ICEA — 20 years of experience at your service
This Policy is issued by I CONSEIL EXPERTISE ASSURANCES SARL, whose registered office is at 23 Grande Allée du 12 Février 1934, 77186 Noisiel, France, registered with the Meaux Commercial Court under SIREN number 508 591 633 and with ORIAS under number 08 046 290 (hereinafter "the data controller").
The purpose of this Policy is to inform visitors of the website hosted at https://www.icea-assurances.fr (hereinafter the "website") of how their data is collected and processed by the data controller.
This Policy reflects the data controller's wish to act in full transparency and in compliance with applicable national provisions, such as Act No. 2018-493 of 20 June 2018, promulgated on 21 June 2018, amending the French Data Protection Act to align national law with the European legal framework, and with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (hereinafter the "General Data Protection Regulation").
The data controller pays particular attention to protecting the privacy of its users and therefore undertakes to take the reasonable precautions required to protect the personal data collected against loss, theft, disclosure or unauthorised use.
"Personal data" is defined as any personal data relating to the user, i.e. any information that makes it possible to identify them, directly or indirectly, as a natural person.
If the user wishes to respond to any of the practices described below, they may contact the data controller at the postal address or email address specified in the "Contact details" section of this Policy.
The data controller collects and processes, in accordance with the arrangements and principles described below, the following personal data:
The data controller may also collect non-personal data. Such data is described as non-personal because it does not make it possible to identify a particular person, directly or indirectly. It may therefore be used for any purpose, for example to improve the website, the products and services offered, or the data controller's advertising.
Should non-personal data be combined with personal data in such a way that the data subjects can be identified, that data will be treated as personal data until it can no longer be linked to a particular person.
The data controller collects personal data in the following ways:
Personal data is collected and processed solely for the purposes set out below:
The data controller may carry out processing that is not yet provided for in this Policy. In that case, it will contact the user before re-using their personal data, in order to inform them of the changes and, where applicable, give them the opportunity to refuse such re-use.
Some of the processing carried out by the data controller is based on the legal ground of its legitimate interests. Those legitimate interests are proportionate to respect for the user's rights and freedoms. If the user wishes to be informed of the detail of the purposes based on the legal ground of legitimate interests, they are advised to contact the data controller (see "Contact details").
As a general rule, the data controller retains personal data only for the time reasonably necessary for the purposes pursued and in accordance with legal and regulatory requirements.
A client's personal data is retained for a maximum of 10 years after the end of the contractual relationship between that client and the data controller.
Once the retention period has elapsed, the data controller does everything possible to ensure that the personal data has been rendered unavailable and inaccessible.
For all the rights set out below, the data controller reserves the right to verify the user's identity.
Any such request for additional information will be made within one month of the user submitting their request.
The user may obtain, free of charge, written communication or a copy of the personal data concerning them that has been collected.
The data controller may charge a reasonable fee based on administrative costs for any additional copy requested by the user.
Where the user submits the request electronically, the information is provided in a commonly used electronic form, unless the user requests otherwise.
Save for the exceptions provided for by the General Data Protection Regulation, a copy of their data will be provided to the user no later than one month after receipt of the request.
The user may obtain, free of charge, as soon as possible and no later than within one month, the rectification of their personal data that is inaccurate, incomplete or irrelevant, and may complete it if it proves to be incomplete.
Save for the exceptions provided for by the General Data Protection Regulation, a request to exercise the right to rectification is handled within one month of being submitted.
The user may at any time, on grounds relating to their particular situation, object free of charge to the processing of their personal data where:
The data controller may refuse to give effect to the user's right to object where it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the user, or for the establishment, exercise or defence of legal claims. In the event of a dispute, the user may bring an action in accordance with the "Complaints" section of this Policy.
The user may also, at any time, object without justification and free of charge to the processing of personal data concerning them where such data is collected for direct marketing purposes (including profiling).
