Home Personal data

Legal

Relyens Charter of Commitment on the Protection of Personal Data

Last updated: August 2026

Preamble

Purpose of the Charter

As a Mission-Driven Company, Relyens is committed to putting loyalty and fairness at the heart of its relationships with its customers, members, employees, partners, suppliers and prospects, while sustainably improving its interactions. Guaranteeing the most complete protection of their personal data is an integral part of this approach.

Through this Charter, Relyens affirms its responsibility in this area towards all its stakeholders. The Group is committed to complying with the highest standards to ensure the security and confidentiality of personal data processed in the context of its activities, by all its companies.

Personal data protection regulations

In the course of their activities, the companies of the Relyens Group process personal data either as data controllers, as joint data controllers, or as processors (within the meaning of Article 28 of the GDPR).

The Data Protection Officers (DPOs) appointed within the Relyens Group can be contacted through the channels indicated in the “Exercising your rights at Relyens” section.

The collection and processing of personal data carried out by the Relyens Group is in strict compliance with the regulations, and in particular with the European General Data Protection Regulation No. 2016/679 of 27 April 2016 (known as the “GDPR”) and specific national texts:

COUNTRY OF ESTABLISHMENTNATIONAL REFERENCE TEXTREFERENCE SUPERVISORY AUTHORITY
FranceLaw No. 78-17 of 6 January 1978, as amended, relating to information technology, files and civil libertiesCommission Nationale de l’Informatique et des Libertés (CNIL) 3, Place de Fontenoy TSA 80715 75334 Paris Cedex 07
ItalyLegislative Decree No. 196 of 30 June 2003 and subsequent amendments and additionsItalian Data Protection Authority (GPDP) Piazza Venezia 11 00187 Rome
SpainOrganic Law 3/2018, of 5 December, on the Protection of Personal Data and Guarantee of Digital RightsSpanish Data Protection Agency (AEPD) C/ Jorge Juan, 6 28001-Madrid
GermanyFederal Act on Data Protection of 30 June 2017 (Federal Gazette I, p. 2097)State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestraße 2-4, 40102 Düsseldorf
BelgiumLaw of 30 July 2018 on the protection of natural persons with regard to the processing of personal dataData Protection Authority (DPA) Rue de la Presse, 35 1000 Brussels
PortugalLaw No. 58/2019 of 8 August 2019 (Personal Data Protection Act)National Data Protection Commission (CNPD) Av. D. Carlos I, 134 – 1.° 1200-651 Lisboa

Presentation of the Relyens group

Relyens, a European mutual group in risk management, specialising in healthcare players and territories, is organised as follows (Click here to consult the organisation of the Relyens group in graphic version):

COUNTRY OF ESTABLISHMENTENTITY NAMETYPE OF ACTIVITIES
FranceRelyens Mutual Insurance – 18 rue E. Rochet – 69372 Lyon cedex 08Insurance Company
Relyens Life Insurance – 18 rue E. Rochet – 69372 Lyon cedex 08Insurance Company
Relyens SPS – Route du Creton – 18110 VasselayInsurance intermediary (brokerage)
Relyens Courtage – 18 rue E. Rochet – 69372 Lyon cedex 08Insurance intermediary (brokerage)
Relyens Proactive Solutions – 18 rue E. Rochet – 69372 Lyon cedex 08Service Company & Insurance Intermediary (Agent)
Manty – 25 rue Claude Tillier – 75012 ParisService Company
ItalyRelyens Mutual Insurance (succursale) Bureau secondaire : Via Carlo Imbonati, n.18 – 20159 MilanInsurance Company
Relyens Proactive Solutions (branch) – 18 rue E. Rochet – 69372 Lyon cedex 08Service Company
SpainRelyens Mutual Insurance (succursale) – Paseo de la Castellana 110 – 28046 MadridInsurance Company
Relyens Proactive Solutions (succursale) – Paseo de la Castellana 110 – 28046 MadridService Company
GermanyRelyens Mutual Insurance (succursale) – Erkrather Str. 228b, 40233 DüsseldorfInsurance Company
Relyens Proactive Solutions (succursale) – Erkrather Str. 228b, 40233 DüsseldorfService Company
BelgiumRelyens Mutual Insurance (under the freedom to provide services) – 18 rue E. Rochet – 69372 Lyon cedex 08Insurance Company
PortugalRelyens Mutual Insurance (under the freedom to provide services)Insurance Company

