• Data security and data retention

 

Privacy Policy

 

We here at Anivo 360 AG (“Anivo”) place great importance on protecting your data. We do our best to ensure that the data you disclose to us remains safe. In this Privacy Policy, we wish to explain to you what data we collect from you and why we do this.

Please ensure that you read the following explanation of how your data is processed when you visit our website (www.anivo.ch) and particularly when you later disclose personal data by completing our forms. This Privacy Policy may be updated from time to time and the most recent version at the time you use the website will apply.

In addition to this Privacy Policy, the applicable data protection laws, and particularly the Swiss Federal Data Protection Act (Bundesgesetz über den Datenschutz) (“DSG”), also apply. Anivo also meets the requirements of the European General Data Protection Regulation (“GDPR”) where applicable.

What personal data do we process?

Anivo helps consumers to search for, compare and obtain health insurance. The services we offer range from simple information about health insurance products, comparative analyses and help with taking out a policy, to managing an insurance portfolio.

In order to allow us to offer our consumers these services, Anivo must collect personal data from its customers, which it then stores and processes, but only for the purposes of fulfilling our duties as per our advisory mandate. We collect the following data when generating offers on Anivo.ch or on the various corporate landing pages operated by Anivo (these are the websites to which Anivo customers are forwarded as part of the process of generating health insurance offers and which are operated by Anivo).

We collect the following personal data in particular:

  1. General customer data: Name, address, email address, telephone number, date of birth, marital status, nationality, bank details.
  2. Technical information: IP address, browser information, cookies, standard HTTP protocol.

When you visit our website, Anivo also collects, stores and uses general, non-personal data. When you access our website, the following data in particular is stored in log files:

  • general transmitted information about your operating system and browser;
  • date and time of access / duration of visit;
  • add-ons used;
  • visitor source (referring website);
  • general information on surfing behaviour such as clicking on advertising banners or downloading files;

 

In order to compile individual quotes for you to compare, we may need to ask you to provide sensitive data (in particular information regarding your health). We require your explicit consent to process sensitive data, which you grant us when you accept Anivo’s General Terms and Conditions. Except for transmitting the data to the insurers to enable them to provide quotes, we will not analyse or use this data in any other way.

Your data is processed in compliance with the relevant provisions of the DSG (Switzerland) as well as Art. 6 para. 1 lit. a GDPR (consent) and/or lit. b (performance of contract) and/or lit. c (legal obligation) of the same provision, where applicable.

If you share personal data belonging to third parties with Anivo, you are responsible for obtaining consent from the affected third parties and ensuring that the information provided is correct. Anivo accepts no responsibility for the disclosure and/or correctness of this third-party data and you fully indemnify Anivo against any claims asserted against Anivo based on an alleged violation of the DSG and/or GDPR, where applicable.

Anivo processes your data for the following purposes:

  • To provide the services offered on the website:
    • To provide insurance mediation and prepare insurance comparisons. Your personal data is required in order to prepare individual offers.
  • To conclude a contract with an insurance company for which Anivo acts as broker:
    • After the customer has selected a product, the provided data will be passed on the respective insurance company so that the policy can be concluded or the insurance application reviewed.
  • To maintain a customer file (CRM management):
    • In order for us to properly perform our duties as per our mandate, we need to maintain a customer file.
  • Internal and external bookkeeping and accounting (legal obligations to retain data).
  • Internal training and quality control;
  • Managing the display of advertisements and our own advertisements (displayed by third parties):
  • Potential disclosure of personal data in the course of any corporate transactions involving Anivo (e.g. sale of Anivo or parts of Anivo to investors);
  • To prevent, detect and combat cases of abuse;
  • To prepare anonymous, statistical evaluations;
  • To respond to legitimate requests made by the authorities to the extent permitted by law or in connection with the enforcement of claims or other legal disputes affecting Anivo or in which Anivo is otherwise involved (legal obligations to disclose information).

 

The legal bases for the data processing we carry out are therefore:

  • performance of contract or purpose of the contract;
  • legal obligation;
  • legitimate interests.

 

Disclosure of data

Your data will only be disclosed to third parties if and to the extent that such is required in order to accomplish one of the aforementioned processing purposes or if you have consented to such. This includes in particular the insurance companies to which your applications are forwarded. Anivo servers, which are hosted in Switzerland, are used to handle your data and compare it against the various insurance products. Our hosting provider meets appropriate industry standards for cyber security.

Any third parties that we commission are contractually bound to only process the data in the same ways that Anivo itself is permitted to do and must ensure the same level of data security. Anivo will only process your data legally, in good faith, proportionately and only for the purposes set out in this Privacy Policy.

