1. Purpose and scope
1.1 This Privacy Policy explains how Compass Point Assist processes personal data in connection with:
a. the Compass Shield website and purchase journey;
b. the Compass Shield customer portal or platform;
c. travel assistance and emergency services;
d. medical and travel case coordination;
e. administrative and payment activities;
f. insurance-related support provided under contractual authority;
g. customer communications, complaints and enquiries; and
h. related compliance, security and fraud-prevention activities.
1.2 This Privacy Policy applies to customers, insured travellers, assistance users, account holders, website visitors, emergency contacts and other individuals whose information is provided to us.
1.3 Separate privacy information may be issued by an insurer, insurance distributor, medical provider or other organisation that independently determines how it processes personal data.
2. Data controller
The controller responsible for processing personal data for the purposes described in this Privacy Policy is:
Compass Point Assist
Schulstrasse 13
82441 Ohlstadt
Germany
2.1 Data-protection contactQuestions and requests concerning personal data may be sent to:
dataprotection@compasspoint-assist.com This address should not be described as belonging to a formal Data Protection Officer unless CPA has appointed a Data Protection Officer in accordance with applicable law.
2.2 Other controllersDepending on the service involved, the following organisations may process personal data as independent or joint controllers:
a. the insurer underwriting the insurance protection;
b. an authorised insurance distributor;
c. medical providers;
d. emergency services;
e. payment providers;
f. public authorities; and
g. other professional organisations that determine their own purposes and means of processing.
Their identities and privacy information may be provided in the insurance, purchase or service documentation.
3. Personal data we collect
We may process the following categories of personal data.
3.1 Identity data
This may include:
a. name;
b. title;
c. date of birth;
d. gender where relevant to medical care or insurance administration;
e. nationality;
f. country of residence;
g. address;
h. passport or identification details where required; and
i. customer, policy, certificate or case reference numbers.
3.2 Contact data
This may include:
a. telephone numbers;
b. email addresses;
c. postal address;
d. emergency contact details; and
e. communication preferences.
3.3 Travel data
This may include:
a. destination;
b. travel dates;
c. itinerary;
d. transport and accommodation details;
e. booking references;
f. reason for travel;
g. travelling companions; and
h. location information supplied during an assistance case.
3.4 Purchase and insurance data
This may include:
a. selected coverage limit;
b. quoted price;
c. insurance premium and service charges;
d. policy or certificate information;
e. eligibility responses;
f. insurance claims information;
g. cancellation and refund information; and
h. communications concerning the purchase or insurance protection.
3.5 Payment and billing data
This may include:
a. billing name and address;
b. payment status;
c. transaction references;
d. payment method type;
e. refund and chargeback information; and
f. fraud-prevention indicators.
CPA should not normally retain complete payment-card details where payment is processed through an external payment provider.
3.6 Assistance and case data
This may include:
a. the nature of the incident;
b. assistance requests;
c. case notes;
d. provider details;
e. estimates, invoices and receipts;
f. guarantees of payment;
g. transport or repatriation arrangements;
h. claim or coverage communications;
i. call and email records; and
j. decisions and instructions received from insurers or other authorised parties.
3.7 Health and medical data
This may include:
a. symptoms and medical history;
b. diagnoses;
c. injuries;
d. treatment information;
e. prescriptions and medication;
f. allergies;
g. medical reports;
h. test results and imaging;
i. treating-provider information;
j. fitness-to-travel information;
k. medical transport requirements; and
l. information relevant to an insurance claim or assistance decision.
3.8 Technical and usage data
This may include:
a. IP address;
b. device and browser information;
c. account identifiers;
d. login records;
e. security and authentication data;
f. portal activity;
g. error and diagnostic logs;
h. cookie and consent preferences; and
i. approximate location derived from technical information, where applicable.
3.9 Compliance data
This may include:
a. sanctions-screening results;
b. identity-verification results;
c. fraud indicators;
d. duplicate-account or duplicate-claim checks;
e. compliance review notes; and
f. information received from regulators, insurers or screening providers.
3.10 Communications
We may retain:
a. emails;
b. chat messages;
c. portal messages;
d. forms;
e. documents provided to us;
f. telephone-call notes; and
g. call recordings where recording is used and lawful notice has been provided.
4. Where we obtain personal data
We may receive information:
4.1 Directly from you
For example, when you:
a. obtain a quote;
b. complete a purchase;
c. create an account;
d. request assistance;
e. submit documents;
f. contact us; or
g. make a complaint or rights request.
4.2 From the purchaser or another traveller
One person may purchase Compass Shield or request assistance on behalf of another traveller. The purchaser must be authorised to provide the information and should make this Privacy Policy available to the other individuals concerned.
