In2Matrix Netherlands B.V. acts as an insurance broker and consultant in the field of risk management, employee benefits and insurance. In2Matrix can also act as a representative of insurers and as a local representative in the international network Brokerslink. In2Matrix strives to protect the privacy and confidentiality of personal data that the company processes in connection with the services that it provides to its customers.
In2Matrix’s services consist mainly of risk advice and insurance mediation.
Identity of Data Controller and contact details
For this explanation, In2Matrix (In2Matrix, we/us or our) means the entity with legal personality, established at Gustav Mahlerlaan 381, 1082 MK, Amsterdam, The Netherlands.
In2Matrix is the data controller of the personal data that we process in the context of our services. In certain cases, we may have reached an agreement with you that we will function as a processor for certain services. When we function as a processor, we will fulfil the obligations laid down in the agreement that we have concluded with you.
Use of personal data
Our services pertain to the processing of personal data (this is data that could be traceable to a natural person), such as:
Personal details, such as name, address, email, telephone, gender, marital status, family information, date and place of birth, employer, position, and employment history. Also, data required for identification, such as a passport number.
Data relevant to the risk that is to be insured, as well as policy information, information about the quotations received by individuals and the policies that they acquire.
We will only process the data that is necessary for our service. If certain information is not provided, it could imply that it will not be possible to provide the requested services, or to settle or compensate any damages. When you provide information to us of third parties (your partner, children, co-insured persons, or details of persons in case of emergency situations), we assume that you have informed them about the processing of their data by In2Matrix and that you have referred them to this privacy statement.
In addition to the information that you provide, we may gather information from third parties, such as:
You and your family members
Your employer
Insurers
Anti-fraud databases and other external databases, including sanction lists
Objectives processing personal data
In2Matrix processes the data in the context of its business operations and services. This includes, amongst others:
Delivering the services requested by - or on behalf of - you
Mediating in the realisation of insurance policies
Investigating complaints in connection with insurance policies or services
Consultancy in the field of risk management
Compliance with legal obligations
Offering other products that may be of interest to you
Legal basis processing personal data
Implementing the agreement: in the context of our services and entering into agreements, we collect and use the necessary personal data for making an offer, the realisation and execution of the agreement.
Compliance with a legal obligation: the processing of data may be necessary for compliance with legal obligations. In2Matrix, for example, is subject to a license under the AFM. In2Matrix is obliged to comply with the applicable regulations.
Legitimate interest: the gathering and use of certain data is necessary to fulfil legitimate commercial interests, for example, offering products that may be of interest to you or doing market research to improve our products and services. When we process your data on this basis, we will take the necessary measures to prevent the processing being an infringement of your rights and freedoms under the privacy legislation.
Permission: we process data based on permission when we process special data, for example, medical data. You are always at liberty to withhold or withdraw permission. In this case it may not be possible to implement our services. Where special data is required and you wish to make use of our services, you must agree to the gathering and use of this special data.
Provision to third parties
We engage third parties in the context of our services. We can provide data in this context to:
Insurers and intermediaries, where necessary, for taking out insurances and providing our services
Investigative authorities, where necessary, to prevent or detect fraud and crime
Government agencies, where necessary, for In2Matrix to meet its legal obligations
Third parties in case of outsourcing of work. This work will be carried out under the responsibility of In2Matrix, in accordance with our security standards and our instructions
Legal successors, in case of the sale of the service to another organisation or takeover or the sale of (a part of) In2Matrix. If, in this case, personal data is shared, the data will continue to be used in accordance with this statement
International transfer of personal data
We provide Personal Data, or grant access to Personal Data, to countries outside the European Economic Area (EEA). The legislation in these countries regarding data protection does not always offer the same level of protection of Personal Data as offered in the EEA. We will protect Personal Data in all cases as described in this Privacy Statement.
Certain countries outside the EEA have been approved by the European Commission as being countries that offer essentially the same protection of Personal Data as under the laws on data protection in the EEA. Based on the EU data protection laws, we may provide Personal Data freely to these countries.
Security
We have physical, electronic, and procedural safeguards built in, tailored to the sensitivity of the information we retain. These safeguards may vary, depending on the sensitivity, layout, location, quantity, distribution, and storage of the personal data and include specific measures to protect personal data from unauthorised access. If applicable, the safeguards include, amongst others, separate servers for storage of data, firewalls, access controls, separation of functions and similar security protocols. We limit access to personal data, namely to staff and third parties who need access to such information for legitimate, relevant business purposes.
Limitation of gathering and storage of personal data
We gather, use, provide and process personal data as required for the purposes mentioned in this privacy statement, or as permitted by law. If we should need personal data for a purpose that is not consistent with the purposes stated in this privacy statement, we will inform you about the new purpose and, if necessary, we will ask you and the persons concerned for permission (or ask other parties to do this on our behalf) in order to process the personal data for the new purposes.
Our retention periods for personal data are based on our business needs and legal requirements. We retain personal data for as long as necessary for the processing purpose(s) for which the data was collected, any other permissible related purpose, or as required by law.
For example, we may retain certain transaction data and correspondence until the time limit for claims that arise from the transaction has expired, or to comply with the legal requirements concerning the retention of such data.
Accuracy of the data
We rely on the correctness of the information that is known to us in order to execute our services in the correct manner. You should therefore also inform us about any changes in your data.
Accountability, transparency and rights
You have the following rights with regard to the data that we process about you:
The right to inspect the processing of your personal data by In2Matrix.
The right to have this data corrected or deleted, especially when the processing of the data is no longer necessary.
The right of objection against the use of data for marketing purposes.
The right to further processing of your personal data.
You can also request us to transfer your details to another party.
Some of these rights can only be exercised in certain cases. If we are unable to follow up on a request, we will inform you accordingly. In order to exercise these rights and to obtain further information about this privacy statement, you can contact the compliance department via an email to Margot.Clarenbeek@in2matrix.com.
In2Matrix will retain your data for as long as necessary for the purposes for which the data was processed. In addition, In2Matrix must keep records in view of the file and safety responsibility obligation and legal position and further to comply with legislation and regulations.
Your opinion will be appreciated. If you have any comments or questions about our privacy statement, please send them to Margot.Clarenbeek@in2matrix.com, or write to us at the address mentioned earlier in this statement.
If you have any complaints about the processing of your personal data by In2Matrix, please let us know. You can contact us in this regard, and we will look at solutions together with you. You have the right to file a complaint with the data protection supervisor, the Personal Data Authority (via www.autoriteitpersoonsgegevens.nl).
This privacy statement is not an agreement, and we can update this privacy statement. The last amendment dates from 1 March 2023. If we make any amendments to this Privacy Statement, we will update the date on which it was last amended. Amendments that we make to this Privacy Statement will take effect immediately.