Valid as of June 1, 2022
Welcome to the Heymoney Website Privacy Policy!
The Heymoney website at www.heymoney.com (“Website“) is operated by IconicFinance (“we” or “us”). In this Privacy Policy we describe how we process your personal data in accordance with the German Data Protection Regulation, the Datenschutzgrundverordnung (“DSGVO”).
Please note the following:
Section A of this Privacy Policy is intended for all visitors to our Website, i.e. interested parties and customers of ours, but also for Allianz representatives and Allianz executives (“Allianz Users“). Section B of this Privacy Policy is for Allianz Representatives only.
Section A – for all Website visitors
This section is intended for all visitors to our Website, including Allianz Users.
1. General Information:
Details of the responsible body:
Company: IconicFinance GmbH
Address: IconicFinance GmbH, Königinstraße 28, 80802 Munich, Germany
E-Mail: datenschutz@heymoney.de
Contact details of the data protection officer:
Data Protection Officer of IconicFinance:
Email: datenschutz@heymoney.de
2. Data processed by us
(a) Use of the Website
Purpose of processing: providing the Website to Website visitors and ensuring the security of the Website
Personal data processed: IP address, type of browser, type of terminal device, operating system, referrer URL, date and time of access to the Website, content of the visited Website (“Website Usage Data“).
Legal basis of the processing:
- Provision of the Website and Website services: Art. 6 (1) lit. b DSGVO (performance of a quasi-contract)
- Security of the Website: Our legitimate interest in providing visitors to the Website with a functioning and technically secure Website (Art. 6 (1) lit. f DSGVO).
Duration of data storage: We process Website Usage Data for the above-mentioned purpose only as long as necessary to provide you with the Website content in a secure manner. Otherwise, we store personal data only for the assertion or defense of legal claims or for the fulfillment of legal retention obligations or to comply with legal obligations.
(b) Sending newsletters to newsletter subscribers
Purpose of processing: sending newsletters to newsletter subscribers; measuring the reach and success of the newsletter; by name Newsletter personalization.
Personal data processed: E-mail address, first name, content of the newsletter; information about delivery and opening of the newsletter as well as information of the called newsletter links (“Newsletter Interaction Data“).
Legal basis of the processing:
- E-mail address for newsletter delivery, first name for the personalization of the newsletter: Art. 6 (1) lit. a DSGVO (consent)
- Newsletter Interaction Data for reach measurement: § 25 (1) TTDSG, Art. 6 (1) lit. a DSGVO (Consent)
Duration of data storage: We process your personal data for newsletter delivery for three (3) years and newsletter interaction data for one (1) year and then delete it. We will not process your data in the future if you have unsubscribed from the newsletter (i.e. revoked your consent). You can unsubscribe from the newsletter at any time via the link provided in the newsletter or by sending us a corresponding message. Otherwise, we only store your personal data to the extent that this is legally permissible and necessary, e.g. to assert or defend legal claims or to comply with statutory retention obligations.
(c) Contact
Purpose of processing: to respond to requests from visitors to the Website
Processed personal data: Email address, content and circumstances (time and nature) of the request and, if provided, first name/last name (“Contact Data“)
Legal basis of processing: Art. 6 (1) lit. b DSGVO (contract performance)
Duration of data storage: We store your Contact Data until we have finally answered your inquiry. Otherwise, we store your personal data only for the defense of legal claims or for the fulfilment of legal storage obligations, or to comply with legal obligations.
(d) Job applications
If you apply for a job with us, we will process your personal data as described in the Privacy Policy at https://iconicfinance.jobs.personio.de/privacy-policy?language=en
3. Categories of data recipients
(a) Third parties (so-called transferees)
To the extent necessary to provide the service, we will share your personal data with other data controllers who process the personal data for their own purposes. We have indicated, where applicable, the respective recipients of the transfer in the relevant data processing operations. The recipients of the transfer may only use the data thus transferred for the purpose for which we transferred it.
The transfer of your personal data for these purposes is carried out for the performance of the contract, Art. 6 (1) lit. b DSGVO or with your consent, Art. 6 (1) lit. a DSGVO (we have indicated the legal basis in each case at the processing purpose).
(b) Processors
Any personal data we process as part of the Website is processed by us or our service providers. We may use external service providers, such as IT service providers for hosting or customer management systems, who act on our instructions to enable us to provide you with our services. These service providers process personal data on our behalf. We have carefully selected these service providers and have entered into order processing agreements with them.
(c) Third country transfer
IconicFinance does not carry out any data processing within the framework of the Website to so-called third countries. All personal data is processed in the EU.
