CARE for MDD Privacy Policy
Welcome to the Otsuka Pharmaceutical Europe Ltd. (“Otsuka/we/us/our”) Privacy Policy (“Privacy Policy”) for the CARE for MDD smart phone therapeutic program application and associated online services (“Application”). CARE for MDD is a digital therapeutic intended for the treatment of major depressive disorder (MDD) in adults. It is intended for use alongside standard of care and supported by a healthcare professional. This Privacy Policy applies to users of the Application (“you/your”) and explains how your personal data is collected, used, shared, and protected by Otsuka.
Otsuka is the data controller of your personal data and has an address at 2 Windsor Dials, Arthur Road, Windsor SL4 1RS, UK which is registered with the Information Commissioner’s Office with registration number Z9584844.
Please read this Privacy Policy carefully. If you do not agree with the contents, please refrain from using the Application. Please see our Terms and Conditions regarding your legal rights in any dispute involving our Application. You should also read any other documents that we give you, that might apply to our use of your personal data in specific circumstances from time to time.
1. About the Application
The Application must be installed on your mobile device for use, and certain personal data and/or special category personal data will be processed by Otsuka and its third parties, including its partners and services providers, as described in this Privacy Policy, in order to provide the Application. To begin using the Application, you will need to enter an access code provided to you by or on behalf of Otsuka. You will then be prompted to create a user account, using your name, mobile phone number and email address. In order to protect your privacy, do not share your password with anyone. As part of using the Application, you will receive periodic SMS text messages, such as personalised messages and reminders about your treatment. Although we believe this feature significantly enhances your experience of CARE for MDD, you may opt-out of receiving these messages via SMS text by replying STOP to any of the messages that you have received. We may also ask for your consent to participate in surveys, questionnaires, and other activities concerning your use of the Application via SMS text messages and other methods. Please note that SMS text messages are not considered to be completely secure forms of transmission and are not always encrypted.2. Data Collection and How We Use Your Personal Data
We collect different categories of personal data when you use the Application, as described in the table below. We use your personal data for a number of different purposes. We must always have a “lawful basis” (i.e. a reason or justification, prescribed by law) for processing your personal data. The table below sets out the purposes for which we process different categories of personal data when you use the Application and the corresponding lawful basis for that processing. For some processing activities, we consider that more than one lawful basis may be relevant – depending on the circumstances.- Category of data: Contact information, i.e. Your name, mobile phone number, e-mail address and access code
- Purpose of processing: Registration
- Lawful basis: Performance of a contract
- Category of data: Health information, i.e. Your usage of the Application
- Purpose of processing: Provision of the application
- Lawful basis: Explicit consent
- Category of data: Technical information, e.g., password, IP address, device identifier, model, operating system version, location information, device time zone information
- Purpose of processing: Provision of the Application
- Lawful basis: Performance of a contract
- Category of data: Usage information, i.e. Your activity within the Application
- Purpose of processing: Research, product development, analysis, modeling
- Lawful basis: Legitimate interests
- Category of data: Contact information, i.e. Your name, mobile phone number and e-mail address
- Purpose of processing: Sending personalised messages and reminders about treatment
- Lawful basis: Legitimate interests
- To Comply with Applicable Law. We may use and share personal data with third parties if we believe that an applicable law, rule or regulation requires us to do so. We will also make our internal practices, books and records relating to our use and disclosure of personal data available to applicable regulators in compliance with applicable laws.
- To Respond to Legal Requests and Process. We may use and share personal data with third parties to respond to and/or comply with a legal request or similar process.
- To Protect Our Legal Rights. We may use and share personal data with third parties to establish and protect our rights, privacy, safety or property, security and/or that of our affiliates, you or others, or to defend against legal claims.
- To Investigate or Address Suspected Wrongdoing. We may use and share personal data with third parties when we believe it is necessary and in our legitimate interests to investigate, prevent or take action regarding safety and security issues, illegal activities, suspected fraud or situations involving potential threats to the physical safety of any person.
- In Connection with Corporate Changes. We may use and share your personal data with third parties if Otsuka is involved in a merger, acquisition, sale of all or a portion of its assets, bankruptcy or other corporate restructuring.
3. How Personal Data May Be Disclosed and Recipients of the Data
We use and share your personal data as described in this Privacy Policy, and otherwise pursuant to your consent or direction. Specifically, we may use and share your personal data consistent with applicable laws for the following purposes:- We may share certain elements of your personal data with your healthcare professional, if authorised by you.
