APP PRIVACY & COOKIE POLICY

This privacy & cookie policy ("App Privacy & Cookie Policy") applies to the mobile application Medela Family App ("App") which is operated and controlled by Medela AG, Lättichstrasse 4b, 6340 Baar, Switzerland ("Medela" or "we").

This App Privacy & Cookie Policy governs the collection, processing and use of your personal data, when you use our App, and explains our practices with respect to the placement of cookies, including the types of cookies we use and how you can manage them.

This App Privacy & Cookie Policy was last revised on March 23, 2023.

1.1 Registration & Usage of our App

In order to use our App you must register an account with us. During the registration process you will be asked to provide certain information, such as your name/nick name, email address, your baby's estimated or actual date of birth, and to choose a password. If you do not register an account, you cannot use the App.

For the registration or log in, you also have the option to authenticate yourself with your existing profile on one of the following social networks: Facebook, Apple or Google. For this purpose, you will find icons of the social networks on the registration page. Once you have clicked on the respective icon a new window will be opened on which you must log in with your login data for the specific social network. After you have successfully logged in, the social network will tell you what data (e.g. name, e-mail address, nick name, profile picture) will be transmitted to us for authentication. If you have given your consent, the respective data will be transmitted to us. No further communication will occur between the account you created with us and your social network account, other than the authentication process. To achieve the authentication process, your IP address is transmitted to the providers of the social network. We have no influence on the purpose and scope of the data collection or on the further processing of the data by the social network providers. For more information, please read the privacy policy of the social network provider.

As part of the registration, we may ask you for further (optional) information, such as your breast pump situation to personalize the content of our App according to your needs and interests. The registration process takes place via a protected server connection to Medela. Unless indicated otherwise in this App Privacy & Cookie Policy (in particular Sections 1.2, 1.3 and 1.4), we will use the personal data you provide only as indicated in this App Privacy & Cookie Policy and to manage your account with us, store and collate your information on our servers (as necessary for the provision of our services), and to offer the functionalities and services requested.

During the registration process we will ask for your consent to use your personal data for marketing purposes in order to provide you with updates about services, products and events of Medela and its affiliated group companies. We may also invite you to participate in surveys we performed. After you provide consent and based upon your region, you may receive a confirmation email which contains a link that you need to click on to confirm your consent. This double-opt-in procedure helps us to ensure the identification of the email-account holder.

Your personal data will not be shared with any third party or used for any purpose other than indicated in this App Privacy & Cookie Policy, unless you have given express prior consent.

By installing/starting our App and registering your account with us, you consent to Medela placing cookies on your device, which are used for certain anonymized analysis by collecting and processing statistical information, such as user behavior, browsing patterns, average time period of use, and areas of interest. We collect and process this information to understand how our customers use our App, and to assess trends, statistics and our customers' needs, which help us improve our App and to better serve our customers, which includes providing you with a more personalized App experience and targeted offers. Please see Sections 2, 2.4 and 2.5 below for a detailed description of the cookies and/or analytic tools we use for this purpose and your rights to opt-out. If you do not agree with the above practices and would like to fully avoid any tracking and collection of your information, even in anonymized form, please do not install the App on your device(s).

1.2 Use of our App's Features

Our App offers different features where you can voluntarily decide to share further information with us. Such information includes personal data concerning both baby (e.g., name, picture, date of birth) and mother (e.g., expectations/experiences with breast feeding and pumping or expected education/job return date). Our App further enables you to track and monitor prenatal activities, such as contraction information, but also postnatal activities, such as your breastfeeding, pumping and bottle-feeding sessions, breast milk management as well as your baby's weight, height, sleep, diaper changes and any further notes. Further, our App enables you to connect with our connected pumps to easily track and log session times, settings used, and record breast milk expressed, to receive reminder messages that keep you on track and notify you when your pump battery is low and to access live lactation support (if this is available in your market). You can also complete questionnaires to measure your breastfeeding success and in order to personalize your user experience with our App, the possibility to register your pump and get free access to the VIP pack (if this is available in your market), to find a store near you to buy our products and to provide feedback regarding the App. In addition, you can use our chatbot functionality and get technical support, product recommendations and breastfeeding support. Finally, you can also ask questions and share knowledge with one another on our “Mums Community” platform (“Community”). We do not request or process any personal data for the Community. However, by participating in our Community you can voluntarily disclose such data to Medela. By accepting our rules and entering such personal data you consent to the processing of such data by Medela. You can withdraw your consent at any time by deleting the respective data or by deleting the App. This will not affect the lawfulness of the data processing according to your consent given prior to the withdrawal.

