Data privacy and protection

Processing of personal data

LA MONDIALE EUROPARTNER with its registered office at 23, Z.A. Bourmicht – L-8070 Bertrange – Luxembourg and LA MONDIALE PARTENAIRE with its registered office at 14-16 boulevard Malesherbes – 75008 Paris - France, members of AG2R LA MONDIALE, (hereinafter “the Entities”) place great importance on the protection of personal data and undertake to comply with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter “GDPR”) and any other applicable regulations in this area.


Glossary

Personal data

Any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”). An “identifiable natural person” is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Sensitive data

All data relating to racial or ethnic origin, political opinions, religious or philosophical beliefs or membership of a trade union, as well as genetic data, biometric data, data concerning health or data concerning sex life, is considered to be sensitive data.

Processing

Any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Controller

The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller may be appointed or the specific criteria for the controller’s appointment may be provided for by Union law or the law of a Member State.

Processor

A natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

Recipient

A natural or legal person, public authority, agency or another body, to which the personal data is disclosed, whether a third party or not. However, public authorities that may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of this data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;

Data Protection Officer

The Data Protection Officer is the person you should contact if you wish to exercise your rights or if you have any questions about the protection of your personal data within our company.

Commission Nationale de l’Informatique et des Libertés (CNIL)

The CNIL is the French authority responsible for the protection of personal data. It helps companies to comply with the law and helps individuals to control their personal data and exercise their rights. Insurance industry professional bodies work with the CNIL within the insurance federation France Assurers to promote the ethical use of your personal data, in particular through the introduction of a compliance pack for the insurance sector.

The National Commission for Data Protection (CNPD)

The CNPD is the Luxembourg authority responsible for the protection of personal data. It helps companies to comply with the law and helps individuals to control their personal data and exercise their rights.

Profiling

Any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular, to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

 

1.    Why is my personal data being collected?

In order to offer you products and services adapted to your needs and to implement them, the Entities must collect a certain amount of data, such as your marital status in order to take out a policy, or your contact details.

We may collect personal data directly from you in the course of our business, including through our website, when you contact us or request information, when you use our services or following an exchange with one or more of our consultants and/or clients or when you visit our premises.


2.    What data do we process?

Depending on the intended purpose, the categories of data processed may include the following:

  • we collect and process data relating to your age, family situation and professional background as needed to study your needs and profile so that we can offer you the most suitable products and services; health data is only collected and processed for health and life protection cover;
  • information on your income, assets and investments to study your requirements and investor profile in order to offer appropriate products, investment vehicles and financial services;
  • your contact details and bank information for the administrative, technical and commercial management of the policy and associated services.

Mandatory data is marked with an asterisk (*) on this website.
 

3.    What is the purpose and legal basis for processing my personal data?

Your personal data is necessary to enable the Entities to carry out all the activities provided for in their articles of association and in accordance with the regulations to which they are subject. 

Within the framework of the provision of personal insurance, data will be collected and used for the following purposes in particular:

  • studying your needs and profile, to advise you and offer you products and services that are tailored to your needs in compliance with our duty to provide an advisory service;
  • taking out policies and the administrative and commercial management of the policy and associated services; 
  • compiling statistics and producing actuarial and financial studies to ensure that our operations are balanced and that we meet our commitments to our policyholders.

Your data may also be used in the legitimate interests of the Entities.  These interests include the protection and development of activities and the improvement of the products and services offered to clients, seeking new products and new clients, combating fraud etc. We carry out this processing under conditions that protect your rights, for example, by informing you or giving you the opportunity to oppose such processing.

Finally, your data is also processed to meet legal and regulatory obligations, in particular: 

  • the fight against money laundering and terrorist financing;
  • mandatory declarations to the authorities and public administrations, such as tax declarations.
     

4.    Automated decisions and profiling

We may decide to implement automated decision-making or profiling processes based on the analysis of your data. Profiling is the automated processing of personal data to evaluate certain personal aspects that may have an impact on the characteristics of your insurance policy.

This means that profiling allows us to meet our obligations to provide advice, determine cover, investments or services and offer you policies and services tailored to your needs.

  • Examples of automated decision-making:

On the basis of information relating to a claim, such as age and salary, the benefit will be approved and paid automatically.
Conditions of cover (contributions or benefits) may vary according to a change in age or family situation, as provided for in the policy.

  • Example of profiling:

Information on your assets, income, occupation and age can be taken into account to determine an investment profile and guide you towards certain investments.
 

5.    Retention period for personal data

Personal data may only be retained for a limited period. This period is determined on the basis of the purpose of the processing and the rules set out in the recommendations of supervisory bodies such as the CNPD or CNIL, or determined on the basis of legal or regulatory obligations.

For information purposes, the data required to manage your policy and related services is retained for the duration of your policy and until the expiry of the statutory limitation periods.


6.    Who are the recipients of personal data?

Your data may be sent to certain recipients as part of processing activities: natural or legal persons, public authorities, agencies or any other bodies that receive personal data.