4.3 From insurers and authorised insurance distributors
We may receive policy, eligibility, claim, authorisation and coverage information.
4.4 From medical and assistance providers
We may receive reports, treatment information, invoices, provider notes and operational updates where needed for assistance or claims support.
4.5 From emergency contacts and representatives
Information may be supplied by family members, employers, travel companions, guardians, legal representatives or other persons acting for the traveller.
4.6 From public and commercial sources
We may obtain information from:
a. sanctions lists;
b. fraud-prevention databases;
c. identity-verification providers;
d. public authorities;
e. publicly available sources; and
f. relevant security or travel-information providers.
4.7 Automatically
Technical data may be collected when a person uses the website, portal or digital services.
5. Why we process personal data and our legal bases
We process personal data only where an appropriate legal basis applies.
5.1 Quotations, purchases and contract administration
Purposes:
a. providing a quotation;
b. confirming eligibility;
c. processing a purchase;
d. issuing confirmation documents;
e. administering Compass Shield services;
f. communicating about the purchase; and
g. handling changes, cancellations and refunds.
Legal bases:
• Article 6(1)(b) GDPR: steps requested before entering into a contract and performance of a contract;
• Article 6(1)(c) GDPR: compliance with legal obligations where applicable.
5.2 Travel and emergency assistance
Purposes:
a. receiving and assessing an assistance request;
b. identifying suitable providers;
c. coordinating medical or travel assistance;
d. communicating with providers and relevant third parties;
e. arranging transport or repatriation;
f. maintaining case records; and
g. protecting the traveller during an incident.
Legal bases for ordinary personal data:
• Article 6(1)(b) GDPR: performance of the Compass Shield service contract;
• Article 6(1)(d) GDPR: protecting vital interests in serious emergencies;
• Article 6(1)(f) GDPR: legitimate interests in effectively coordinating services, protecting travellers and maintaining accurate case records.
5.3 Insurance administration and claims support
Purposes:
a. transmitting information to the insurer or authorised distributor;
b. confirming insurance details;
c. obtaining authorisation;
d. supporting claims administration;
e. reviewing invoices and documentation;
f. preventing duplicate payments; and
g. communicating decisions within CPA’s authority.
Legal bases:
• Article 6(1)(b) GDPR where necessary for contractual services requested by the traveller;
• Article 6(1)(c) GDPR where processing is legally required;
• Article 6(1)(f) GDPR for legitimate interests in administering insurance-related services, preventing fraud and maintaining records.
The insurer or authorised distributor may rely on separate legal bases described in its own privacy documentation.
5.4 Payment processing
Purposes:
a. processing payments;
b. issuing refunds;
c. reconciling transactions;
d. handling chargebacks; and
e. preventing payment fraud.
Legal bases:
• Article 6(1)(b) GDPR;
• Article 6(1)(c) GDPR for accounting and tax obligations;
• Article 6(1)(f) GDPR for fraud prevention and financial security.
5.5 Legal, regulatory and sanctions compliance
Purposes:
a. sanctions screening;
b. identity and eligibility checks;
c. anti-fraud controls;
d. responding to regulators and authorities;
e. maintaining legally required records;
f. complying with tax and accounting duties; and
g. establishing, exercising or defending legal claims.
Legal bases:
• Article 6(1)(c) GDPR where required by applicable law;
• Article 6(1)(f) GDPR for legitimate interests in legal compliance, risk management, fraud prevention and protecting legal rights.
5.6 Platform operation and security
Purposes:
a. creating and maintaining accounts;
b. authenticating users;
c. preventing unauthorised access;
d. monitoring technical performance;
e. detecting security events;
f. troubleshooting; and
g. improving platform reliability.
Legal bases:
• Article 6(1)(b) GDPR where necessary to provide the platform;
• Article 6(1)(f) GDPR for legitimate interests in security, service reliability and prevention of misuse;
• consent where required for non-essential cookies or similar technologies.
5.7 Customer service and complaints
Purposes:
a. answering enquiries;
b. investigating complaints;
c. maintaining correspondence;
d. resolving disputes; and
e. complying with complaint-handling obligations.
Legal bases:
• Article 6(1)(b) GDPR;
• Article 6(1)(c) GDPR where complaint handling is legally required;
• Article 6(1)(f) GDPR for customer service, dispute resolution and protection of legal rights.
5.8 Service analysis and improvement
We may use appropriately limited or aggregated information to understand service performance, improve operational processes and train staff.
Legal basis:
• Article 6(1)(f) GDPR for legitimate interests in quality assurance, service improvement and staff training.
