Privacy Policy
Privacy Policy
As an independent insurance intermediary within the meaning of Art. 43 para. 1 of the Federal Act on the Supervision of Insurance Undertakings (ISA; RS 961.01), Tikall Assurances Suisse SA (hereinafter Tikall or we) is duly registered with the Swiss Financial Market Supervisory Authority FINMA.
Tikall acts as an intermediary between you and the health insurers. There is no legal, economic or other link between these insurers and Tikall.
1 - Data controller
Tikall Assurances Suisse SA (CHE-238.303.705)
Place Saint-François 7 ; 1003 LAUSANNE
contact@tikall.ch
076 478 60 18
2 - What types of personal data do we process?
Basic data: By basic data, we mean the data we need, in addition to contractual data (see below), for the performance of our contractual and other business relationships or for marketing and promotional purposes, such as your name and contact details, as well as information on your role and function, bank details, date of birth, customer history, powers of attorney, signature authorisations and consent declarations. We process your basic data if you are a customer or other business contact, or if you work for one of them (e.g. as a contact person of a business partner), or because we wish to contact you for our own purposes or those of a contractual partner (e.g. in the context of marketing and advertising, invitations to events, with vouchers, with newsletters, etc.). We receive basic data from you (e.g. when you make a purchase or register), from the persons you work for, or from third parties such as contractual partners, associations and address brokers, as well as from public sources such as public registers or the internet (websites, social networks, etc.). We may also collect basic data from our shareholders and investors. We generally retain basic data for 10 years from our last exchange with you or the end of the contract. This period may be longer if necessary for evidence purposes, to comply with legal or contractual requirements, or for technical reasons. For contacts used solely for marketing and advertising purposes, the retention period is generally much shorter, usually no more than 2 years from the last contact.
Contract data: This is data collected in the context of concluding or executing a contract, e.g. information on contracts and services provided or to be provided, as well as data relating to the period before a contract is concluded, information required or used for the performance of a contract, and customer comments (e.g. complaints, customer satisfaction data, etc.). We generally collect this data from you, from contractual partners and third parties involved in the performance of the contract, but also from third-party sources (e.g. credit information agencies) and public sources. We generally retain this data for 10 years from the last contractual activity or the end of the contract. This period may be longer when necessary for evidence purposes, to comply with legal or contractual requirements, or for technical reasons.
We disclose your personal data to the relevant health insurers only to the extent that it is necessary for them to prepare insurance offers for the health insurance you have selected. In addition, we process other personal data concerning you. The main categories are as follows:
Technical data: When you use our website, we collect the IP address of the device you are using (terminal) and other technical data. This data includes logs of the use of our systems. We generally retain technical data for 6 months. In order to guarantee the functionality of these services, we may also assign you an individual code or assign a code to your terminal (e.g. in the form of a cookie, see below point 9). As such, technical data does not allow conclusions to be drawn about your identity. However, technical data may be linked with other categories of data (and potentially with you as a person) in the context of user accounts, registrations, access controls or performance of a contract.
Communication data: When you are in contact with us via the contact form, by email, by telephone, by post or any other means of communication, we collect the data you exchange with us, including your contact details and the metadata of the communication. If we need to determine your identity, for example in the context of an information request, a press access request, etc., we collect the data enabling us to identify you (e.g. a copy of an identity document). We generally retain this data for 12 months from our last exchange with you. This period may be longer if necessary for evidence purposes, to comply with legal or contractual requirements, or for technical reasons. Emails in the personal inbox and written correspondence are generally retained for at least 10 years.
Behavioural and preference data: Depending on the relationship we have with you, we try to get to know you better and to tailor our products, services and offers to your needs. For this purpose, we collect and process data concerning your behaviour and preferences. We do this by evaluating information relating to your behaviour in our field, and we may also supplement this information with information from third parties, including from public sources. On the basis of this data, we can, for example, determine the probability that you will use certain services or behave in a certain way. The data processed for this purpose is either already known to us (e.g. where and when you use our services), or we collect it by recording your behaviour (e.g. how you navigate our website). We anonymise or delete this data when it is no longer relevant for the purposes pursued.
Other data: We also collect data about you in other situations. For example, we process data that may concern you (such as files, evidence, etc.) in the context of administrative or judicial proceedings.
