Skip to main content

Privacy policy

Below you can read Mysafety's entire privacy policy. It concerns the collection, use, and processing of your personal data, which is collected when you are in contact with us, e.g., via the website or our customer service, or when you become a customer with us by purchasing an insurance policy or a product.

More about GDPR and your rights

You can learn more about GDPR, your rights, and how your information is stored and used. Read more about GDPR and your rights.

MYSAFETY PRIVACY POLICY

1. GENERAL

1.1 At Mysafety, personal data is processed in cases where it is necessary for us to operate our company. This means that high demands are placed on us, both internally and externally, regarding the way we process personal data. It is important for us to be transparent about how and why we process your personal data. This document contains Mysafety’s policy for the collection, use, and processing of personal data.

1.2 The data controller for all processing is, unless otherwise specified, Mysafety AB, CVR number 556522-0612 with address Tegeluddsvägen 21, 115 28 Stockholm (“Mysafety”, “we” or “us”).

1.3 “Personal data” means information that can be attributed directly or indirectly to a living natural person, such as name, address, telephone number, email, customer number, or IP addresses.

1.4 “Processing” means any operation performed on personal data, such as collection, organization, storage, use, deletion, and transfer.

1.5 The information in the pre-contractual information and/or insurance conditions regarding the processing of personal data is the responsibility of the respective insurance company.

2. PERSONAL DATA BEING PROCESSED

2.1 Mysafety processes several different types of personal data. The categories processed vary and depend on your relationship with us, for example, whether you are a customer or merely a visitor to our website. The following categories of personal data are processed to varying degrees by Mysafety:
a) Name;
b) address;
(c) e-mail address;
(d) phone number;
(e) CPR number;
(f) customer number;
(g) IP address;
(h) bank account number;
(i) payment history;
(j) the registration number of the car, and
k) information about any other person (e.g., the insured) who is covered by the insurance, but who is not the policyholder: name, CPR number, address, telephone number, and email address.

2.2 In most cases, we receive personal data from you when you become a customer with us, or if, for example, you have accepted a free service or participated in a campaign. We may also receive your contact information through one of our partners, where our services may be included in the partner's membership terms or offered in another way. Some of the information we receive from third parties is collected from public registers, competitions, or other activities. In these cases, we are careful to ensure that our partners always clearly inform you that and for what purpose the information is being sent to Mysafety.

2.3 If we process your personal data in our capacity as a co-insured, we have received the data from the person who took out the insurance (the policyholder).

2.4 Sensitive personal data
We may process sensitive personal data as part of our claims handling for certain types of insurance, such as accident, unemployment, or health insurance. This may include medical certificates or other similar documents necessary to process and settle a claim. We process this data when it is necessary to establish, exercise, or defend a legal claim.

3. THE PURPOSES OF THE PROCESSING

3.1 We process the above personal data for one or more of the following purposes:
(a) to market and sell insurance and other services;
b) to fulfill our obligations under the agreement with you as a customer;
(c) to deliver an appropriate level of customer service;
d) in order to comply with our legal obligations pursuant to law or a decision by an authority;
(e) to recruit and hire personnel;
f) to evaluate, develop, and improve our insurance products, services, and systems

3.2 Your personal data will never be processed in a way that is incompatible with the purposes for which they were collected.

4. MARKETING AND PROFILING

4.1 As part of the purpose of selling and marketing insurance and other products, we, both independently and together with partners, perform various analyses of our customer database, which may include profiling. This means that based on specific information (e.g., purchase history, age, place of residence, and gender), we create customer segments that can help us define relevant target audiences. The purpose of the analyses is to get to know our customers so that we can tailor our marketing and target the most relevant offers to as many as possible. In this type of processing, we never analyze individuals, but only handle anonymized information.

4.2 It is important for Mysafety not to contact individuals who have expressed that they do not wish to be contacted for marketing purposes. Therefore, we have a number of procedures in place to ensure, as far as possible, that this does not happen and that we do not violate the applicable marketing rules. Examples of such procedures are:
a) We always “wash” our phone number lists against the Do-Not-Call registry before we call.
b) We comply with all marketing legislation and monitor case law in the area.
c) We follow the extra-judicial standards collectively known as ”good marketing practice”.
d) We comply with SWEDMA's and Kontakta's ethical rules for direct marketing.
e) We monitor and follow the statements of the Swedish Consumer Agency and the Direct Marketing Board.

