Annex I — Treatment Order — PolizaTracker
Developed and operated by RMTracker S.L.
This document is the Annex I to the Terms of Use of PolizaTracker and forms an inseparable part of them. It regulates the processing of personal data that RMTracker is carried out by
the insurance broker holding the account, in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR).
1. Who is who Data controller:
the insurance broker holding the account. Decides how and for what purpose the data is processed, and responds to those affected and to the supervisory authority.
- Data processor: RMTracker S.L. («RMTracker»)
- Tax ID: B88803085
- Address: Avenida de Andalucía n.º 36, Local 2, 29793 Torrox, Málaga (Spain)
- Contact for data protection matters:
legal@rmtrackersolutions.com
RMTracker processes the data only to provide the service. It does not use them for its own purposes, it does not pass them on to third parties unless legally required, it does not sell them and it does not use them to train artificial intelligence systems.
2. Object, nature and purpose
RMTracker provides the broker with a platform to manage their portfolio: customers, policies, receipts, claims, quotes and communications, with access also for policyholders. In the course of that service RMTracker hosts and processes the personal data of individuals contained in those contracts and files. The processing consists of hosting, storing, organizing, making available, and deleting that data, and has no other purpose.
3. Duration
This annex comes into effect when accepted and lasts as long as the service contract is valid. Upon termination, section 9 applies.
4. Categories of data
| Category | What it includes |
|---|---|
| Identification and contact | Name, surname, identification document, date of birth, address, phone number and email address of principals, insureds and beneficiaries. |
| Policy data | Branch, company, policy number, coverage, capital, validity, premium and insured risk data. |
| Economic data | Receipts, payment status, refunds and domiciliation data as recorded by the brokerage. |
| Claims | Statement of fact, dates, place, damage, and documents and photographs provided, including amicable parties and reports. |
| Health data | When required by the claim or branch. Special category: see section 5.1. |
| Quotes and pricing | Data provided to obtain a price, including that of the person requesting the quote and who is not yet a customer. |
| Communications and activity | Messages exchanged on the platform and registration of new, modifications and cancellations made to files. |
5. Categories of interested parties
- Policy takers intermediated by the brokerage.
- Insureds and beneficiaries that appear in those policies, although they are not the policy takers.
- Third parties involved in an accident, such as the other driver of a friendly collision.
- Those who request a quote and are not yet customers.
- Employees and collaborators of the brokerage that use the platform.
5.1 Special category data
In health, life and accident insurance, and whenever personal damage is declared, the description of an incident and the accompanying documents may contain health data, which are special category data from Article 9 of the GDPR.
The controller processes them in accordance with Article 9.2.f of the GDPR in relation to Additional Provision 17 of Law 3/2018. RMTracker does not decide on them and does not use them for any purpose: it stores them and makes them available to whoever the controller has authorized.
In addition to these data, two specific rules are also governed in Section 7: access is limited by permissions within the brokerage itself, so that not all staff have access to a health record, and every admission, modification or termination is recorded.
Among the interested parties there may be minors, for example children included in a health or life insurance policy. It is incumbent on the controller to ensure that legal representation is correct.
6. Obligations of RMTracker as a manager
In accordance with Article 28.3 of the GDPR, RMTracker it is obliged to:
- Process data only according to documented instructions of the responsible party, including those relating to international transfers. The normal use of the service constitutes that instruction. If RMTracker understands that an instruction violates data protection regulations, will immediately notify you.
- Ensure confidentiality of those who access the data, through express agreement or legal obligation, which continues after the end of the relationship.
- Apply the measures of article 32, described in section 7.
- Do not use another person as an agent without authorization. The responsible person authorizes: the deputies listed in section 8. Any new appointment or replacement will be communicated with thirty days in advance, and the responsible party may object; if they object and the change is necessary to provide the service, they may terminate the contract without penalty.
- Attend the supervisor in order to be able to exercise the rights of access, rectification, deletion, limitation, portability and objection. If an affected person contacts us directly to RMTracker, será redirigido al responsable y éste será informado de inmediato.
- Attend the supervisor in compliance with articles 32 to 36: security, breach notification and impact assessment.
