Privacy policy and cookies

Here you can read more about how we handle personal data and how we use cookies when you visit our website

Europæiske Rejseforsikring A/S, facilitated by its Swedish branch office Europeiska ERV Filial, registration number 516410-9208, is responsible for processing your personal information according to the General Data Protection Regulation (2016/679) (GDPR)

Go directly to the part about cookies >

Introduction

Europæiske Rejseforsikring A/S (herinafter referred to as "Europeiska ERV", "we", "us" or "our") is committed to protecting the confidentiality, integrity and availability of information about our clients, suppliers, collaborators and employees, including personal data.

When processing personal data in connection with delivery of insurance service, we consider ourselves data controller, as we are processing data in order to conclude an insurance agreement with a customer. We also enter data processing agreements when entering into contracts with third parties who process data on our behalf, setting out instructions and terms and conditions for our and the other party’s processing of personal data.

This Data Protection Policy provides information about Europeiska ERV’s processing of personal data in our capacity as data controller. Read more about this below.

The Policy contains the information we need to give you according to the General Data Protection Regulation (GDPR) in particular Article 5 and Section 2.

GENERAL

1. Our processing activities

We collect and process personal data in the following situations:

  • When you take out and purchase an insurance
  • Administration of the policy, including claims handling and issuing documents
  • When corresponding with you, in order to maintain our obligations towards you and at the same time comply with the legal requirements we have to fulfill.
  • When entering or administering cooperation agreements with you or your employer
  • When visiting our establishments, web-pages or delivering to us

We collect and process personal data in connection with our collaboration with our customers. We collect only the personal data required for the agreed purpose, and we only ask our customers to share personal data where it is strictly necessary for such purposes.

GDPR Article 5 in particular.

What data is collected?

Non-sensitive personal data, including information about name, address, telephone number and e-mail address of our customers as well as name, job title, phone number and e-mail address of any corporate customer. In addition, we collect social security number in order to ensure clear identification of our customers. In some cases, i.e. when handling claims, we may collect and process sensitive personal data about your health in order to ensure that your and our rights are protected.

Storing

We store personal data as long as needed to fulfill the purpose of collecting it. This means we keep information in the period; where we may be met with a claim, are required to do so by law (e.g. bookkeeping and financial regulatory law) or where we have another particular purpose.

In the main, we keep claims records to the maximum of the statute of limitations, meaning 10 and 30 years respectively from date of reporting and for any additional limits in case of reopened claims.   

The purpose of and legal basis for collecting the information

We process non-sensitive personal data for the purpose of performing the contract with the customer, including:

  • Issuing of insurances
  • Claims handling
  • Invoicing premium

Furthermore, processing is necessary as it enables Europeiska ERV to pursue a legitimate interest in developing our business and services (e.g. identify customer needs and improvement of the provided service).

In case of deliveries and cooperation agreements, we process data necessary for fulfillment of our agreements and legitimate interests.

SPECIFIC

1. Recording

When you call us, we may ask permission to record your conversation. Recording of conversations for training and documentation purposes will not happen without your acceptance. We use the recordings when training our employees to continually improve our service to you, our insurance products and case management as well as for documentation for the agreements we make with you. The recording is stored in a separate part of our system and can only be accessed by a select group of employees. The recordings are deleted after three (3) months unless continued processing, law or authority prevents it in which case deletion follows our standard routines.

Our basis for collecting, use and internal transfer of data is consent as in GDPR article 6. par. 1, letter a. (consent) for normal personal data and GDPR article 9. par. 2, letter a -ref. article 6. par. 1, letter a. for special categories such as health data.  

You can at all times recall your consent, of which you can read more in paragraph title: Your Rights as an Individual, item 11. Below.

2. Europeiska ERVs services (insurance and services hereto)

We collect and process personal data about our leisure customers and corporate customers’ employees.

What data is collected?

We process non-sensitive personal data, including name, address, email address and telephone number of the customer and the customer’s employees and sensitive data concerning your health, and social security data.

