OPTEVEN GROUP PRIVACY POLICY

Privacy, security and
personal data protection policy

The OPTEVEN Group, through its entities and affiliates (hereinafter “we”, “us“), attaches the utmost importance to the protection of the personal data of its customers, representatives, suppliers, business partners or users of its websites (hereinafter “you“).

We are particularly committed to ensuring that any processing of personal data (as defined below) is carried out in compliance with applicable data protection laws, including, among others, Regulation (EU) 2016/679 of 27 April 2016 (the “GDPR”) and the French Data Protection Act No. 78-17 of 6 January 1978, as amended.

The purpose of this personal data protection policy is to inform you about the nature of the personal data we collect, the processing we carry out and its purposes, the people with whom we share this data, the length of time we keep it, the means implemented to ensure its security, as well as the rights you have over it.

 

The Personal Data Protection Policy consists of thirteen (13) sections:

1. Definitions

2. Who is the data controller?

3. What personal data do we process?

4. On what legal basis and for what purposes do we process your personal data?

5. Who processes your personal data?

6. With whom do we share your personal data?

7. Where is your personal data processed?

8. How long do we keep your personal data?

9. What are the rules for direct marketing?

10. How do we ensure the security of personal data processing?

11. What are your rights over your personal data?

12. How can you contact us to exercise your rights?

13. Policy Changes

 

1. DEFINITIONS

What is personal data?

Personal data is any information that directly or indirectly identifies a natural person:

  • by reference to an identifier, such as a name, address, identification number (e.g., claim number), online identifier (e.g., email), telephone number, date of birth;
  • by reference to one or more specific elements specific to their physical identity (e.g. handwriting, photo, etc.), economic (bank details) or social (subscriptions, social networks, etc.);
  • by cross-referencing several of the data mentioned above.

Personal data will be referred to herein as “personal data“.

What is data processing?

Data processing is any operation or set of operations performed on personal data, whether or not by automated means which includes, in particular, collection, recording, organisation, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

What is a data controller?

A data controller is any natural or legal person who, alone or jointly with others, determines the purposes and means of the processing. If the processing is supervised by more than one person, it is then referred to as joint controllers.

What is a data processor?

 A data processor is any natural or legal person who processes personal data on behalf of the data controller. The OPTEVEN Group’s data processors act under its responsibility, control, and according to its instructions for the processing of all or part of personal data necessary for the performance of their services.

 

2. Who is the data controller?

Depending on the nature of the relationship we have with you and/or the contract(s) you have entered with the entities of the OPTEVEN Group, the data controller of your personal data may be one of the following entities, or several of the following entities jointly:

  • OPTEVEN Assurances, a French public limited company (société anonyme) with a Management Board and Supervisory Board, having a share capital of EUR 5,335,715, an insurance undertaking governed by the French Insurance Code, registered with the Lyon Trade and Companies Register under number 379 954 886, with its registered office located at 10 rue Olympe de Gouges, 69100 Villeurbanne, France;
  • and/or OPTEVEN Services, a French simplified joint-stock company with a sole shareholder (SASU), having a share capital of EUR 365,878, registered with the Lyon Trade and Companies Register under number 333 375 426, with its registered office located at 10 rue Olympe de Gouges, 69100 Villeurbanne, France;
  • and/or OPTEVEN Courtage, a French simplified joint-stock company with a sole shareholder (SASU), having a share capital of EUR 6,384,430, registered with the Lyon Trade and Companies Register under number 843 914 300, with its registered office located at 10 rue Olympe de Gouges, 69100 Villeurbanne, France, registered with ORIAS (www.orias.fr) under number 18008174 as an insurance broker.

For example, if your contract concerns a “mechanical breakdown” insurance service, the data controller will be OPTEVEN Assurances. If your contract concerns a maintenance service for your vehicle, the data controller will be OPTEVEN Services. The data controller is identified on your contract.

When an OPTEVEN entity acts as a data processor, you can refer to the general or specific conditions of your contract for additional information regarding the determination of the data controller.

