Life5 Privacy Policy
Version 3.0 · Published on 10 September 2026. Replaces the previous version.
1. Who is responsible for your data
The data controller is YOUR LIFE CORREDURÍA DE SEGUROS, S.L. ("Life5"), a Spanish insurance brokerage, Tax ID B-42.814.236, registered office at Paseo de la Castellana 140, 1º A, 28046 Madrid, Spain, authorised by the Dirección General de Seguros y Fondos de Pensiones under key J3945, operating in France under the freedom to provide services and through its subsidiary GETLIFE FRANCE, SASU, 128 rue La Boétie, 75008 Paris, registered with the Paris RCS and with ORIAS under number 22005926, supervised by the ACPR.
Life5 is an insurance intermediary. The insurance company with which you take out your policy is independently responsible for the processing it carries out to assess the risk, issue the contract and handle claims. Section 6 tells you which company it is and where to find its privacy information.
2. Data Protection Officer
Life5 has appointed Ana Geis as Data Protection Officer for the whole group, including GETLIFE FRANCE. You can contact her about any question regarding the processing of your data or the exercise of your rights at dpo@life5.com, or by post at the address in section 1, for the attention of the Data Protection Officer.
3. What data we process and where it comes from
We process the data you give us when you request a quote, take out a policy, manage it or contact us, the data generated by those interactions and, where indicated, data we receive from third parties.
- Identification and contact: name and surname, date of birth, identity document number, nationality and residence, postal address, email and telephone.
- Health data: your answers to the health questionnaire needed to assess the risk, including height, weight, tobacco use, declared illnesses and treatments and, where applicable, additional information you provide to our underwriting team. These are special-category data and are processed as explained in section 5.
- Professional and personal situation: occupation and risk activities, sum insured requested, insurance with other companies, and the details of the beneficiaries you designate.
- Financial and payment data: payment instrument and status of receipts. Your full card or account details are collected directly by our payment provider; Life5 only keeps a reference and the last digits.
- Identity and signature: images of your identity document and, if you use video verification, the biometric data derived from it, processed by the provider named in section 6; the electronically signed contract.
- Communications: recordings of telephone calls, WhatsApp messages and emails exchanged with us, and whether you open the emails we send you.
- Browsing and source: device and campaign identifiers, pages visited and app usage data, according to your cookie settings.
- External sources: if you reach us through a comparison site or a partner, we receive your contact details and the quote information from them; if you take out a policy through a partner broker, we receive the details of your application from them.
Data marked as mandatory in each form is needed to provide the service; without it we cannot quote or issue a policy. Health data is needed to assess the risk and, without it, no policy can be issued.
4. Why we process your data and on what legal basis
| Purpose | Legal basis |
|---|---|
Prepare your quote and answer your requests for information | Pre-contractual steps at your request (art. 6.1.b GDPR) |
Assess the risk and decide on the policy, its price and coverage, including the automated assessment described in section 5 and the review by our underwriting team | Necessity for the contract (art. 6.1.b) and, for health data, your explicit consent (art. 9.2.a GDPR) |
Verify your identity and prevent fraud and money laundering | Legal obligation (art. 6.1.c; French Monetary and Financial Code) and, for biometric verification, your explicit consent |
Issue and manage the policy, collect premiums, handle renewals, changes, cancellations and claims, and communicate with you about your contract | Performance of the contract (art. 6.1.b) and legal obligations under the French Insurance Code (art. 6.1.c) |
Handle your queries and complaints by phone, email, WhatsApp or the app, and record calls as evidence of what was agreed and for quality control | Performance of the contract and pre-contractual steps (art. 6.1.b); legitimate interest in service quality and evidence (art. 6.1.f) |
Send you commercial information about our products by email, WhatsApp or phone, and measure whether our messages are opened | Your consent (art. 6.1.a) if you are not a customer; legitimate interest (art. 6.1.f and art. L34-5 of the French Postal and Electronic Communications Code) if you are, for similar products, with the right to object at any time |
Analyse the use of our services, prioritise commercial follow-up and improve products, using profiles based on your interaction with us | Legitimate interest (art. 6.1.f), with the right to object. No health data is used for these purposes |
Improve service quality and train our team using a sample of calls and conversations | Legitimate interest (art. 6.1.f), with the right to object. Conversations containing health data are excluded |
Comply with requests from authorities, defend our rights and keep the records required by insurance, tax and anti-money-laundering rules | Legal obligation (art. 6.1.c) and legitimate interest (art. 6.1.f) |
You may withdraw your consent at any time without affecting the lawfulness of prior processing. If you withdraw consent for your health data before taking out the policy, we will not be able to complete the risk assessment.
5. Automated risk assessment and automated decisions
When you request a quote or apply for a policy, we assess your application automatically using the information you provide: age, sum insured and coverage requested, occupation, country of residence and your answers to the health questionnaire, including height, weight and tobacco use. The logic applies the actuarial tables and underwriting criteria of the insurer and its reinsurer: each answer maps to a predefined outcome and the outcomes are combined.
The result may be one of the following:
- acceptance at the calculated price;
- a surcharge on the premium because of health, body mass index, tobacco use or occupation;
- the exclusion of certain illnesses or coverage;
- referral to a review by our underwriting team, which may ask you for further information or a medical examination;
- the inability to offer you the insurance because of age, sum insured, residence, occupation or your health answers.