4. Data subject rights
Provided the relevant legal requirements are met, you have the following rights under the DSGVO in relation to your personal data that we process:
(a) Right of access
You may ask us to tell you whether we are processing your personal data and, if so, to provide you with a copy of that data (together with any other relevant information).
(b) Right to rectification
If any personal data we process about you is incorrect or incomplete, you have the right to request that it be corrected or completed.
(c) Right to erasure (right to be forgotten)
Under certain circumstances, you may request that we delete your personal data.
(d) Right to restriction of processing
In certain circumstances, you may request that we restrict the processing of your personal data.
(e) Right to object
You can ask us to stop processing your personal data if we:
- process your data on the basis of a legitimate interest and cannot demonstrate compelling legal grounds for further processing, or
- use your personal data for direct marketing.
(f) Right to data portability
In certain circumstances, you have the right to request that we provide your personal information to us in a structured, commonly used, electronically readable format.
(g) Right to withdraw consent
If we process your personal data on the basis of your consent, you have the right to revoke your consent at any time for the future. The processing of your personal data before the revocation remains lawful.
(h) Right of appeal
You have the right to lodge a complaint with the competent data protection authority at any time if you believe that the processing of personal data by us violates applicable data protection law.
5. Contact
You can contact us via e-mail, via datenschutz@iconicfinance.io, via section 1 of this privacy policy or via the contact details provided in the imprint https://heymoney.de/impressum. For general issues, please contact hello@heymoney.de.
Section B – For Alliance Users
The following information relates to sections of the Website that are intended for Allianz Users only and for which, for example, Allianz log-in data or an Allianz e-mail address are required. All information (including information about your rights) in section A applies to you as an Allianz User as well and “Website” in section A is the services you use (e.g. the Agency Portal).
1. Heymoney Academy
Purpose of processing: access to information in the Heymoney Academy
Personal data processed: IP address, date and time of the request, time zone difference to GMT, content of the accessed Website, access status (HTTP status), amount of data transferred, website from which you accessed our Website, web browser, operating system, language and version of the browser (together “Log Data“).
Legal basis of processing: Art. 6 (1) lit. b DSGVO (contract performance)
Duration of data storage: We process the Log Data as long as this is necessary to provide you with the information in the Heymoney Academy. Otherwise, we store your personal data only for the defense of legal claims or to comply with statutory retention obligations, or to comply with legal obligations.
2. Allianz Executive Support
Purpose of processing: Enrollment in executive support in the form of information specifically for Allianz executives.
Personal Data Processed: Email address, office, job title and first name, last name (“Executive Data“) and newsletter interaction data.
Legal basis of the processing:
- E-mail address, first name, last name: Art. 6 (1) lit. a DSGVO (consent)
- Office, job title: Our legitimate interest in being able to assign and organise managers, e.g. for the provision of new information for customer care (Art. 6 (1) lit. f DSGVO)
- Newsletter interaction data for reach measurement: Our legitimate interest in measuring the success of our management support (Art. 6 (1) lit. f DSGVO).
Duration of data storage: We process your personal data for the stated purpose only as long as you have not unsubscribed from the executive support (i.e. revoked your consent). We only process newsletter interaction data for as long as is necessary to use it as a basis for improvements to our executive information. Otherwise, we store your personal data only for the assertion or defense of legal claims or to comply with statutory retention obligations, or to comply with legal obligations.
3. Agency Portal
Purpose of processing: Registration for and provision of the Heymoney Agency Portal, where Allianz agencies / representatives can find certain information on the use of the Heymoney App by their customers and information material for Heymoney. We also process the personal data for managing Allianz Users who use the Agency Portal.
We host the information about customers that we provide to Allianz Users on the Agency Portal as a processor. For this purpose, we have entered into a data processing agreement with the respective Allianz Users, which contains further details on this.
Personal data processed:
- Allianz Log-in (Single Sign-On) Information (agency name and successful login) to enable access to the Agency Portal. The login itself takes place via the Allianz logins of the Allianz Users
- For the registration for the Agency Portal and the administration in our CRM: title, first and last name, e-mail address, agency number, agency name
- Log-in data, in order to be able to provide the Agency Portal technically
- Data from Allianz agency search (name, address, contact details)
Legal basis of processing: Art. 6 (1) lit. b DSGVO (contract performance)
Duration of data storage: We process your log-in data as long as this is necessary to successfully log you in. We process the remaining data as long as this is necessary to provide you with the information in the Agency Portal. Otherwise, we store your personal data only for the defense of legal claims or for the fulfillment of legal retention obligations, or to comply with legal obligations.
Status June 2022
For prior version, see here