Information protection
Privacy and personal data
This policy explains how HILEO processes the contact details, answers and documents provided by website visitors, prospects and clients.
This English translation is provided for information. In the event of any discrepancy, the French version prevails.
Data controller
The data controller is HILEO, a French simplified joint-stock company (société par actions simplifiée — SAS) with share capital of €1,000, registered with the Nanterre Trade and Companies Register under number 106 671 118, whose registered office is located at 46 rue du Bois de Boulogne, 92200 Neuilly-sur-Seine, France.
For any question or to exercise your rights: iris@hileo-assurances.com or HILEO, 46 rue du Bois de Boulogne, 92200 Neuilly-sur-Seine, France.
Data protection contact: Iris Monderer, available at iris@hileo-assurances.com.
Data and purposes
| Data concerned | Purpose of processing | Legal basis |
|---|---|---|
| Name, business contact details and company | Respond to a request, understand the need and arrange a discussion. | Steps taken at your request prior to entering into a contract. |
| Answers to the policy review questionnaire | Understand the insurance programme, prepare the review and tailor the response. | Pre-contractual steps and legitimate interest in handling business enquiries efficiently. |
| Policies, endorsements and other documents provided | Analyse cover, exclusions, limits, overlaps and gaps against the circumstances described. | Pre-contractual steps or performance of the engagement entrusted to HILEO. |
| Client relationship and contract data | Advice, distribution and monitoring of policies, renewals, claims and regulatory obligations. | Performance of the contract and compliance with legal obligations applicable to insurance brokerage. |
| Complaints and supporting documents | Investigate and monitor complaints, comply with regulatory deadlines and protect HILEO’s rights. | Legal obligation and legitimate interest. |
| Technical connection data | Secure the website, prevent abuse and diagnose incidents. | Legitimate interest in ensuring the security of the service. |
Required fields are identified in the forms. Without them, HILEO may be unable to respond or provide the requested service.
Recipients
Within the scope of their duties, data may be accessed by Iris Monderer and persons authorised by HILEO. It may also be processed by service providers required for hosting, email, client relationship management, electronic signatures, secure document transfer, appointment booking and IT security.
Policies and information are only shared with an insurer or other partner for a market exercise after informing the client and in accordance with the instructions agreed with them.
Selected processors must be bound by an agreement compliant with Article 28 of the GDPR and act only on HILEO’s documented instructions.
Analysis support tools
HILEO may use software tools to assist with classifying documents, extracting clauses or facilitating comparisons. These tools do not replace professional analysis: findings and recommendations are reviewed and validated by Iris Monderer.
No decision producing legal effects or significantly affecting an individual is made solely on the basis of automated processing. Documents must not be used to train a model on behalf of a provider without a specific agreement and appropriate safeguards.
Retention periods
- Prospect enquiries and questionnaire answers where no contractual relationship follows: up to three years after the prospect’s last contact.
- Policies and documents received for a review that does not proceed: for the time required to assess the request, then deleted no later than six months after the request is closed or abandoned, unless required by law or litigation.
- Client files: for the duration of the contractual relationship, then archived for the applicable statutory retention and limitation periods, generally five years, subject to specific requirements.
- Complaints: for the time required to handle them, then for the applicable regulatory or limitation periods.
- Technical security logs: no longer than twelve months, unless required in connection with an incident.
At the end of the applicable period, data is deleted, anonymised or placed in restricted-access intermediate archives where required by an obligation or the protection of a legal right.
Hosting and international transfers
The website is hosted by Netlify, Inc., 101 2nd Street, San Francisco, CA 94105, United States. Data entrusted to other providers is hosted and processed under the terms applicable to each service.
Where providers located outside the European Economic Area are involved, HILEO ensures that transfers are covered by a mechanism recognised under the GDPR, such as an adequacy decision or the European Commission’s Standard Contractual Clauses, supplemented where necessary.
The Calendly module is loaded only when the user chooses to display the calendar. Calendly may then receive technical data and, if pre-filled, the contact details entered. Users should review Calendly’s terms and privacy policy before confirming an appointment.
Cookies and third-party services
The website may use trackers that are strictly necessary for its operation and security. Non-essential trackers, particularly those enabling monitoring by a third-party service, must only be placed after the user has made a valid choice.
The website currently loads Google Fonts resources and may load Calendly on request. These services may receive the IP address and technical browser information. This policy will be updated if other services or trackers are installed.
Your rights
Under the conditions provided by the GDPR and the French Data Protection Act, you may request access to, correction or deletion of your data, restriction of processing, object to certain processing, request data portability where applicable and withdraw consent at any time where processing is based on consent.
You may also issue instructions concerning the handling of your data after your death. Proof of identity may be requested only where necessary to prevent disclosure to a third party.
HILEO responds within the statutory time limits. If, after contacting HILEO, you believe that your rights have not been respected, you may lodge a complaint with the French Data Protection Authority (Commission nationale de l’informatique et des libertés — CNIL).
Security and confidentiality
HILEO implements technical and organisational measures appropriate to the sensitivity of the information processed, including access restrictions, authentication, encryption in transit, backups, logging and oversight of service providers. As no system can provide absolute security, any incident presenting a risk is handled in accordance with applicable requirements.
A confidentiality agreement may be signed before any insurance policies are shared. For sensitive documents, use only the secure channel specified by HILEO.