Privacy Note | Generali
website-loader
Privacy Notice

Privacy Notice

Your privacy is important to us. That is why we are committed to protecting your personal information and treating it with the utmost care and attention. In this privacy notice, we will transparently explain how we collect, use, share and protect your personal information.

DATA CONTROLLER DETAILS

Generali Hellas Insurance Company S.A. (the “Company”) will process your Personal Data, acting as Data Controller. If you want to contact us, please use the following details:

Syggrou Ave. & 40 Lagoumitzi str.
117 45 Athens
Telephone: +30 2108096100
e-mail: info@generali.gr

If you have any questions regarding the processing of your Personal Data, if you wish to exercise any of your rights, or file a complaint in respect of your Personal Data, you may contact our Data Protection Officer by post to Generali's address or via e-mail at dpo@generali.gr.

WHY DO WE PROCESS YOUR PERSONAL DATA AND ON WHICH LEGAL GROUND?

If you are a policyholder or insured, the Company will collect and process your Personal Data for:

  1. INSURANCE PURPOSES
ActivityLegal ground
1. Concluding and managing insurance products and services contracts. It includes underwriting activities, such as preparing estimates and submitting quotations, and portfolio management activities, such as premium adjustments, cancellation, renewal.Necessary for the performance of a contract to which the data subject is party or for the performance of pre-contractual measures taken at the data subject's request.
2. Concluding and managing Reinsurance and Co-insurance contracts related to your contract, when necessary
3. Handling and verifying claims
4. Managing payments and reserves
5. Managing the relationship with you, including assistance services channels, customer care, contact center and information requests and complaints
6. Managing network and information IT and Security (such as Company asset management, continuity)It is necessary to fulfil a legal obligation to which the data controller is subject (e.g. DORA) and its legitimate interest to grant its functioning and protection, for the processing activity not falling under legal obligations
7. Using statistical and data analysis to better understand your needs and improve our products and services. This helps us make informed business decisions that support our goals and ensure alignment with the Group’s overall strategy and interests.
This entails activity such as:
a. Assess and report on contract and portfolio performance
b. Perform controls activities
c. Assess risk indicators
d. Monitor operational effectiveness
e.  Improve our insurance products, our services, processes and assets,
We rely on our legitimate interest to grant enhancing of Company’ insurance offerings, improving customer service, increasing operational efficiency, innovating and granting alignment with Group strategic plan and governance for the processing activity not falling under legal obligations
8. We share a limited and strictly necessary set of your Personal Data with Assicurazioni Generali S.p.A., our Group parent company.
This allows them to carry out statistical and analytical activities, such as business intelligence or KPI analysis, to support the Group’s strategic coordination, planning, controlling, and oversight.
We rely on our legitimate interest in contributing to the Group’s strategic coordination, control and oversight for the processing activity not falling under legal obligations
9. The Company might send your Personal Data to  Assicurazioni Generali S.p.A., Group parent company, for improving services, products, statistical and analytics by new technological solutionsWe rely on the legal ground, from time to time, deemed appropriate (consent or legitimate interest).
10.  Company strategic development, taking part in corporate transactions, mergers and acquisitions, restructuring, extraordinary operations.We rely on our legitimate interest to evaluate and conclude strategic operations, to make informed business decisions, ensure business continuity and integration, protect our strategic and economic interests.
11.  Insurance fraud prevention and detection activities.
This activity uses statistical and data analytics.
We rely on our legitimate interest of preventing and reducing frauds and frauds related risks
12.  Exercising or defending the Company's rights in court.We rely on our legitimate interest to defend the rights of the Company, its officers, representatives and shareholders in a potential dispute.
13.  Fulfilling regulatory and legal obligations (national and supranational, such as anti-money laundering, financial reporting and tax obligations).
Within this fulfilling activity, the Company can send a strictly necessary subset of your Personal Data to Assicurazioni Generali S.p.A., Group parent company, to contribute to the fulfilment of Group related regulatory and legal obligations.
It is necessary to fulfil a legal obligation to which the data controller is subject.
14.  Activities to find out your level of satisfaction with purchased products and servicesWe rely on our legitimate interest
  1. PROFILED COMMERCIAL AND MARKETING PURPOSES

The Company processes your Personal Data also to inform you about news and opportunities that may be of interest to you, as well as improve your experience. This activity is done by profiling your consumption habits preferences and interests, which allows us to better understand your needs and offer you a tailor-made marketing experience.

