Privacy Policy

Glooko logo

Privacy Policy

We at Glooko Inc. (“Glooko”) and Novo Nordisk Inc. (“Novo Nordisk”) (jointly “we,” “us,” “our”) respect your concerns about privacy. We know that you care about how your personal information is used and shared, and we take your privacy seriously.

By expressly accepting the Terms of Use and this Privacy Policy for the Cornerstones4Care® – Powered by Glooko App (the “App”) you acknowledge that you accept the practices and policies outlined in this Privacy Policy, including Glooko’s sharing of your Personal Information with Novo Nordisk so that Novo Nordisk may be able to provide you with and improve the App in collaboration with Glooko. Novo Nordisk also uses your Personal Information for other purposes, including performing analysis and research for the purpose of gaining insights and knowledge in order to improve medical care for you and others with similar conditions. Please see Section 3 b below for detailed information about Novo Nordisk’s use of your Personal Information. Glooko and Novo Nordisk rely on your consent as the legal basis for the collection and use of your Personal Information.

In addition to the other transfers described below, users with preexisting Cornerstones4Care online accounts also consent to the transfer of any data entered into such Cornerstones4Care online accounts to Glooko for the purposes of prepopulating data fields within the App to expedite the configuration process, and otherwise enhancing the user experience within the App.

Capitalized terms not defined herein shall be given the meaning set forth in our Terms of Use.

The App is made available to assist you in monitoring your blood glucose levels as well as tracking other data associated with managing diabetes. In order to use the App, you must register for the App.

This Privacy Policy outlines how Glooko collects your Personal Information, shares it with Novo Nordisk and how Glooko and Novo Nordisk are each using it for their own purposes independently of each other.

This Privacy Policy is organized according to the sections below:

1. What does this Privacy Policy Cover?
2. What Personal Information does Glooko collect and for what purpose?
3. Glooko’s sharing of Personal Information with Novo Nordisk and Novo Nordisk’s use of Personal Information

a) What information is shared with Novo Nordisk?

b) How does Novo Nordisk use your Personal Information?

c) Does Novo Nordisk share your Personal Information with third parties?

d) How long does Novo Nordisk store your Personal Information?

e) How does Novo Nordisk keep your Personal Information safe?

f) What are your rights specifically related to the sharing of your Personal Information with Novo Nordisk and Novo Nordisk’s use of your Personal Information?

g) Novo Nordisk’s contact information

4. Does Glooko share the Personal Information with anyone other than Novo Nordisk?

5. What about links to other third party sites and services?

6. How does Glooko keep your Personal Information safe?

7. What Personal Information stored by Glooko can I access?

8. What rights and choices do I have in relation to Glooko’s collection and use of your Personal Information?

9. Will I be notified of changes to your privacy practices?

10. How do I request access or changes/deletion of/ to Personal Information stored by Glooko?

11. How do I request alternate communication methods from Glooko?

12. Who can I contact with a privacy question to Glooko?

1. WHAT DOES THIS PRIVACY POLICY COVER?

This Privacy Policy covers Glooko’s and Novo Nordisk’s use of personally identifiable information (“Personal Information”) that Glooko collects when you use the App and then shares with Novo Nordisk. This Privacy Policy does not apply to the practices of companies that Glooko or Novo Nordisk do not own or control, or to individuals that Glooko or Novo Nordisk do not employ or manage.

2. WHAT PERSONAL INFORMATION DOES GLOOKO COLLECT AND FOR WHAT PURPOSE?

The information Glooko collects from you enables Glooko to (i) personalize and improve the App in collaboration with Novo Nordisk, including sharing Personal Information with Novo Nordisk, (ii) operate Glooko’s in-clinic offerings and MyGlooko web portal (“Glooko’s Other Services”), (iii) allow you to set up an account and profile for the App, (iv) provide you with information, updates, offers and other communications related to the App and Glooko’s Other Services, (v) analyze and report on the results of the App in an aggregate manner, and (vi) support your use of the App and Glooko’s Other Services. Glooko collects the following types of information from you:

a. Personal Information You Provide to Glooko:
Glooko receives and stores any information you enter in connection with the App or provide to Glooko in an authorized way. The types of Personal Information that are collected include your name, email address, password, phone number, IP address, mailing address, gender, age, weight, height, photograph, food, health and well-being related information (including without limitation blood glucose monitor readings and other sensitive medical information), type of glucose meter, continuous glucose monitor and exercise device you use. If you have purchased or have received any Glooko Hardware (such as Glooko’s MeterSync Blue device) and are using it in connection with the App, Glooko will also collect the Lot number of such Product. You can choose not to provide Glooko with certain information, but then you may not be able register with Glooko or take advantage of all of the App’s functionalities. You can choose to enable the Bluetooth Low Energy (BLE) syncing feature in the App in order to background sync your devices while the App is closed and to eliminate the need for manual syncing. BLE syncing collects your device and health data from a connected device for use in the App. The Android version of the App requires you to grant location permission in order to sync with BLE supported devices. Your location data will be collected in order to sync with BLE supported devices. Glooko does not store or use location data generated by your use of the BLE syncing feature.