The purpose of and legal basis for collecting the information

We process information for the purpose of providing the insurance you have bought from Europeiska ERV. Processing is necessary to comply with a legal obligation (the insurance contract you have entered into).

Processing of personal data can have different legal grounds. When we process your personal data it will be for:

  • fulfill our insurance agreement with you or to enter into it. GDPR article 6. par. 1 letter b.

  • fulfillment of our legal obligations in relation to the party in our agreement who has taken out a group insurance or the like, through which you are covered. Ref. GDPR article 6. par. 1 letter c.

  • the reason that we as an insurer can pursue a legitimate interest. Ref. GDPR article 6. par. 1 letter f.

  • In the course of administering the insurance we also have a legitimate interest in assessing and verifying claims with the purpose of controlling and containing costs and avoiding insurance fraud etc., to better balance insurance premiums. See General Data Protection Regulation (GDPR) article 6. par. 1 letter f. on legitimate interests, as well as article 9. par 2 letter f. on legal claims.

CPR-number DK

Processing of a CPR Number enjoys special protection in the Danish law on data protection (DBL). This means that our processing happens on the basis of your consent, ref. DBL § 11. sec. 2, nr. 2.

In case of an insurance claim your CPR-Number is processed as described below under Health Information.   

CPR-number SE

Swedish law (2018:218) with additional orders to the EU-GDPR §10 states that SE CPR can be processed without consent when it is clearly motivated amongst other things in cases where it is needed to ensure correct identification, or for another evident purpose.

Our clear motivation for the processing of CPR in this case is the evident purpose of fulfilling our contract and obligations as well as ensuring that this happens towards you as the correct person. 

Health Information

Information concerning health belongs to the special sensitive category of personal information.

We process information about your health in connection with our administering and regulation of your insurance claim. This means that when we process information about your health it is necessary for the establishment, exercise and defense of a legal claim. Ref. GDPR article 9. sec. 2, letter f.

We may however still need to ask for your consent to process CPR and Health Information as it can be a specific requirement for some partners like medical doctors that the needed information is exchanged on that ground in particular.

Automated decision making

In some cases when entering claims or health data on our web, you may be subjected to automated approval based on the input you provide. All cases not automatically approved are deferred to manual handling by claims and medical experts and therefore there are no risks connected to the automated processing.

Trustpilot

Europeiska ERV may contact you via email to invite you to review any services and/or products you received from us [in order to collect your feedback and improve our services [and products]] (the “Purpose”).

We use an external company, Trustpilot A/S (“Trustpilot”), to collect your feedback which means that we will share your name, email address and reference number with Trustpilot for the Purpose. If you want to read more about how Trustpilot process your data, you can find their Privacy Policy ere.

3. Supplier- and collaborator administration

We collect and process personal data in relation to our suppliers and collaborators, including personal data of their staff.

What data is collected?

We process solely non-sensitive information, including contact information.

The purpose of and legal basis for collecting the information

We process personal data in order to manage the contract, to receive goods and services from our suppliers and collaborators and, where relevant, to provide professional services to our customers.

The legal basis for our processing of personal data is to fulfil the contract to which the data subject is a party. If the data subject is not a party to the contract, we process data based on a legitimate interest in relation to being able to perform the contract with our supplier or collaborator.

GDPR article 6. sec. 1, letter b. (entering and fulfilling contract) and article 6. sec. 1, letter f. (legitimate interest).

4. Visitors to our office

We collect and process personal data about visitors, including customers and other guests.

What data is collected?

In the registration process, we collect name, company and name of the host at Europeiska ERV. Moreover, we process personal data obtained from video footage.

The purpose of and legal basis for collecting the information

We process information for security purposes. Our legal basis for processing personal data is the legitimate interest of Europeiska ERV to ensure a high level of security.
We require visitors to our offices to sign in at the reception. We keep a record of visitors for a short period of time. Our visitor records are securely stored and only accessible on a need to know basis (e.g. to look into an incident).