Anivo will not make your data available to any recipients domiciled outside of Switzerland and who do not ensure adequate data protection, unless Anivo makes appropriate contractual arrangements with such recipients in other countries.

Non-sensitive data will be forwarded to a service provider located in the USA for the purpose of preparing and sending newsletters. This service provider has signed an agreement under the terms of which they are obligated to comply with the necessary data protection provisions.

Our website and the infrastructure required to maintain such are guaranteed by Anivo IT Services GmbH. Anivo IT Services GmbH may access your data for quality assurance purposes and where there is a need to make changes to digitally recorded policies, applications or other documents. Anivo 360 AG and Anivo IT Services GmbH are parties to a Data Processing Agreement that ensures the protection of your data.

 

Data security

We protect your data by complying with current industry standards in the field of cyber security. Anivo ensures appropriate data security in accordance with the statutory provisions of the DSG and GDPR. We ensure the security of our website and the systems entrusted to handle your data by taking adequate technical and organisational measures to prevent your data being lost, destroyed, accessed, changed or disseminated by unauthorised persons.

 

How long do we store your data?

We only store your data for as long as such is required to fulfil a legitimate purpose or until you request its deletion in writing. Legal obligations to retain data are reserved.

If a contract is not concluded after your data has been forwarded to the chosen health insurance provider(s), your health data will be deleted after a holding period of 14 days. If a contract is successfully concluded, your application, together with the health data it contains, will be stored for evidentiary purposes until the expiry of any applicable limitation periods. In such a case your data will be deleted. Your health data will not be used for any other purpose (including the completion of new forms or when searching for a new health insurance offer).

With the exception of sensitive data, Anivo reserves the right to use your data, in anonymised form, to carry out statistical analyses and where appropriate, to occasionally share with you offers similar to those you have viewed or purchased based on general criteria (e.g. age or location). You can choose to unsubscribe from such communications at any time by writing to privacy@anivo.ch or by clicking the unsubscribe link in our email.

 

Children

Anivo does not collect any data relating to children under the age of 14 without the consent of their legal guardian. We take technical steps to ensure wherever possible that no data relating to individuals under the age of 14 can be collected by unauthorised means. However, should this occur, for whatever reason, the data will be deleted as soon as we are made aware of its existence and have verified it. If you believe or have information indicating that we are processing such data without authorisation, please get in touch with us by writing to: privacy@anivo.ch.

 

Cookies

This website uses “cookies”. These are small text files that are sent to the customer’s browser by the relevant server when they first visit a website and stored on the customer’s device or in their browser’s cache. If the website is accessed again using the same device, the browser checks to see if a corresponding cookie is already available. The browser then sends the data that is stored in the cookie back to the web server. This allows the browser to detect whether or not the browser has already visited the website in question.

Anivo only uses the data collected through the use of cookies to improve its services and to carry out anonymised analyses of website use. The data is not used for any other purpose. Under no circumstances will it be used to identify you personally.

Cookies are only used for the purposes of ensuring website functionality and web analysis, so that we can design the Anivo.ch website and various corporate landing pages in a way that is user-friendly and tailored to your needs.

You can change your browser’s settings to prevent cookies from being stored on your hard drive or to delete cookies that are already stored on your device. However, we wish to point out that this may result in limited access to some of this website’s functions. By deactivating cookies via your browser, you also assert your right to object to the placement of cookies.

This data is processed on the legal basis of legitimate interest according to Art. 6 (1) lit. (a) GDPR.

 

Google Analytics/Google AdWords

This website uses Google Analytics, a web analysis service provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, California 94043, USA (“Google”). Google Analytics uses cookies that are stored on the customer’s computer and allow their use of the website to be analysed. The information about use of this website (including IP address) which is generated by the cookie, is transmitted to a Google server in the USA and stored there. If you activate IP anonymisation on this website, your IP address will first be truncated by Google within member states of the European Union or in other states which are party to the agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and stored there. Google will use this information to evaluate use of the website in order to compile reports on website activities for the website operator and provide further services relating to website and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google’s behalf. Under no circumstances will the IP address transferred from the customer’s browser as part of Google Analytics be linked with any other data held by Google.

You can stop cookies being stored by selecting the appropriate settings in your browser software. In addition, you can prevent the data generated by cookies and relating to your use of the website (including your IP address) from being collected and processed by Google by downloading and installing the browser plug-in, available at the following link: The current link to this is: http://tools.google.com/dlpage/gaoptout?hl=de.

