Privacy Policy — PolizaTracker
Developed and operated by RMTracker S.L.
Who is who
PolizaTracker it is the application that one uses insurance agency makes available to its clients, with the brand of the agency itself. This clarifies the roles and responsibilities, and it is important to understand this before continuing:
- Their agency is responsible for processing the data. It is he who decides which data is processed and for what purpose, who registers him, and who maintains the insurance distribution relationship with him.
- RMTracker S.L. he is in charge of the treatment (Article 28 of GDPR): provides the tool and infrastructure, and processes data in accordance with the instructions of the supervisory authority.
Data identifying the person in charge:
- RMTracker S.L. ("RMTracker)
- Tax ID: B88803085
- Activity (NACE): 6210 - Computer programming activities
- Registration data and address: those that are in Terms and Conditions of RMTracker Solutions.
- Email:
legal@rmtrackersolutions.com
To exercise your rights, please first contact your insurance broker, which is responsible and who has designated, if applicable, a Data Protection Delegate. If you write to RMTracker, it will be forwarded to the relevant insurance broker and you will be informed: you will not be left without a means of exercising your rights.
2. No open account
It is not possible to create an account in PolizaTracker. It is your insurance broker who invites you, and the invitation expires. This means that if you are using the application, it is because there is a prior relationship with a specific insurance broker.
Each insurance broker works in a separate space. The data of one insurance broker is not accessible from another: the separation applies in the database itself, not just on the screen.
3. What data is processed
3.1 About you, as a user
- Identification and access: email address and password. The password is never stored in plain text; it is managed by the authentication system.
- Customer data: name or company name, identification document (DNI/NIF), email, phone number and address.
- Devices: device name and platform from which you access, in order to show you your sessions and send you notifications.
3.2 Your policies
- Contract Data: company, line of business, product, policy number, effective and expiration dates, premiums and receipts.
- Coverage and conditions: guarantees, deductibles, clauses and exclusions.
- Insured assets: according to the line of business, vehicle, house or asset in question.
3.3 Third party data on the policy
A policy almost never mentions a single person. In PolizaTracker the case, when the contract requires it:
- Policyholder: name, identification document, email and phone number.
- Insureds: name, identification document and relationship with the policyholder. They can be minors —children included in a health or life insurance policy—, and in this case the data is provided by the person who holds their legal representation.
- Beneficiaries: name, identification document and percentage assigned.
The brokerage incorporates these data from the insurance contract. It is the brokerage that must inform those people that their data is being processed here.
3.4 Claims
- The claimant: date and location of the incident and a free description regarding what happened.
- If there were personal injuries., if third parties intervened and if any authority intervened, with reference to the report when it exists.
- Documents that you provide: photographs, friendly parts, invoices, reports and any supporting documents, in PDF or image format. You can choose them from your device or take the photo at the moment with the camera.
- What can be read from the friendly letter: if he takes a photo of the printed document, the application recognizes its text within their own phone and it proposes the data that has already been entered —date, location, registration numbers, insurance companies, policies, and driver information, including the other one— for you to confirm or correct. Both what you confirm and what the application proposed are saved, so that it can be proven later which information was read by the machine and which was reviewed by a person.
- Process: history of states, comments and requests for additional information.
Two important warnings about this section:
- In insurance of health, life and accidents, and whenever personal injuries are claimed, the description and documents may contain health data, which are special category data (Article 9 of the GDPR). They are processed in accordance with Additional Provision 17 of the LOPDGDD 3/2018 and of the execution of the insurance contract.
- The reference to an attestation or intervention by authorities may constitute data relating to infractions (art. 10 GDPR). It is limited to what appears in the incident file.
3.5 Communications and activity recording
- Messages exchanged with your broker within the application.
- Audit log: what action was performed, on what, from which IP address and with which browser or application. This is in order to prove who accessed what, which is precisely one of the guarantees that the regulation requires when dealing with health data.
- Acceptance of these texts: when you accept a version of this policy, it saves which version you accepted, when, from which IP and with which device. This is the way to prove consent.
3.6 If you have only requested a quote
The public price setter does not require an account. If you use it, your name, email, phone number and postal code are saved, and only if you explicitly check the acceptance box. These data cannot be read with the application's public key: only the receiving broker can consult them.
4. What we do NOT do
- We do not sell or transfer your data for commercial purposes.
- There is no advertising or profiling. The application does not incorporate any analytics or advertising SDK.
- We do not access your microphone or location. The application does not request those permissions.
- The camera is only used if you open it. It is used to photograph the friendly and damages, and nothing more: it does not activate itself or record in the background. You can deny the permission and continue using the application normally, choosing the photos that you already have on the device.
