This Privacy Policy is adopted with the purpose of providing registered individuals, hereinafter referred to as "individuals", information on how Sjóvá uses personal data. It is intended to ensure the integrity of data, the quality of processing and the protection of information on individuals, and that personal data is processed in accordance with current legislation on personal data protection.
The main purpose of processing personal data at the Sjóvá group is to provide personalised services in the field of optional and mandatory insurance.
Data controller is Sjóvá-Almennar tryggingar hf., (Sjóvá) Reg. No. 650909-1270, Kringlan 5, 103 Reykjavík. Sjóvá-Almennar líftryggingar hf., Reg. No. 650568-2789 is a subsidiary of Sjóvá and all its activities are outsourced to the parent company. The companies act as joint controllers regarding the processing that the life insurance company outsources to the parent company. The companies are insurance companies and operate under the Act on Limited-liability Companies, No. 2/1995; the Act on Insurance Activities, No. 100/2016; and Act on Insurance Groups, No. 60/2017. The Sjóvá Group, hereafter referred to as “Sjóvá” operates in the insurance market and is a comprehensive insurance company with operations in Iceland in the field of non-life and life insurance.
The policy applies to Sjóvá's customers, representatives of customers who are legal entities, individuals who contact Sjóvá or visit the company's premises, as well as job applicants. Data processing agreements, which Sjóvá concludes with parties who are responsible for processing data on behalf of Sjóvá, must comply with the policy.
Personal data consists of information that can be traced directly or indirectly to a specific individual. This includes, for instance, names, Id. Nos., addresses, location data, e-mail addresses, telephone numbers, cadastral numbers, car registration numbers, credit card numbers, internet identifiers (such as IP addresses), information on bank accounts, identifiers, passports or other identity documents, photos, videos and usernames.
Sensitive personal information includes health information, political opinions, religion, genetic and biometric data.
The processing of personal data is defined as any operation or set of operations that are performed upon personal data, whether the processing is manual or electronic.
For the most part, Sjóvá processes information that registered individuals provide directly themselves, such as when purchasing insurance or submitting claims for loss or damage. Individuals supply personal information such as their name, Id. No., address, phone number, and email address. The company may, however, also process data that identify such persons, such as information on the financial and health circumstances of individuals. Sjóvá may also obtain information from other sources, such as lawyers, police, healthcare institutions, other insurance companies and from the insurance companies' claims database.
The processing of individuals’ personal data is carried out to prepare offers for insurance coverage, purchasing insurance, in claims services, for processing Stofn benefits in the customer loyalty program Stofn, which in some cases is provided by external parties, retailers and service providers, in presenting information on customer pages on Mitt Sjóvá, for use in the Innsýn remote inspection solution, in communications and marketing, customer surveys, for internal control, audits and risk management, and in communication with and processing of representatives of clients who are legal entities.
Processing may also occur in connection with individuals' communications with Sjóvá regarding feedback, compliments and complaints to Sjóvá, giving and receiving information during online chat and chatbot interactions, in connection with requests for sponsorship from Sjóvá and when processing job applications.
The company may also, in connection with an appropriate risk assessment, obtain information on politically exposed persons (PEPs), as provided for in the Act on Actions to Combat Money Laundering and Terrorist Financing.
The processing of personal data also takes place in Sjóvá's electronic monitoring, in the form of call recording and camera surveillance at Sjóvá's establishments. Telephone calls to and from Sjóvá may be recorded to ensure accuracy and traceability of information and business instructions, to ensure the safety of employees and to provide proof in connection with insurance transactions. Audio recording can also be part of employee training and used to improve service.
The processing of personal data may also occur in interaction with a chatbot. Such interactions are stored in a database, and the stored data may be used to train and improve the chatbot and for the purpose of improving the service.
A surveillance camera system is in operation at Sjóvá's facilities to ensure the safety of employees and the security of premises and assets.
Sjóvá's authorisation to process the data is mainly based on the provisions of Act No. 90/2018 concerning the data subject's consent to processing, the need to enter into a contract with the data subject and to protect the legitimate interests and legal obligations of the company.
When determining the terms and conditions for insurances and their renewal, the company relies on a specific classification of customers that is processed automatically in the company's systems. Premiums, claims history and business history form the basis of that classification, which is intended to contribute to a fairer distribution of premiums and is part of Sjóvá’s risk diversification. Sjóvá has a legitimate interest in classifying customers according to risk, as this is an important element of premium setting and consequently affects the terms and conditions offered to customers as well as the price of insurance policies for individuals. Customer classification is also used for marketing and statistical purposes, with the company's legitimate interests serving as the legal basis for such processing.
The processing of personal data and the determination of contractual terms based on a risk assessment are prerequisites for entering into an agreement between Sjóvá and its customers. Individuals always have the right to request human intervention, express their point of view, obtain an explanation of the decision, and contest it by contacting Sjóvá by telephone at +354 440 2000 or through the online chat service.
Under certain circumstances, Sjóvá uses automated decision-making in the provision of its services. Automated decision-making involves information technology systems processing data automatically on the basis of predefined criteria, with the outcome being communicated either to employees or directly to individuals. Sjóvá uses automated decision-making in the following processes, where the decision is based on the information available about individual persons and their transactions.
