the App, we may collect and process personal data about you. Personal data means any information relating to an identified or identifiable natural person. Since the protection of your privacy when using the App is important to us, this Policy was prepared to govern which personal data we process when you use the App and how we handle this data.
You can access this Policy at any time under the menu item "[Designation]" within the App.
Please note that the following information includes applicable legal requirements in the United States. This Policy does not address uses of the App or the use of data outside of the United States or by individuals other than U.S. citizens and residents.
1. Information on the processing of your data
1.1 Information collected during the download
When downloading the App, certain required information is transmitted to the app store selected by you (e.g., Google Play or Apple App Store), in particular the username, the e-mail address, the customer number of your account, the time of the download, payment information and the individual device identification number may be processed. The processing of this data is carried out exclusively by the respective app store and is beyond our control. Please note and read the corresponding information on data protection and terms of use provided via the app store you are using.
App Store:
https://www.apple.com/legal/privacy/data/en/app-store/
https://support.apple.com/en-us/HT211970
Google PlayStore:
https://support.google.com/googleplay/answer/11416267?hl=en&co=GENIE.Platform%3DAndroid
1.2 Information that is collected automatically
When opening the App, we automatically collect certain data that is required to use the App. This includes:
- Access data (email and password)
- Random (generated by Firebase or Okta) unique user ID
- Device information (device ID, device type, device-specific settings and app settings as well as app properties, the browser type and operating system).
- Date and time
- IP address
- Location
- Language setting
- Referrer
- Amount of data transferred and the message whether the data exchange was complete, crash of the App, including error messages
- User interactions (views accessed, content opened or downloaded, call-to-actions).
This data is automatically transmitted to us,
(1) to provide you with the Service and related features;
(2) improve the functions and performance features of the App; and
(3) Prevent and eliminate misuse and malfunctions.
The App does not set cookies. However, user interactions are tracked using a user ID for quantitative analysis of App usage.
Consent to tracking within the App via the end device you are using (Apple/Android - systems)
The providers of the end device you use to run the App (e.g., a smartphone) offer different technologies for requesting and setting your consent for the tracking of information and data when using apps. A request for consent can be made when opening the App for the first time and then managed via the settings of your personal device in the data protection/privacy area under the respective app, including for the App. Abiomed has no influence on these technologies, in particular we cannot revise to what extent app tracking is allowed or prevented by using these settings. We therefore ask you to familiarize yourself with the settings and associated information of your respective end device provider.
Some applications may transmit “do-not-track” signals. Our App does not currently monitor or respond to these “do-not-track” signals.
1.3 Creation of a user account (registration) and login
When you create a user account or register, we use your access data (e-mail address and password) to grant you access to your user account and to manage it ("mandatory data"). Mandatory Data within the registration process are marked with an asterisk and are required for the conclusion of the Terms of Use. Since the App is aimed at healthcare professionals and the content is accordingly geared towards this target audience, you will also be asked to provide profession-related information during registration and asked to confirm this. If you do not provide this data or do not wish to confirm your professional expertise, you will not be able to create a user account.
In addition, you can provide voluntary information about your field of study and interests as part of the registration process. Insofar as you authenticate yourself via biometric features (e.g. fingerprint, facial geometry), these are also processed. However, these are only stored locally and encrypted on your end device.
We use the mandatory information to authenticate you when you log in and to follow up on requests to reset your password. We process and use the information you provide during registration or login to (1) verify your eligibility to manage the User Account; (2) enforce the App's Terms of Use and any rights and obligations associated therewith; and (3) contact you to send you technical or legal notices, updates, security messages, or other communications relating to, for example, the management of the User Account.
We use voluntary information to display relevant information within the App according to the settings you have made.
1.4 Use of the app
Within the App, you can manage and edit your personal information in your profile. This Information includes in particular:
- First and last name
- Password
- Country
- Hospital/Facility
- Profession and specialty
- Interests
- Notification selection
The App also requires the following permissions :
Internet access: This is required to store your edits on our servers and to provide and update information and functions.
2. Disclosure and transmission of data
Apart from those situations expressly disclosed in this Policy, your personal data will not be transferred by us to any third-party without your express prior consent, unless such transfer is expressly permitted or otherwise required by law.
2.1 Intracompany disclosure
The data you provide during registration and on your profile will be shared within the Abiomed group of companies for internal administrative purposes, including joint customer support and marketing of Abiomed and its products.
2.2 Business transfer
As our business evolves, we may change the structure of our business by changing its legal structure, establishing, buying or selling subsidiaries, divisions or components. In such transactions, customer information may be transferred along with the part of the company being transferred. For any transfer of personal information to third parties to the extent described above, we will ensure that it is done in accordance with this Policy and applicable data protection laws.
2.3 Disclosure for the fulfillment of a legal obligation and for the assertion, exercise and defense of legal claims
If it is necessary to clarify illegal or abusive use of the App or for legal prosecution, personal data will be forwarded to law enforcement agencies or other authorities and, if necessary, to harmed third parties or legal advisors. However, this only happens if there are indications of unlawful or abusive behavior. A transfer may also take place if this serves the enforcement of terms of use or other legal claims. We are also legally obligated to provide information to certain public authorities upon request. These are law enforcement agencies, authorities that prosecute administrative offenses subject to fines, and the tax authorities.