ActivityLegal ground
1. Sending tailor-made special offers related to our insurance products and servicesThe person concerned has consented to the processing of his or her Personal Data.
2. Delivering satisfaction questionnaires and quality surveys on products/services; market research and statistical surveys
3. Sending communications for participation in prize competitions or loyalty programs related to our products and services
4. Sending promotional initiatives relating to other Group companies or third parties’ products and services
5. Performing statistical and data analytics activities to improve the special offers related to our products and services, and the other above listed initiatives
6. Performing statistical and data analytics activities to assess and report on the above activities' performanceNecessary for the pursuit of the legitimate interest of the data controller.
7. ‘Soft spam’: sending offers concerning similar products or services to those already purchased, through the same channel provided at the time of purchase (e.g. e-mail or telephone).Art. 11 par. 3 of L. 3471/2006

The consent we ask you for the aforementioned purposes is free and optional. If you decide not to provide it, there will be no effect on the provision of the insurance products and services you subscribed to. Your choice will in no way affect the quality or availability of the services we offer to you.

If you are a supplier or a professional/independent service provider, the Company will collect and process your Personal Data for:

Activity Legal Ground
1. Executing all the necessary pre-contractual actions in the context of procurement processesNecessary for the performance of a contract to which the data subject is party or for the performance of pre-contractual measures taken at the data subject's request.
2. Implementing the contract that may be concluded and performing its necessary administrative, accounting and fiscal activities.
3. Handling complaints and allegations, fulfilling the obligation to establish internal channels for reporting violations of Union law and to take the necessary measures for their monitoring, for fighting economic crime, for the imposition of financial sanctions, for checking politically exposed persons, for the mandatory exchange of information in the field of taxation, possibly with the use of automated tools and for complying with court decisions and for responding to requests from public authorities.It is necessary to fulfil a legal obligation to which the data controller is subject
4. Complying with the corporate policies and procedures of the Company and of Assicurazioni Generali S.p.A., the parent company of the Group, and carrying out internal audits.We rely on our legitimate interest
5. Exercising or defending the Company's rights in court.We rely on our legitimate interest to defend the rights of the Company, its officers, representatives and shareholders in a potential dispute

WHICH PERSONAL DATA WE COLLECT AND PROCESS

We only process Personal Data necessary for the performance of the activities indicated above. This Data includes:

  • your identification details (name, surname, personal identification number, tax identification number, nationality, special registration number, etc.);
  • your contact details (address, telephone number, email, etc.);
  • your bank account details (IBAN) or your credit or debit card details;
  • data regarding your income (settlement slip, etc.) if required;
  • data related to your insurance policy, such as policy number, coverage details, claims history, and your health data, e.g., in case you have chosen personal accident coverage (and the insured risk occurs);
  • any other Personal Data that the Company maintains in its records from previous transactions with you;
  • creditworthiness data through the ICAP database, as well as details of your property through the National Cadastre, depending on the type of insurance contract you have chosen (e.g., liability of any kind, fire, etc.);
  • in cases of a claim for compensation due to a reported loss event or accident, Personal Data of third parties that come to the Company’s knowledge due to the accident in which these persons are involved, including any health data in case they suffer bodily injuries;
  • information related to your visit to the Company’s website (e.g. IP address, date, time, and duration of your visit, etc.). If you use the contact or complaint submission form, we will additionally collect your full name, email, phone number, city of residence, and your tax identification number;
  • cookies will also be stored on the device you use when browsing our website. For more information about cookies, you can click here.
  • if you use the FastPay service, you will be redirected to the secure environment of the bank we cooperate with; therefore, we will not collect your credit/debit card details;
  • if you call our call center, your call will be recorded, and the phone number from which you called will be logged;
  • if you visit Generali’s offices, upon entering the building, we will collect your full name, ID number, purpose and duration of your visit, while the closed-circuit security system (CCTV) will record your image.

Health Data

Your consent will be required in case of processing of special categories of data, such as health data. This data is only processed when strictly necessary for the provision and management of your insurance product, service, related risk assessment and claims handling included.

Card Data

If you choose to pay insurance premiums through the MyGenerali application and/or activate a standing order for charging your credit or debit card, the data you provide to the Company will be processed:

(i) by the Company itself, for the purpose of paying premiums by charging your card, and

(ii) by “NEXI Payments Greece S.A.”, which is licensed by the Bank of Greece as a payment institution, according to the information available on NEXI’s website, exclusively for the operation of your card as a payment instrument.

Your card details (Card Number and CVV) will not be collected by the Company but will be entered into the information systems of “NEXI Payments Greece S.A.”, which is solely responsible for the processing carried out by it.

PERSONAL DATA ORIGIN

The Personal Data the Company processes for the purposes described in points 1 and 2 are provided by you (directly, such as when you fill in a form or contact customer service or indirectly, such as when you interact via our website, apps, chatbots) or acquired from third parties (such as data brokers, Authorities, etc.). Data may also be observed, inferred or generated relaying on the previous ones.

HOW DO WE PROCESS YOUR PERSONAL DATA?

The Company processes your Personal Data in both manual and automated form, using the best solutions.

We use statistical and artificial intelligence (AI) systems and analytical solutions.

