The Baloise Group takes great care to protect your privacy when processing your personal data. The Baloise Group processes your personal data in compliance with the Swiss Federal Act on Data Protectio and the European General Data Protection Regulation (EU-GDPR) and in accordance with the following principles:
Data privacy is an important issue for Baloise in the light of the rapid progress of digitalisation in the world today. Your personal information is processed with strict confidentiality and in compliance with the latest laws on data protection. Protecting your privacy and your data against unauthorised third-party access, loss and misuse is a top priority for us.
2. Body responsible and contact details
The body responsible for the data processing described herein:
Baloise Insurance Ltd, Aeschengraben 21, 4002 Basel, email@example.com (hereinafter “Baloise” or “we”).
If you have any questions please contact our data protection officer at firstname.lastname@example.org. He is also at your disposal if you have an information request, suggestion or complaint.
3. Use and transmission of personal data limited to specific purposes
Your data is used only for the purpose that is specified when it is collected, for which you have given your consent or that is provided for by law. We oblige our employees to maintain confidentiality, observe the data protection law and – in the case of banking services – to maintain banking secrecy.
4. Handling personal data
Personal data means any information relating to an identified or identifiable natural person. A natural person is deemed to be identifiable if they can be identified directly or indirectly, particularly by means of assignment to a characteristic, e.g. their name, email address or telephone number. Data on an individual’s predilections such as hobbies or club memberships, or on their preferred websites, also counts as personal data. Data that is anonymised or aggregated and can no longer be used to identify a particular person is not deemed to be personal data. “Processing” refers to any handling of personal data, regardless of the means and procedures used, including, in particular, the acquisition, retention, use, alteration, disclosure, archiving or destruction of data.
5. Server logfiles
Baloise uses server logfiles to capture data about your visit to the website. This access data includes:
- name of the website you accessed,
- file name,
- the date and time of your visit,
- the volume of data transferred,
- notification of successful access,
- your browser type and version,
- your operating system,
- the referrer URL (the previous page visited),
- the IP address and the requesting provider.
Baloise uses this logged data for analytical purposes only to ensure the operation and security of our IT systems, and to optimise the website within the meaning of Art. 6 (1) (f) GDPR in order to provide you with a secure and trouble-free user experience at all times. Baloise does, however, reserve the right to verify logged data subsequently, should it have concrete grounds to suspect that the website has been used unlawfully. The server logfiles are deleted after a period of 30 days.
6. Contact form and email
The legal basis for the processing of your data when you contact us by email is Art. 6 (1) (f) GDPR. We only process your personal data in order to process your enquiry. This is where our required legitimate interest in processing the data lies.
If the aim of the email contact is to enter into a contract, Art. 6 (1) (b) GDPR provides an additional legal basis for processing the data.
On the Baloise web pages you have the option to subscribe to our newsletter. If you do so, the data you provide (title, last name, first name and email address) is transmitted to us from the data entry screen. We then send you a confirmation email to verify your consent (double opt-in process). The legal basis for this processing of data is Art. 6 (1) (a) GDPR. For the purpose of customised and targeted advertising, the data you transferred when registering for the newsletter may be passed on within the Group companies.
You have the right to revoke your consent at any time. If you no longer wish to receive our newsletter you may unsubscribe via the link provided in each issue of the newsletter. The revoking of your consent does not affect the legality of the data processing carried out up until the revocation based on your former consent.
We would also like to make you aware that you can adjust cookies on an individual basis in your browser settings. However, blocking all cookies there may result in this and other websites no longer being displayed correctly. If you want a comprehensive and up-to-date overview of all third-party access to your internet browser, we recommend that you install a browser plugin created for this purpose. You can also configure your computer to issue a warning whenever a cookie is sent. Alternatively, you may elect to disable all cookies. To do this, you can change the browser settings in any browser you use and on any device you use. Each browser is slightly different in its handling of these settings. You can consult the Help menu in your browser to find out how to change your cookie settings. If you disable cookies, the result may be that you do not have access to numerous applications that make the pages and apps more efficient, and some of our services may no longer work for you.
9. Integration of third-party services and content
Our website content consists, to some extent, of third party content such as YouTube videos, maps from Google Maps, RSS feeds or images from other websites. This always requires that the providers of such content (hereinafter referred to as “Third-Party Providers”) identify your IP address. Without this IP address, the third-party providers cannot send the content to your browser. We only integrate this content into our web page to provide you with useful information, or to make a process easier for you without additional data processing. The legal basis for this data processing can thus be found in Art. 6 (1) (f) GDPR. Our legitimate interest lies in the fact that we are able to offer you this content as a service. In addition, certain services are only activated as described above when you actively select them. In these cases data processing is based on Art. 6 (1) (a) GDPR. If you do not want this content, you can select the appropriate settings in your browser settings. We make every effort to use content from providers that use the IP address only for the delivery of such content. However, we cannot influence whether or not third-party providers use the IP address for statistical purposes, for example. We notify users if we become aware of any such usage.