If you complete an online form on glooko.com or you engage with Glooko Support, you will be asked to include Personal Information about yourself in order to help resolve your issue. You understand that providing your Personal Information over the Internet involves some risk and understand that in order to receive the support you are requesting, you are accepting that risk.

Please note that Glooko may use and share aggregated and anonymized data derived from your information, but not in a manner that would readily identify you personally:

b. Personal Information Collected Automatically:
Glooko receives and stores certain types of information whenever you interact with the App.

Generally, the App automatically collects usage information including the number and frequency of download of and visitors to the App, and its components, and how you interact with and use the App. Glooko only uses this data in aggregate form, that is, as a statistical measure, and not in a manner that would identify you personally. This type of aggregate data enables Glooko to figure out how parts of the App are used so that the App can be improved and made useful for as many users as possible.

If you are using the Product in connection with the App, you understand and acknowledge that when you use your blood glucose monitor, continuous glucose monitor, or exercise device in connection with the Product, readings from your monitor will be automatically uploaded to the App. These automatically collected readings are considered Personal Information for the purposes of this Privacy Policy. Further, when you seek support from Glooko, you understand and acknowledge that the individual(s) providing you with support may need to access these readings in order to diagnose the problem for which you are seeking support.

c. E-mail and Text Message Communications:
You may receive emails or text messages from Glooko or Novo Nordisk regarding your use of the App. If you do not want to receive email, text messages, or other mail from us, please contact us at [email protected] or simply opt-out from each message type. Please note that if you have opted out of receiving email or other messages from Glooko or Novo Nordisk, we may still need to contact you via email, but only with regard to the status of your account (for example, to notify you when your subscription is about to expire or to inform you of changes to this privacy policy); you cannot opt-out of these emails unless you cancel your account entirely.

3. GLOOKO’S SHARING OF PERSONAL INFORMATION WITH NOVO NORDISK AND NOVO NORDISK’S USE OF PERSONAL INFORMATION

As part of Glooko’s and Novo Nordisk’s collaboration in providing you with the App, Glooko shares all your Personal Information that is collected by Glooko in accordance with this Privacy Policy with Novo Nordisk.

Novo Nordisk uses your Personal Data for its own purposes independently of Glooko. This section of the Privacy Policy relates specifically to the sharing of your Personal Information with Novo Nordisk and how Novo Nordisk uses your Personal Information for those purposes. It does not relate to Glooko’s collection and use of your Personal Information as outlined in the remaining sections of this Privacy Policy.

a. What information is shared with Novo Nordisk?
Glooko shares with Novo Nordisk all your Personal Information that Glooko collects in accordance with this Privacy Policy when you use the App, also including Personal Information that is collected automatically as outlined above in Section 2 and by other means.

b. How does Novo Nordisk use your Personal Information?
Novo Nordisk is using your Personal Information for its own purposes, independently of Glooko. Novo Nordisk’s uses include (i) providing you with and improving the App in collaboration with Glooko, (ii) analysis, research and studies for the purpose of gaining insights and knowledge in order to improve medical care and develop additional offerings (either similar to the App or in other formats) for you and others with similar conditions in the future, (iii) analysis for the purpose of gaining insights and knowledge about how the App interacts and operates together with other Novo Nordisk products (e.g. Novo Nordisk insulin injection pens) in order to improve both Novo Nordisk products and the App, and (iv) supporting your use of the App, including providing you with information, updates and offers and other communications related to the App.

c. Does Novo Nordisk share your Personal Information with third parties?
Novo Nordisk may share your Personal Information with service providers that work on its behalf for the purposes described above. These service providers are contractually restricted from using the Personal Information that is shared with them beyond what is necessary to provide their services or as otherwise required by law.

Novo Nordisk may also share your Personal Information with independent third parties that Novo Nordisk may collaborate with in order to develop future offerings for other patients or users, including those with similar conditions as you.