Glossary

Personal data

This is any information relating to an identified or identifiable natural person. An “identifiable natural person” is one who can be identified, directly or indirectly, by cross-referencing several pieces of information, in particular by reference to an identifier, such as a name, an identification number, location data, an online identifier, or to one or more factors specific to his or her physical, physiological or genetic identity, psychological, economic, cultural or social.

“Sensitive” personal data

Special categories of personal data include those that reveal racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, as well as genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health and data concerning a natural person’s sex life or sexual orientation (Article 9 GDPR).

In France, the following are also assimilated to this category: – the N.I.R (Social Security Number) and the I. N.S (National Health Identifier) – data relating to criminal convictions or offences (Article 10 of the GDPR) – data containing assessments of people’s social difficulties.

Treatment

Processing means any operation or set of operations which is performed on personal data, whether or not by automated means, such as collection, recording, storage, alteration, retrieval, consultation, transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Pseudonymization and anonymization

Pseudonymisation is a technique that consists of replacing personal data with a pseudonym. For example, in a dataset, a person’s first and last name is replaced by an identifier: ‘Norbert Smith’ becomes ‘Client2983-AN’. To re-identify ‘Norbert Durand’ a posteriori, you must have a file containing the correspondence between his name and surname and the associated identifier (pseudonym).

A dataset is considered anonymised if it is impossible to re-identify the persons a posteriori, by any means whatsoever. Anonymization is irreversible, while pseudonymization is reversible, i.e. there is a possibility of re-identifying people by cross-referencing information or files.

In short, anonymization provides a higher level of protection than pseudonymization.

Data controller

This is the legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

Processor

A processor is the legal person, public authority, agency or body that processes personal data on behalf of the controller.

Who is concerned

this is the identified or identifiable natural person to whom the personal data relates (e.g. a health professional who is a client of Relyens, a beneficiary of Relyens guarantees, an agent of the Relyens client, etc.).

Data Protection Officer

Better known by its Anglo-Saxon acronym “DPO” (for Data Protection Officer), it is the person within Relyens responsible for ensuring compliance with the regulations on the protection of personal data. This is the person to contact for any question relating to the processing of personal data carried out by the Relyens Group and to exercise the rights provided for by the regulations (for more details, see the dedicated section of this Charter).

Collection and processing of personal data at Relyens

The personal data collected by the companies of the Relyens group meet specific objectives (purposes) which are systematically brought to the attention of the persons concerned.

In addition, to be lawful, any processing of personal data implemented must be based on a legal basis (also known as a “legal basis”). For the companies of the Relyens group, this lawfulness is based on one of these four legal bases:

  • The execution of pre-contractual or contractual measures: Art. 6.1.b) GDPR;
  • The consent of the data subject: Art. 6.1.a) GDPR;
  • The legitimate interest pursued by the companies of the Relyens group: Art. 6.1.f) GDPR;
  • A legal or regulatory obligation: Art. 6.1.c) GDPR.
Purpose of the processingLegal basisExample(s)
Underwriting, management and execution of insurance contracts (including the performance of pre-contractual measures)Execution of pre-contractual or contractual measures (Art. 6.1.b GDPR)Drawing up an estimate or an insurance contract (collective or individual), compensation for a medical accident or sick leave, etc.
Risk management servicesExecution of pre-contractual or contractual measures (Art. 6.1.b GDPR)Carrying out a psychological support support mission, an audit in an Emergency Department, etc.
Implementation of the legal, regulatory and administrative provisions in forceCompliance with a legal or regulatory obligation (Art. 6.1.c GDPR)Verification of an Individual’s Identity in the Context of Anti-Money Laundering and Countering the Financing of Terrorism
Compilation of financial and trade statisticsLegitimate interest pursued by the companies of the Relyens group (Art. 6.1.f GDPR)Establishment of a claims report over the last 3 years
Claims ManagementExecution of pre-contractual or contractual measures (Art. 6.1.b GDPR)Sending an acknowledgement of receipt to a customer who has filed a claim on their compensation file
Fraud PreventionLegitimate interest pursued by the companies of the Relyens group (Art. 6.1.f GDPR)Exchange of information on a fraudulent claim with the Insurance Fraud Control Agency (A.L.F.A)
Publication of institutional content, carrying out commercial prospecting and marketing actions by electronic meansLegitimate interest pursued by the companies of the Relyens group (Art. 6.1.f GDPR)Sending a B to B emailing to present to a health professional a new risk management service launched by Relyens …
Keeping the general accounts and the auxiliary accounts that may be attached to itCompliance with a legal or regulatory obligation (Art. 6.1.c GDPR)Payment of an expense report, issuance of an insurance receipt
Sending newsletters, participation in digital events RelyensConsent of the data subject (Art. 6.1.a GDPR)Participation in a webinar on medical control
Carrying out satisfaction surveys and pollsLegitimate interest pursued by the companies of the Relyens group (Art. 6.1.f GDPR)Sending a satisfaction questionnaire following professional training on the follow-up of the patient file

In certain situations, companies in the Relyens group may act as subcontractors of their customers: this is particularly the case for Relyens Proactive Solutions and Manty.

Processing by design and default compliance

The companies of the Relyens group integrate the protection of privacy from the design phase of their products and services, and throughout their life cycle, from the collection of personal data to its deletion or anonymization. The Relyens Group is committed to applying a level of protection to personal data by default that meets the requirements of the applicable regulations in this area.

The Relyens Group applies the principle of data minimisation to each processing operation, which is concretely reflected in the following:

  • Only personal data that is strictly necessary for the purposes of the processing in question is collected and processed;
  • Personal data is not kept for longer than the time required for the said purposes (deletion or anonymization if necessary);
  • Personal data is only accessible to Relyens employees and authorized recipients;
  • Personal data is, as soon as the situation allows, pseudonymised or even anonymised.

In addition, prior to any new project involving the processing of personal data, the DPO of the Relyens company concerned is consulted in order to collect his recommendations to ensure the security and confidentiality of the data.

Transparency and information on the processing carried out

No personal data is collected by the companies of the Relyens group without the data subjects being informed.

Whether for example in quotes, contracts, or contact forms on the Web, information mentions specify (non-exhaustive list):

  • The identity of the Data Controller;
  • The purposes of the processing of personal data;
  • The legal basis (legal basis) legitimizing the processing;
  • The (categories of) recipients of the data;
  • The maximum data retention period;
  • The rights of the data subject;
  • The contact details of the DPO.

Categories of Personal Data Collected

The categories of personal data collected by Relyens group companies may vary depending on the purpose of the processing, the type of data subjects and the product or service concerned.