 

3. What personal data do we process?

According to the principle of data minimisation, we only collect data that is strictly necessary for the fulfilment of the specified processing purposes.

Depending on the insurance contract taken out or the service offered, we may collect certain categories of personal data directly (if you have taken out a contract with an OPTEVEN entity) or indirectly (if you are the beneficiary of an insurance guarantee taken out by one of our partners):

  • identification data: surname, first name, date and place of birth, identity card number, driving licence, etc.;
  • personal contact details: postal address, email address, landline and/or mobile telephone number, etc.;
  • your vehicle data: registration plate, engine/ car chassis number, VIN (vehicle identification number), etc.;
  • data relating to your contract: customer identification number, contract number, guarantee number, claim number, etc.;
  • data relating to claims reports: history of claims reports, etc.;
  • financial information: bank account details, number and expiry date of your bank card, etc.;
  • connection and traceability data [1] : IP address, logs, connection identifier to our websites and/or mobile applications, etc.;
  • location data: GPS position of the mobile phone in the context of the use of mobile applications dedicated to assistance, published by OPTEVEN, to enable the provision of assistance services and to allow beneficiaries to monitor the arrival of the assistance provider assigned to their case;
  • data relating to telephone interactions with our services: where calls are recorded, such data may include, in particular, the recording of the conversation, the voices of the participants, the content of the exchanges, and metadata associated with the call, such as its date, time, duration and purpose.

[1] For more information, please refer to the OPTEVEN Group’s cookies policy.

 

4. On what legal basis and for what purposes do we process your personal data?

The processing of personal data is only lawful if it falls within one of the legal bases laid down by Article 6 of the GDPR, and if the data collected meets specific, explicit and legitimate purposes:

  • The processing is necessary for the conclusion or performance of a contract between us (including the performance of pre-contractual measures) for:
  • develop quotes offering solutions adapted to your needs;
  • Collect your needs to ensure that informed and consistent customer advice is provided;
  • implement the services provided for in your contract;
  • ensure the proper management of claims;
  • handling complaints and disputes;
  • provide an online assistance service dedicated to users of mobile applications published by OPTEVEN, as beneficiaries of assistance services…
  • You have consented to the processing of your personal data for one or more specific purposes, such as:
  • electronic direct marketing activities [2];
  • the deposit of certain categories of cookies when browsing a website whose publisher is one of the entities of the OPTEVEN Group, etc.
  • The processing is necessary for compliance with a legal obligation to which the OPTEVEN Group is subject, such as:
    • the fight against money laundering and the financing of terrorism;
    • the fight against corruption and influence peddling;
    • responding to any official request from a duly authorised public authority (supervisory authority) or judicial authority;
    • monitoring and risk management.
  • The processing is necessary for the purposes of the legitimate interests pursued by the OPTEVEN Group:
  • the fight against fraud;
  • training and raising awareness of our staff through the recording of calls made or received by our call platforms;
  • carrying out actuarial studies or statistics;
  • the carrying out of direct marketing activities not subject to your consent [2];
  • the management of opinions and consultations on products, services or content, etc.

[2] For more information about your rights in terms of direct marketing, please refer to section 9 “What are the rules for direct marketing?”

 

5. Who processes your personal data?

Your personal data is collected and processed by the entities of the OPTEVEN Group as part of their missions and attributions.

All employees of the OPTEVEN Group who are required to process personal data are duly authorised to do so by their chain of command.

They are also aware of the principles of confidentiality and data security, as well as compliance with the internal rules enacted by the OPTEVEN Group in accordance with the applicable French and European regulations.

 

6. With whom do we share your personal data?

As part of our activities, we are required to share some of your personal data to various recipients, such as our subcontractors, service providers duly authorised by the OPTEVEN Group (tow trucks, receivables management, online marketing, IT service providers, printing, logistics, opinion surveys, market research, etc.), partners, lawyers, or experts who need it in the context of their activities.

