What is the purpose of this Privacy Policy?
MIA Assurances, which operates the website www.mia-assurances.com, attaches great importance to the protection and confidentiality of your personal data, which for us represent a guarantee of seriousness and trust.
In this respect, our Privacy Policy reflects our commitment to ensuring compliance within MIA Assurances with all applicable rules relating to personal data protection, and in particular those of the General Data Protection Regulation (GDPR).
In particular, this Privacy Policy aims to inform you how and why we process your personal data in connection with the services we provide.
Who does this Privacy Policy apply to?
This Privacy Policy applies to you, regardless of your place of residence, provided that you are at least 15 years old, whether you are a client, a job applicant at MIA Assurances, or a visitor to the website www.mia-assurances.com.
If you are under the legal age specified above, you are not authorised to use our services without the prior and explicit consent of a parent or legal guardian, which must be sent to us at: dpo@mia-assurances.com.
If you believe that we hold personal data relating to your children without your consent, please contact us at the address above.
Why do we process your personal data and on what legal basis?
We process your personal data mainly for the following purposes:
- To enable you to browse our website, benefit from needs analysis and personalised quotes, and allow us to respond to your requests (e.g., information requests, complaints), based on our Terms of Use and our legitimate interest in providing the best possible service
- To manage our customer service, based on contract performance and our legitimate interest in responding effectively to your requests and complaints
- To keep you informed of our latest offers and events by email, based on our legitimate interest in retaining customers and prospecting new ones
- To inform you of our offers and events by email based on your consent if you are not yet a client
- To keep you informed by phone, based on our legitimate interest in customer retention and prospecting
- To manage billing and any outstanding payments, based on our legitimate interest in receiving payment for our services and on our contractual terms
- To allow you to follow and comment on our publications on social networks, based on our legitimate interest in maintaining a social media presence
- To send you our newsletter based on our legitimate interest in customer retention
- To process job applications, based on our exchanges during recruitment and our legitimate interest in hiring and selecting candidates
- To enable video content on our website, based on our legitimate interest in providing video content
- To allow you to book meetings with our teams, based on our legitimate interest in facilitating contact
- To geolocate your position with your prior consent to improve service accessibility
- To send satisfaction surveys, based on our legitimate interest in improving our services
How do we collect your personal data?
Your data is collected directly from you when you are a client or a visitor to our website. We undertake to process it only for the purposes described above.
However, we may also obtain your data indirectly from partners, where you have previously given your consent. This may include purchasing prospect databases from data providers.
Your data may also be collected indirectly through trade fairs or social networks (e.g. LinkedIn).
When you voluntarily publish content on social media pages we manage, you acknowledge that you are solely responsible for any personal data you share.
What personal data do we process and for how long?
We process the following categories of data:
- Professional identification data (name, job title, company, etc.) and contact details (email, phone), retained for the duration of the service plus applicable limitation periods (generally 5 years)
- Financial data (bank account number, verification code, etc.), retained for the duration required for transactions and billing plus legal retention periods (5 to 10 years)
- Phone number used for telephone prospecting, retained for up to 3 years from the last contact
- Email address, retained for up to 3 years from the last contact, or until newsletter unsubscription
- Geolocation data, retained for up to 2 months
- Recruitment data (CV, cover letters), retained during the recruitment process and for 2 years thereafter
- Video analytics data, anonymised and retained indefinitely
- Connection data (logs, IP address), retained for 1 year
- Cookies, retained for a maximum of 13 months
At the end of these retention periods, your data is permanently deleted. Only anonymised data may be retained for statistical purposes.
In case of legal proceedings, your data may be retained for the duration of the case.
What rights do you have over your data?
You have the following rights, free of charge, at any time:
- Right of access and copy
- Right to rectification
- Right to object (in particular to marketing processing)
- Right to erasure (“right to be forgotten”)
- Right to restriction of processing
- Right to data portability
- Right to define instructions regarding your data after death
Requests must be sent to dpo@mia-assurances.com and may require proof of identity.
We respond within one month, extendable to three months if necessary. We reserve the right to refuse excessive or unfounded requests.
Who can access your personal data?
Your data is processed solely by our teams and our technical service providers to operate our services.
We ensure that all providers comply with data protection regulations.
We guarantee that we never sell or transfer your data to third parties or commercial partners.
Are your data transferred outside the EU?
Your data is hosted within the European Union.
We strive to use only EU-based providers. If not, we ensure appropriate safeguards are in place to guarantee data protection.
How do we protect your data?
We implement all necessary technical and organisational measures to ensure the security of your data and prevent loss, alteration or unauthorised disclosure.
Do we use cookies?
We do not use advertising cookies.
However, we use:
- Statistical cookies for traffic analysis
- Technical cookies required for website operation
You can manage cookies via your browser settings (Chrome, Edge, Safari, Firefox, Opera).
Who can you contact for more information?
We have appointed an independent Data Protection Officer (DPO).
You can contact them at any time at: dpo@mia-assurances.com
How can you contact the CNIL?
You can contact the French Data Protection Authority (CNIL):
CNIL Complaints Department
3 place de Fontenoy – TSA 80751
75334 Paris Cedex 07
Phone: +33 1 53 73 22 22
Can this Privacy Policy be modified?
We may update this Privacy Policy at any time to reflect legal changes or new data processing activities.