ICEA logo

Privacy Policy

This is a courtesy English translation. The French version is the legally binding one; in the event of any discrepancy, the French version prevails.

Purpose

This Policy is issued by I CONSEIL EXPERTISE ASSURANCES SARL, whose registered office is at 23 Grande Allée du 12 Février 1934, 77186 Noisiel, France, registered with the Meaux Commercial Court under SIREN number 508 591 633 and with ORIAS under number 08 046 290 (hereinafter "the data controller").

The purpose of this Policy is to inform visitors of the website hosted at https://www.icea-assurances.fr (hereinafter the "website") of how their data is collected and processed by the data controller.

This Policy reflects the data controller's wish to act in full transparency and in compliance with applicable national provisions, such as Act No. 2018-493 of 20 June 2018, promulgated on 21 June 2018, amending the French Data Protection Act to align national law with the European legal framework, and with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (hereinafter the "General Data Protection Regulation").

The data controller pays particular attention to protecting the privacy of its users and therefore undertakes to take the reasonable precautions required to protect the personal data collected against loss, theft, disclosure or unauthorised use.

"Personal data" is defined as any personal data relating to the user, i.e. any information that makes it possible to identify them, directly or indirectly, as a natural person.

If the user wishes to respond to any of the practices described below, they may contact the data controller at the postal address or email address specified in the "Contact details" section of this Policy.

What data do we collect?

The data controller collects and processes, in accordance with the arrangements and principles described below, the following personal data:

  • the user's domain (automatically detected by the data controller's server), including the dynamic IP address;
  • the user's email address if previously disclosed, for example by sending messages or questions via the website, or by communicating with the data controller by email;
  • the user's identification and contact details (surname, first name, postal address, telephone number) when completing a form available on the website;
  • all information relating to the pages the user has viewed on the website;
  • any information the user has provided voluntarily, for example as part of a request for a study, a quotation request or an appointment booking.

The data controller may also collect non-personal data. Such data is described as non-personal because it does not make it possible to identify a particular person, directly or indirectly. It may therefore be used for any purpose, for example to improve the website, the products and services offered, or the data controller's advertising.

Should non-personal data be combined with personal data in such a way that the data subjects can be identified, that data will be treated as personal data until it can no longer be linked to a particular person.

Collection methods

The data controller collects personal data in the following ways:

  • the contact form;
  • the quotation and pricing request form;
  • the online appointment booking module;
  • email or telephone exchanges following on from those requests.

Purposes of processing

Personal data is collected and processed solely for the purposes set out below:

  • to manage and monitor the performance of the services offered;
  • to prepare the requested studies, quotations and insurance proposals;
  • to monitor the contractual relationship and the management of policies;
  • to answer the user's questions;
  • to produce statistics;
  • to improve the quality of the website and of the products and/or services offered by the data controller;
  • to send information about the data controller's new products and/or services;
  • for commercial prospecting purposes;
  • to better identify the user's areas of interest.

The data controller may carry out processing that is not yet provided for in this Policy. In that case, it will contact the user before re-using their personal data, in order to inform them of the changes and, where applicable, give them the opportunity to refuse such re-use.

Legitimate interests

Some of the processing carried out by the data controller is based on the legal ground of its legitimate interests. Those legitimate interests are proportionate to respect for the user's rights and freedoms. If the user wishes to be informed of the detail of the purposes based on the legal ground of legitimate interests, they are advised to contact the data controller (see "Contact details").

Retention period

As a general rule, the data controller retains personal data only for the time reasonably necessary for the purposes pursued and in accordance with legal and regulatory requirements.

A client's personal data is retained for a maximum of 10 years after the end of the contractual relationship between that client and the data controller.

Once the retention period has elapsed, the data controller does everything possible to ensure that the personal data has been rendered unavailable and inaccessible.

Exercising your rights

For all the rights set out below, the data controller reserves the right to verify the user's identity.

Any such request for additional information will be made within one month of the user submitting their request.

Access to data and copies

The user may obtain, free of charge, written communication or a copy of the personal data concerning them that has been collected.

The data controller may charge a reasonable fee based on administrative costs for any additional copy requested by the user.

Where the user submits the request electronically, the information is provided in a commonly used electronic form, unless the user requests otherwise.

Save for the exceptions provided for by the General Data Protection Regulation, a copy of their data will be provided to the user no later than one month after receipt of the request.

Right to rectification

The user may obtain, free of charge, as soon as possible and no later than within one month, the rectification of their personal data that is inaccurate, incomplete or irrelevant, and may complete it if it proves to be incomplete.

Save for the exceptions provided for by the General Data Protection Regulation, a request to exercise the right to rectification is handled within one month of being submitted.

Right to object to processing

The user may at any time, on grounds relating to their particular situation, object free of charge to the processing of their personal data where:

  • the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller;
  • the processing is necessary for the purposes of the legitimate interests pursued by the data controller or by a third party, unless overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data (in particular where the data subject is a child).

The data controller may refuse to give effect to the user's right to object where it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the user, or for the establishment, exercise or defence of legal claims. In the event of a dispute, the user may bring an action in accordance with the "Complaints" section of this Policy.

The user may also, at any time, object without justification and free of charge to the processing of personal data concerning them where such data is collected for direct marketing purposes (including profiling).

Where personal data is processed for scientific or historical research purposes or for statistical purposes in accordance with the General Data Protection Regulation, the user has the right to object, on grounds relating to their particular situation, to the processing of personal data concerning them, unless the processing is necessary for the performance of a task carried out in the public interest.

Save for the exceptions provided for by the General Data Protection Regulation, the data controller must respond to the user's request as soon as possible and no later than within one month, and must give reasons for its response where it does not intend to act on such a request.

