Personal Data

PHENOMEN places particular importance on the protection of personal data processed in connection with its activities and the use of the Meetch website.

This policy explains what data may be processed, why it is used, who may receive it, how long it is kept and the rights available to the individuals concerned.

The data controller is PHENOMEN, 141 avenue de Wagram, 75017 Paris, France. For any privacy question or to exercise your rights, contact dpo@meetch.io.

Article 1: Purposes and legal bases of processing

Personal data processed by PHENOMEN may in particular be used to:

  • respond to contact and demo requests and enable the use of the services offered on the Meetch website;
  • assess the needs of a client, prospect, insured person or beneficiary;
  • enable the subscription of an insurance contract and carry out the necessary pre-contractual measures;
  • ensure the monitoring, management and performance of insurance and/or reinsurance contracts;
  • manage reimbursement requests, claims and related benefits;
  • manage recourse actions, complaints and disputes;
  • manage invoicing, payments, unpaid amounts and related accounting operations;
  • comply with legal and regulatory obligations, in particular those relating to anti-money laundering and counter-terrorist financing, asset freezing, fraud prevention and obligations applicable to insurance distributors;
  • prevent fraud, misuse and information system security incidents;
  • carry out statistics, internal studies, satisfaction surveys and research and development activities.

Depending on the processing concerned, PHENOMEN relies on the performance of a contract or of pre-contractual measures, compliance with a legal obligation, consent where required, or its legitimate interests, provided that those interests do not override the rights and freedoms of the persons concerned.

Article 2: Data collected and processed

“Personal data” means any information relating to an identified or identifiable natural person, directly or indirectly. Depending on the processing concerned, PHENOMEN acts as data controller.

Data that may be processed
  • identification and contact information, including surname, first name, title, postal address, email address, telephone number and, where relevant, nationality;
  • information submitted through the website forms, such as a demo request: contact details, company, industry and the needs described;
  • contact preferences and communication choices;
  • professional, family, economic, financial or asset-related information, where necessary for the service, the contract or the assessment of a risk;
  • account identifiers and authentication information;
  • information relating to insurance contracts, service orders, invoicing and payments;
  • bank details such as IBAN, SWIFT or BIC, where needed for a payment or a reimbursement;
  • information required to assess a risk and manage an insurance contract;
  • information relating to claims, reimbursements, losses, benefits, beneficiaries and victims;
  • complaints and exchanges with PHENOMEN teams;
  • information relating to personal circumstances or to the use of insured property, where directly relevant to the insured risk;
  • technical, connection and traceability information, including account connections and, where applicable, cookies or similar technologies described on the Cookie Management page.
Health data and other data requiring enhanced protection

Where strictly necessary to provide insurance services, underwrite certain contracts or manage a claim, PHENOMEN may process health data, for example information contained in supporting documents, medical certificates or medical questionnaires. Such data is processed only when necessary and with the safeguards required by applicable law.

Where a person provides information about a third party, they must ensure that they are authorised to do so and, where required, that the third party has been duly informed or has given their consent.

Article 3: Recipients of personal data

Data is accessible only to PHENOMEN teams whose duties require it. Where necessary for the purposes described above, it may also be disclosed to:

  • insurers, insurance partners, agents and processors involved in providing or managing the service;
  • technical, hosting, payment and other service providers acting on behalf of PHENOMEN, including the website host, OVH SAS, in France;
  • experts, lawyers, medical advisers and other authorised professionals, where necessary;
  • judicial, administrative or supervisory authorities and other legally authorised recipients;
  • auditors, internal control functions and statutory auditors.

Processors and service providers may use the data entrusted to them only for the purposes of their assignment, in accordance with PHENOMEN’s instructions and applicable law.

Article 4: Rights of data subjects

Subject to the legal conditions applicable to each processing activity, individuals have the following rights:

  • right of access: know whether personal data concerning them is processed and obtain a copy;
  • right to rectification: have inaccurate or incomplete information corrected;
  • right to erasure: request deletion where the legal conditions are met;
  • right to restriction: request, in certain cases, the temporary restriction of processing;
  • right to object: object to processing based on legitimate interests, unless there are compelling legitimate grounds for continuing it;
  • right to portability: receive eligible data in a structured, commonly used and machine-readable format;
  • right to withdraw consent at any time where processing is based on consent, without affecting processing lawfully carried out before the withdrawal.
How to exercise your rights

Requests can be sent by email to dpo@meetch.io or by post to PHENOMEN – 141 avenue de Wagram, 75017 Paris, France.

PHENOMEN responds without undue delay and, in principle, within one month of receipt. This period may be extended by a further two months where justified by the complexity or number of requests; you will then be informed within the first month. Proof of identity is requested only where there is reasonable doubt about the identity of the requester, and only to the extent necessary.

Manifestly unfounded or excessive requests, in particular because of their repetitive nature, may be refused with reasons or be subject to a reasonable fee where permitted by law. The right to erasure remains subject to the legal and regulatory retention obligations applicable to PHENOMEN, in particular in connection with its insurance activities.

Complaint to the CNIL

Any individual may lodge a complaint with the French data protection authority (Commission nationale de l’informatique et des libertés – CNIL): www.cnil.fr/fr/plaintes.

Article 5: Transfers outside the European Economic Area

Some services may involve transfers of personal data to recipients located outside the European Economic Area, in particular in the United Kingdom or Switzerland.

Where required, these transfers rely on a mechanism recognised by applicable law, such as an adequacy decision or standard contractual clauses of the European Commission, or on another appropriate safeguard ensuring an adequate level of protection.

Information about the safeguards applicable to a specific transfer can be requested at dpo@meetch.io.

Article 6: Storage and retention

Data is hosted by technical service providers acting on behalf of PHENOMEN and bound by confidentiality and security obligations.

Personal data is kept only for as long as necessary for the purpose for which it was collected, then for any additional period required or permitted by applicable law. Where no contract is concluded, data relating to a prospect or an information request may be kept for up to three years from collection, subject to any more specific rule applicable to the processing concerned.

At the end of the applicable period, data is deleted, anonymised or securely archived where its retention remains necessary to comply with a legal obligation or to establish, exercise or defend legal claims.

Article 7: Security and confidentiality

PHENOMEN implements technical and organisational measures designed to preserve the confidentiality, integrity and availability of personal data and to protect it against loss, accidental destruction, alteration, disclosure or unauthorised access.

These measures may include access controls, authentication mechanisms, connection logging, encryption of certain data and physical or organisational safeguards adapted to the identified risks. As no Internet-connected system can offer absolute security, PHENOMEN regularly reviews and adapts its safeguards as risks, practices and technologies evolve.

Article 8: Updates to this Privacy Policy

PHENOMEN may update this policy to reflect legal, regulatory, technical or organisational developments. The applicable version is the one published on the Meetch website.

Last updated: 13.09.2026