1. Introduction
The Poli Assistantapplication ("the App") is developed and distributed by International-brokers.com("we", "the company"), an insurance brokerage registered in Greece. The App is the quick day-to-day assistant of the existing partners of the International Brokers & Agents companies: it gives them access to their client portfolio, their clients' policies and outstanding balances, plus communication and organization tools (calendar, appointments, tasks, messaging).
This Privacy Policy describes how we collect, process, store and protect personal data in the context of the App's operation, in compliance with the EU General Data Protection Regulation (GDPR — Regulation 2016/679) and Greek Law 4624/2019.
Data Controller: International-brokers.com
Email: info@international-brokers.com
Phone: +30 210 8733000
Address: 77 Alexandras Avenue, 11474, Athens, Greece
2. Who can use the App
Poli Assistant is a professional tool. It is available on the App Store, but using it requires an authorized partner accountwith the International Brokers & Agents companies. Each intermediary sees exclusively their own client portfolio.
The App is not intended for:
- Clients / insured persons as end-users
- Children under 16
- Individuals without a partner account with the company
3. Data we collect and process
The App processes the following data categories in the course of insurance work:
3.1 User data (intermediary)
- Partner email — Authentication, audit trail
- Name, role — UI display, audit logs
- Login activity (timestamps, IP) — Security, audit
- Biometric ID (Face ID / Touch ID) — Local authentication; we do not store this
- Push notification tokens — Notifications for messages, appointments and portfolio updates
- User content — Messages (internal chat), activities, appointments, notes and deals entered by the user
3.2 Client / insured-person data
The App displays and processes data of the clients in the intermediary's portfolio, for the purposes of insurance intermediation:
- Identification data — Name, date of birth, name day
- Contact details — Email, phone numbers, addresses
- Policies — Policy numbers, lines of business, insurers, effective dates and renewals
- Financial — Outstanding balances, invoices, collections
- Communications— The intermediary's notes and activity history
3.3 Technical data
- Error logs (anonymized)
- Device information (iOS version, model)
- Network connectivity status
- Crash reports (via Apple)
4. Legal basis for processing
The processing is based on:
- Contract with the client (Art. 6(1)(b) GDPR) — performance of insurance intermediation
- Legal obligation (Art. 6(1)(c) GDPR) — record-keeping obligations under insurance law (Greek Law 4583/2018, IDD)
- Legitimate interest (Art. 6(1)(f) GDPR) — operation and security of the business information system
- Consent (Art. 6(1)(a) GDPR) — for specific uses such as promotional activities (where applicable)
For sensitive health data(in health-insurance cases) we rely on Art. 9(2)(h) GDPR (necessary for the provision of health services) and the data subject's consent.
5. Device permissions
The App requests the following permissions on the user's (intermediary's) device:
- Contacts (optional) — Used exclusively on-device to suggest additional phone numbers and emails for the clients in the portfolio. Contacts data is never sent to our servers.
- Caller ID (Call Directory)— The phone numbers of the portfolio's clients are stored locally on the device so iOS can display the client's name on incoming calls. This runs entirely inside the operating system (CallKit); the App does not monitor, log or record calls.
- Face ID / Touch ID — Secure app sign-in
- Notifications — Push notifications for messages and reminders
- Network — Communication with our servers
- Background refresh — Periodic portfolio sync so caller ID stays up to date
We do not request or access: camera, microphone, Photos library, location (GPS), Bluetooth, Apple Health data.
6. Categories of data recipients
To deliver its services, the App works with the following categories of third-party processors:
- Cloud infrastructure provider — Database, authentication and file storage · EU
- Apple platform — App distribution and push notifications · EU / USA
Each of the above is bound by a Data Processing Agreement (DPA) under Art. 28 GDPR and — where required — Standard Contractual Clauses (SCCs) for transfers outside the EU.
All communications are transmitted over strong encryption (TLS / HTTPS).
Calls, SMS and greetings to clients are performed via the device's built-in apps (Phone / Messages) — the App simply pre-fills the text and does not gain access to the content or history of those communications.