Where reasonably possible, information used for analysis or training will be anonymised or pseudonymised.
5.9 Marketing
CPA should only include this section if marketing is actually performed.
Where applicable, we may send information about related services:
• with consent where consent is legally required; or
• on another lawful basis where applicable.
Customers may unsubscribe at any time.
Health or assistance-case information will not be used for direct marketing.
6. Processing of health and other special-category data
6.1 Health data is subject to enhanced protection under Article 9 GDPR. Processing is prohibited unless a specific Article 9 condition applies.
6.2 Depending on the circumstances, CPA may rely on one or more of the following conditions:
a. Article 9(2)(a) GDPR — explicit consent, for example where the traveller authorises CPA to obtain and share medical information for assistance or claims coordination;
b. Article 9(2)(c) GDPR — vital interests, where processing is necessary to protect the vital interests of the traveller or another person and the traveller is physically or legally incapable of giving consent;
c. Article 9(2)(f) GDPR — legal claims, where processing is necessary to establish, exercise or defend legal claims;
d. Article 9(2)(h) GDPR — health or care-related processing, but only where the legal and professional conditions required by that provision are satisfied; and
e. another condition permitted by applicable EU or national law.
6.3 CPA should not describe Article 9(2)(h) as automatically applying to all assistance or claims processing. Its use should be confirmed in light of CPA’s actual role, professional obligations and contractual structure.
6.4 Explicit medical-data authorisation
Where appropriate, the traveller may be asked to provide a specific authorisation such as: “I explicitly consent to Compass Point Assist processing and sharing health and medical information where necessary to assess and coordinate my assistance request, communicate with medical providers and relevant insurers, and administer the related case.”
The consent wording should explain that withdrawal will not affect processing already lawfully completed and may limit CPA’s ability to continue providing assistance where the information is necessary.
6.5 Emergencies
In a serious emergency, CPA may process relevant health and location information without prior consent where a lawful vital-interests or other emergency basis applies.
7. Whether you must provide personal data
7.1 Some information is required to:
a. provide a quotation;
b. establish eligibility;
c. complete a purchase;
d. issue insurance or service documents;
e. provide assistance;
f. process payment; or
g. comply with legal obligations.
7.2 Where required information is not provided, CPA may be unable to:
a. provide a quotation;
b. complete or administer the purchase;
c. confirm eligibility;
d. coordinate assistance;
e. obtain insurer authorisation; or
f. process a request.
7.3 We will indicate where information is mandatory where reasonably practicable.
8. Sharing personal data
We may disclose personal data only where necessary and lawful.
8.1 Insurers and insurance distributors
Information may be shared to:
a. confirm coverage;
b. issue documents;
c. obtain authorisation;
d. administer claims;
e. handle complaints;
f. prevent fraud; and
g. satisfy regulatory requirements.
8.2 Medical and assistance providers
This may include:
a. hospitals;
b. doctors;
c. clinics;
d. laboratories;
e. pharmacies;
f. ambulance services;
g. air-ambulance providers;
h. repatriation providers;
i. local assistance companies; and
j. medical advisers.
8.3 Travel and operational providers
This may include:
a. airlines;
b. transport companies;
c. accommodation providers;
d. security providers;
e. translators; and
f. logistics providers.
8.4 Technology and communications providers
This may include providers of:
a. hosting;
b. cloud storage;
c. email;
d. telephony;
e. customer-management systems;
f. mapping and risk-information services;
g. document delivery;
h. cybersecurity; and
i. technical support.
Where they act only on CPA’s instructions, they should be subject to appropriate data-processing agreements.
8.5 Payment providers
Payment information may be shared with payment processors, banks and fraud-prevention providers.
8.6 Professional advisers
This may include lawyers, accountants, auditors, medical consultants and compliance advisers.
8.7 Public authorities
We may disclose information where required or permitted by law to:
a. courts;
b. regulators;
c. law-enforcement authorities;
d. tax authorities;
e. sanctions authorities;
f. data-protection authorities; and
g. emergency or public-health authorities.
8.8 Corporate transactions
Information may be disclosed in connection with a proposed merger, acquisition, restructuring or sale, subject to appropriate confidentiality and legal safeguards.
9. Controller and processor relationships
9.1 The legal role of each recipient depends on the relevant processing activity.
9.2 An insurer will generally determine its own purposes for underwriting, policy administration and claims decisions and may therefore act as a separate controller.
9.3 Medical providers generally determine how they provide treatment and maintain medical records and will normally process that information under their own professional and legal responsibilities.