The processing of personal data and the determination of contractual terms based on a risk assessment are prerequisites for entering into an agreement between Sjóvá and its customers. Individuals always have the right to request human intervention, express their point of view, obtain an explanation of the decision, and contest it by contacting Sjóvá by telephone at +354 440 2000 or through the online chat service.
Sjóvá does not share personal information with third parties except where necessary for the company to fulfil its obligations and agreements or for other legitimate purposes.
Sjóvá may pass on your personal information to third parties, such as service providers who provide Sjóvá with reinsurance services, IT services, collection services for debt collection or to other third parties, such as workshops and claims service providers, as well as other services related to the processing and the company’s operations. Processing is based on Sjóvá’s legitimate interests and contractual obligations.
In some cases, Sjóvá avails itself of expert assistance from external parties regarding claims, for example, with impact and speed calculations, evaluation of medical data, reporting and inspections in connection with claims; such processing is based on the data processing agreements currently in effect between Sjóvá and the processor. Processing is based on the legitimate interests of Sjóvá.
Sjóvá shares information on claims with the insurance companies’ claims database stored at Creditinfo. This includes information on registered claims reported to the company, apart from claims covered by life and sickness insurance and claims concerning children under the minimum age of criminal responsibility. The claims database is a joint registration and reference database of insurance companies. The purpose of the database is to prevent insurance fraud and overpayment of insurance compensation. Questions and answers about the claims database .
If required under current laws or regulations, personal data may be provided to third parties such as the authorities or courts.
Sjóvá does not, as a general rule, transfer personal data outside the European Economic Area (EEA). However, in certain circumstances, it may be necessary to transfer personal data to countries outside Iceland. Where personal data is transferred outside the EEA, Sjóvá ensures that such data is afforded a level of protection equivalent to that provided within the EEA. This may include, among other measures, ensuring that the transfer is permitted under applicable data protection laws, that appropriate technical and organisational security measures are in place in accordance with Sjóvá’s requirements, and that suitable contractual arrangements have been entered into with the recipient to ensure an adequate level of protection for the personal data.
Individuals have the right to request access to their personal data, however, subject to the limitations provided for under Act No. 90/2018 and any other lawful restrictions. An individual has the right to a copy of their personal data and may submit such a request by completing the request form available on the company's website and here. Sjóvá shall provide the requested information within 30 days of receiving the request.
Sjóvá places great emphasis on ensuring that personal data is reliable and accurate at any given time. Individuals have the right, under certain circumstances, to request the rectification of their personal data, the erasure of such data, or the restriction of its processing. Requests for rectification and, where applicable, erasure or restriction of processing may be submitted to personuvernd@sjova.is.
Individuals also have the right to object to the processing, transfer their own data and to withdraw their consent for processing. Due to the nature of insurance companies’ operations, the contractual relationship is dependent upon the provision of accurate and necessary information. Consequently, the withdrawal of consent can result in the termination of a contractual relationship or impede the processing of an application or claim and determination of compensation.
Individuals have the right to submit a complaint regarding the processing of their personal data with Sjóvá by contacting personuvernd@sjova.is and/or with Persónuvernd (The Icelandic Data Protection Authority), which supervises compliance with data protection legislation, the processing of personal data, and adjudicates disputes relating to data protection matters.
Complaints may be submitted to the Icelandic Data Protection Authority by email at postur@personuvernd.is or through its website.
Sjóvá places a strong emphasis on security in the handling and processing of personal data. To support this objective, the Sjóvá has established an access control policy and implemented procedures governing the access rights of employees and agents. Through these measures, Sjóvá seeks to ensure that personal data is accessible only to those individuals who require access to it for the performance of their duties. Sjóvá has also implemented the ISO/IEC 27001 information security standard and is certified in accordance with that standard.
Sjóvá outsources the operation of its information systems and requires its hosting providers and service providers to comply with applicable requirements relating to the protection of personal data and information security.
Sjóvá has established a records retention policy with provisions on how long data is to be retained, including personally identifiable data. Retention periods are determined based on differing needs for retention depending on the nature of the data. This period is determined in part by legislation and regulations, such as statutes of limitations which may prescribe periods between 4 and 20 years, accounting rules which require 7 years retention, and rules governing electronic monitoring which provide for a maximum retention of 90 days. Job applications are retained for 6 months and are then deleted. When data is no longer required for the purposes for which it was retained, it is securely and irreversibly deleted. To this end, Sjóvá has established internal procedures governing the deletion of data.
Individuals found to have acted fraudulently or threatened an employee of the company may be barred from further business dealings with the company. The same applies to individuals who are in significant arrears with the company. The company will use its customer database to identify those who are excluded as clients for these reasons.
Where there is a suspicion of fraudulent activity, one aspect of the investigation may involve obtaining personal data from sources other than the data subject. Such processing is carried out for the purpose of preventing insurance fraud and thereby helping to ensure that policyholders do not bear the cost of unjustified insurance payouts through increased premiums.
Sjóvá has appointed a Data Protection Officer whom individuals may contact regarding any matters relating to the processing of their personal data and how they can exercise their data protection rights. Enquiries, comments, and requests may be directed to Sjóvá's DPO by email at personuvernd@sjova.is.
This privacy policy is reviewed and updated as necessary, particularly if there are changes to Sjóvá’s processing of personal data, amendments to applicable data protection legislation, or changes to relevant regulations.