The use of AI allows us to analyze your Personal Data more deeply and quickly, improving our ability to respond to your specific needs. These systems help us customize our products and services, optimise internal processes and pursue the purposes above mentioned at points 1 and 2, thus ensure a high level of quality experience and that all is aligned with the Group's overall strategy and interests. As said, we process your Personal Data only when strictly necessary, encouraging the use of anonymized or aggregated datasets, when possible.

TO WHOM DO WE DISCLOSE YOUR PERSONAL DATA?

Your Personal Data will be processed by Company’ employees and contractors within the scope of their duties and according to their instructions. Your Personal Data will only be shared with third parties expressly appointed to carry out activities related to the management of your relationship with the Company, such as:

  • Entities that are part of the so-called “insurance chain”, such as insurance intermediaries, banks and financial institutions (including the company Interbanking Systems S.A.), co-insurers and reinsurers, pension funds, lawyers, doctors, technical consultants, healthcare units, claims and contract settlement companies, and other contracted service providers, such as roadside assistance and accident care companies, vehicle technical service companies, companies providing electronic damage cost estimation and valuation of commercial value, companies offering health consulting and auditing services, etc.
  • The subsidiary company ARISTON SERVICES S.A., which provides call center services, coordination center, and accident care.
  • The Statistical Service (Y.S.A.E. archive) of the Hellenic Association of Insurance Companies and the Electronic Service of the Direct Payment System (Friendly Settlement of Claims System).
  • Companies of the Generali Group.
  • Other third-party companies providing services such as IT, telematics, financial, administrative, archiving, correspondence management, auditing and certification, as well as companies specializing in service quality research.
  • Third parties assigned to perform certain activities related to your relationship with us, if you are a supplier or an independent professional/service provider.
  • Public or Judicial Authorities, Chambers of Commerce Associations, etc.
  • the Bank of Greece, being the Supervisory Authority of the insurance companies

Depending on the activity carried out, the parties mentioned above may act as data processors, joint controllers, or autonomous data controllers. When your data are sent to Assicurazioni Generali S.p.A. in the exercise of its parent company activities, it acts as an autonomous data controller.
As a rule, we do not transfer your personal data to countries outside the European Economic Area (EEA).
In exceptional cases, limited to the purposes set out above, we may transfer your personal data to third parties or public bodies who so request -given that the request is justified and legitimate -, including countries outside the EEA. In all cases, transfers will be made in accordance with applicable law and international agreements in force and based on appropriate and adequate safeguards (such as, for example, to countries deemed adequate by the EU Commission or through the adoption of standard contractual clauses approved by the EU Commission).

Automated Individual Decision-Making

Depending on the type of insurance contract you have chosen, we may handle  a processing activity in a fully automated way, which means that no human intervention takes place in the processing activity. This is possible because the processing
- is necessary for entering into or fulfilling a contract between you and the Company. /
- is based on your explicit consent.
Remember that you can always request human intervention, as per applicable regulations.

WHAT RIGHTS CAN YOU EXERCISE AS A DATA SUBJECT?

You can exercise the right of access, rectification, updating, integration, cancellation, limitation to processing, and portability in respect to your Personal Data.
In case you provided your consent to the processing of Personal Data, you may withdraw it at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
If your Personal Data are transferred outside the European Economic Area, you have the right to obtain a copy of such data as well as an indication of the Country/Countries where the data have been made available.
If you believe that the protection of your Personal Data is being compromised in any way, you may file a complaint before the Hellenic Data Protection Authority: (address:1-3, Kifissias Ave., 115 23 Athens), www.dpa.gr.
You can exercise your rights by contacting the Data Protection Officer at the contact details above indicated. The request of exercise of rights is free of charge unless the request is manifestly unfounded or excessive.
For more information on the way and the conditions for the exercise of your rights, you can click here.

HOW LONG DO WE STORE YOUR PERSONAL DATA?

Your Personal Data are kept for as long as necessary for the management of the relationship, in accordance with current legislation, considering the Company's need to access them to exercise a right or defend itself in court.
The deletion/anonymization of Personal Data acquired for the performance of contractual or pre-contractual measures will take place twenty years after the termination of your policy, or five years in case the insurance policy was finally not issued.
The data collected following your consent for marketing purposes will be stored for a maximum of 36 months.
Recorded calls are stored for 12 months and then deleted, while closed-circuit TV (CCTV) recordings are stored for 15 days. In the event of an incident against the Company, its employees or third-party visitors, the images on which this incident has been recorded may be kept in a separate archive for a longer period in compliance with applicable legislation.

 
 
 
Privacy Notice – Motor Insurance
Privacy Notice – Motor Insurance through Alpha Bank
Privacy Notice – Life and Health Insurance through Alpha Bank
Privacy Notice – Retail Non Life Non Motor, Corporate Insurance
Privacy Notice – Retail Non Life Non Motor, Corporate Insurance through Alpha Bank
Privacy Notice – Life and Health Insurance
Privacy Notice – CCTV
Data Privacy Notice for the Reporters & other Persons involved in the Reports