9.4 Technology suppliers that process data only on CPA’s documented instructions may act as processors.
9.5 Where CPA and another organisation jointly determine purposes and means, the parties will put in place an appropriate joint-controller arrangement and make the essence of that arrangement available where required.
Controller and processor status is determined by the parties’ actual roles in deciding why and how data is processed.
10. International transfers
10.1 Compass Shield provides global assistance. Personal data may therefore be transferred to or accessed from countries outside the European Economic Area.
10.2 Transfers may occur because:
a. the traveller is outside the EEA;
b. a medical provider or assistance partner is outside the EEA;
c. an insurer or service provider operates internationally;
d. cloud or communication infrastructure is located abroad; or
e. emergency coordination requires communication with overseas organisations.
10.3 Where required, CPA may use safeguards such as:
a. an adequacy decision;
b. European Commission Standard Contractual Clauses;
c. additional contractual, organisational or technical safeguards;
d. binding corporate rules where applicable; or
e. another legally recognised transfer mechanism.
10.4 In limited situations, a transfer may be made under an applicable derogation, including where it is:
a. necessary to perform a contract with the traveller;
b. necessary to conclude or perform a contract in the traveller’s interests;
c. necessary for important reasons of public interest;
d. necessary to establish, exercise or defend legal claims;
e. necessary to protect vital interests where the person cannot consent; or
f. based on the traveller’s explicit and informed consent.
10.5 In urgent medical situations, it may not be possible to ensure that an overseas recipient offers protection equivalent to the GDPR. CPA will limit the information disclosed to what is reasonably necessary.
10.6 Information about applicable safeguards may be requested from dataprotection@compasspoint-assist.com.
11. Data retention
11.1 CPA retains personal data only for as long as reasonably necessary for the purpose for which it was collected and for applicable legal, regulatory, contractual and claims-related requirements.
11.2 Indicative retention approachSubject to confirmation against CPA’s legal and operational obligations:
| Data category | Indicative retention approach |
|---|
| Quote data where no purchase occurs | Normally 12 months, unless needed longer for fraud, complaint or legal reasons |
| Purchase and contract records | For the contractual period and applicable statutory accounting, commercial and limitation periods |
| Payment and invoice records | Normally in accordance with applicable tax and accounting retention requirements |
| Assistance and case records | For the active case and an appropriate period afterward for claims, complaints, audit and legal purposes |
| Medical information | Only for as long as necessary for the assistance, claim, legal defence and applicable recordkeeping requirements |
| Call recordings | Normally 24 months, unless needed for a complaint, investigation or legal claim |
| Account information | For the life of the account and an appropriate period following closure |
| Security logs | Normally 24 months, unless required longer for an incident or investigation |
| Sanctions and fraud records | For as long as necessary to demonstrate checks, prevent fraud and comply with legal requirements |
| Data-protection requests | Normally retained for an appropriate period to document compliance |
11.3 A blanket statement that all case and purchase data is retained for ten years should only be used if CPA can identify and document the legal or operational need for that period for each relevant data category.
11.4 Data may be retained longer where:
a. a claim remains open;
b. litigation or a complaint is anticipated or ongoing;
c. fraud is suspected;
d. a regulator or authority requires preservation;
e. a legal hold applies; or
f. limitation periods have not expired.
11.5 When information is no longer required, it will be deleted, anonymised or securely restricted.
12. Security
12.1 CPA uses appropriate technical and organisational measures designed to protect personal data against:
a. accidental or unlawful destruction;
b. loss;
c. alteration;
d. unauthorised disclosure;
e. unauthorised access; and
f. other unlawful processing.
12.2 Measures may include:
a. access controls;
b. authentication measures;
c. role-based permissions;
d. encryption in transit and, where appropriate, at rest;
e. backups;
f. monitoring and logging;
g. staff confidentiality obligations;
h. training;
i. supplier due diligence;
j. incident-response procedures; and
k. data-minimisation practices.
12.3 No online or communication system is completely secure. Travellers should avoid sending health data to general or unencrypted email addresses where a secure channel is available. The BayLDA itself warns that sensitive information should not be sent by unencrypted email because of the associated security risks.
13. Cookies and similar technologies
13.1 The Compass Shield website and portal may use cookies, local storage, pixels or similar technologies.
13.2 Strictly necessary technologies may be used to:
a. operate the website;
b. maintain secure sessions;
c. authenticate users;
d. remember privacy choices;
e. prevent fraud; and
f. complete a purchase.
13.3 Non-essential analytics, personalisation or advertising technologies will only be used where an appropriate legal basis, including consent where required, has been obtained. Under § 25 TDDDG, consent is generally required to store or access information on a user’s device unless the technology is strictly necessary to transmit a communication or provide a digital service expressly requested by the user.