4.3 If you do not wish us to call you, you can fill out the form at https://www.mysafety.dk/privatlivspolitik/gdpr-og-dine-rettigheder/ or choose to be blocked from marketing.

4.4 Calls are recorded when you call our customer service. The audio files are then transcribed into text and become searchable at the word or phrase level. The purpose of this processing is to improve our customer service and to quickly be able to identify dissatisfaction or various types of problems. If you do not wish to be recorded and/or have your call transcribed, please contact us via another channel, email, or our chat function.

5. LEGAL BASIS

5.1 We only process personal data if the processing can be supported by a legal basis in accordance with the EU General Data Protection Regulation (GDPR). One or more of the following legal bases are used when Mysafety processes your personal data:

5.2 Performance of a contract. When you become a customer with us, it is necessary for us to process your personal data at various stages in order to enter into an agreement with you and subsequently fulfill our obligations under the agreement. This means that your personal data is added to our customer database, and we may request additional information if you file an insurance claim. If you take out insurance or another service by phone, part of the telephone conversation is also recorded to ensure that we have spoken with the right person and that we have obtained your consent to send a written offer.

5.3 Legal obligation. Certain processing of your personal data is necessary for us to comply with our legal obligations under applicable law. We are obligated to comply with sanctions issued regarding personal connections to terrorism and affiliation with certain regimes, and in connection with claims payouts, we will therefore cross-reference the personal data with EU and UN sanctions lists to ensure that the payout is permitted. It is also necessary for us to process certain information regarding premium payments and claims in order to fulfill our obligations under accounting and tax legislation.

5.4 Legitimate interest. Some of our processing activities are based on Mysafety's legitimate interest as the legal basis. This only occurs after a balancing of interests has shown that the data subject's interests or fundamental rights and freedoms do not override Mysafety's legitimate interest in processing the data for the purpose. The processing of personal data is based on the following legitimate interests of Mysafety:
a) Our legitimate interest in selling and marketing insurance and other products or services
b) Our legitimate interest in providing a high level of customer service
c) Our legitimate interest in being able to recruit and hire staff
d) Our legitimate interest in maintaining a high level of security in our activities
e) Our legitimate interest in evaluating, developing and improving our practices and systems

6. TRANSFER OF PERSONAL DATA

6.1 We share and transfer your personal data to our partners to the extent necessary to provide and market our services and those of our partners. We share your information within our group with SBM Forsikring for marketing purposes. We always disclose personal data to the insurer if you have taken out insurance through us, as well as to companies that assist us with the distribution of information, customer service, and billing. We also share and transfer your personal data to our IT service providers (apps, SMS services, etc.) so that we can provide a good service. Personal data is disclosed to our cybersecurity partners to enable ordered monitoring.

6.2 In our claims handling, we share your personal data with your insurance company if it is necessary to process the insurance claim. We will never share more information than necessary.

6.3 When we share your personal data with other companies, the receiving company is either a data processor for Mysafety or an independent data controller. The companies that act as data processors process the personal data on our behalf and in accordance with our instructions. We vet all data processors to ensure that they can provide sufficient guarantees regarding the security and confidentiality of personal data.

6.4 We always strive to process your personal data within the EU/EEA, and all our own IT systems are located within the EU/EEA. If we share your personal data with a data processor who, either independently or via a sub-supplier, is established or stores information in a country outside the EU/EEA, the personal data may be stored outside the EU/EEA. In cases where personal data is processed outside the EU/EEA, the level of protection is ensured either through a decision by the European Commission that the country in question ensures an adequate level of protection, or through the use of so-called appropriate safeguards. Examples of appropriate safeguards are an approved code of conduct in the recipient country, standard contractual clauses, or binding corporate rules.

6.5 Unless you have blocked the use of cookies in your browser, some information is also shared with others for the purpose of increasing knowledge about our visitors; see more in section 8.

6.6 If we are required to do so by law or in the event of suspected criminal activity, we may share your personal data with public authorities such as the police, the Danish Tax Agency (Skattestyrelsen), or other authorities.

7. RESPONSE TO A LEGAL REQUEST AND PREVENTION OF HARM

7.1 We may access, preserve, and share your personal data in response to a legal request (such as a search warrant, court order, regulatory order, or similar), or when it is necessary to detect, prevent, and address fraud and other illegal activity, as well as to protect ourselves, you, and other users, including as part of an investigation.