These decisions are necessary for entering into the contract (art. 22.2.a GDPR) and, as regards health data, are based on your explicit consent (art. 22.4). You have the right to have a member of our team review the decision, to express your point of view, to obtain an explanation of the logic applied to your case and to contest the outcome. To do so, write to dpo@life5.com quoting your quote or policy number; we will reply within one month. Whenever the outcome is a surcharge, an exclusion or the inability to offer cover, we will tell you and give the reason.
Health data is only accessible to authorised underwriting staff, to the medical team of the insurer and its reinsurer, and to the technical providers that host it under contract. We do not use it for marketing, commercial profiling or training models. At renewal your health is not reassessed: the price is updated only for age and sum insured according to your policy terms.
6. Who we share your data with
Insurers and reinsurers, responsible for their own processing
- Squarelife Insurance AG as insurer and SCOR SE as reinsurer, for the death-cover products distributed under the Life5 brand in France, including the Tempo Décès contract.
We share with them the data needed to assess the risk, issue the policy and handle claims, including the health data you consent to provide.
Other recipients
- Your beneficiaries, only in the event of a claim and as far as necessary to process it.
- Intermediaries and partners through which you reached us, as far as necessary to manage your application and commissions.
- Public bodies and authorities where the law requires it: ACPR, TRACFIN, the tax administration, courts.
Processors acting on behalf of Life5
Companies that provide services to us under contract and may only use data on our instructions: hosting and corporate email (Google Cloud and Google Workspace, in data centres in the European Union); payments (Stripe); email delivery (Mailgun); business messaging (Confluent); telephony and call recording (Cloudtalk and Telnyx); WhatsApp (Meta Platforms); identity verification and electronic signature (Signaturit and Viafirma); sales management (HubSpot); and artificial-intelligence assistants that help our team organise customer care and read documents (Anthropic and OpenAI), without taking decisions about you.
7. International transfers
Your data is hosted in the European Union. Some providers are established outside the European Economic Area or may access data from there: Stripe, HubSpot, Meta, Anthropic, OpenAI and Telnyx in the United States, and Squarelife's platform in Switzerland. These transfers rely on the European Commission's adequacy decision for Switzerland, on the EU-US Data Privacy Framework for certified providers and, otherwise, on the standard contractual clauses approved by the Commission, with supplementary measures where appropriate. You may request a copy of these safeguards at dpo@life5.com.
8. How long we keep your data
| Data | Period | Reason |
|---|---|---|
Quotes and applications that do not lead to a contract, including the health questionnaire | 12 months from the last activity | So you can resume your application; then deleted or anonymised |
Contract, risk assessment and claims data | For the life of the policy and 10 years after it ends | Limitation periods (art. L114-1 of the French Insurance Code) and legal obligations; up to 30 years for beneficiaries' rights in the event of death |
Identity documents and verifications | 5 years from the end of the relationship | Anti-money-laundering rules (art. L561-12 of the Monetary and Financial Code) |
Recordings of sales calls and conversations without a contract | 5 years | Evidence of pre-contractual information |
Recordings and communications related to a policy | With the contract | They form part of the file |
Data for commercial communications | Until you object or 3 years without interaction | CNIL recommendation |
Technical and security logs | 90 days | Service security |
While a period is running, data is kept blocked and used only to meet legal liabilities. Once the period expires, it is deleted or irreversibly anonymised.
9. Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, withdraw the consents you have given and request human review of an automated decision by writing to dpo@life5.com or by post to the address in section 1, proving your identity. We will reply within one month, extendable by two further months in complex cases, in which case we will let you know. You can unsubscribe from commercial communications through the link in each message or by the same means.
You may also set out instructions on what should happen to your data after your death. If you believe we have not honoured your rights, you may lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (cnil.fr, 3 place de Fontenoy, 75007 Paris). The lead supervisory authority of the Life5 group is the Spanish Data Protection Agency; the CNIL remains your point of contact. We ask you to contact us first at dpo@life5.com.
10. Beneficiaries, third parties and minors
If you designate beneficiaries or give us another person's data, you undertake to have informed them of this policy. We will process their data only to manage the policy and any claim, and we will inform them directly at our first contact with them. Life5 does not take out insurance with persons under 18; the data of minor beneficiaries is provided by, and is the responsibility of, the policyholder.
11. Calls, WhatsApp, email and artificial-intelligence assistants
Telephone calls are recorded and you are told at the start of each call; if you do not want a call recorded, the same team can assist you by email or through the app. WhatsApp conversations are handled through WhatsApp Business and stored in our customer-care system. Commercial emails include an open indicator that you can switch off in your cookie settings or through the link in each message.
We use artificial-intelligence assistants to help our team organise customer care, summarise cases and extract data from documents. No decision about your application, your policy or your rights is taken by such a system without a person. We do not use your health data to train models.
12. Cookies
The use of cookies and similar technologies on our websites and apps is explained in the Cookies Policy, where you can change your preferences at any time.
13. Security
We apply technical and organisational measures appropriate to the risk: encryption of health and identity data, role-based access control, logging of access to sensitive information and periodic reviews. If a security breach occurred that posed a high risk to you, we would inform you without undue delay.
14. Changes to this policy
We will publish any change on this page with its date and version number and notify you when it affects your rights or the purposes. The version you accepted is recorded together with your consent.