When Novo Nordisk shares your Personal Information with such independent third parties, it will be pseudonymised (deidentified), which means that it will not have your name included in the information. It will also not include your address, telephone number or anything else that directly identifies you. The goal of this pseudonymisation (deidentification) process is to make it difficult to link the information to you without having access to an identification key. Novo Nordisk will endeavor to keep the identification key confidential at all times and will not deliberately share it with the third parties.

Protection of Novo Nordisk and Others: Novo Nordisk may release Personal Information when it believes in good faith that the release is necessary to comply with law, necessary for the establishment, exercise or defense of legal claims, or otherwise necessary for reasons of substantial public interest. This may include exchanging information with other companies and organizations for fraud protection and credit risk reduction.

Except as outlined above, Novo Nordisk will not intentionally share your Personal Information with anyone else without your express consent unless Novo Nordisk is required to do so by law.

d. How long does Novo Nordisk store your Personal Information?
Novo Nordisk will keep your Personal Information for as long as you are registered as a user of the App. Thereafter, Novo Nordisk will continue to retain the information in accordance with applicable laws for as long as necessary to fulfill the purposes described in section 3b above (“For what purposes is Novo Nordisk using your Personal Information?”).

Novo Nordisk may also seek to anonymize your Personal Information (i.e., to alter your information so that it can no longer be identifiable). Such “Anonymized Data” may be retained indefinitely and used for a variety of purposes.

e. How does Novo Nordisk keep your Personal Information safe?
Novo Nordisk makes an effort to keep your Personal Information safe and private, although complete security can never be guaranteed. Novo Nordisk will maintain administrative and technical safeguards to protect against unauthorized disclosure, use, alteration and destruction of the personal information in our possession. Novo Nordisk is committed to providing appropriate security controls to protect personal information Novo Nordisk has about you against foreseeable hazards. Unauthorized entry or use, hardware or software failure, and other factors, may however compromise the security of your information at any time. Your Personal Information will be stored electronically in the databases of Novo Nordisk’s business partners located in the United States (US) and other countries worldwide, which are processing your Personal Information on its behalf.

Novo Nordisk may need to transfer your Personal Information outside the US, including to the European Union (EU) or other countries that may not have data protection laws which are as detailed as the laws in the US, but will under such circumstances take any measures required to ascertain an adequate level of protection, including the use of standard contractual clauses or binding corporate rules.

f. What are your rights specifically related to the sharing of your Personal Information with Novo Nordisk and Novo Nordisk’s use of your Personal Information?
You are entitled to request access to your Personal Information being stored and used by Novo Nordisk (including copies of the suitable safeguards taken for any third country transfer); to require it to be corrected if it is inaccurate; or, under certain circumstances to require that it is erased. If required by applicable law you may also request a copy of your Personal Information and that your Personal Information is transferred to another data controller, provided this is technically feasible.

You are also entitled to restrict Novo Nordisk’s use of your Personal Information and at any time to withdraw your consent to Glooko’s sharing of your Personal Information with Novo Nordisk. If you wish to do so, please use the contact information provided below. If you withdraw your consent you have the right to have your data erased. This will not affect the lawfulness of processing based on consent before its withdrawal.

If you change your mind and withdraw your consent, you may, however, no longer be able to use the App, as Glooko and Novo Nordisk are providing you the Service in collaboration.

g. Novo Nordisk’s contact information
If you have any questions about Novo Nordisk’s collection, storing, or use of your Personal Information, you can contact Novo Nordisk at: [email protected]

Novo Nordisk Inc.

800 Scudders Mill Road

Plainsboro, NJ 08536

(888) 870-3901

4. DOES GLOOKO SHARE THE PERSONAL INFORMATION WITH ANYONE OTHER THAN NOVO NORDISK?

In addition to sharing your Personal Information with Novo Nordisk, Glooko may share your Personal Information with other third parties as described below:

Agents: Glooko may share your Personal Information with service providers that work on its behalf in order to provide you with and to improve the App in collaboration with Novo Nordisk. These service providers are contractually restricted from using the Personal Information that is shared with them beyond what is necessary to provide their services or as otherwise required by law.

Business Transfers: In some cases, Glooko may choose to buy or sell assets. In these types of transactions, customer information is typically one of the business assets that is transferred. Moreover, if Glooko or substantially all of its assets were acquired, or in the event that Glooko goes out of business or enters into bankruptcy, customer information is one of the assets that may be transferred or acquired by a third party. Likewise, customer information may be among the assets implicated by any financing arrangements that Glooko chooses to enter. You acknowledge that such transfers may occur and that any acquirer of Glooko may continue to use your Personal Information as set forth in this Privacy Policy.