- Report security breaches without undue delay and, in any case, within forty-eight hours those who need to be informed about them, with the information provided in article 33.3. Forty-eight and not seventy-two because the responsible party needs a margin to meet their own deadline.
- Delete or return the data upon completion, according to section 9.
- Make available to the responsible party the information necessary to demonstrate compliance with this annex, and allow and contribute to audits, according to section 10.
7. Security measures
The measures are described by what the system does, not by what is usually said in a contract. They are verifiable:
- Isolation between agencies imposed by the database through security at the row level. An agency does not access another's data even if the application fails.
- Access control by permissions within the agency: personnel only have access to what their function requires, and files with health data are not accessible to all personnel.
- Second authentication factor required, and mandatory for operations on the agency staff.
- Encryption in transit in all communications and encryption at rest of storage.
- Documents and photographs of accidents are stored in private containers, without public URL, with the same isolation rule.
- Audit log of new entries, modifications and deletions on files.
- The text of a friendly statement photographed is recognized on the device itself; the image is not sent to any third party for analysis.
- Both the data confirmed by the person and the one proposed by the machine are retained, so that it can be proven later who put each thing.
The measures may evolve. RMTracker will not degrade them: any change will maintain an equivalent or superior level of protection.
8. Authorized Deputies
| Deputy | For what | Where |
|---|---|---|
| Supabase | Accommodation, database, document storage and authentication. | European Union, region eu-central-1 (Frankfurt). |
With each sub-contractor RMTracker maintains a contract that imposes the same obligations as this annex, and is liable to the person in charge of his actions as well as to the own.
9. End of the assignment
When the contract ends, RMTracker will delete the personal data processed by the responsible party, or will return them to in a common format and machine-readable if requested before deletion, and will delete existing copies.
With an exception that is not RMTracker: insurance regulations and the prevention of money laundering impose on the brokerage specific retention and blocking periods. While they are in force, the data of a policy or a claim are retained even if the contract with RMTracker has ended, and its early deletion cannot be requested from RMTracker because it is not his obligation.
10. Audit
The responsible party may request, once a year and with fifteen days' notice, the information necessary to prove compliance with this annex. He can also carry out an audit, either himself or through an independent third party that is not a competitor RMTracker, previa acuerdo con respecto a la fecha, el alcance y la confidencialidad, y sin interrumpir el servicio.
Additional audits resulting from a security breach, a requirement by the regulatory authority, or an established non-compliance are not subject to that annual limit.
11. Confidentiality Agreement
This section replaces a separate confidentiality agreement, so there is no need to sign a separate document.
Both parties agree to keep the confidential information of the other party secret that they come into possession of as a result of this relationship, to use it only for its intended purpose and not disclose it to third parties without written authorization. Technical, commercial, financial, and organizational information that is not publicly available is considered confidential, in particular, personal data processed under this annex.
The following information is not confidential:
- be made public before it is received, or remain so without violating this commitment;
- it would already be legitimately in the possession of the receiving party without any obligation of confidentiality;
- has been developed independently without using the other party's information; or
- must be disclosed by legal obligation or by the requirement of a competent authority, in which case prior notification will be given to the other party whenever it is permissible.
This commitment remains in effect. three years after ending the relationship. For personal data, there is no expiration date: the obligation of confidentiality under Article 28.3(b) of the GDPR does not expire.
12. Responsibility
Each party is liable for any damages caused by failing to comply with the obligations imposed on it by this annex and the GDPR, in accordance with Article 82 of the Regulation. RMTracker does not respond for the instructions of the responsible person nor for the legality of the treatments that he decides to carry out.
Acceptance without signature
This annex is accepted electronically when creating the account, in the format that it supports. Article 28.9 of the GDPR, and does not require a handwritten signature. A record is kept of each acceptance, including who made it, when, and which version of the text was in effect. The responsible party can request a certificate of their acceptances at any time.
If this annex changes, it will be notified in advance and a new acceptance will be required. The previous ones remain: they are the history of what was valid at each time.
14. Applicable law
This annex is governed by the GDPR, Law 3/2018 on the Protection of Personal Data and Digital Rights Guarantee, and Spanish legislation. In matters not covered here, the Terms of Use of PolizaTracker, which it forms part of.
legal@rmtrackersolutions.com.