For Android users only: When you connect our App with a Bluetooth enabled Medela pump, the operating system requires access to the location (GPS) of the device. However, Medela does not store or use your location data at any time. Not allowing the location permission leads to problems with the connection of the pump.

Unless you have given your explicit consent, and unless indicated otherwise in this App Privacy & Cookie Policy, we will store, process and use such information only as necessary to enable your use of our functionalities and services, including to provide you with personalized content, educational information, helpful tips based on your unique data and progress in the App as well as the possibility to send us your feedback about the App.

You may determine your areas of interest and/or alter your choices by changing your personalization settings in the App (Tools Menu → Tests → Content Personalization) at any time. If you do not wish to receive any personalized content or services at all, you are free not to provide any personal information (and should abstain from completing the personalization questions in the App).

You may further change your personal notification settings in the App (More → General App Settings → Notifications) at any time.

To enable you to upload a picture of your baby, our App will ask for the permission to access your camera/pictures. We will not use the permission granted other than as necessary for this purpose.

Other than as explained above, we will further use any personal data we receive only in anonymized form (i.e., in a non-personally identifiable form which does not allow for any conclusions as to your identity) for statistical purposes and for internal evaluation to improve our products and services. Your personal data will not be processed for other purposes or beyond the scope of this Privacy Policy, except where expressly permitted or required by applicable law.

1.3 Processing of sensitive personal data

Generally, we do not request or process any sensitive personal data (e.g., health information, genetic/biometric data). However, by using our App you can voluntarily disclose such data (e.g. contraction information, baby's weight/height) to Medela. By registering an account with us and by entering such sensitive personal data you explicitly consent to the processing of such data by Medela. You can withdraw your consent at any time by deleting the respective data or deleting the App. This would not affect the lawfulness of the data processing according to your consent given prior to the withdrawal.

1.4 Creating one Single Record with Information from other Sources

In case you decide to use other services offered by us, such as where you register for Medela Family through the Website, which provides you with free access to additional educational information and direct marketing communications about our products and services, we may create one single record for you which combines the data we receive from you through your use of these other services with the data we receive from you through your use of the App. By registering your account with us in the App you are automatically registered for the entire Medela Family Program. You can opt-out from individual Medela Family services at any time by changing the settings in your profile.

This single record helps us to better understand your needs and preferences in order to more efficiently provide you with the requested products and services, including enabling you to benefit from a more personalized experience.

Other than as indicated in this App Privacy & Cookie Policy, we will not use the information for any other purposes or share the information with third parties, except where expressly permitted or required by applicable law.

2.1 Essential Cookies

Cookies are small text files that our App asks to place on your tablet, smartphone or other device. If your device is set to accept cookies, then the text will be added in a small file thereon.

Except as indicated otherwise in this App Privacy & Cookie Policy, the cookies used by us are essential for the functioning and performance of our App, such as by making our App work more efficiently and facilitating your use of the functionalities and services provided. These functionality and/or performance cookies will be deleted from your device after two (2) weeks of not using our App. We will not use the information stored in essential cookies for any other purpose than as strictly necessary to provide you with the services and functionalities requested.

2.2 Consent to Placement of Non-Essential Cookies and Use of Analytic Tools

When you install/start our App and register your account with us, you consent to Medela placing additional cookies on your device and/or to Medela’s use of certain tracking and analytic tools. These cookies and tools will not be strictly necessary to ensure the functioning and performance of our App but will help us to collect some non-personalized information relating to your App usage behavior in order to improve our App offering and services and/or to provide you with more personalized information and services, including providing you with targeted offers through our App (see also below Sections 2.4 and 2.5 for an explanation of certain tracking and analysis tools we use).