- We may share your personal data with our affiliates and third parties, including to perform a technological, business, or other professional function for us (examples include software development, information technology services, maintenance, and hosting our Application, performance and analytics, communication services, and customer support). We only provide our affiliates and third parties with the necessary information required to perform their functions.
- We also may disclose information about you for the essential purposes identified above to regulators (e.g., public health authorities), including but not limited to where we are required to do so by law or legal process, to prevent harm or financial loss, to investigate or address fraudulent or illegal activity, or for safety and security reasons.
- We reserve the right to transfer the information we maintain to buyers or other third parties in the event we sell or transfer all or a portion of our organisation or assets. If we engage in such a sale or transfer, we will make reasonable efforts to direct the recipient to use your personal data, to the extent it forms part of a sale or transfer, in a manner that is consistent with this Privacy Policy.
4. Your Rights
You have several rights in relation to your personal data, subject to certain conditions and/or restrictions. These rights are:- The right to be informed
You have the right to be provided with clear, transparent and easily understandable information about how your personal data is used and your rights in relation to your data. This is provided through this Privacy Policy and any other privacy policies or notices (including updates) we may provide to you from time to time. - The right of access
You have the right to obtain confirmation as to whether or not your personal data are being processed and, if so, access to such data. - The right to rectification
You have the right to have your personal data corrected if it is inaccurate or incomplete. - The right to erasure
You have the right to request the deletion of your personal data. This is not an absolute right and there are certain exceptions. For example, we may have a legal obligation which requires us to keep certain personal data. - The right to restrict processing
You have the right to ‘block’ or ‘suppress’ further use of your personal data in certain circumstances. When processing is restricted, we can still store your information, but may not use it further. Please note that your right to restrict processing is limited in certain situations; for example, when you contest the accuracy of your personal data processed by us or where we no longer need to process your personal data however you need it for a legal claim. - The right to data portability
You have the right to receive your personal data, provided to us, in a structured, commonly used and machine-readable format and to have such data passed on to another data controller. Please be aware this right only exists where we process your personal data on the basis of your consent or pursuant to a contract and such processing is carried out by automated means. - The right to object
You have the right to object to our processing of your personal data in certain circumstances such as when we rely on our legitimate interests. Otsuka may, however, assert compelling legitimate grounds for the continued processing of your personal data, or where we require continued processing for the establishment, exercise or defence of legal claims. If this is the case, we will inform you in a timely manner. - The right to withdraw consent
Where your personal data is processed based on your consent, you have the right to withdraw your consent at any time. If exercised, this will not affect the lawfulness of processing prior to withdrawal. - The right to lodge a complaint with a data protection authority
You have the right to complain to a data protection authority about our collection and use of personal data. For more information, please contact your local data protection authority.
Contact details for the UK data protection authority (the Information Commissioner’s Office (“ICO”) can be found here.
For questions, or to request to exercise any of these choices, please contact us by emailing privacy@otsuka-europe.com
5. Retention
We will only retain your personal data for a limited period of time, and for no longer than is necessary for the purposes for which we are processing the data for. This will depend on a number of factors, including:- any laws or regulations that we are required to follow;
- whether we are in a legal or other type of dispute with each other or any third party which requires the retention of certain data (e.g., when we are subject to a legal hold);
- the type of information that we hold about you; and
- whether we are asked by you or a regulatory authority to keep your personal data for a valid reason.
6. International Data Transfers
Since Otsuka is part of a global company, we will sometimes need to transfer your personal data outside the United Kingdom, in particular to the European Union, the USA and our headquarters in Japan. We will only make that transfer if:- that country ensures an adequate level of protection for your personal data;
- the recipient or recipient country is subject to an approved certification mechanism or code of conduct with binding and enforceable commitments which amount to appropriate safeguards for your personal data;
- we have put in place appropriate safeguards to protect your personal data, such as a contract with the person or entity receiving your personal data which incorporates specific provisions as directed by the ICO;
- the transfer is permitted by applicable laws; or
- you explicitly consent to the transfer.
7. Security
- Application Measures. We use appropriate technical and organisational measures to protect the personal data that we collect and process about you. The measures we use are designed to provide a level of security appropriate to the risk of processing your data. Specific measures we use include designing and testing the Application rigorously, encrypting data in transit and at rest and having an independent, external and CREST approved third party to periodically test our systems for security vulnerabilities.
- Your Responsibilities. You are responsible for the security of your Application password. Do not share your password with anyone. You are also responsible for safeguarding and securing your smartphone. If you leave your smartphone unattended, or if it is lost or stolen, you understand that your personal data in the Application may be accessible to others.