Depending on the case, this may include:

Data TypeCategories of dataExamples of data that may be processed
Non-sensitive dataIdentification dataName, address, photograph …
Personal dataLeisure activities, lifestyle habits…
Employment status dataCV, professional training, positions held…
Economic, financial, patrimonial or tax information, payment dataPayslips, income tax notices, bank card numbers, etc.
Location dataTravel list to calculate mileage allowances …
Login detailsIP address, date and time of connection to the Customer Area…
Data necessary for risk assessment, contract underwriting and management, claims compensation, performance of servicesMedical speciality practiced, surface area of buildings, police report…
Sensitive Data (1)Social Security Number, National Health Identifier (INS)Registered social insured person 1.69.05.78.524.259 / 42
Health dataPatient file, medical certificate of sick leave…
Data relating to criminal convictions or offences (2)Judgment of the Criminal Court following the assault of a town hall agent, conviction for driving under the influence of alcohol
Other sensitive data (religious or philosophical beliefs, sexual orientation and life, trade union membership, etc.) (3)Assessment of sexual injury in the context of a medical accident

(1) See definition in the Glossary.
Sensitive data is specific personal data that must be subject to specific protections and whose processing is strictly regulated by regulations.
The lawfulness of the processing of special categories of personal data, in particular health-related data, is based on one of the conditions of Article 9.2 of the GDPR.
For the Relyens Group, the possible scenarios are as follows:
(a) the data subject has given his or her explicit consent to the processing of such personal data for one or more specific purposes, except where Union law or the law of the Member State provides that the prohibition referred to in paragraph 1 cannot be waived by the data subject;
(b) the processing is necessary for the performance of the obligations and the exercise of the data controller’s or the data subject’s own rights under labour, social security and social protection law, to the extent that such processing is permitted by Union law, by the law of a Member State or by a collective agreement concluded pursuant to the law of a Member State which provides appropriate safeguards for the fundamental rights and interests of the data subject;
(f) the processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in the exercise of their judicial function;
(h) the processing is necessary for the purposes of preventive or occupational medicine, the assessment of the worker’s capacity to work, medical diagnoses, health or social care, or the management of health care or social protection systems and services on the basis of Union law, the law of a Member State or under a contract concluded with a health professional and subject to the conditions and guarantees referred to in paragraph 3;

(2) Data relating to criminal convictions or offences are collected and processed mainly in the context of motor vehicle and legal protection contracts.

(3) Sensitive data other than those relating to health and criminal convictions/offences are only collected and processed on an exceptional basis by the Relyens Group, and only when the situation justifies it.

When personal data is collected directly by the companies of the Relyens group, it is specified whether the information to be provided is mandatory (generally materialized by the presence of an asterisk in the section).

If certain mandatory information is not provided, the companies of the Relyens group may find themselves unable to respond to a request, to establish a price proposal, to manage/execute an insurance contract or to provide services.

Categories of recipients to whom the data are disclosed

In view of and depending on the processing purposes pursued, personal data may be exchanged within the companies of the Relyens group to enable them to carry out their missions, in compliance with the principle of data minimisation (the smallest possible volume of data, the smallest possible number of recipients, etc.).

Data may also be communicated to other stakeholders involved in the processing of said personal data.

The table below specifies, by main categories, the potential recipients of personal data from the companies of the Relyens group (non-exhaustive list):

Categories of recipients (variable depending on data processing)Example of a field of activityExample(s)
Employees of Relyens Group companies (intra-Group data exchange)Insurance, risk management, servicesTransfer of contact details between Relyens Mutual Insurance and Relyens Proactive Solutions to respond to a request for a quote
Relyens’ subcontractorsDelegation of managementHealthcare and pension expense manager on behalf of Relyens
Relyens service providersConsultingLawyers, medical experts, automotive experts
Computer ScienceDevelopers, software publishers, cybersecurity companies, data hosting providers
EducationProfessional training in risk management
AuditMedical control expert, medical risk auditor
Archive ManagementStorage of contracts and claims in paper format in a dedicated warehouse
Relyens PartnersInsuranceCo-insurers, reinsurers, insurance brokers
AssistanceCompany ensuring the repatriation of goods and people
OtherPartnerships with learned societies, commercial partners
Professional bodiesInsuranceOrganizations for the fight against fraud, for the settlement of automobile claims in the U. E
Social organizationsSocial protectionSocial organizations, complementary health insurance companies
Third parties with a right of communicationAll areasPolice authorities, courts, insurance supervisory authority (ACPR), supervisory authorities for the protection of personal data (e.g. CNIL), professional mediators
Persons involved in – or interested in – the contract (other than service providers)All areasMinisterial officers, guardians, curators, beneficiaries of the guarantees of a Relyens contract, beneficiaries

Place of data processing

The companies of the Relyens group favor the processing and storage of personal data in the European Union.

