1. About Us
Prodromou & Makriyiannis Insurance Underwriting Agencies & Consultants (hereinafter referred to as “the Company” or “Prodromou & Makriyiannis Insurance Underwriting Agencies & Consultants”) with T.I.C. 12005027C engages in insurance activities across Cyprus, having its main office at Kolokotroni 14, 2408 Engomi, Nicosia and phone no. 22761010.
This text aims to provide you with intelligible, transparent, and direct information about the processing of your personal data, collected and processed by us in the context of fulfilling our obligations to you. Our Company is bound by the applicable legislation to secure and to safeguard your rights and protect you against illegal processing of personal data. The Company also aims to protect your right to privacy, as well as to protect the personal data maintained by us and which is of concern to you.
Your personal information may help us to better understand your insurance needs and to offer you a more comprehensive and customized service. However, we understand that maintaining security and confidentiality of your personal data is a big responsibility which we take very seriously. For this reason, we have drawn up this Policy, among other things, which aims at informing you about the kind of data we collect, why we collect it and how we use it.
This Policy is addressed to natural persons, who are current or potential customers of the Company, beneficiaries of insurance policy contracts, authorized persons, third persons, suppliers and associates. By providing your personal information or the information of some other person, such as a beneficiary of the Insurance Policy or a person who files a claim and for whom you have consented or obtained authorization towards the processing of their personal data, you accept that we will use such information in the manner which is analytically explained in this Policy. You should identify the person whose personal data you give to the Company, to this Policy.
Further Processing Notices may be delivered to you at a later stage, underlining specific uses of your personal information.
It is also likely that certain changes will be made to this Policy in order to keep it in line with evolution in the legislation as well as with operational and technological developments. From time to time you should check the website of the Company and update yourself with the latest version of the Policy.
In the Policy, your data may sometimes be referred to as “personal data”, “personal information” or “data.” For the purposes of the Policy, personal data is any information concerning a natural person, whose identity may be established whether directly or indirectly, particularly by reference to an identification detail, such as full name, identity card number or one or more factors relating to the physical, physiological, genetic, psychological, financial, cultural or social identity of the said natural person.
The term personal data also includes, among other things, certain sensitive data (or special categories data), as for example the data concerning a natural person’s state of health, any penal convictions and data revealing the racial or ethnic origin of the person.
When we say that your personal data is a subject to “processing”, this term includes every action undertaken in relation to this data, such as the collection, registration, organization, structure, storage, adaptation, variation, recovery, search for information, usage, transmission, diffusion, disposal, correlation, combination, limitation, erasure, and destruction.
In case you require more information on how we process your personal data, you may apply to the Data Protection Officer of the Company at the address of our registered office, Kolokotroni 14, 2408 Engomi, Nicosia or by emailing firstname.lastname@example.org.
2. Personal Data Processing Principles
When we collect sensitive personal data, we are bound by the General Regulation for the Protection of Personal Data (EU) 2016/679 and, we take into consideration all the necessary organizational measures. Then we proceed to the processing stage, which is based on the following principles that govern the processing of personal data:
- it shall be subjected to legitimate and lawful processing in a transparent manner,
- it shall be collected for specified, express and legitimate purposes and shall not be subjected to further processing in any way incompatible with the purposes for which this data is collected by the company,
- only the appropriate and relevant data shall be collected, limited to the necessary purpose for which it has been collected,
- it shall be accurate and updated as necessary,
- it shall be retained only for as long as required and for the purposes for which they have been collected,
- it shall be subjected to processing in a manner guaranteeing their required security against non-authorised or unlawful processing and accidental loss, destruction or wear, among other things, through the use of suitable techniques and or organizational measures,
- when we transmit your personal data whether to another country or to a person who carries out the processing on behalf of the Company, the necessary measures shall be taken by us for the protection of your personal data, as for example through the conclusion of specialized contracts for data processing.
3. How we Collect your Personal Data
Quite often the collection of personal data is performed directly by you or through consultants or intermediaries. The relevant information may be received through a proposition submitted to us whether directly or indirectly (via associates or/and agents) or by way of the agreement between us by telephone or any other kind of communication with you.
Nevertheless, in some cases the collection of personal data may be effected by third parties, when for example you are named by someone as party to an offer/Company contract. Your personal details may be collected either by third persons (associates, agents, lawyers, authorized individuals) or by other insurance companies or even by sources available to the public at large.