3 - For what purposes do we process your personal data?
As set out in point 2 above, we process your personal data primarily to execute the contractual relationship with you and to enable the relevant health insurers to send you their insurance offers. In addition, we process your personal data for marketing and relationship management purposes, e.g. to send you personalised advertising for products and services that we offer or that third parties offer (e.g. advertising partners). This may take the form of newsletters and other regular contacts (electronically, by email or by telephone), via other channels for which we have your contact details, but also in the context of marketing campaigns (e.g. events, competitions, etc.) and may also include free services (e.g. invitations, vouchers, etc.). You may object to such contacts at any time or refuse or withdraw your consent to our contacting you for marketing purposes. With your consent, we may target our online advertising on the Internet more specifically for you (see below point 9). We also process your personal data for market research purposes, to improve our services and business activities, and for product development. We may also process your data for security and access control purposes. We process personal data to comply with laws, directives and recommendations from authorities and internal regulations. We also process data in the context of our risk management and corporate governance, including the organisation and development of business. We may process your data for other purposes, for example in the context of our internal processes and administration or for quality assurance and training purposes.
4 - On what basis do we process your personal data?
When we ask for your consent for certain processing activities, we inform you separately of the processing objectives concerned. You may withdraw your consent at any time with effect for the future by sending us a written notification (by post) or, unless otherwise indicated or agreed, by sending us an email; you will find our contact details above in point 1. To withdraw your consent to online tracking, see below point 9. As soon as we have received notification of the withdrawal of consent, we will no longer process your information for the purpose(s) to which you consented, unless we have another legal basis for doing so. The withdrawal of consent does not, however, affect the lawfulness of processing based on consent before its withdrawal.
When we do not ask for consent for processing, the processing of your personal data is based on the necessity of the processing to initiate or execute a contract with you (or the entity you represent) or on our legitimate interest or that of a third party in the processing in question, in particular in pursuing the purposes and objectives set out above in point 3 and in implementing related measures. Our legitimate interests also include compliance with legal regulations, insofar as this is not already recognised as a legal basis by applicable data protection legislation (e.g. in the case of the EU General Data Protection Regulation (GDPR), laws in the EEA and, in the case of the Federal Act on Data Protection (FADP, RS 235.1), Swiss law).
When we receive sensitive personal data (e.g. data concerning health, data revealing political opinions, religious or philosophical convictions, as well as biometric data for the purpose of uniquely identifying a natural person), we may process your data on the basis of other legal bases; for example, in the event of a dispute, for the needs of a potential dispute or for the enforcement or defence of legal claims. In certain cases, other legal bases may apply and, where applicable, we will inform you separately.
5 - With whom do we share your personal data?
Within the framework of our contracts, website, products and services, legal obligations, protection of our legitimate interests, and the other purposes set out above in point 3, we may communicate your personal data to third parties, in particular to the following categories of recipients:
Service providers commissioned by us: We work with service providers in Switzerland and abroad who process your data on our behalf or as joint controllers with us or who receive data about you from us as independent controllers (e.g. IT service providers).
Health insurers: We transmit your personal data to the extent necessary for them to prepare insurance offers for you.
Authorities: We may disclose personal data to agencies, courts and other authorities in Switzerland and abroad if we are legally obliged or entitled to make such communications or if this appears necessary to protect our interests.
6 - What are your rights?
Applicable data protection laws give you the right to object to the processing of your data in certain circumstances, including processing for direct marketing purposes, profiling for direct marketing purposes and other legitimate interests in processing. To help you control the processing of your personal data, you have the following rights regarding our processing of your data, in accordance with applicable data protection legislation:
The right to ask us for information to find out whether we process personal data about you and, if so, which data. The right to ask us to correct data if it is inaccurate. The right to request erasure of the data. The right to request that we provide certain personal data in a commonly used electronic format or transfer it to another controller. The right to withdraw your consent, when our processing is based on your consent. The right to obtain, upon request, other useful information for exercising these rights.
If you wish to exercise the above rights with us, you can contact us in writing at our address or, unless otherwise specified or agreed, by email; you will find our contact details above in point 1. In order to prevent abuse, we must identify you (e.g. by means of a copy of your identity card, if identification is not possible otherwise).