However, if a transfer of personal data outside the European Union is necessary to carry out certain specific processing, this transfer is only made with countries with an adequate level of protection. Failing this, the transfer of personal data is subject to an appropriate technical and legal framework and after prior consultation with the DPO of the Relyens group.

In any event, this transfer will be carried out in compliance with the provisions of Chapter V of the GDPR entitled: “Transfers of personal data to third countries or to international organisations”. Depending on their role in the processing, these external recipients will process the data either as independent data controllers or as processors duly appointed by the companies of the Relyens Group, in accordance with the legislation on the protection of personal data.

Data retention period

The companies of the Relyens group are committed to setting retention periods for personal data that are appropriate to the purpose of the processing concerned, while taking into account any legal limitation periods that may apply and the specificities inherent to each country in which the Relyens group operates.

When the data has reached its retention limit according to the reference framework defined by the Relyens group, the companies of the Relyens group delete or anonymize it (a process that excludes any possibility of re-identifying the person concerned).

The following table indicates the maximum retention period for personal data retained by the companies of the Relyens group as data controllers (non-exhaustive list):

Purposes of processingData retention period
Commercial prospectingCommercial prospecting: 3 years from the last contact with the prospect
Pre-contractual measuresQuote (or offer) that has not been followed up or refused: 5 years from the effective date of the quote/offer
Underwriting and management of insurance contractsThe entire duration of the contract, including any subsequent warranty period, plus the applicable statutory limitation periods (*)
Claims managementUntil the claims have been closed, plus the applicable legal statute of limitations (*)
Fight against fraudIn the event of a relevant alert, the data is kept for a maximum period of 5 years from the closure of the fraud file.
AML/CFT controls5 years from the date of the inspection

(*) For practical reasons, due to the multitude of products and services historically marketed by the companies of the Relyens group, it is not possible within the framework of this Charter to exhaustively reproduce the different applicable retention periods, which vary in particular according to the insurance product, the guarantees taken out and the occurrence or not of claims on the contract.
To find out the retention period applicable to a particular data processing, contact the DPO of the Relyens company concerned.

Data security at Relyens

Relyens’ Information System (IS) is at the heart of the service delivery system for its customers. This Information System is built to guarantee an efficient and adapted quality of service.

Relyens has a team of more than 100 professionals and IS experts who work on a daily basis to manage and constantly develop this Information System.

The Information System is built on robust and secure technical infrastructures, with the use of modern and innovative technologies. These infrastructures are based on constantly renewed equipment.

The entire infrastructure is hosted in two cross-data centers, located in two geographically distant locations. Based on this redundant infrastructure, the Business Continuity Plan is designed and tested annually to ensure the continuity of services in the event of a major disaster or cyber attack.

Both the business applications and the customer areas are developed and maintained in-house and are based on standard and market-leading technologies.

A dematerialization chain for all incoming mail allows Relyens to build efficient management processes.

The security of access to information is based on a proven and recognized authentication and access control solution as well as on traceability of the actions performed.

The IS Security Manager manages an IS Security Management System (ISMS) within Relyens. This ISMS is based on a security policy describing the organization and the security principles followed. A permanent control is carried out through internal or external audits and allows the regular adjustment of security measures. As alterações visam a melhoria contínua do SGSI e o ajustamento das medidas face à evolução dos riscos de segurança da informação.

The changes aim to continuously improve the ISMS and adjust measures in line with the evolution of IS risks. In this dynamic, the Medical Civil Liability perimeter for healthcare establishments (insurance underwriting, insurance contract management, and claims management processes), led by the legal entity Relyens RMI France, has been ISO 27001:2022 certified.

