Legal document
Claimio privacy statement
1. Scope and contact
This privacy statement explains how Claimio processes personal data when you use our websites, Claimio, a claim scan, an account or another Claimio service. Claimio is established in Rijswijk, the Netherlands, and registered with the Dutch Chamber of Commerce under number 93665938.
For a specific claim program, a partner or representative organisation may act as an independent or joint controller for part of the processing. Before we share a dossier, we inform you about the organisation involved, the purpose of the transfer and the data to be shared. Questions about this statement can be sent to [email protected].
2. Purposes of processing
We process personal data only for defined purposes, including:
- creating, securing and managing your account;
- performing a scan initiated by you and showing possible matches;
- creating, retaining and reviewing a dossier submitted by you;
- sending necessary messages about your registration or dossier;
- transferring a dossier to a partner chosen by you and approved for the program, after the required information and authorisation have been recorded;
- handling questions, complaints and requests under the GDPR;
- securing, monitoring and improving our services and preventing misuse.
A scan result is a technical, preliminary assessment. It does not establish that you have an enforceable claim or a right to compensation.
3. Legal bases
Depending on the purpose, we process personal data on the basis of your consent, performance of a contract or pre-contractual steps requested by you, a legal obligation or a legitimate interest. Where a source connection or other processing requires consent, we request that consent separately and for a specific purpose. Consent is not automatically the legal basis for every processing activity within the platform.
4. Whose data we process
This statement may apply to website visitors, Claimio users, people who start a claim scan or registration, partner contacts and people whose data is supplied by an authorised partner. A partner may supply personal data only where a valid legal basis exists and the data subject has been appropriately informed.
5. Categories of personal data
Depending on the service selected, we may process:
- identity and contact data, such as name, address, email address and phone number;
- account, authentication and security data;
- data about a possible claim, counterparty, event and relevant period;
- documents, correspondence and other evidence supplied by you;
- data from a source connected by you, such as selected transaction or vehicle data;
- consents, mandates, signatures and a history of relevant actions;
- technical data, such as session, device, security and access-log data;
- payment data where required for a specific settlement.
We do not request more data than is reasonably necessary for the relevant step.
6. Special-category and sensitive data
Documents or transaction descriptions may reveal information about health, political views or other sensitive circumstances. We seek to avoid or limit such data. Where processing is nevertheless necessary, we assess the applicable legal basis, necessity, access restrictions and additional safeguards in advance. Do not upload sensitive data that is not relevant to your scan or dossier.
7. Recipients and service providers
Where necessary, we may provide personal data to:
- service providers for hosting, storage, security, communications and support;
- GoCardless or another open-banking provider when you initiate a bank connection;
- the claim partner, representative organisation or legal service provider chosen by you, within the recorded program and authorisation scope;
- regulators, law-enforcement bodies or other parties where required by law.
We do not sell personal data. A partner does not gain access to your dossier merely by having an account. Access requires a valid role, program assignment and the required authorisation.
8. Processing outside the EEA
We seek to process personal data within the European Economic Area. If a service provider processes data outside the EEA, we apply a valid transfer mechanism and the required additional safeguards. You may request information about a specific transfer.
9. Security
We implement appropriate technical and organisational measures proportionate to the nature of the data and the risks of processing. These measures include access management, encryption where appropriate, logging, data minimisation, secure storage, backups and incident procedures. No digital system is entirely risk-free, and we therefore do not give an absolute security guarantee.
10. Retention periods
We retain personal data no longer than necessary for the purpose for which it was collected, unless a statutory retention duty, pending dispute, legal claim or another legitimate reason requires a longer period. The period may differ for account, dossier, evidence, communication and audit data. You may ask through your dashboard or by email which period applies to your data.
11. Withdrawing consent
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before that time. It may mean that a source connection, scan or other optional function is no longer available. Processing based on another valid legal basis does not automatically end when consent is withdrawn.
12. Questions and complaints
If you have a question or complaint about the processing of your personal data, contact us at [email protected]. You also have the right to lodge a complaint with the Dutch Data Protection Authority. We appreciate the opportunity to investigate your complaint first, but this is not mandatory.
13. Your privacy rights
To the extent provided by the GDPR, you may request information, access, rectification, erasure, restriction of processing or transfer of your data. You may also object to processing and, where applicable, request human intervention in automated decision-making. We may verify your identity and must take account of statutory retention duties and the rights of others. You may submit a request through your dashboard or at [email protected].
14. Changes
We may amend this privacy statement when our services, partnerships or legal obligations change. The current version and date appear on this page. Where a change has material effects, we will notify you through an appropriate channel before it takes effect, to the extent required by law.