13.4 Further details should be provided in a separate Cookie Notice, including:
a. the name of each cookie or technology;
b. its provider;
c. its purpose;
d. its duration;
e. whether it is essential; and
f. how consent can be withdrawn.
14. Automated decision-making
14.1 CPA may use automated tools to support:
a. sanctions screening;
b. fraud detection;
c. identity verification;
d. eligibility checks;
e. security monitoring; and
f. routing of assistance requests.
14.2 CPA should state clearly whether any decision is made solely by automated means and produces legal or similarly significant effects.
14.3 Where such automated decision-making is used, the customer will be provided with the additional information and rights required by law, including information about the logic involved and the possibility of human review where applicable.
14.4 If CPA does not use solely automated significant decision-making, the policy may state: “CPA does not currently make decisions producing legal or similarly significant effects based solely on automated processing.”
This statement should only be included if operationally accurate.
15. Children and minors
15.1 Compass Shield may include travellers under the age of 18 where a parent, guardian or other authorised adult completes the purchase or requests assistance on their behalf.
15.2 The previous wording stating that Compass Shield is “not directed to individuals under 18” may be inaccurate if family travel or dependent children can be covered.
15.3 Where data concerning a minor is provided, the purchaser must be legally authorised to provide it and act on the minor’s behalf.
15.4 In an emergency, CPA may process a minor’s information where necessary to protect the minor’s vital interests or on another applicable legal basis.
15.5 CPA may request evidence of parental responsibility or authority where appropriate.
16. Information about other people
16.1 Where a customer provides personal data concerning another traveller, emergency contact, family member or representative, the customer confirms that they are authorised to provide the information.
16.2 The customer should make this Privacy Policy available to those individuals unless doing so is impossible or would involve disproportionate effort, or another legal exception applies.
16.3 CPA may contact the person directly where necessary to provide privacy information, verify authority or administer services.
17. Your data-protection rights
Subject to applicable conditions and exceptions, individuals may have the following rights.
17.1 Access — the right to obtain confirmation of whether personal data is processed and receive a copy of the relevant data.
17.2 Rectification — the right to correct inaccurate or incomplete information.
17.3 Erasure — the right to request deletion where there is no longer a lawful reason to retain the information.
17.4 Restriction — the right to request restricted processing in certain circumstances.
17.5 Data portability — the right to receive certain information in a structured, commonly used and machine-readable format and, where technically feasible, have it transmitted to another controller.
17.6 Objection — the right to object to processing based on legitimate interests, taking account of the particular circumstances. Where personal data is used for direct marketing, the individual may object at any time.
17.7 Withdrawal of consent — where processing is based on consent, consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
17.8 Rights concerning automated decisions — where applicable, the right not to be subject to certain significant decisions based solely on automated processing.
17.9 Complaints — the right to lodge a complaint with a competent supervisory authority.
17.10 Exercising rights — requests may be sent to
dataprotection@compasspoint-assist.com. CPA may request information necessary to verify identity and protect personal data against unauthorised disclosure.
18. Supervisory authority
Individuals may lodge a complaint with the supervisory authority responsible for their place of residence, workplace or the location of the alleged infringement.
CPA’s competent supervisory authority in Bavaria is expected to be:
Bayerisches Landesamt für Datenschutzaufsicht – BayLDA
Promenade 18
91522 Ansbach
Germany
Email:
poststelle@lda.bayern.deThe BayLDA currently recommends using its online complaint form for complaints and enquiries.
19. Data breaches
19.1 CPA maintains procedures for identifying, investigating and responding to personal-data breaches.
19.2 Where required by applicable law, CPA will notify the competent supervisory authority.
19.3 Where a breach is likely to result in a high risk to affected individuals, CPA will also notify those individuals unless a legal exception applies.
20. Changes to this Privacy Policy
20.1 CPA may update this Privacy Policy to reflect changes in:
a. services;
b. technology;
c. providers;
d. data-processing activities;
e. law or regulation; or
f. internal procedures.
20.2 The current version will be made available through the Compass Shield website or portal.
20.3 Material changes will be communicated by an appropriate method where required.
20.4 The effective date and version number will be updated whenever the policy changes.
21. Contact
For privacy questions or to exercise a data-protection right, contact:
Compass Point Assist
Schulstrasse 13
82441 Ohlstadt
Germany
Email:
dataprotection@compasspoint-assist.comFor emergency medical or travel assistance, use the emergency contact information shown in the Compass Shield confirmation documents. The data-protection email address is not an emergency assistance channel.