You have the right to withdraw your consent and/or to individually opt-out from the placement of cookies and/or any collection of your information for the different purposes through the tracking and analytic tools at any time with effect for the future. For this purpose, please follow the instructions outlined in the sections below. To completely withdraw your consent and to avoid any tracking and collection of your information, please delete the App from your device(s).

2.3 Managing your Cookie Settings

Most mobile devices are initially set to accept cookies. If you prefer, you can change your settings to generally refuse cookies, to delete cookies that have already been placed on your device, or to warn you before a cookie is placed. Please refer to your device instructions or to www.allaboutcookies.org to learn more about how to adjust or modify your mobile device settings.

If you choose not to accept cookies, this may impair the usability of the App and you may not be able to take advantage of some of our features and services offered.

If you use different mobile devices to access our App (e.g., smartphone, tablet, etc.) you will need to ensure that the settings on each device are adjusted to reflect your cookie preferences.

2.4 Use of Google Mobile App Analytics

This App uses Google Mobile App Analytics ("Google Analytics"), a web analytics service provided by Google, Inc. (USA) and Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (for EU) ("Google"). Google Analytics may use certain tracking technologies to help us analyze how users use our App, including the number of active users and user behavior (e.g., average time period of use, returning users, screen views per month, top articles). As a rule, any information generated about your use of our App will be transmitted to and stored by Google on servers in the USA. Since this App has implemented the IP-anonymization functionality offered by Google, your IP address will, before being transferred to the USA, be shortened by Google within the Member States of the European Union or in other contractual states of the Treaty on the European Economic Area. Only in exceptional cases your full IP address will be transferred to a server of Google in the USA and be shortened there.

Google will use this information as our commissioned data processor to help us evaluate the use of our App, to compile reports on App activity and to provide other statistical and analytical services relating to usage of our App. The IP address transmitted by your mobile device within the framework of Google Analytics will not be associated with any other data held by Google.

If you do not wish to be tracked by Google Analytics you can opt-out at any time by deleting the App from your mobile device.

For an overview of privacy at Google, please click here.

2.5 Use of App Analytic Tools

Medela further uses certain app analytic tools and services to gather aggregated and anonymized statistical information about the usage of our App.

We use iTunes Connect App Analytics provided by Apple, Inc. ("Apple"). This tool collects anonymized and aggregated data from app users on mobile Apple devices using iOS. iTunes Connect App Analytics provides us with metric App usage data, such as the total number of times the App has been installed, the number of times the app has been used, and the number of active sessions within a specific period.

We further use similar analytics and statistics services provided by Google Inc. (USA) and Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (for the EU) ("Google") through the Google Play Developer Console and/or Google Firebase Console. The information we receive only includes aggregated and anonymized statistical information from app users on Android devices, such as install and upgrade numbers, crash numbers, information about a crash, user ratings, acquisition channels, and visitor regions.

If the respective feature is enabled on your device, Apple or Google (respectively) will collect, process and use such information to help us evaluate the use of our App, to compile reports on App activity and to provide other statistical and analytical services relating to the usage of our App.

We only receive the above information if you have opted-in to share your data with third-party providers on your mobile device. You can make and alter your choice (opt-in or opt-out) at any time in the settings menu of your device (for iOS devices see: Settings → Privacy → Diagnostics & Usage; for Android devices see Settings → User and backup → Google → More → Usage & diagnostics).

Medela is responsible for operating the App as data controller. However, to ensure the customer relationship with you is handled efficiently, and to provide you with a good customer experience, your customer relationship may be managed on local level also by the Local Group Company, which is our affiliated group company responsible for your country. Apart from that, our affiliated group companies may only receive anonymized statistical reports and other analytical data on App usage and activity which will not contain any personally identifiable information.

