TERAPIÙ

INFORMATION ON THE PROCESSING OF PERSONAL DATA

Last update: 01.03.2024

The use of the TERAPIÙ Service involves the collection and processing (treatment) of some of your personal data. Before you give us your data, we invite you to carefully read the following information, provided pursuant to art. 13 of EU Regulation 2016/679, which describes the methods of management and treatment applied by Bayer S.p.A. (Data Controller) to the personal data concerning you, resulting from the use of TERAPIÙ.

  1. Identity and Contact Details of the Data Controller

The Data Controller is Bayer S.p.A. (Tax ID No. 05849130157), with registered office at Viale Certosa No. 210, (20156) Milan, Italy.

  1. The data protection officer

The data protection officer of Bayer S.p.A. can be contacted by sending an email to the following email address: italy.infoprivacy@bayer.com

  1. Type of personal data processed

Using the TERAPIÙ Service, some of your personal data, including data capable of revealing your health status, will be processed in accordance with current legislation on the protection of personal data. The use of the App, the web application, and the Service, is particularly connected to the processing of the following types of data:

  1. data relating to your authentication (email address and password);
  2. data relating to your authentication (email address and password); purely technical data relating to the computer device used to access the Service (such as, for example: the IMEI code identifying your mobile device, information relating to the version of the operating system installed on your computer system, the IP address identifying the network host, etc.) and to the use of the Service itself;
  3. Health-related data, such as: information regarding current or past illnesses or adverse events, details about the medications you must take and have taken, data related to blood pressure, cholesterol levels, blood sugar levels, any food intolerances or allergies, electrolyte levels, triglyceride levels, HDL, LDL, platelet count, your height and weight, and your smoking habits.
  4. General information such as: age and gender
  5. Images taken from your mobile device containing information about the medications you are taking and your profile picture
  6. When you access our website, your browser will transfer certain information to our web server. This is necessary for technical reasons and to provide you with the information you request. To facilitate access to our website, the following information is collected, stored temporarily, and used:IP Address
    • IP address
    • Date and time of access
    • Time zone difference to Greenwich Mean Time (GMT)
    • Content of request (specific site)
    • Status of access/HTTP status code
    • Transferred volume of data
    • Website requesting access
    • Browser, language settings, operating system version, and browser version
    Furthermore, to protect our legitimate interests, we will retain this information for a limited period of time in order to be able to initiate monitoring of personal data in the event of actual or attempted unauthorized access to our servers (Art. 6(1)(f) General Data Protection Regulation).
  1. Purposes and Legal Bases for Processing