5. Visitors to erv.se

We collect the personal data provided by you on Europeiska ERV’s website or to which you give your explicit consent.

When is collection made?

When you visit erv.se, we inform you of the collection of your personal data. The use of services on Europeiska ERV’s website, such as taking out and purchasing of insurances, filling out health declarations and reporting claims online requires that you provide certain personal data. This also applies if you register for our newsletters.

What data is collected?

The personal data collected by Europeiska ERV may comprise your name, e-mail address, address, social security number and other identification data. We also collect information about your activity on erv.se.

The purpose of and legal basis for collecting the information

Europeiska ERV collects your personal data in order to be able to issue insurances or provide a given service to you, to send you newsletters and other information relating to our business and services. Moreover, Europeiska ERV collects your personal data for the purpose of internal market analyses, targeted marketing and statistics.
Our basis for processing personal data is your consent or that Europeiska ERV aims to pursue a legitimate interest in developing its business and adapting its marketing.

GDPR article 6. sec. 1, letter a (consent) and article 6. sec. 1, letter f. (legitimate interest).

Europeiska ERV’s use of cookies

Our website uses “cookies”.

A cookie is a small text file that is stored in the web browser on your computer, smartphone, iPad or any other device you use for net surfing when you visit our website. Cookies enable the recognition of your computer etc. and the collection of information about your net activity, including what sites and features are visited by your browser, and ensure the technical function of the website. In some cases, the use of cookies is the only way to make a website work as intended. A cookie is a passive file and it cannot collect information on your computer, spread computer virus or other malware. Cookies are anonymous and contain no personal data. Cookies are used by almost all websites.

Read more about Europeiska ERV's use of cookies here >

6. Security of processing

Europeiska ERV takes information security very seriously. We have security measures in place to ensure data protection of customer information, personal data and other confidential information.

See in particular GDPR chapter IV.

7. Source

Europeiska ERV collects personal data directly from you and/or any third party or public authorities.

8. Transferal of personal data

We transfer personal data only when we have a legal basis for doing so:

Transfer of data can be done with reference to the General Data Protection Regulation, articles 6, 9 and 45, 46, 49. Concerning transfers to third countries and the necessary guarantees, any transfer is made with due regard for Chapter V. (five) of the regulation.  

For Sweden – to other parties

If we share your data with others, it is only with a legal ground fitting to the type of data and relationship you have with us, such as may for example mean your consent.

We ensure all information is adequate, relevant and kept at a minimum. 

For Denmark – to other parties

Transfer can also happen under DK Financial Business Act §117. sec. 1, ref. GDPR article 6. sec. 1, ref. sec. 2, 3 and 4.

Hereto also related DK-DBL §13. sec. 2.

Recipients:

- Others in the ERV-group

Europeiska ERV is a wholly owned subsidiary of the German insurance company Europäische Reiseversicherung AG, part of the German group ERGO. Europeiska ERV, in its capacity as Data Controller, does not release any personal data to Europäische Reiseversicherung AG/ERGO without the necessary security guarantees.

- Other third parties providing goods or services

Europeiska ERV may engage third parties, e.g. subcontractors, in connection with our delivery of services. To this end, personal data necessary for the delivery of the agreed services may be disclosed to such third parties.

When we share data with others, we put contractual arrangements and security mechanisms in place to protect the personal data and to comply with our data protection obligations.

- Professional advisers

We may disclose personal data to professional advisers like lawyers, medical advisors, or specialist investigators in case of for example claims or fraud inquiries etc. to be able to receive advice and counselling.

- Public authorities or third parties as required under and in accordance with applicable law or regulation

Occasionally, we may be ordered to disclose personal data to public authorities or third parties which we comply to if required by applicable law and regulation. The purpose may be to check that we are complying with applicable law and regulation, to investigate an alleged crime, to establish, exercise or defend legal rights.
We will only fulfil requests for personal data where we are permitted to do so in accordance with applicable law or regulation.