When acting as processors within the meaning of the GDPR, these recipients are contractually obligated to respect the confidentiality and security of your personal data, and to use it only for the exclusive purpose of the services we have entrusted to them.

Information exchanges are carried out through secure protocols. To ensure an appropriate level of security of your personal data, our processors are subject to control and audit measures.

Apart from the recipients listed above and unless compelled to do so by a judicial authority, by law, or to defend our interests in court, we undertake not to communicate, share, make available, sell or rent your personal data to third parties without your express and prior consent.

 

7. Where is your personal data processed?

Your data is processed within the European Union.

We may transfer your personal data to processors located outside the European Union to the extent that this is necessary for the performance of the contractual services, or to meet a legal obligation (e.g. tax reporting obligations).

In such a situation, the transfer of your personal data is limited to countries subject to an adequacy decision adopted by the European Commission. For other countries, such a transfer can only take place if the data controller attaches appropriate safeguards to the transfer, such as standard contractual clauses approved by the European Commission, or binding corporate rules.

Exceptionally, and in limited cases, the transfer to a third country may derogate from the above-mentioned conditions, if, for example, it is necessary for the performance of the contract, or if it is based on your explicit and prior consent.

 

8. How long do we keep your personal data?

We undertake to keep your personal data in a secure environment, only for the period that does not exceed that necessary to achieve the purposes for which it was collected or for the periods imposed by applicable legislation, in civil, tax, commercial and criminal matters.

This includes the interim storage of certain personal data at the end of our contractual relationship, in order to comply with our legal obligations and for evidentiary purposes for the establishment, exercise or defence of our legal claims in the context of any legal proceedings.

Examples of retention periods include:

  • the data processed in the context of a contractual relationship are kept for the entire duration of the contract, then are subject to interim archiving until the end of the applicable legal requirements;
  • the data processed for billing purposes is kept for a period of ten (10) years from the end of the contract;
  • in the absence of the conclusion of a contract, the data transmitted in the context of a quote will be kept for a maximum period of three (3) years after the last contact with you and then deleted at the end of this period;
  • data processed in the context of the fight against money laundering and the financing of terrorism are kept for five (5) years from the end of the contractual relationship;
  • data processed in the context of the fight against fraud is kept for five (5) years in the event of proven fraud, or one (1) year in the event of suspicion of fraud being closed without further action;
  • Cookies and other trackers subject to consent deposited on your device are kept for a period of thirteen (13) months from their deposit or collection (it being specified that your choices relating to the acceptance or refusal of these trackers are kept for a period of six (6) months);
  • Telephone recordings are kept for six (6) months.

At the end of these retention periods and, where applicable, the intermediate archiving period, your data may be deleted or anonymised, for use for statistical, performance analysis or reporting purposes. Anonymization consists of irreversibly modifying personal data so that it no longer allows, directly or indirectly, the identification of a natural person. Once anonymised, this data no longer constitutes personal data within the meaning of the GDPR.

 

9. What are the rules for DIRECT MARKETING?

We carry out various marketing actions to offer our prospects and customers the products and services best suited to their needs.

To protect the privacy and data of the persons concerned, these actions are regulated according to the method of direct marketing:

  • in the case of electronic direct marketing (email/SMS/MMS): your express and prior consent is required, unless you are already an OPTEVEN customer, and the direct marketing relates to similar products or services offered by the same OPTEVEN entity. You retain the right to withdraw your consent at any time;
  • In terms of telephone direct marketing: you can object to this type of activity as soon as your data is initially collected, or at any time during our contractual relationship. Where available in your country of residence, you may register on a national opt-out register to object to telephone direct marketing calls.

In France, this service is provided free of charge through BLOCTEL, available at www.bloctel.gouv.fr.

You have the same right to object to direct marketing based on the analysis of your behaviour or consumption habits (“profiling”).