The data related to your authentication (a) and those purely technical in nature concerning the computer device used to access the Service and the use of the Service itself (b) will be processed for purposes strictly connected and instrumental to the execution of the App, web application, and the Service (including authorizing your access to the Service, identifying your user account within the Service, enabling your device to interconnect with the computer systems queried when receiving and sending requested information and data, protecting data from unauthorized access), within the contractual relationship between you and the Data Controller. The legal basis for such processing is to be found in Art. 6, para. 1, letter b) of the EU Regulation 2016/679. These data may also be processed to fulfill any legal obligations, as well as - after complete anonymization - to compile statistical and aggregate information on the use of the Service. The personal data and additional data, including special data, concerning you (c) and the data related to your health (e) will be processed to perform specific functionalities and provide you with the services inherent to the TERAPIÙ Service, aimed at supporting your therapeutic adherence journey. In particular, the personal data and additional data, including special data, concerning you (c), are collected and processed to better define your user profile, in order to optimize the adherence to the therapeutic plan through personalized management of your user account. The data related to your health (e) that you may provide, modify, and update, even during the use of the Service, are processed to support your therapeutic adherence (management of medication intake processes, management of your therapy history), in line with the purposes of the Service. The processing operations concerning your personal data, so-called "common" data, are carried out within the framework of the contractual relationship between you and the Data Controller, which involves the provision of the Service. The legal basis for such processing is to be found in Art. 6, para. 1, letter b) of the EU Regulation 2016/679. The processing of your special personal data, including health-related data, is carried out solely upon your explicit and specific consent for processing. The legal basis (consensual) for such processing is to be found in Art. 9, para. 2, letter b) of the EU Regulation 2016/679. Contact data (d), such as email address and mobile phone number, may be processed for different purposes, subject to different legal bases. Your email address may be processed to manage the recovery processes of your authentication credentials. This processing takes place within the contractual relationship between you and the Data Controller, and the legal basis is represented by Art. 6, para. 1, letter b) of the EU Regulation 2016/679. Your email address may also be processed, if you have decided to subscribe to the newsletter service, to send you related communications. The processing in question is carried out solely upon your specific consent; the legal basis (consensual) for processing is to be found in Art. 9, para. 2, letter b) of the EU Regulation 2016/679. Furthermore, your email address may be processed to invite you to participate in anonymous surveys, in which personal data is not collected. This processing is carried out solely to best tailor our services to your needs; the legal basis for processing is to be found in GDPR Art. 6 (1) f) – Assessment of interests of the EU Regulation 2016/679. Your mobile phone number may be processed if you intend to receive notifications, in the form of messages or other prompt communications (so-called push notifications), such as reminders regarding medication intake. This processing is carried out solely upon your specific consent; the legal basis (consensual) for processing is to be found in Art. 9, para. 2, letter b) of the EU Regulation 2016/679. Finally, your personal data, including special data falling under categories c (personal data and additional data, also of a special nature, concerning you), d (contact data), and e (data related to your health), may be processed to fulfill any request made by you for the provision and communication of such information to another party accessing the Service as your "caregiver." This processing is carried out solely upon your specific consent; the legal basis (consensual) for processing is to be found in Art. 9, para. 2, letter b) of the EU Regulation 2016/679. General data (f) are processed on the basis of legitimate interest, according to Art. 6, para. 1, letter b) of the EU Regulation 2016/679. The data will be processed using the Google Analytics tool to tailor the offering to application users. Based on Article 6, paragraph 1, letter a) of the General Data Protection Regulation, you may, on a voluntary basis, provide access to your camera to enable the integrated camera features (g). Through our services, you will be able to take a photo and add it to your profile, as well as take a photo of the medications you are taking to improve medication management. The collection of information about medication intake is subject to your explicit consent (Article 6, paragraph 1, letter a) of the General Data Protection Regulation). If you disable this feature, you will not be able to use this specific functionality, but our main services will remain available. The shared information will be stored on our server and deleted once your user account is removed.

  1. Data Processing Methods

The processing will be carried out using electronic or automated means, in accordance with the principles of necessity and minimization, and only for the time strictly required to achieve the intended purposes. The data controller adopts technical and organizational measures to ensure a level of security appropriate to the type of data processed.

  1. Recipients and Scope of Data Communication

Your data will be processed solely by the Data Controller, any Data Processors (such as IT service providers on behalf of the Data Controller) specifically appointed in accordance with current legal provisions and within the limits of the tasks and functions conferred upon them, and by their specifically trained staff, in order to ensure the same level of security offered by the Data Controller. Your data, upon your specific request and expression of consent to the processing, may be made available, always through the Service and within the context of the security measures guaranteed by it, to another party accessing the Service, as your "caregiver." Subject to the above, your data will not be disclosed to third parties, except to fulfill any specific legal obligations, and will not be disseminated for any reason.

  1. Transfer of Personal Data to Countries Outside the European Union

The data collected and processed will not be transferred to companies or other entities outside the European territory.

  1. Nature of data provision

The provision of contact data (d), general data (f), and health-related data (e) is optional. You can provide and update the relevant data at any time. The failure or partial provision of data will not prevent access to the Service, but it will make it impossible to provide the main functions of the Service. If you do not provide the application with access to your device (g), you will not be able to use this specific function, but our main services will remain available.

  1. Data retention period

The processing operations of personal data resulting from the use of the App, web application, and the Service involve a data retention period equal to the period for which you intend to keep your profile and your user account active. The common and special personal data acquired and processed during the operation of the Service will essentially be retained as long as you intend to continue using the functionalities of the TERAPIÙ service. Considering the scope of the Service - also to protect your personal data in relation to possible unjustified retention periods - we advise you that, in the absence of at least one access to the Service for a period exceeding 150 (one hundred fifty) days, the user termination process will be initiated, after which all your personal data will be permanently deleted. After the considered retention periods have elapsed, personal data may only be further retained in compliance with specific legal obligations. Aggregated and anonymized data, on the other hand, may be retained indefinitely.

  1. Automated Processes and Profiling You

Your personal data will not be subject to any fully automated decision-making process, including profiling, which, according to the provisions of Art. 11, EU Regulation 2016/679, may have legal effects on you or significantly affect your person.