Within AG2R LA MONDIALE, services in relation to you and your beneficiaries (customer relations, administrative management etc.), member organisations of AG2R LA MONDIALE involved in the provision of insurance benefits or services.

Outside AG2R LA MONDIALE: subcontractors that the Group may engage to provide our services, financial partners such as reinsurers or bankers involved in collections and payments and, lastly, the tax and regulatory authorities for our company’s mandatory declarations.

A list of these recipients is available here: https://www.ag2rlamondiale.fr/protection-des-donnees-personnelles

At LA MONDIALE EUROPARTNER S.A, the recipients in question are specifically those employees who have authorisation and who have dealings with you or your advisor. Outside LA MONDIALE EUROPARTNER S.A, the recipients in question are the subcontractors that we may engage to provide our services, financial partners such as reinsurers or bankers involved in collections and payments and, lastly, the tax and regulatory authorities for our company’s mandatory declarations.


7.    Will my data be transferred outside the EU/EEA?

Our preferred hosting and data processing facilities are located in the national territory of each Entity. However, in the event of a personal data transfer taking place outside the European Economic Area, we undertake to comply with the applicable regulations and, where applicable, to apply appropriate security safeguards to ensure an adequate level of data protection.
As a rule, no personal data is transferred outside the EU/EEA. All data transfers are carried out in accordance with Chapter V of the GDPR and applicable data protection laws and regulations. Appropriate measures, usually in the form of standard contractual clauses, are put in place whenever a third-party service provider processes personal data outside the EEA in the course of the provision of services.


8.    Security of the processing of personal data

We use appropriate technical and organisational measures to provide a level of security that is commensurate with the risk in order to ensure that processing complies with the GDPR and applicable data protection laws. The specific purpose of these technical and organisational measures is to prevent the data from being altered or damaged, or accessed by unauthorised third parties. Sensitive data, particularly health data, is subject to specific security measures. 

We have implemented systems to restrict access to your data in order to enhance security and confidentiality. This means that your data is only visible to authorised employees who are aware of the issues involved in protecting personal data. In the event of a breach of your personal data, the Entities are obliged to notify the responsible supervisory authority (CNIL OR CNPD) and to inform you as quickly as possible so that you can take the necessary measures.

As security requirements continue to evolve, effective security requires frequent assessment and regular improvement of security measures that have become obsolete. We are committed to the continuous evaluation, enhancement and improvement of the measures we implement.


9.    What are my rights?

You have the right to request:

  • Access to your personal data: you can ask the Entities directly for information on the processing of your personal data;
  • Rectification: you may request the rectification of inaccurate information if the information that the Entities hold about you is out of date or incorrect;
  • The deletion of your data (right to be forgotten): you have the right to have the Entities delete your personal data when there is a reason provided for by law, such as the fact that the data is no longer required or the withdrawal of your consent for any processing based on such consent;
  • Opposition: you have the right to oppose the processing of your data at any time, for reasons relating to your particular circumstances. Accordingly, the Entities will no longer process any of your data that is not necessary for the management of your policy or the fulfilment of a legal obligation, unless it can be demonstrated that there are legitimate, overriding grounds for the processing (in particular with regard to the establishment, exercise or defence of legal claims).

In addition, if your data is collected for canvassing purposes, you have the right to object at any time to the processing of your personal data, including profiling insofar as it is linked to such canvassing. 


For the La Mondiale Partner Entity, in the event of telephone canvassing, if you do not wish to be the subject of sales canvassing, you can register free of charge on the BLOCTEL telephone canvassing opposition list. Further information is available at www.bloctel.gouv.fr. Any person registered on this list may not be canvassed by telephone, “except in the case of approaches made as part of the performance of an existing contract and related to the subject of that contract, including when the purpose is to offer the consumer products or services related to or complementary to the subject of the existing contract or likely to improve its performance or quality.”

  • Data portability: you have the right to receive your data in digital format. This right only applies where you provide us with personal data that is processed on the basis of your consent or for the execution of a policy.
  • Finally, you can also define general and specific instructions, stating how you wish these rights to be exercised after your death.

Please note that to be able to respond favourably to your request and to guarantee the security of your personal data, you may be asked to provide documentation proving your identity, in particular, if necessary, a photocopy of your identity document, if it is difficult to identify you or if there is reasonable doubt as to your identity.


10.    How do I exercise my rights?
 

With regard to LA MONDIALE PARTENAIRE:

These rights may be exercised by completing the form.
or by writing to
AG2R LA MONDIALE, for the attention of the Data Protection Officer, at the following address:

AG2R LA MONDIALE
For the attention of the Data Protection Officer
154 rue Anatole France
92599 Levallois-Perret Cedex 

 
or by sending an e-mail to informatique.libertes@ag2rlamondiale.fr

 

With regard to LA MONDIALE EUROPARTNER S.A.: 

These rights may be exercised by writing to:

LA MONDIALE EUROPARTNER
For the attention of the Data Protection Officer
23, Z.A. Bourmicht, 
L-8070 Bertrange
LUXEMBOURG 

or by sending an e-mail to dpo@lamondiale.lu
 

For life protection policies managed by Digital Insure, these rights can be exercised by writing to:

Digital Insure SAS – Protection des Données Personnelles
38 rue de la Condamine,
75017 PARIS (France)

Or by sending an e-mail to dpo-lmep@protectionlmep.lu 
Or by submitting a request in the secure personal portal.
 