8. COOKIES, PIXELS AND OTHER TECHNOLOGIES

8.1 We collect information using technology such as cookies, pixels, and local storage in your browser or device. We do this to increase our understanding of who visits our website so that we can improve your user experience.

8.2 The information shared via cookies is never directly identifying, but relates primarily to the IP address as well as information about browser, response time, operating system, screen resolution, geographical location, etc. For complete information on which cookies we use and which companies we share information with, visit https://www.mysafety.dk/cookies/.

8.3 Your IP address is also processed by us when you contact customer service using the chat function on the website, in order to prevent misuse of the service.

8.4 Your personal data and Facebook:
As part of our services, we use certain Facebook products for analytics and/or marketing. These products share your personal data with Facebook, such as name, address, email, and phone number. In addition, this involves interactions on our website or on our Facebook page, where, for example, IP address and behavioral information (what you have searched for or clicked on) on the website are shared. You can find more information about Facebook's use of this information in the Facebook Custom Audiences Terms and the Facebook Business Tools Terms. Facebook Ireland Limited is the joint data controller for this personal data. For information on joint controllership for personal data and Facebook Ireland Limited's responsibilities, visit the Facebook Data Protection Addendum. You can find more information about how Facebook processes personal data and how you can exercise your rights in the Facebook Ireland Data Policy. Facebook Ireland Limited transfers personal data from the EEA to Facebook Inc. in the US for storage and further processing. For information regarding this transfer, visit the Facebook EU Data Transfer Supplement.

9. STORAGE PERIOD

9.1 We store your personal data for varying periods depending on the nature of the data and the purpose of the processing. We have established internal rules for the storage and deletion of personal data, which we follow at all times. Personal data is never stored longer than necessary for the relevant processing, and never longer than we are entitled to under applicable law.

9.2 Information processed to fulfill our agreement with you is processed until the termination of the contractual relationship. Following this, we process the information for an additional 12 months for marketing purposes, unless you have objected to such processing in accordance with section 10.5 below.

9.3 Pursuant to the Danish Insurance Contracts Act, you, as the policyholder, have the right to file a claim up to 10 years after the incident, which is why we must retain certain information regarding your personal insurance history (name, customer number, and Civil Registration (CPR) number) and the insurances you have held for 10 years after you cease to be a customer with us. The information will not be used for any purpose other than settling a potential insurance claim.

10. YOUR RIGHTS

10.1 Right of access. You have the right to request access to your personal data and further information about the processing. This means you will receive a free copy of the personal data about you that we process. If you request extracts very frequently, we may charge a reasonable fee to cover administrative costs. In order for us to provide you with access to your personal data, we must be able to securely identify you, for example via Bank ID.

10.2 Right to rectification. We are responsible for keeping the personal data we process updated and accurate. If you discover that we have incorrect information about you, you have the right to ask us to correct it. You also have the right to add any personal data that you believe is missing and that is relevant to the purpose of the processing. If the information has been corrected at your request, we will ensure that we inform the parties to whom we have disclosed the information that the information has been corrected, unless this proves impossible or involves a disproportionate effort.

10.3 Right to erasure. You have the right at any time to contact us and ask to have your information deleted. In some cases, however, we are prevented from deleting the personal data, for example, if they are necessary to fulfill an agreement with you. In the following cases, we will always delete the information upon your request:
(a) if the information is no longer necessary for the purposes for which it was collected
b) If you have objected to processing pursuant to section 10.5 below, and we cannot demonstrate compelling legitimate grounds for continuing the processing.
c) if the personal data have been processed in a way that violates the law.
d) If the personal data must be erased to comply with a legal obligation to which we are subject.

10.4 Right to data portability. If you are a customer of ours, you have the right to have your personal data transferred in a machine-readable format directly to another data controller.

10.5 Right to object. If you object to the processing of your personal data based on a legitimate interest for Mysafety, we will cease processing your personal data for these purposes, unless we can demonstrate compelling legitimate grounds for the processing. However, you always have the right to object to your personal data being processed for direct marketing purposes. If you choose to object to direct marketing, Mysafety will no longer process your personal data for this purpose. However, it may be necessary for us to continue processing the data for other purposes, such as to fulfill our obligations under the agreement with you as a customer.

10.6 To exercise any of the above rights, please fill out the form on our rights page: https://www.mysafety.dk/privatlivspolitik/gdpr-og-dine-rettigheder/