Protection of Glooko and Others: Glooko may release Personal Information when it believes in good faith that the release is necessary to comply with law; enforce or apply the App Terms of Use and other agreements; or protect the rights, property, health or safety of Glooko, its employees, you, or others. This includes exchanging information with other companies and organizations for fraud protection and credit risk reduction.

With Your Consent: Except as set forth above, you will be notified when your Personal Information may be shared with third parties, and in general, you will be able to prevent the sharing of this information.

5. WHAT ABOUT LINKS TO OTHER THIRD PARTY SITES AND SERVICES?

The App may contain links to or other information regarding other sites and services. Glooko and Novo Nordisk are not responsible for the privacy policies and/or practices of these other sites and services. When accessing another site or service you should read the privacy policy stated on that site. This Privacy Policy governs only that information collected by Glooko and shared with Novo Nordisk in connection with the App.

6. HOW DOES GLOOKO KEEP YOUR PERSONAL INFORMATION SAFE?

Your Glooko account Personal Information is protected by a password for your privacy and security. You need to prevent unauthorized access to your account and Personal Information by selecting and protecting your password appropriately and limiting access to your computer, mobile device, and browser by signing off after you have finished accessing your account.

Glooko will take steps to keep your Personal Information safe and private. However, Glooko cannot guarantee the security of such information. Unauthorized entry or use, hardware or software failure, and other factors, may compromise the security of your information at any time.

7. WHAT PERSONAL INFORMATION STORED BY GLOOKO CAN I ACCESS?

Glooko allows you to access certain categories of information about you for the purpose of viewing, and in certain situations, updating or deleting that information. These categories may change as the App changes. Any information that is automatically uploaded from a Product to the App cannot be later changed or updated. Certain information is required to fully utilize the functionalities of the App, so your deletion of certain information, or provision of inaccurate information, may render the App inoperable, in whole or in part. Please note that Glooko may use aggregate data derived from your information after you have requested it be modified or deleted, but not in a manner that would readily identify you personally.

8. WHAT RIGHTS AND CHOICES DO I HAVE IN RELATION TO GLOOKO’S COLLECTION AND USE OF YOUR PERSONAL INFORMATION?

As stated previously, you can opt not to disclose, or allow to be disclosed, certain information to Glooko, even though it may be needed to take advantage of certain features of the App or to register for the App.

You are able to add or update certain information within the App. When you update information, however, Glooko often maintains a copy of the unrevised information in Glooko’s private records. As mentioned above in Section 7 (“What Personal Information Stored by Glooko Can I Access”), deleting or modifying information may render the App inoperable, in whole or in part.

You may opt-out of most communications from Glooko, as set forth above in Section 2 (“What Personal Information Does Glooko Collect and for What Purpose?”). Please note that if you do not want to receive legal notices from Glooko, such as this Privacy Policy, those legal notices will still govern your use of the App, and you are responsible for reviewing such legal notices for changes. If you’ve registered the Product with Glooko as provided in the Product Terms of Sale, you may receive notices from Glooko if the Product and/or the Adapter is ever recalled. Please note that if you subsequently opt out of any communications from Glooko, you will not receive that recall notice. You acknowledge that certain communications between you and Glooko are required to provide you with the App and maintain your account.

9. WILL I BE NOTIFIED OF CHANGES TO THIS PRIVACY POLICY?

This Privacy Policy may be amended from time to time. Data processing by Glooko and Novo Nordisk is, provided that the amendments do not require your consent, subject to the Privacy Policy in effect from time to time. If changes are made in the way Glooko and/or Novo Nordisk use your Personal Information, or otherwise require your consent, you will be notified by posting an announcement through the App or by sending you an email or other notification. You are bound by any changes to the Privacy Policy when you consent to such changes. Neither Glooko nor Novo Nordisk will process your Personal Information in accordance with any changes, prior to your consent of them.

1. HOW DO I REQUEST ACCESS OR CHANGES/DELETION OF/TO PERSONAL INFORMATION STORED BY GLOOKO?
Glooko offers email-based and online support tools. You may access support resources or contact our support by visiting https://glooko.com/support/.

1. HOW DO I REQUEST ALTERNATE COMMUNICATION METHODS FROM GLOOKO?
You may contact our support department to make this request by visiting https://glooko.com/support/ and clicking on “Contact Support.”

1. WHO CAN I CONTACT WITH A PRIVACY QUESTION TO GLOOKO?
If you have questions or concerns regarding this Privacy Policy, please contact the Glooko Privacy Officer at [email protected].

PP 0002 Rev A

Effective Date: 3/26/2021

IT-0016 01