Your request will be processed within one (1) month of confirmation of your identity. This period may be extended by a further two (2) months in the event of a complex request or a large number of requests.


11.    Can I make a complaint if there is no response or if my request to exercise my rights is rejected?

The Entities treat the personal data that they process with the utmost care. However, if you consider that the processing of your data infringes your rights, you may make a complaint: 

  • With regard to LA MONDIALE PARTENAIRE: the Commission Nationale Informatique et Libertés (CNIL), 3 Place de Fontenoy - TSA 80715 - 75334 PARIS
  • With regard to LA MONDIALE EUROPARTNER:   the Commission nationale pour la protection des données (CNPD), 15 Boulevard du Jazz, L-4370 Belvaux (Luxembourg).
     

12.    Information about cookies

When you visit a website, cookies may be placed on your computer at any time during the session. In general terms, a cookie is a small text file placed on your hard drive by the server of the site you are visiting. A cookie may contain:

  • the name of the server that created it;
  • usually an identifier in the form of a unique number;
  • possibly an expiry date.

 
These files are used for different purposes, depending on their type:

  • cookies that are strictly necessary for the operation of the site and audience measurement: these are used to measure the audience for our sites (in particular the number of visits, the number of pages viewed, visitor activity on the site and the frequency with which visitors return);
  • these cookies are exempt from the requirement to obtain consent, as permitted by CNIL Deliberation No. 2020-091, insofar as they are strictly necessary for the operation of the site;
  • functional cookies, which remember your choices (e.g. choice of language, username etc.);
  • performance cookies, which are used to improve the performance of the site or to analyse how it is used;
  • advertising cookies, which are used to present you with the most relevant advertisements based on your interests and internet browsing habits. This means that they can enable you to be recognised on the sites you usually visit, to make purchases on commercial sites, or to send information about your browsing.

Please note: cookies never enable us to view or record access or passwords to personal or subscriber spaces that you might visit during a session.

 
Prior to any cookies being placed, current legislation on the protection of personal data requires the presence of a cookie banner, i.e. a pop-up message which gives the user a free, clear and fair choice between multiple options before using the service, including the placing of certain cookies or other trackers on their computer or smartphone.
 
This means that you have the choice of accepting all cookies, accepting some of them depending on the type of cookie, or rejecting all of them.
 
The cookie banner on this site informing you of the existence of cookies looks like this:

Cookies.png

Consent may or may not be required for the use of cookies.

Consent is not required where the use of a type of cookie is based on a statutory or regulatory provision or where a solution has been exempted from consent by the Commission Nationale de l’Informatique et des Libertés (CNIL).
 
The solution we use, Analytics Suite Delta from AT Internet in the version available on 30 March 2021, is used as strictly necessary for the operation and day-to-day administration of the website and in accordance with the CNIL configuration guide.
 
When your data is collected using cookies, you have a choice:

  • If you click on “Accept and close”, the page offering cookie options will close, and only data enabling you to be identified along with non-identifying data that only relates to your browsing activity will be collected.
  • If you click on “Continue without accepting”, only non-identifying data that only relates to your browsing activity will be collected.
  • If you click on “Personalise my choices”, you decide whether to grant access to certain cookies or not. However, even with personalisation, the cookies required for the site to function, such as audience measurement cookies, will be active and will collect the information needed to ensure that the site functions properly.

For cookies requiring consent, the user's choice is retained for 6 months. The retention periods for cookies (deposit and data) can be found in the table below:
 

Name Related solution Function Duration of cookies Duration of consent Retention periode for personal data collected via cookies
_pcid Piano analytics Visitor ID 6 months 6 months 24 months from placement
_pctx Piano analytics Piano context storage 6 months 6 months 24 months from placement
pa_privacy Piano analytics Form of consent: exempt or opt-in 6 months 6 months 24 months from placement
TC_PRIVACY Trust commander (CMP) Allows you to find out about and remember the cookies and trackers to which you consented when browsing the site 6 months 6 months 24 months from placement
TC_PRIVACY_CENTER Trust commander (CMP) Allows you to find out about and remember the cookies and trackers to which you consented when browsing the site 6 months 6 months 24 months from placement
TC_TRUST_bannerconsent Trust commander (CMP) Allows you to find out about and remember the cookies and trackers to which you consented when browsing the site 6 months 6 months 24 months from placement
TCPID Trust commander (CMP) Allows you to find out about and remember the cookies and trackers to which you consented when browsing the site 6 months 6 months 24 months from placement
JSESSIONID   Allows you to manage user sessions and distribute the load across different servers Length of session Length of session 24 months from placement


Access your cookie preferences to learn more about AG2R LA MONDIALE cookies and how to configure your browser to accept or refuse cookies.