2.4 Processor
We rely on contractually affiliated companies of the Abiomed Group including the following third-party companies and external service providers to provide our service:
- Google LLC for authentication via Firebase Authentication
- Google LLC and Google Ireland Limited for quantitative analysis of App usage
- Okta Inc. for authentication via Okta Authentication
- HubSpot Inc. for central internal management and customer support
- Veeva Systems Inc. as a global content delivery network to deliver media content
3. Data storage period
We delete or anonymize your personal data as soon as they are no longer required for the purposes for which we have collected or used them in accordance with the above paragraphs. Unless otherwise specified, we store your personal data for the duration of the usage or contractual relationship via the App plus a period of 14 days, during which we keep backup copies after deletion, unless this data is needed longer for criminal prosecution or to secure, assert or enforce legal claims.
Specific statements in this Policy or legal requirements for the retention and deletion of personal data, in particular data that we are obligated to retain for tax or commercial law reasons, remain unaffected.
4. Data security
We secure our systems through technical and organizational measures against the loss, destruction, access, amendment or distribution of your personal data by unauthorized persons. However, no transmission is ever fully secure or error-free.
5. Right to correct data
You have the right to demand that we immediately correct the personal data concerning you if it is incorrect. Within the App, you can manage and edit your personal information in your profile yourself at any time.
If you have any further questions or wish to exercise your right to rectification, please contact us using the contact addresses provided or use the data protection web form.
6. Right to deletion
You have the right to request that we delete the personal data concerning you if your personal data is no longer necessary for the purposes for which it was collected or otherwise processed. For the period of data storage, please also see section 4 of this privacy policy.
To exercise your right of deletion, you can request the deletion of your account in the App at any time under Profile Management/Interests or please contact us at the indicated contact addresses or use our data protection web form.
7. Additional privacy notice for California residents
The California Consumer Privacy Act (CCPA) and California Civil Code § 1798.83 provide residents of the U.S. State of California with specific rights regarding their personal data/information. For more information about what Abiomed is doing to protect your rights, you may go to our Additional Privacy Notice for California Residents.
California Civil Code Section § 1798.83
California Civil Code Section § 1798.83 permits California residents that are our customers to request certain information regarding Abiomed’s disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please send an e-mail to [email protected]
California Consumer Privacy Act (CCPA)
Through the App we may collect and use personal data from California residents ("Personal Information," as defined by the CCPA) in the following Personal Information categories:
- Identifiers such as a real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, or other similar identifiers;
- Personal Information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e));
- Commercial information, including records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies;
- Biometric information;
- Internet or other electronic network activity information;
- Geolocation data;
- Audio, electronic, visual, thermal, olfactory, or similar information;
- Professional or employment-related information;
- Non-public education information;
- Inferences drawn from other Personal Information to create a profile about a consumer reflecting the consumer’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes; and
- "Sensitive Personal Information" (as defined by the CCPA)
We obtain the Personal Information directly from you, directly and indirectly from activity through our App, or from third parties in connection with the provision of services.
We may use the Personal Information we collect for one or more of the business purposes described in this Privacy Notice.
For information about long we retain your Personal Information, please see the "Data storage period" section of this Privacy Notice.
We do not “sell“(as such term is defined by the CCPA) your Personal Information. We do not "share" (as such term is defined by the CCPA) your Personal Information.
To exercise your CCPA rights, please submit a request to us via our privacy webform, by telephone at: +1 978.646.1400, by email at: [email protected] or by mail at Chief Compliance Officer, Abiomed Inc., 22 Cherry Hill Drive, Danvers, MA 01923, Attn: CCPA Rights.
When you submit a request to exercise your CCPA rights, we will do our best to respond to your request as soon as possible after we verify your identity, and, in any event, no later than 45 days after receiving your request.
8. Additional privacy notice for Nevada residents
Section 603A of the Nevada Revised Statutes permits Nevada residents who are our "consumers" to at any time, submit a request to an "operator" of a website or online service in Nevada directing the operator not to make any sale of any "covered information" the operator has collected or will collect about the consumer. We do not currently "sell" or plan to sell covered information as defined in the Nevada law. If you are a Nevada resident, you may submit a verified request by contacting us by sending an email to [email protected] or contacting us through our privacy webform at https://www.abiomed.com/privacy-policy/webform to opt out of sales and we will record your instructions and incorporate them in the future if our policy changes. We will respond within the time required by law.
10. Additional U.S. state privacy laws
Some additional state laws may provide residents specific rights, subject to some limitations, exclusions and the verification of your identity. These rights may include, but not be limited to: (1) the right to know whether we are processing your personal data; (2) the right to access the personal data that we process; (3) the right to correct inaccuracies in your personal data that we process; (4) the right to delete your personal data; (5) the right to obtain a copy of your personal data; (6) the right to opt-out of the processing of your personal data for targeted advertising, profiling activity and the sale of personal data; (7) the right to not be discriminated against for exercising your rights; and (8) the right to appeal a decision with regard to a request you make. To exercise your state privacy rights (as applicable), please contact us as described in the "Contact" section below, emailing [email protected] or contacting us through our privacy web form.
We are committed to compliance with state privacy laws and continues to monitor developments.
11. Children
Abiomed cares about protecting the online privacy of children. We will not intentionally collect any personal data (such as a child’s name or e-mail address) from children under the age of 13. If you think that we have collected personal information from a child under the age of 13, please contact us using Abiomed’s Privacy Webform or at [email protected].
12. Contact
If you have any questions or comments about our handling of your personal data, or if you wish to exercise the rights as a data subject set out in this Privacy Notice, please contact:
Chief Compliance Officer at the following contact information at: [email protected]
If you have any questions or comments about the practical use and operation of the App, or if you have any support requests, please contact: [email protected]
13. Changes to this privacy policy
We always keep this privacy policy up to date. It was last updated February 15, 2023. The current version of the privacy policy is always available within the app.
NPS - 624