In addition, Medela and/or the Local Group Company may use external technical service providers which are authorized to provide services on its behalf and in accordance with its instructions. These entities may have access to your personal data but only to the extent necessary to enable your use of our App, including providing related services or handling your requests or enquiries. For instance, Medela (and/or, as applicable, the Local Group Company) may use service providers to develop and/or host the App, to store your data, to enable the chatbot functionality, to enable sharing functionality via Social Media, to manage the customer relationship, to simplify the authentication process, to provide marketing related communications about our products and services, to process your rental request, to give voice commands supported by Siri (iOS) and Google Assistant (Android) or analyze the information collected as explained in this policy. These service providers may not disclose your personal data to any unauthorized third parties or use your personal data for any purposes other than as instructed. Some of these service providers may be located in countries outside Switzerland and the EU/EEA which may not provide for the same level of data protection as in your country of residence. However, Medela and/or, as applicable, the Local Group Company have appropriate agreements in place with these service providers to ensure that they will take all necessary measures to protect your personal data in accordance with applicable requirements. For further information about our service providers, please contact us as further explained in the Section, Your Rights and How to Contact Us.

We may provide your personal data to third parties to process transactions (e.g., address validation, shipping, tax calculation).

By participating in our Community and publishing your personal data, your personal data can be viewed by the public.

Other than as indicated above, we will not provide your personal data to any third party without your prior consent, unless we are compelled by law to do so.

Your data will be stored on servers in Ireland and the Netherlands. USA and Canadian user data will be stored in the USA, additionally. Furthermore, Medela and/or, as applicable, the Local Group Company may use cloud service providers located in countries outside Switzerland and the EU/EEA, including the USA, to host and process your personal data for storage, communication, support and marketing purposes. While the laws of those countries may not provide for the same level of data protection as considered adequate in Switzerland or the EU/EEA, we have taken the necessary measures to ensure your personal data will be handled and protected appropriately and only be processed on our behalf and in accordance with our instructions.

All your personal data will be irreversibly and automatically deleted after one year of inactivity (not using the App). Personal data of USA and Canadian residents will be deleted after three years of inactivity.

Any publication on our Community allows access to your personal data from anywhere in the world. This means that countries that do not guarantee the same level of data protection as your country of residence might, can also access the data.

We reserve the right to delete all your personal data irreversibly and automatically after one year of inactivity (not using the App). You can delete all your personal data upon your request (go to “more”  “mom profile”  “delete account”). Personal data of USA and Canadian residents will be deleted after three years of inactivity or upon your request. This deletion schedule is not applicable for any publication in our Community. Personal data published in the Community will be stored until you delete it.

We will treat your personal data confidentially. We have implemented appropriate technical and organizational security measures to protect your personal data against unauthorized disclosure, access, alteration, misuse, accidental or unlawful destruction or loss.

To the extent that you may disclose "protected health information" as defined under U.S. law while accessing or using our App, please refer to our HIPAA Privacy Policy and Notice of Privacy Practices to understand your rights and how we may use and disclose your protected health information.

Medela’s Privacy Notice for California Residents supplements the information contained in this App Privacy & Cookie Policy and applies solely to visitors, users, and others who reside in the State of California, USA.

You may have rights pursuant to your local data protection and privacy laws to request that we disclose to you all personal data that we have about you, request the correction, deletion and/or blocking of your personal data, object to the processing of your personal data for legitimate reasons, or request an electronic copy of your personal data for purposes of transmitting it to another company (data portability).

You may further at any time, with effect for the future, withdraw any consent you may have given by deleting the App from your device(s) and requesting a deletion by email to the email address identified below.

In case of any questions about the collection, processing and/or use of your personal data or to exercise your rights please send us an email at privacy@medela.com.

USA residents: In order to exercise your rights to delete or know what information we have collected about you, please complete the Privacy Request Form and return the completed form to us by email at privacy.us@medela.com.

Nevada residents: Without limiting the foregoing, Nevada law may allow you to specifically direct us not to sell your covered information to third parties. If you are a Nevada resident, you may submit such opt-out requests by email at privacy.us@medela.com. To be effective, your request must include your full name, address and email address so that we may attempt to verify the authenticity of your request.

We reserve the right to make changes to this App Privacy & Cookie Policy at any time with effect for the future. The then current version of this App Privacy & Cookie Policy will be made available within the App. While we do not intend to make changes to this policy very often, it is always a good idea to double check our most current policy statement when you visit us to be sure that you have read and agree with what information we collect, how we use it and under what circumstances we disclose it.