10. Analysis of use behaviour and other services
10.1. Google Analytics and Tag Manager
The following data may be stored and analysed anonymously and exclusively for statistical purposes:
- the pages visited and the sequence in which they are accessed,
- the operating system and browser used,
- the date and time of the page views,
- the address of the website visited directly beforehand, if your visit has been made via a direct link to us from there, and
- information about the origin.
10.2. Google Places API
10.3. Google AdWords Conversion Tracking and Google Remarketing
We use Google AdWords Conversion Tracking and Google Remarketing for advertising purposes.
10.4. DoubleClick by Google
11. Social media and advertising
11.1. Facebook remarketing / retargeting
Our pages have remarketing tags from the social media network Facebook, 1601 South California Avenue, Palo Alto, CA 94304, USA, integrated into them. When you visit our pages, the remarketing tags establish a direct connection between your browser and the Facebook server. Facebook is thereby informed that you, and your IP address, have visited our website and/or made a purchase. This allows Facebook to associate the visit to our pages and any purchase with your Facebook user account. The information obtained in this way can be used by us to display Facebook Ads and further used for marketing analyses and/or other targeting measures. We would like to point out here that we do not receive any details of the content of the data that is transmitted, or its use by Facebook. Further information about this is available in Facebook's data policy at https://www.facebook.com/about/privacy/. If you do not want to have data collected via Custom Audience, you can deactivate this feature here.
Buttons for the Twitter service are integrated into the pages of our website. The buttons are provided by Twitter Inc., 795 Folsom St., Suite 600, San Francisco, CA 94107, USA. They are recognisable by the use of terms such as “Twitter” or “Follow”, accompanied by the “blue bird” icon. These buttons can be used to share a post or page on Twitter, or to follow us on Twitter.
Pressing these buttons results in your browser establishing a direct connection with the Twitter servers. The content of the Twitter buttons is sent directly from Twitter to your browser. We would like to point out here that we do not receive any details of the content of the data that is transmitted, or its use by Twitter.
12. Consent / revocation of consent regarding data collection and storage
By using this website, you agree to the processing of the data collected about you in the manner described and for the stated purposes.
With regard to revoking consent to the collection and storage of data, we refer you to your rights pursuant to Section 15 below and to the deactivation options listed under the individual services or in general with regard to browser settings in Section 8 above.
13. Data security
Please note that the internet is a global, open network. When you transmit data over the internet, you always do so at your own risk.
Any personal data transmitted by you is protected by means of state-of-the-art encryption mechanisms using the latest security standards (Secure Socket Layer). Despite comprehensive technical and organisational security measures being taken, data may be lost, intercepted by unauthorised persons and/or manipulated. Baloise has implemented appropriate technical and organisational security measures to prevent such occurrences within the Baloise systems. Your computer, however, is beyond the reach of the Baloise IT security measures. It is therefore your responsibility, as the user, to obtain information about the necessary security precautions and to take appropriate measures. Baloise is under no circumstances liable for any damage that may result from loss or manipulation of data.
14. Secure Socket Layer (SSL)
Secure Socket Layer (SSL) is a protocol for enabling secure data transmission via the internet. Most browsers support this procedure. SSL uses the public key method, in which data encrypted using a publicly accessible key can only be decrypted using a specific private key. Most browsers use a key or padlock symbol at the top of the screen to indicate whether the current connection is secure or not.
15. Your rights
If you wish to receive information about your personal data that is processed by us, you can do so by submitting to us your written request for information with an enclosed copy of your identity card or passport.
You may demand that we rectify inaccurate data or complete incomplete data, or to a certain extent you can rectify or complete this yourself in the customer portal at any time.
You may also demand the deletion of your data, provided we are not required or authorised by applicable law or regulation to retain your data.
You have the right to demand that the processing of your data is restricted under statutory requirements. In this case we shall not process your data further with the exception of storing it and subject to the assertion of legal claims.
In all cases where data processing is based on your consent you have the right to revoke this consent at any time. The revoking of your consent does not affect the legality of the data processing carried out up until the revocation based on your former consent. In our Cookie Preference Center you can amend your cookie settings at any time
In addition, you have the right to complain to the competent data protection supervisory authority.
You have the right to receive your data from Baloise in a structured, commonly used and machine-readable format provided your data is processed using automated procedures and this processing is based on your consent or a contract.
You may inform us of your objection to the processing of your data, which we carry out on the basis of Art. 6 (1) (f) GDPR for legitimate interest.
You can submit your relevant requests to our data protection officer at email@example.com.
We reserve the right to amend or supplement these data protection provisions at any time.
If we process your data for any purpose other than that for which your data was collected, we will inform you beforehand in an appropriate manner about this other purpose.