This Privacy Policy explains how PolicyWallet processes your personal data — whether you use the platform as an individual policyholder, as an insurance intermediary, or simply visit our website.
It is drafted in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and Greek Law 4624/2019. When the way we process data changes, we update the text and the date at the top of the page.
The controller of your data is Insurance Martech IKE, GEMI registration number 188863359000, with registered seat at Kalamoti, 82102, Chios, Greece, which operates the PolicyWallet platform (policywallet.gr).
For any data-protection matter you can contact our privacy officer at dpo@policywallet.gr or at info@policywallet.gr.
Account data: name, email address, phone number (optional), role (policyholder or intermediary), language and settings.
Insurance policy documents: the PDFs you upload and the details extracted from them — insurer, coverages, premiums, dates, vehicle or property details. Health policies may contain health data, a special category of data under Article 9 GDPR, which we process only with your explicit consent.
Payment data: your subscription plan and billing history. Your card details are handled exclusively by Stripe — they never reach PolicyWallet's systems.
Usage data: technical logs (IP address, device type, in-platform actions) necessary for the security and reliability of the service.
Intermediary-collaboration data: if you connect with an insurance intermediary, we record your consent, the scope of access you granted, and the full history of granting and revoking it.
Each processing activity rests on a specific GDPR legal basis:
| Purpose | Legal basis |
|---|---|
| Providing the service: account, policy storage, renewal reminders | Performance of a contract — Article 6(1)(b) |
| AI analysis of insurance policies | Consent — Article 6(1)(a); for any health data, explicit consent — Article 9(2)(a) |
| Subscription billing and invoicing | Performance of a contract — Article 6(1)(b); record-keeping: legal obligation — Article 6(1)(c) |
| Security, abuse prevention, request rate limiting | Legitimate interest — Article 6(1)(f) |
| Sharing information with the intermediary you choose | Consent — Article 6(1)(a), revocable at any time |
| Newsletter emails | Consent, with an unsubscribe option in every message |
| Keeping records of consents and GDPR requests | Legal obligation and accountability — Articles 6(1)(c) and 5(2) |
We do not sell personal data to third parties and do not use it for advertising profiling.
We do not make decisions based solely on automated means that produce legal effects concerning you, within the meaning of Article 22 GDPR — the platform's analyses are informational.
Policy analysis runs only after you give explicit consent inside the app, through a separate, recorded action. You can revoke it at any time; revocation stops future analyses and does not affect the storage of your documents.
For the analysis, the policy content is transmitted to an AI model provider acting as a processor on our behalf: primarily Google (Gemini models), with Anthropic and OpenAI available as alternate providers. The providers' API data-processing terms do not permit the use of your data to train their models.
Analysis results are informational, may contain errors, and do not constitute insurance advice — see the Terms of Service for details.
We use a limited number of technical providers (subprocessors) for hosting, the database, payments, email delivery and AI analysis. All are bound by data processing agreements under Article 28 GDPR and process only what their role requires.
The full list — with each provider's role, data and processing location — is published and kept up to date on the subprocessors page.
If you connect with an insurance intermediary through the platform, they gain access only to the information covered by your consent. You can revoke it at any time from your account — the revocation is recorded and takes effect immediately.
Our primary infrastructure is located in the European Union: the database, authentication and your files are hosted on Supabase infrastructure in the eu-west-3 region (Paris, France).
Some providers — notably the AI providers, Stripe and Vercel — may process data outside the European Economic Area, mainly in the United States. These transfers are covered by an adequacy decision (EU-U.S. Data Privacy Framework) and/or the European Commission's Standard Contractual Clauses.
Retention periods per category:
| Data category | Retention period |
|---|---|
| Policy documents and their analyses | Until you delete them or until your account is deleted |
| Account data | For as long as you keep an account; deleted upon completion of a deletion request |
| Invoices and billing records | 5 years after the end of the relevant tax year (tax legislation) |
| Records of consents and GDPR requests | 5 years from revocation or request completion, for accountability purposes |
| Technical logs | Up to 12 months |
| Newsletter subscription | Until you unsubscribe |
You have the right of access, rectification, erasure, restriction of processing, portability and objection, as well as the right to withdraw any consent — without the withdrawal affecting the lawfulness of prior processing.
From within the app: you can submit a data export request (a full copy in machine-readable form) and an account deletion request. Every request is handled through an internal GDPR workflow with a full action history.
By email: at dpo@policywallet.gr or info@policywallet.gr. We respond within one month at the latest, as provided by Article 12 GDPR.
If you believe the processing violates the law, you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA), Kifisias 1-3, 115 23 Athens, Greece — www.dpa.gr.
Data is encrypted in transit (TLS) and at rest. System access is role-restricted and logged, and request rate limits and other technical and organizational measures are applied.
No system is absolutely secure. If a breach incident likely to affect you occurs, we will notify you and the HDPA in accordance with Articles 33 and 34 GDPR.
We use cookies strictly necessary for the platform to operate (sign-in, storing your consent preferences). Analytics or marketing cookies are activated only if you accept them via the cookie banner.
When this policy changes materially, we update the date at the top and, for significant changes, notify you in the app or by email before they take effect.