Please note that conditions, exceptions and restrictions may apply to the exercise of these rights under applicable data protection legislation (e.g. to protect third parties or trade secrets). Where applicable, we will inform you.
7 - How long do we keep your personal data?
We process your data for as long as our processing purposes, legal retention periods and our legitimate interests in documentation and evidence preservation require it, or as long as storage is a technical requirement. As soon as your personal data is no longer required for the aforementioned purposes or processing has ceased as part of our regular processes, we will delete or anonymise it.
8 - How do we protect your data?
We take adequate security measures to ensure the necessary security of your personal data and to guarantee the confidentiality, integrity and availability of your data, to protect it against unauthorised or unlawful processing, and to minimise the risk of loss, accidental alteration, unauthorised disclosure or unauthorised access.
9 - Cookies / trackers and other online technologies in connection with the use of our website
9.1 - What usage data do we collect?
When you contact us, data is collected by us and by third parties on our website and in our applications using various technologies. We generally assign this data to data we have already collected (e.g. user account), namely:
- Usage data transmitted or collected automatically (e.g. date and time of use, previous and visited page, IP address, data on the browser used, device identification, current location, insofar as this information is shared, etc.).
- Interactive data, insofar as it is accessible without installing additional software on the computer (e.g. mouse movements and clicks, keyboard keys used on our website).
We collect and process this data in order to continuously improve our products and services and to adapt them to your needs, to identify trends, to create and analyse statistics on the use of our digital offers. This data is also used to offer you a high-quality user experience. You have the possibility at any time to prevent the processing of non-personal data. To find out how to do this, please refer to point 9.3 below.
9.2 - What technologies do we use and why?
Our website generally uses "cookies" and similar techniques to identify your browser or device. A cookie is a small file that is sent to your computer or automatically stored on your computer or mobile device by the web browser you use when you visit our website. If you visit this website again, we will be able to recognise you, even if we do not know who you are. In addition to cookies that are only used during one session and are deleted after your visit to our website ("session cookies"), cookies can also be used to store user settings and other information for a specific period (e.g. two years) ("permanent cookies"). However, you can configure your browser to reject cookies, save them for a single session only, or delete them prematurely. The settings of most browsers are preset so that you accept cookies. We use permanent cookies in order to better understand how you use our offers and content and to be able to display offers and advertisements tailored to your needs.
On our website, we occasionally use elements and third-party services (such as Google or Facebook) that provide us with usage statistics for the display of third-party advertising or allow the user to access social networks and other third-party offers. These third-party services, which may be located in any country in the world (in the case of Google, this is Google LLC in the United States), allow us to measure and evaluate (in a non-personal manner) the use of our website. Permanent cookies set by the provider are also used for this purpose. The provider does not receive any personal data from us (and also does not store any IP address), but may track your use of our website, combine this information with data from other websites you have visited that are also tracked by the provider, and use this information for its own purposes (e.g. to control advertising). To the extent that you have registered with the provider yourself, the provider also knows you. The processing of your personal data by the provider is then the responsibility of that provider, in accordance with its data protection provisions. The provider merely informs us about the use of our website (and does not provide any information about you personally).
9.3 - How to prevent tracking and the use of cookies?
To protect your privacy, we take into account browser settings indicating that tracking is not desired and work only with third parties who also respect these settings. However, when you click on the link of an advertisement or another third-party offer, you leave our sphere of influence, and we are not able to control the data subsequently collected. On this point, you should refer to the conditions of the third parties concerned.
The settings of most Internet browsers are preset so that cookies are automatically accepted. However, you are free to configure your browser in such a way that it generally refuses cookies by selecting the "Do not accept cookies" option in your browser settings, or in such a way that it asks you each time whether you wish to accept a cookie from a website you are visiting. You also have the possibility to delete cookies from your computer or mobile device by selecting the appropriate function in your browser. Please be aware that you must disable cookies on all your devices or delete them from all your devices. If you decide to opt for one of the possibilities described above, all or part of our website may be inaccessible or unusable.
10 - Can we update this privacy policy?
This privacy policy is not part of a contract with you. We may change this privacy policy at any time. The version published on our website is the current version.