- Other Insurance Companies

Other Insurers, for example in case of recourse, where we collect dues on an insurance in another company or where others do so towards us. But also, where an exchange is needed in order to establish, exercise or defend a legal claim such as in potential fraud cases. Here we first and foremost have a legitimate interest in controlling that a claim for compensation is correct and legitimate, but also in regulating premiums justly towards clients and to establish, exercise or defend a potential legal claim

General Data Protection Regulation (GDPR) Art. 6, itm. 1, letter f on legitimate interest, and Art. 9 itm. 2 letter f on legal claim.

9. Security guarantees and third party countries

In cases where data is transferred to third party countries (outside the EU / EEA), this is done with due regard to extra security measures where needed, including EU Standard contract clauses. You can read more about the security measures here.

10. Data retention

Europeiska ERV deletes personal data when we no longer have a work-related need to process them. The retention period is fixed in relation to the obligations of Europeiska ERV under applicable law, supervisory authorities on auditing, other public authorities and to secure documentation.

11. Your rights as an individual

As an individual, you have certain rights over your personal data, which Europeiska ERV as data controller are obligated to fulfil.

You can contact us to get access to personal data held by us as a data controller. Similarly, you are entitled to have any inaccurate or inadequate personal data rectified. Please contact Europeiska ERV if you want to have your personal data deleted or you want to restrict or object to Europeiska ERV’s processing of such data. If you wish to exercise your right to data portability, please let us know.

Where we process personal data based on consent, individuals have a right to withdraw consent at any time. To withdraw consent to our processing of your personal data please contact us. If you no longer wish to receive e-mails with information or marketing material about Europeiska ERV, please click on the unsubscribe link in the relevant e-mail received from us.

Contact information

The data controller is Europæiske Rejseforsikring A/S, CVR no. 62 94 05 14, Frederiksberg Allé 3, DK-1790 Copenhagen V, Denmark.

If you want to exercise your rights as described above, or if you have any questions about this privacy statement or how and why we process personal data, please contact us at:

Europeiska ERV
Hantverkargatan 11B
112 21 Stockholm
Telephone: +46 770 456 900
E-mail: info@erv.se

You are always entitled to know whether we process personal data about you and, if so, when including possible additional information about you. Additional information includes details about the purpose of the processing, the types of personal data and the recipients of your personal data.
Provided that the rights of others are not affected, you may receive a copy of the personal data we hold about you. You also have the opportunity to get any incorrect and incomplete personal information about you corrected.

Complaints and questions

In case of questions in regards to the processing of personal data you can send an email to dpo@erv.se.

We hope that you won’t ever need to, but if you do want to complain about our use of personal data, please send an e-mail with the details of your complaint to our customer embassy at kundambassaden@erv.se. We will consider the complaint and return.

You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection in relation to your rights and to Europeiska ERV’s processing of your personal data. For further information about how to complain to the Swedish Authority for Privacy Protection, please refer to the Swedish Authority for Privacy Protection website imy.se.

Cookies

We use cookies on our site. A cookie is a small text file stored on your computer that is required for some features of the site to work properly. Cookies thus make it easier for you as a customer, for example, filling out a form or making an application for compensation. Cookies are also used to provide statistics about how our visitors use the site so that we can increase relevance, improve experience and content on both the site itself and in advertising.
 
There are two types of cookies. One of the types of cookies is stored for a long time on the visitor's computer as the cookie has an expiration date. Once the date has passed, the cookie is deleted.
 
The other type of cookies, so-called session cookies lacks expiration date. They are only used during your visit to the site, the cookie is then stored temporarily in your computer's memory and usually disappears when you close your browser. These are cookies such as allows you to fill in a notification of compensation, sign an insurance or jump back and forth in a feed without having to fill in the information you have already filled in before.
 
Europeiska ERV uses both types of cookies.
 
In your browser settings, you can set which cookies are allowed, blocked or deleted. Europeiska ERV follows a recommendation for the use of cookies used by many Swedish companies and organizations.