Right to restriction of processing

The user may obtain restriction of the processing of their personal data in the cases listed below:

  • where the user contests the accuracy of an item of data, and only for the period needed for the data controller to verify it;
  • where the processing is unlawful and the user prefers restriction of processing to erasure;
  • where, although no longer necessary for the purposes of the processing, the user needs the data for the establishment, exercise or defence of legal claims;
  • for the time needed to examine the merits of an objection submitted by the user, in other words the time needed for the data controller to weigh its legitimate interests against those of the user.

The data controller will inform the user when the restriction of processing is lifted.

Right to erasure (right to be forgotten)

The user may obtain the erasure of personal data concerning them where one of the following grounds applies:

  • the data is no longer necessary in relation to the purposes of the processing;
  • the user has withdrawn consent to the processing of their data and there is no other legal basis for the processing;
  • the user objects to the processing and there are no overriding legitimate grounds for the processing, and/or the user exercises their specific right to object in respect of direct marketing (including profiling);
  • the personal data has been unlawfully processed;
  • the personal data must be erased in order to comply with a legal obligation (under Union or Member State law) to which the data controller is subject;
  • the personal data was collected in relation to the offer of information society services addressed to children.

Erasure does not apply, however, in the following cases:

  • where processing is necessary for exercising the right of freedom of expression and information;
  • where processing is necessary for compliance with a legal obligation requiring the processing under Union or Member State law to which the data controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  • where processing is necessary for reasons of public interest in the area of public health;
  • where processing is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, in so far as the right to erasure is likely to render impossible or seriously impair the achievement of the objectives of that processing;
  • where processing is necessary for the establishment, exercise or defence of legal claims.

Save for the exceptions provided for by the General Data Protection Regulation, the data controller must respond to the user's request as soon as possible and no later than within one month, and must give reasons for its response where it does not intend to act on such a request.

Right to data portability

The user may at any time request to receive, free of charge, their personal data in a structured, commonly used and machine-readable format, in particular with a view to transmitting it to another data controller, where:

  • the data processing is carried out by automated means; and where
  • the processing is based on the user's consent or on a contract concluded between the user and the data controller.

Under the same conditions and arrangements, the user has the right to obtain from the data controller that the personal data concerning them be transmitted directly to another data controller, in so far as this is technically feasible.

The right to data portability does not apply to processing that is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller.

Recipients of the data and disclosure to third parties

The recipients of the data collected and processed are, in addition to the data controller itself, its employees or other processors, and its carefully selected commercial partners — in particular the insurance undertakings with which policies are taken out — which work with the data controller in connection with the marketing of products or the provision of services.

The data controller uses technical service providers acting as processors for website hosting, email delivery, customer relationship management and online appointment booking. Those providers act only on the data controller's instructions and are bound by contractual confidentiality and security commitments.

Where processing involves a transfer of personal data outside the European Union, that transfer is governed by the appropriate safeguards provided for in Chapter V of the General Data Protection Regulation, in particular the standard contractual clauses adopted by the European Commission.

Should the data be disclosed to third parties for direct marketing or commercial prospecting purposes, the user will be informed beforehand so that they can choose whether to accept the transfer of their data to third parties.

Where such a transfer is based on the user's consent, the user may withdraw that consent for that specific purpose at any time.

The data controller complies with applicable legal and regulatory provisions and will in all cases ensure that its partners, employees, processors or other third parties with access to such personal data comply with this Policy.

The data controller discloses the user's personal data where a law, legal proceedings or an order from a public authority makes such disclosure necessary.

Security

The data controller implements appropriate technical and organisational measures to ensure a level of security of the processing and of the data collected that is appropriate to the risks presented by the processing and to the nature of the data to be protected. It takes into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the risks to users' rights and freedoms.

The data controller always uses encryption technologies recognised as industry standards within the IT sector when transferring or receiving data on the website.

The data controller has put in place appropriate security measures to protect against and prevent the loss, misuse or alteration of information received on the website.

Should the personal data controlled by the data controller be compromised, it will act promptly to identify the cause of the breach and take appropriate remedial measures.

The data controller informs the user of such an incident where the law requires it to do so.

Complaints

If the user wishes to respond to any of the practices described in this Policy, they are advised to contact the data controller directly.

The user may also lodge a complaint with the French data protection authority (CNIL):

  • on the CNIL website, www.cnil.fr, via the online complaint service or, in cases not covered by that service, via the "Besoin d'aide" help service;
  • by post, writing to: CNIL — 3 Place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07, France.

Contact details

For any question and/or complaint relating to this Policy, the user may contact the data controller:

Amendments

The data controller reserves the right to amend the provisions of this Policy at any time. Amendments will be published directly on the data controller's website.

Governing law and jurisdiction

This Policy is governed by the national law of the data controller's principal place of establishment.

Any dispute relating to the interpretation or performance of this Policy will be submitted to the courts of that national law.

Last updated: August 3, 2026

ICEA footer logo

23 Grande Allée du 12 Février 1934, 77186 Noisiel, France

ORIAS logo

I Conseil Expertise Assurances is registered with the French ORIAS under number 08046290.

An insurance broker who listens to find the best solution on the market for you

Facebook iconLinkedIn icon

Société Nouvelle d'Assurances et de Réassurances Intercontinentales. SARL active since 2008, specialised in the business of insurance agents and brokers. Registered with the RCS on 16 October 2008 and with INSEE on 16 October 2008. SIREN 508591633. SIRET 50859163300021.

© 2008 - 2026 I CONSEIL EXPERTISE ASSURANCES | DESIGN & DEVELOPMENT: ITERU.AGENCY