More analytically, personal data may be collected:
(a) Straight from you (directly or indirectly):
- Through the information completion form in the context of filing an application for an insurance offer
- In the context of submitting an inquiry or objection and filing a complaint or claim on your part
- On line by the client or through an intermediary
- On line by the client when he chooses to pay through the JCC or an intermediary
- On line through a bank
- Personal details submission form
- By personal contact directly with the natural persons
- Via a hand-written curriculum vitae, email, employees, supervisor, department Director
(b) From various other/ “third” sources (indicatively):
- Through other insurance contracts in which you are named as part thereto (e.g. if you are nominated as driver in a motor vehicle insurance policy)
- Through other insurance services
- Through Insurance companies that we cooperate with
- Through our branches
- Through our associates, brokers or agents
- Through your next of kin (in the event you are unable to provide us with information)
- Through medical practitioners or other related health professionals (e.g. during the evaluation of a claim for damages),
- Through lawyers, agents, brokers, new associate completion form and insurance agent contract
- Company’s representatives, medical centers
- Through legal consultants (e.g. when you are not insured with us but you have a claim against a client of ours due to an accident),
- Through banks
- Through the Department of Road Transport, Public Services, Tax Department and Official Recipient Insolvency Service
- Through specialists and experts such as surveyors
- By telephone, through the Police, fax, websites, Photographs
- Through an electronic email message.
4. What kinds of Personal Data is Processed by us?
Our insurance company collects and processes various kinds of personal data, depending on the services provided in each particular case. Our policy applies to both our current and or potential customers directly or indirectly involved.
For all of the aforementioned reasons, our insurance company collects and processes personal data depending on the insurance coverage that will be provided for you as follows:
- Contact details (such as full name, Date of Birth, Identity Card Number, home address, email address, telephone, occupation, Social Insurance Number, etc.)
- Biographical details, competence statement, penal record, financial standing, social insurance number, School Leaving Certificate, Degree or/and Post Degree certificates, seminar attendance certificates, performance, grading, Name, Address, NIN, IBAN, TIN(AFT), date of birth, Telephone, Previous Salaries, clocking in and out, content of complaint.
- Information and contact details for third parties, who are named in any way as part of the contract (eg named drivers in motor vehicle insurance), spouse name and dependents (name, ID number, age, driver’s license dates, citizenship)
- Personal information, which is mentioned in the ID / passport (such as date of birth, citizenship, ID number, passport number, etc.)
- Credit card number (copy of JCC company clipping), name, contract number, Your banking information (eg IBAN), Swift bank
- Vehicle details
- Alien ID and passport numbers, social security numbers, copy of passport, alien visa
- Personal information about your state of health, both medical and mental as well as information on previous accidents, illnesses and their treatment.
- Income tax clearance and social security, jurisdiction, death certificate
- Information about your past such as bankruptcies, penalties, your previous claims or even if a lawsuit is pending against you.
- Information about the object, which is provided or will be provided by the Insurance Companies with which we cooperate (such as for example your vehicle, your boat, your home, etc. depending on the insurance product)
- Report from the police / fire department / relevant competent authority, expert report, Medical Certificates, Diagnostic Tests, accident photos, copy of driving license, copy of vehicle title deed
- Previous insurance coverage details
- Information about the property (movable and immovable), what is inside it and any kind of charges that concern it (mortgages, debts, etc.).
- Information necessary and corresponding to the respective insurance coverage.
- Claim form details, supporting documents, diagnoses, valuations, etc.
5. How we use your Personal Data
After your data has been collected by us, it may be subjected to processing within our insurance company, as previously mentioned, by our employees, associates and or agents, in order to provide you with a customized service.
We use your personal data for the following purposes:
- To communicate with you
- To improve the quality our services
- For the prevention, detection and investigation of crimes, including fraud and the legalisation of the proceeds from illegal activities, as well as the appraisal and management of other trading risks.
- To conduct research and analyse data, including an examination of our client basis and other individuals, who have given us their personal details and information (for instance, third persons claiming damages), and the risks faced by our enterprise, always in accordance with the prevailing Cypriot and European legislation (including the obtaining of consent when required).
- For promotional marketing and advertising activities. We may undertake the conduct of promotional activities in accordance with your preferences and upon your consent, using email messages
- For the personalization of your experience and the analysis and recording of your needs in relation to the insurance products that you have received from the insurance companies with which our Company cooperates, presenting information, advertisements and other promotions for new services.
- For the compliance of our company with the applicable laws and statutory obligations, European Union directives and guidelines, court decisions and other legal processes, and in order to respond to requests by public and state authorities, as stipulated in Cypriot and European legislation.
- To enforce and defend our legitimate rights and to protect our business activities, including those of our business associates, and to safeguard our rights, individual privacy, security or property assets, as well as the rights of our business associates, yours and those of other persons’ or third parties’; for the purpose of imposing our terms and conditions and pursuing all available recovery measures and containing our damages.
6. Sharing Your Personal Data
It might be necessary to share your personal data with our associates so that we could provide for you the required insurance, (i.e expert, loss adjustors) among others with Insurance Companies / Brokers / Employees / Partners, with JCC, with Microsoft, with Golden Telemedia, Domain Star, depending on the case with the Police, Insurance Companies Control Service, Insolvency department, with Cyprus Income Tax, with Insurers, with Bank and intermediaries (authorized to contact bank customers for services), with Immigration, with Auditors, third party the data subject asked us to contact, with Government Services, with Reinsurers, with Analysis Laboratories, with medical consultants, doctors, brokers, with the Supervisory Authority, with Consortium (MIF), with Home care service, with roadside assistance, lawyers, Social insurance (employer liabity), ΤΟΜ (vehicle insurance), business associations, with Financial Commissioner, with insolvency service, with Human Resources Development Authority, seminar organizers / training centers, with Investment / stock exchange / management companies and investment consultants, with Printing centers, with internal control, with brokers, with Courier Company, post office, Consultants, Legal Consultants.