- The photo of the damage is read on your own phone. Text recognition occurs within the device, without sending the image to any third party to process it. What is read is shown to you so that you can confirm or correct it before saving: nothing is considered valid without your review.
- There are no automated decisions with legal implications for you. The estimator proposes prices; who decides to hire and under what conditions are you, your brokerage firm and the insurance company.
5. For what purpose and with what legal basis
| Purpose | Legal basis |
|---|---|
| Consult your policies, receipts and coverage | Execution of the insurance contract or pre-contract (art. 6.1.b GDPR) |
| Declare and process a claim, including the health data that the damage requires | Art. 6.1.b and art. 9.2.f GDPR, in relation to D.A. 17ª LOPDGDD 3/2018 |
| Pricing and quotes in multi-estimator | Precontractual measures at the request of the interested party (art. 6.1.b) and, in the public form, consent (art. 6.1.a) |
| Obligations of insurance distribution and prevention of money laundering | Legal obligation (art. 6.1.c GDPR) — RDL 3/2020 and Law 10/2010 |
| Expiration notices and communications about your policies and claims | Contract execution (art. 6.1.b GDPR) |
| Audit and platform security registration | Legitimate interest (art. 6.1.f GDPR) and required security measures (art. 32) |
6. Who else is involved
- Your brokerage: is the responsible and natural recipient of everything you enter.
- Insurance companies with which your policies are contracted or for whom a quote is requested. The transfer is inherent in the insurance contract.
- Avant2 (multi-broker). If your brokerage has it enabled, the price configurator loads from Avant2 servers within the application, so that the data you enter to obtain a quote reaches that provider. Avant2 contracts each brokerage on its own, so that the contractual and data protection relationship with this provider is maintained by your brokerage, not RMTracker.
- Supabase (hosting, database, storage and authentication), contracted by RMTracker as the data controller. Your data resides in the
European Union, in the region
eu-central-1(Frankfurt, Germany).
The relationship with Supabase is governed by its data processing agreement, which forms part of its terms of service and incorporates the Standard Contractual Clauses approved by the European Commission when necessary. Supabase maintains a public list of its sub-controllers and is obliged to communicate any changes in advance.
How long do they last?
- Policy and claim data: while the contract is in effect and, subsequently, frozen for the applicable prescription periods. For reference, the regulations on insurance distribution and anti-money laundering impose terms of between six and ten years.
- Access data and profile: as long as the account is active.
- Audit and consent records: the necessary time period in order to be able to demonstrate compliance, which is the very reason for their existence.
- Estimates without hiring: the time required to process the request and to prove that it has been processed.
"Blocked" is not the same as "available": it means that the data remains reserved and can only be accessed to serve judges, courts, public administrations, or in response to demands for accountability.
8. Their rights
You can exercise the rights of access, rectification, erasure, limitation, portability and opposition. before his office, which is responsible for the treatment. It can also be written to: legal@rmtrackersolutions.comwill be forwarded to the appropriate office.
If you believe that your rights have not been adequately addressed, you can file a complaint with the Spanish Agency for Data Protection.
Please note that the right of objection it does not reach what the law requires it to preserveThe data of a policy or claim cannot be deleted while the legal period is in effect, regardless of whether you stop using the application.
9. Account deletion
You can delete your account in two ways, and both do the same: from within the app, in Profile → Delete my account, or from the web, without needing to have a session started, in the account deletion form.
What is deleted: your access to the application, your credentials, your registered devices and your notification preferences.
What is not deleted, and why: your policies and your claims remain under the custody of your broker during the period that the law imposes. We cannot delete them even if you request it: the obligation of conservation is legal and falls on the broker as a distributor of insurance. Deleting your account removes your access to the application; it does not cancel your policy or interrupt the processing of an open claim.
10. Security
- Access is restricted in the database itself:: each broker only accesses its data, and each customer only theirs. It does not depend on the screen hiding the information.
- Policy and claim documents are stored in private containers private, organized by broker, and served via limited duration signed links. There is no public URL that allows access to them.
- Only PDF or image documents are accepted, with a maximum size per file.
- New entries, modifications and deletions are recorded in an audit history. Queries are not logged.
11. Not applicable to minors
PolizaTracker This policy is not directed at minors and accounts are not opened in their name. However, minors may be included as insureds or beneficiaries in a policy: their data is provided by their legal representatives or the broker from the contract, and they are treated with the same protection as the rest.
12. Changes to this policy
Versions are recorded with their effective date, and the application saves which one you accepted. If a change significantly affects the treatment, you will be informed through the available contact methods.
legal@rmtrackersolutions.com.