 

10. How do we ensure the security of personal data processing?

The security of personal data processing, and more generally the security of its information system, is a priority for the OPTEVEN Group, which relies on an Information Systems Security Policy (ISSP) to this end, as well as an internal IT charter that meets several requirements:

  • principle of secure processing: the OPTEVEN Group implements technical and organisational measures designed to guarantee an appropriate level of security in the processing of personal data, the effectiveness, consistency and efficiency of which are considered by the ISSP;
  • Continuous monitoring principle: security tests and audits are regularly carried out to help prevent any security breach that could lead to a personal data breach;
  • Data Breach Management: A personal data breach is a security, malicious or accidental breach that results in the destruction, loss, alteration or unauthorized disclosure of data.

Despite our best efforts to ensure that your personal data is kept in a secure environment, we cannot completely protect ourselves from any risk of hacking.

We take all necessary measures to limit intrusive actions and malicious acts. In the event of a breach of your personal data, we notify the French Data Protection Authority — Commission Nationale de l’Informatique et des Libertés (CNIL) — of the breach as soon as possible, and if possible, no later than 72 hours after becoming aware of it, unless the incident in question is not likely to cause a risk to your rights and freedoms.

Where such a violation is likely to result in a high risk to your rights and freedoms, we will notify you of the violation as soon as possible.

We are particularly vigilant about the protection of your banking data, and secure exchanges during transactions and payment acts by using robust encryption protocols.

 

11. What are your rights over your personal data?

You have the following rights over your personal data:

  • right of access: you can obtain confirmation of whether or not personal data concerning you are being processed, as well as access to said data and any information relating to the conditions of their processing;
  • right to rectification: you may request that your personal data be updated if you consider that it is inaccurate or incomplete;
  • right to erasure: you can request the deletion of all your personal data in the cases provided for by the regulations;
  • right to restriction of processing: you can request to cease for a limited period of time any processing other than the storage of data on some of your personal data, because you contest the accuracy of this data (the time for us to carry out the necessary verifications), or you contest the lawfulness of the processing carried out on this data, or you wish to use this data for the establishment, exercise or defence of legal claims when we are about to delete them;
  • Right to object on legitimate grounds: only for processing based on our legitimate interest, you may object to the processing of your personal data insofar as this is justified by reasons relating to your particular situation or in the event that this objection concerns direct marketing, including profiling. In the latter case, you have a general right to object which we will implement without you having to justify a particular situation;
  • Right to portability: You may obtain the recovery of the personal data we have in electronic format, for your personal use or that of another data controller, when such personal data meets the following cumulative conditions:
    • you have provided this data to an OPTEVEN entity, or it results from your use of our services,
    • this data has been collected based on your consent or the performance of the contractual relationship that binds you to an OPTEVEN entity;
  • right to withdraw your consent: when you have given your consent to the processing of your personal data, you can easily withdraw it at any time, without calling into question the operations carried out prior to such withdrawal;
  • Where applicable under local law, the right to determine the fate of your post-mortem data: You can define general or specific directives relating to the fate of your personal data after your death (concerning their retention, erasure, and, where applicable, their communication).

 

12. How can you contact us to exercise your rights?

The OPTEVEN Group has appointed a Data Protection Officer (DPO), who can be contacted at: dpo@opteven.com.

If you wish to exercise your rights indicated above or for any information on the protection of personal data, we invite you to send us your request by email to the DPO electronic address or by post to the following address OPTEVEN, DPO / Legal and Compliance Department, 10 rue Olympe de Gouges – 69100 Villeurbanne.

When exercising these rights, you may be asked to provide proof of identity and, where appropriate, the information required to process your request.

You may also lodge a complaint with your local data protection supervisory authority. If you are located in France, you may contact the Commission Nationale de l’Informatique et des Libertés (CNIL) through its website: https://www.cnil.fr.

 

13. Policy Changes

This policy may be revised according to legal or regulatory developments, or an internal modification of the conditions of processing of personal data.

We invite you to consult it regularly in the “Privacy Policy” section of the website https://group.opteven.com/.

Back to top