A more detailed document on the protections implemented by the Group is available to customers and prospects on request.

Exercising your rights over personal data at Relyens

The rights provided for by the regulations

In accordance with the applicable regulations, individuals have the following rights over their personal data:

Types of EntitlementNature of the right
Right of accessObtain information about the processing of personal data, and obtain a copy of it
Right to rectificationHave inaccurate or incomplete personal data amended
Right to erasureRequest the deletion of personal data, within the limits of what is permitted by the regulations
Right to LimitationRequest the limitation of the processing carried out on personal data
Right to objectTo object to the processing of personal data, for reasons relating to the particular situation of the data subject. This right also makes it possible to object, unconditionally, to the processing of personal data for the purposes of commercial prospecting, including profiling insofar as it is related to such prospecting
Right to portabilityRecover, in certain cases, the personal data provided, or where technically feasible, request its transfer to another data controller
Withdrawal of consentWithdraw consent at any time (for processing of personal data based on the consent of the individual). The data subject may withdraw his or her consent at any time, without this calling into question the lawfulness of the processing implemented prior to such withdrawal
Post-mortem rightsDefine guidelines for the retention, erasure and disclosure of personal data after death

How to exercise your rights at Relyens?

Persons wishing to exercise any of the rights listed above may contact Relyens’ Data Protection Officer (DPO), whose contact details are indicated below:

Relyens EntityDPO contact addressDPO contact email (*)
Relyens M.I France18 rue E. Rochet – 69372 Lyon cedex 08privacy.santesocialXXXrelyens.eu
Relyens Brokerage18 rue E. Rochet – 69372 Lyon cedex 08privacy.santesocialXXXrelyens.eu
Relyens SPSRoute du Creton – 18110 Vasselayprivacy.spsXXXrelyens.eu
RPS France18 rue E. Rochet – 69372 Lyon cedex 08privacy.rpsXXXrelyens.eu
Manty25 rue Claude Tillier – 75012 ParisrgpdXXXmanty.eu
Relyens M.I ItalySeconaria headquarters: Via Carlo Imbonati, n.18 – 20159 Milanprivacy.itXXXrelyens.eu
Relyens M.I SpainPaseo de la Castellana 110 – 28046 Madridprivacy.esXXXrelyens.eu
Relyens M.I GermanyKönigswall 22 – 44137 Dortmundprivacy.deXXXrelyens.eu
Relyens M.I Belgium18 rue E. Rochet – 69372 Lyon cedex 08 (France)privacy.beXXXrelyens.eu
Relyens M.I PortugalPaseo de la Castellana 110 – 28046 Madrid (Spain)privacy.ptXXXrelyens.eu
RPS Italy18 rue E. Rochet – 69372 Lyon cedex 08 (France)privacy.rpsXXXrelyens.eu
RPS Spain18 rue E. Rochet – 69372 Lyon cedex 08 (France)privacy.rpsXXXrelyens.eu
RPS Germany18 rue E. Rochet – 69372 Lyon cedex 08 (France)privacy.rpsXXXrelyens.eu

(*) Replace XXX with @ in the email to reconstitute the DPO’s contact email (anti-spam measure).

Important :

These e-mail addresses are dedicated solely to the management of requests relating to the processing of personal data carried out by the companies of the Relyens group. Please do not use them for any other purpose (e.g. contact a Compensation Manager, send a CV, etc.) as the application will not be processed.

When the situation justifies it, the Data Protection Officer (DPO) may ask the person exercising their rights to provide a supporting document (national identity card, etc.) to verify their identity.

If the response provided by the Relyens group does not satisfy him/her, the data subject has the possibility of filing a complaint with the competent supervisory authority (refer to the section “Personal data protection regulations” in the preamble to this Charter for contact details).