A list of the specific recipients is available on request at info@international-brokers.com (Art. 15 GDPR).
7. Where data is stored
- Primary data store: Secure cloud infrastructure located in the EU (Germany)
- On-device: Portfolio cache for offline operation and caller ID, with device-level encryption
- Backups: Automatic daily encrypted backups
8. Retention periods
- Policies (active + history): For the full term + 5 years after expiry
- Client data: For the duration of the relationship + 5 years after termination
- Financial records: 10 years (tax law)
- Messages / activities / appointments: 5 years (unless tied to an active matter)
- System logs: 30 days (auto-cleanup)
- On-device data: Removed on logout or when the app is uninstalled
After the retention period, data is securely deleted or anonymized.
9. Data subject rights
Under the GDPR, every person whose data we process (clients, employees, partners) has the following rights:
- Access (Art. 15) — request to info@international-brokers.com, response within 30 days
- Rectification (Art. 16) — submit requested changes
- Erasure("right to be forgotten", Art. 17) — subject to the exceptions in Art. 17(3) (legal obligations)
- Restriction of processing (Art. 18) — suspension of processing in specific cases
- Portability (Art. 20) — receive your data in a structured, commonly used format
- Objection (Art. 21) — to processing based on legitimate interest
- Withdraw consent — where processing is based on consent
- Lodge a complaint with the Greek DPA — www.dpa.gr
To exercise your rights:
Email: info@international-brokers.com
Post: 77 Alexandras Avenue, 11474, Athens, Greece
Phone: +30 210 8733000
10. Security measures
We apply appropriate technical and organizational measures to protect data:
Technical:
- Strong encryption (TLS) for all communications
- Application sandboxing per platform standards
- Device-level encryption for on-device data
- Per-row / per-user access policies in the database — each intermediary sees only their own portfolio
- Biometric authentication (Face ID / Touch ID) in-app
- Multi-factor authentication (MFA) for admin access
- Daily backups and disaster recovery procedures
- Encryption at rest for all files
Organizational:
- Need-to-know access — authorized partners only
- Audit logs for all significant actions
- NDAs signed by all employees
- Data protection training for staff
- Incident response plan for breaches
In the event of a data breach:
- Notification of the Greek DPA within 72 hours (Art. 33 GDPR)
- Notification of affected persons if there is a high risk
11. Cookies & local storage
The Poli Assistant app itself does not use cookies (it is not a web app). It uses on-device local storage for:
- User preferences
- Portfolio cache for offline use and caller ID
- Authentication tokens
All local data is protected by device-level encryption and is removed when the user uninstalls the app or signs out.
12. Transfers outside the EU
The App's data is hosted in the EU. To the extent that platform providers (e.g. Apple, for push notifications) process data outside the EU, we rely on:
- Standard Contractual Clauses (SCCs) issued by the European Commission (2021 versions)
- EU-US Data Privacy Framework (DPF) where applicable
- Supplementary technical measures as recommended by the EDPB
We do not transfer data to countries lacking an adequate level of protection.
13. Children
The App is a professional tool. It is not intended for children under 16. We do not knowingly collect data from children.
In the context of adult-client insurance, we may process children's data (e.g. family health insurance). In those cases:
- Consent is given by parents / guardians
- Children's data is handled with particular care
- It is never used for any marketing / promotional purpose
14. Changes to this policy
We reserve the right to amend this Policy. Changes will be published on this page with an updated date at the top.
For material changes we will notify users via in-app notice.
15. Contact
For any data-protection question or regarding this Policy:
International-brokers.com
Email: info@international-brokers.com
Web: international-brokers.com
Phone: +30 210 8733000
Address: 77 Alexandras Avenue, 11474, Athens, Greece
Supervisory Authority
You have the right to lodge a complaint with the:
Hellenic Data Protection Authority (HDPA)
Kifissias 1-3, 11523, Athens
Email: contact@dpa.gr
Phone: +30 210 6475 600
Web: www.dpa.gr