As processors we may transfer your personal data to the insurance companies with which you contract through us, so that they can provide you with insurance coverage. We have contracted with all the insurance companies with which we cooperate to comply with the provisions of the General Data Protection Regulation (GDPR).
In no case, however, are we going to share your personal data for processing for purposes contrary to those described in this Policy without your prior notification.
In each case arising from our relationship, your personal data may be transmitted to public authorities, researchers, reinsurance companies, the Registrar of Insurance Companies, who shall undertake to process them on behalf of the Company in the capacity of processors, on the basis of the agreement between us. Personal data may be transmitted abroad to associated third providers, reinsurance companies, lawyers and experts. .
In each transmission to third parties every measure shall be taken beforehand so that only the necessary data shall be transmitted for the implementation of the contract, along with the effective requirements for their legitimate and lawful processing; moreover, the organizations to which the data is being transmitted shall undertake a written commitment that they shall comply on their part with the provisions of the General Data Protection Regulation. Exempt are those cases in which the communication of the data is effected due to some legal or statutory obligation. In cases where it is necessary to communicate your personal data to countries outside the European Union, which do not offer adequate guarantees for the protection of your personal data, our insurance company shall be obliged and hereby undertakes the responsibility to conclude contractual clauses between our Company and the Company to which the data is communicated, in order to safeguard the information transmitted.
7. Retention Period for your Personal Data
Our insurance Company shall retain your personal data in its records only for the time period required for the fulfillment of the insurance contract between us, unless legal or statutory obligations provide otherwise. This also applies to those cases where our agreement has been interrupted for any reason.
Trying to achieve harmonization with the Regulation, we have determined the time periods for the retention of your personal data, depending on the processing to which they are being subjected. The parameters that have been taken into consideration for the determination of the time periods are your better service, our operational needs, our legal obligations and the safeguarding of our legal interests.
In order to be accurately informed on the retention periods, please contact the Data Protection Officer of our Company.
8. What are your rights?
The General Data Protection Regulation defines your rights in regard to your personal data. On account of this, our insurance Company has developed a mechanism for the satisfaction of requests concerning your personal data, as follows:
- Right to access: You have a right to access your data maintained by us and you may at any time obtain a copy thereof provided we possess them in electronic form.
- Right to rectification: You have a right to access and rectify your personal details. You may at any stage of our relationship check and update your personal data, always presenting the necessary documentation and requesting the rectification or completion of inaccurate information. .
- Right to be forgotten: You have the right to ask for the erasure of the whole or part of the data that concerns you. We would like to underline however that our Insurance Company shall be obliged to erase only those personal data which can be erased as per our data erasure policy.
- Right to restriction: You hold the right to ask for the processing of your personal data to be restricted, even when the accuracy of the data is disputed or furthermore when the data is no longer useful to the insurance company but you request its retention due to legal claims.
- Right to object: You may at any time whatsoever raise objections about the processing of your personal data. In case you make use of this right, the processing shall immediately cease, unless the Company can prove the existence of legal interest or the need to use the data in support of a legal/judicial case.
- Right to data portability: You have the right to portability, that is, to transfer your personal data to another organization in a legitimate and commonly used form. The said data shall be erased as specified in the erasure policy of the Company.
- Right to recall consent: You have the right at any time to withdraw your consent to the processing of your personal data, without however affecting the legality upon which our policy was based prior to your withdrawal. We would like to inform you that the recall of your consent may possibly lead to the termination of the relevant services. .
- Right to launch complaint: You have a right to launch a complaint with the Commissioner for the Protection of Personal Data, regarding the processing of your personal data.
If, when filing your complaint, you feel that you have been wronged by us or if you have any doubts about the outcome of your request, you may submit it in writing to the Commissioner for the Protection of Personal Data at the below address:
Office of the Commissioner for the Protection of Personal Data
Iasonos 1, 2nd Floor
P.O. Box 23378
Τel.: 22818456 Fax No.: 22304565
In order to exercise your rights as above or in the case you require more information concerning your rights, you may communicate with the Data Protection Officer of our Company, at the address of our registered office or through the email address email@example.com.
9. Changes to our Policy
Changes in the Legislation or technological developments impose corresponding modifications on our part.
You are kindly asked to keep apace with our Policy, which may at any time change in order to adapt to new developments and facts.
Our reviewed policy shall be posted on our website at the address www.pminsurancebrokers.com.
Finally, you may ask to be supplied with a copy of the most recent version of the Policy in printed form.
Copyright Stylianos N. Christoforou & Associates LLC