For the Munich Re Location Risk Intelligence On-Demand Service (the “On-Demand Service”), this notice explains how personal data collected in this On-Demand Service is processed and informs you of your rights as client and/or user or other interested party under data protection law.

1. Who is responsible for the processing of personal data?

Munich Re Service GmbH
Königinstrasse 107
80802 Munich, Germany

Tel.: +49 (0)89 38 91 - 0
Fax: +49 (0)89 399056
Email: risk-management-partners@munichre.com

You may contact our Data Protection Officer at the aforementioned address, or via the e-mail address dpo@munichre.com.

2. Which data will be collected and processed?

This On-Demand Service uses essential technical cookies which are required to execute the services. Such cookies help to make the On-Demand Services usable by enabling basic functions such as authentication and access to secure areas. In addition, they serve the anonymous evaluation of user behaviour, which we use to develop our On-Demand Service constantly for you. Moreover, the On-Demand Service does not use any social-media plug-ins.

(a) We (Munich Re Service GmbH), collect, process and store only the following of your personal data which are related to your effected purchase of On-Demand Credits in the On-Demand Service:

  • customer details (email, name, date of birth, company, address, phone number, your last IP address, your last activity date; your account password is, however, encrypted);
  • order details (order number, order status, the total number of orders you have effected via the On-Demand Service, shipping method, the date on which the order was created, billing details such as billing name, billing email, billing company, billing address, billing phone number, used payment method, VAT number, customer IP address, paid date, authorization transaction ID); as well as
  • order item details (name, price quantity).

We do not store any of this data.

(b) Stripe Payments Europe, Limited, The One Building, 1 Grand Canal Street Lower, Dublin 2, Co. Dublin, Ireland, our payment provider (see item 4 below) is the only entity that collects and processes

  • payment details (name, credit card number, credit card provider, dates of credit card validity)

for the purpose of processing the order via the On-Demand Service.

The data are, however, not stored neither by Stripe, Inc. with the exception of the last four digits of your credit card number.

(c) As Consent Management Platform (CMP) we use an online service by Usercentrics GmbH, Rosental 4, 80331 Munich.

(d) During an online session, we use the tracking pixel technology of WiredMinds GmbH, Lindenspürstraße 32, 70176 Stuttgart, to analyze visitor behavior. Here, the IP address of a visitor is processed. The processing takes place exclusively for the purpose of collecting company-relevant information such as the company name. IP addresses of natural persons are excluded from further use (whitelist procedure). The IP address is not stored at WireMinds. The data collected by WiredMinds does not allow any conclusion to be drawn about a natural person at any time. WiredMinds GmbH uses this information to create anonymous usage profiles relating to visitor behavior on our website. The data obtained in this way is not used to personally identify visitors to our website. We base the processing of the data on a legitimate interest (Art. 6 para. 1 c DSGVO).

3. For what purpose and on which legal basis will your data be processed?

We process your personal data in compliance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and all other applicable laws.

In order to fulfill (pre-)contractual duties, Art. 6 para. 1 lit b) GDPR, we collect, process and store your personal data in the On-Demand Service in order to allow the purchase by credit card of packages of On-Demand Credits in the On demand Service as well as the immediate invoicing by email or download of such purchased On-Demand Credits pursuant to Art. 6 para. 1 lit b) GDPR (i.e. to fulfill (pre-) contractual duties).

You may revoke your consent at any time. Revoking the consent applies only for the future and does not affect the validity of the data processing until the revocation.

4. Who receives your data? What categories of recipients might we disclose your data to?

Where is your data being transmitted to?

a) Your customer details, order details and order item details are made available to Munich Re Service GmbH, your contractual partner. Subcontractor for the processing of your order is

Münchener Rückversicherungs- Gesellschaft
Aktiengesellschaft in München

(Munich Reinsurance Company),
Königinstr. 107,
80802 Munich, Germany.

b) Your payment details are transmitted to the payment provider:

Stripe Payments Europe, Limited
The One Building
1 Grand Canal Street Lower Dublin 2
Co. Dublin
Ireland

c) Accounting data in connection with your purchase in the On-Demand Service are transmitted to

Erwein von Fürstenberg & Partner,
tax adviser company,
Liebigstr. 3,
84030 Landshut, Germany

The accounting data is stored at Erwein von Fürstenberg & Partner in accordance with statutory law.

d) Personal data (name, year of birth) are further transmitted to

IVXS UK Ltd.,
90 Long Acre, 4th floor,
London, England, WC2E 9RA

in order to effect a financial sanctions check via their software ComplyAdvantage. Such data is, however, not stored.

e) The validity of your VAT number is transferred to the

European Commission,
Rue de la Loi 200,
1049 Brussels, Belgium

for verifying purposes via the VIES VAT number validation tool. No data is stored there.

5. How long do we store your data?

As a rule, we anonymise or delete your personal data as soon as it is no longer necessary for the aforementioned purpose, unless statutory documentation and retention rules (e.g. Commercial Code (HGB) or Tax code (AO)) Munich Re Service GmbH require us to keep it for longer. We will store your personal data for longer than that only in exceptional cases, where necessary in connection with claims asserted against Munich Re (Group) (statutory limitation period of up to 30 years).

6. Which data protection rights do you have?

In addition to your right to object, you have a right to information, a right to rectify or erase data under certain conditions, as well as a right to restrict data processing. Upon request, we will make the data that you provided available in a structured, accessible and machinereadable format. Please contact the aforementioned address to exercise these rights.

Right to revoke your consent: If we process your data on the basis of your consent, you may revoke the consent for the future at any time without consequences. We will then stop the processing.

7. Would you like to file a complaint about how your data is being handled?

You may contact the aforementioned Data Protection Officer or the data protection authorities. The authority responsible for us is:

Bayerisches Landesamt für Datenschutzaufsicht
(Data Protection Authority of Bavaria for the Private Sector),
Promenade 27, 91522 Ansbach, Germany

Tel.: +49 (0) 981 53 1300,
E-mail: poststelle@lda.bayern.de or
Web: https://www.lda.bayern.de/en/contact.html

8. How am I informed about changes of the privacy policy?

If we change this privacy policy, it will be updated in the privacy section of the On-Demand Service.

(Last updated: June 2023)