 

This website also uses Google AdWords, another analysis service provided by Google, as well as the conversion tracking this entails. If you have been directed to our website via an advertisement that has been placed by Google, Google AdWords will store a cookie on your computer. The cookie for conversion tracking will be stored on a computer if a user clicks on an advertisement that has been placed by Google. These cookies become invalid after 30 days and cannot be used to identify you personally. If the user visits certain pages of our website and the cookie has not yet expired, we and Google can see that the user has clicked on the advertisement and has been forwarded to this page. The information gathered with the help of conversion cookies is used to compile conversion statistics for AdWords customers who have opted to use conversion tracking. The customer can find out how many users have clicked on their advertisements and have been forwarded to a page containing a conversion tracking tag. If you do not wish to be tracked, you can stop the required cookie being stored on your device. This can be done by using the browser setting that deactivates the automatic placement of all cookies for example, or by changing your browser settings to block cookies from the “googleleadservices.com” domain.

[The placement of Google Analytics and AdWords cookies is carried out on the basis of the statutory provisions of Art. 6 (1) lit. f (legitimate interest).]

We have concluded a commissioned data processing agreement with the provider that guarantees compliance with our data protection standards.

 

Social plugins

The website uses social plugins (“plugins”) from the social networks facebook.com, which is operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”), twitter.com, which is operated by Twitter Inc., 795 Folsom Street, Suite 600, San Francisco, CA 94107, USA (“Twitter”), plus.google.com, which is operated by Google Inc., 1600 Amphi-theatre Parkway, Mountain View, California 94043, USA (“Google+”), Instagram.com, which is operated by Instagram LLC., 1601 Willow Road, Menlo Park, CA 94025, USA (“Instagram”), youtu-be.com, which is operated by YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA (“Youtube”) (Youtube, Facebook, Twitter, Google+ and Instagram shall be referred to collectively as “social networks”). The plugins are identified by the logo of the respective social network.

When you access a website that contains plugins, your browser establishes a direct connection to the servers of the respective social network. The content of the plugins is transmitted directly from the respective social network to your browser, which integrates it directly into the website. By integrating plugins, the social network knows when you have visited the website.

If you are logged into the respective social network, it can link the visit to your account on the respective social network. If you interact with the social plugins, by clicking on Facebook’s ‘Like’ button or leaving a comment for example, the corresponding information is transmitted from your browser directly to the respective social network and stored there.

You can find out more about the purpose and scope of this data collection and the further processing and use of the data by the respective social network, in addition to your associated rights and settings options for protecting your privacy, by referring to the privacy policies of Facebook, Twitter, Google+, Instagram or Youtube.

 

Mixpanel

The website also uses the analysis service Mixpanel, provided by Mixpanel Inc., which is based in Delaware, USA. Mixpanel uses cookies in order to provide us with statistical data on your use of the website. The data collected from you is stored by Mixpanel. If you are located in a member state of the European Union or another state which is party to the agreement on the European Economic Area, Mixpanel will automatically truncate your IP address. Only in exceptional cases will your full IP address by transmitted to a Mixpanel server and then stored there. Mixpanel compiles statistics on our behalf using the collected data and passes these on to us. This allows us to improve our website to better suit your needs and to make individual functions more user-friendly. The collected data contains information about your user activity as well as the contents of the accessed pages of our website. You can deactivate the use of Mixpanel by installing a cookie that prevents information on your website activities from being collected. You can find this at http://www.mixpanel.com/optout/.

[The placement of Google Analytics and AdWords cookies is carried out on the basis of the statutory provisions of Art. 6 (1) lit. f (legitimate interest).]

We have concluded a commissioned data processing agreement with the provider that guarantees compliance with our data protection standards.

 

Links to other websites

The Anivo website contains links to other websites. Anivo is not responsible for the data protection aspects or content of these other websites and accepts no liability in this respect. Questions should be directed to the owner of the respective website.

 

Your rights

In principle, you have the rights to information, rectification, erasure, restriction, data portability, revocation and objection with respect to personal data concerning you, provided these rights do not conflict with ongoing contracts or Anivo’s legitimate interests. You can revoke your consent to data processing for marketing purposes (e.g. e-mail market and newsletters) at any time by writing to privacy@anivo.ch or by clicking on the unsubscribe link.

 

Exercising your rights

If you wish to exercise one of the aforementioned rights or have questions relating to these rights, please direct your enquiries to:

Anivo 360 AG
Allmendstrasse 11
6312 Steinhausen
Switzerland
email: privacy@anivo.ch

Data controller

The data controller is Anivo 360 AG, Allmendstrasse 11, 6312 Steinhausen, Switzerland.

Contact information

 

Anivo 360 AG, Allmendstrasse 11, 6312 Steinhausen, Switzerland.
Email: info@anivo.ch