Where personal data is processed for scientific or historical research purposes or for statistical purposes in accordance with the General Data Protection Regulation, the user has the right to object, on grounds relating to their particular situation, to the processing of personal data concerning them, unless the processing is necessary for the performance of a task carried out in the public interest.
Save for the exceptions provided for by the General Data Protection Regulation, the data controller must respond to the user's request as soon as possible and no later than within one month, and must give reasons for its response where it does not intend to act on such a request.
The user may obtain restriction of the processing of their personal data in the cases listed below:
The data controller will inform the user when the restriction of processing is lifted.
The user may obtain the erasure of personal data concerning them where one of the following grounds applies:
Erasure does not apply, however, in the following cases:
Save for the exceptions provided for by the General Data Protection Regulation, the data controller must respond to the user's request as soon as possible and no later than within one month, and must give reasons for its response where it does not intend to act on such a request.
The user may at any time request to receive, free of charge, their personal data in a structured, commonly used and machine-readable format, in particular with a view to transmitting it to another data controller, where:
Under the same conditions and arrangements, the user has the right to obtain from the data controller that the personal data concerning them be transmitted directly to another data controller, in so far as this is technically feasible.
The right to data portability does not apply to processing that is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller.
The recipients of the data collected and processed are, in addition to the data controller itself, its employees or other processors, and its carefully selected commercial partners — in particular the insurance undertakings with which policies are taken out — which work with the data controller in connection with the marketing of products or the provision of services.
The data controller uses technical service providers acting as processors for website hosting, email delivery, customer relationship management and online appointment booking. Those providers act only on the data controller's instructions and are bound by contractual confidentiality and security commitments.
Where processing involves a transfer of personal data outside the European Union, that transfer is governed by the appropriate safeguards provided for in Chapter V of the General Data Protection Regulation, in particular the standard contractual clauses adopted by the European Commission.
Should the data be disclosed to third parties for direct marketing or commercial prospecting purposes, the user will be informed beforehand so that they can choose whether to accept the transfer of their data to third parties.
Where such a transfer is based on the user's consent, the user may withdraw that consent for that specific purpose at any time.
The data controller complies with applicable legal and regulatory provisions and will in all cases ensure that its partners, employees, processors or other third parties with access to such personal data comply with this Policy.
The data controller discloses the user's personal data where a law, legal proceedings or an order from a public authority makes such disclosure necessary.
The data controller implements appropriate technical and organisational measures to ensure a level of security of the processing and of the data collected that is appropriate to the risks presented by the processing and to the nature of the data to be protected. It takes into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the risks to users' rights and freedoms.
The data controller always uses encryption technologies recognised as industry standards within the IT sector when transferring or receiving data on the website.
The data controller has put in place appropriate security measures to protect against and prevent the loss, misuse or alteration of information received on the website.
Should the personal data controlled by the data controller be compromised, it will act promptly to identify the cause of the breach and take appropriate remedial measures.
The data controller informs the user of such an incident where the law requires it to do so.
If the user wishes to respond to any of the practices described in this Policy, they are advised to contact the data controller directly.
The user may also lodge a complaint with the French data protection authority (CNIL):
For any question and/or complaint relating to this Policy, the user may contact the data controller:
The data controller reserves the right to amend the provisions of this Policy at any time. Amendments will be published directly on the data controller's website.
This Policy is governed by the national law of the data controller's principal place of establishment.
Any dispute relating to the interpretation or performance of this Policy will be submitted to the courts of that national law.
Last updated: August 3, 2026
23 Grande Allée du 12 Février 1934, 77186 Noisiel, France
Société Nouvelle d'Assurances et de Réassurances Intercontinentales. SARL active since 2008, specialised in the business of insurance agents and brokers. Registered with the RCS on 16 October 2008 and with INSEE on 16 October 2008. SIREN 508591633. SIRET 50859163300021.
© 2008 - 2026 I CONSEIL EXPERTISE ASSURANCES | DESIGN & DEVELOPMENT: ITERU.AGENCY