  1. Data Subject Rights and Exercise Methods

As the data subject, you have the right to exercise, in cases expressly provided for by law (Art. 15 et seq., EU Regulation 2016/679), the following rights:

  1. Request the data controller to access the personal data concerning you, and/or their possible correction or deletion;
  2. Request the data controller to limit the processing concerning you, or to object to the processing;
  3. Demand the so-called "portability" of data (or their communication in a structured, commonly used, and machine-readable format), also in order to communicate your personal data to another data controller;
  4. Revoke, at any time, the consent to the processing of your data (without prejudice to the lawfulness of the processing carried out before the revocation of consent);
  5. Submit a complaint to a supervisory authority (the Guarantor for the protection of personal data).

What Are Cookies?

This site uses so-called "cookies". Cookies are small text files stored in the memory of your device through your browser. They store certain information (such as language or preferred site settings) that your browser can (depending on the cookie's duration) transmit back to us on your next visit to our website.

What cookies do we use?

We distinguish between two categories of cookies: (1) functional cookies, without which the functionality of our website would be reduced, and (2) optional cookies used for website analysis and marketing purposes. The following table contains a detailed description of the optional cookies we use:

Strictly necessary cookies (for technical purposes)

Name Purpose and Content Lifespan Provider
ARRAffinity Used to distribute site traffic over several servers to optimize response times. Session terapiu.it
ARRAffinitySameSite Used to distribute site traffic over several servers to optimize response times. Session terapiu.it
G_ENABLED_IDPS Used to log in to the website securely with a Google account. 2913921 days terapiu.it
oauth2_cs::#.apps.googleusercontent.com Used to log in to the website securely with a Google account. Session accounts.google.com
TERA_CONSENT Used to store active cookie settings chosen by the user. 6 months terapiu.it
TERA_CONSENT_CLOSE Used to store the successful viewing of the cookie information banner. 6 months terapiu.it

Optional Cookies

Name Purpose and Content Lifespan Provider
Website analysis with Google These cookies assign a randomly generated ID to your device, allowing your device to be recognized the next time you log in.For details on website analysis with Google, please refer to the relevant section 6 Months Google Inc.

Change Cookie Settings

Subject to your consent

We will only use optional cookies if we have obtained your consent (Art. 6(1)(a) General Data Protection Regulation). Upon first access to our website, a banner will appear, asking you to consent to the setting of optional cookies. If you consent, we will place a cookie on your computer, and the banner will not be displayed again as long as the cookie is active. If you actively delete the cookie or it expires, the banner will reappear on your next visit to our website and ask for your consent again

How to prevent the installation of cookie

Of course, you can use our website without having cookies installed. In your browser, you can configure or completely disable the use of cookies at any time. However, this may lead to a limitation of functions or have a negative impact on the user-friendliness of our website. At any time, you can object to the installation of optional cookies using the "On/Off" option indicated in the previous table.

Website Analysis:

On our website, we use a web analytics service provided by Google Inc., 1600 Amphitheater Parkway, Mountain View, CA 94043, United States ("Google"). Google analyzes the usage of our website on our behalf. For this purpose, we use cookies as described in more detail in the previous table. The information collected by Google regarding the use of our website (such as the referring URL, pages visited by you, type of browser, language settings, operating system, and screen resolution) will be transmitted to a Google server in the United States, where it will be stored and analyzed. The respective results will then be made available to us in an anonymous form. During this process, your usage data will not be connected to your full IP address. We have activated the IP anonymization function on our website provided by Google, which will remove the last 8 bits (IPv4 type) or the last 80 bits (IPv6 type) of your IP address after each data transfer to Google. Additionally, Google is certified under the EU-US Privacy Shield (LINK to https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI), ensuring an adequate level of protection for personal data concerning the processing of personal data by Google in the United States. You can revoke your consent for web analysis at any time by downloading and installing the Google Browser Plugin or by managing your consents in the previous table, in which case an opt-out cookie will be set. Both options will prevent analysis as long as you use the browser in which the plugin is installed and until you disable the opt-out cookie.


For any questions regarding data privacy and/or your consent, or if you wish to exercise your rights, please contact our corporate data protection officer: Bayer S.p.A., Viale Certosa 130, 20156 Milan, Italy, or send an email to italy.infoprivacy@bayer.com

This Privacy Policy was drafted on 01/03/2024