Commitment For Protecting Your Privacy

Using our service means that you’ve read and agreed to what’s written here, so please take a moment to go over it.

We will never, ever, not in a million years, sell your data to others, or use it for purposes other than our main business!

Keeping your personal information secure is incredibly important to us, and we invest a lot of effort in protecting it.

We only collect information in accordance with the applicable data protection law that we’ll need to conduct our business, improve our products, provide adequate pricing, help us with marketing and prevent fraud.

For that, we may collect data such as general location, network information and other indicators.

And now, for the legal version...

Last updated: August 2022

You’re now using the Lemonade Germany website ("Website"), where we offer personalized services as well as information about our company and services. Lemonade also offers a mobile application which you may download to a mobile device ("App"), for which this Privacy Policy also applies. Transparency and integrity during the processing of your personal data is very important to us. We comply with the data protection regulations, in particular the EU General Data Protection Regulation ("GDPR") as well as those in the German Federal Data Protection Act (Bundesdatenschutzgesetz, "BDSG") and the German Telemedia Act (Telemediengesetz, "TMG").

In this Privacy Policy, we will describe the types of information and personal data used during your visit to our above-mentioned Website or App (“Internet Service”), and the rights you have in respect to your personal data. Please note, some parts of this Privacy Policy only apply to processing either the Website and/or the App due to technical differences between the two.

I. Personal Data Responsibility

Responsibility for the personal data processing falls on

Lemonade Insurance N.V.
Spuistraat 112A, 1012 VA, Amsterdam,
Manager: Jonathan Jaffe
Email: [email protected].

Where this data protection declaration speaks of “we” or “us”, this relates in each case to the aforementioned company.

Our Data Protection Officer can be contacted via the email set out above.

II. Basic Principals

We only process your personal data in compliance with the data protection regulations, where a statutory provision allows us to do so, or where you have granted consent. This also applies during the processing of personal data for marketing and advertising purposes.

In the scope of our Internet Services, we may in principle also collect information that, taken as such, does not allow any identification of you in person. In certain cases – in particular in combination with other data – this information may still be regarded as “personal data” in the sense of the data protection laws. Further, we may, by way of the Internet Services, also capture such information that does not allow us to identify you either directly or indirectly; this is e.g. the case for aggregated information on all users of this Website.

III. Which data is processed by us? For which purposes and under what legal basis is the processing in effect?

When downloading the App, information is transmitted to the App Store. We are unable to influence this kind of collection of data and are not responsible for it. We will only process this data to the extent required for the downloading of the App onto your mobile device.

Further, you may access certain public parts of our Internet Service without providing us with your personal details (such as your name, postal address, or your email address). Also in this case, we need to collect and store certain information in order to enable your access to our Internet Service. On our Website and in our App, we use certain analysis tools and have integrated functionalities via third party providers. Further, we offer certain functionalities on our Internet Service for which we need to collect personal data.

We collect and process personal data on our Internet Service to the following extent:

  1. Logfiles: If you visit our Website, our web server will automatically store data and information relating to the device and browser you use. This could include technical information such as browser,system type, and IP-address . We process this technical information in the logfiles of our systems. We process the technical information in order to enable your access to our Internet Service, to secure the functionality of our Internet Service and the security of our IT systems, and to optimize our Internet Service. The legal basis for this data processing is Art. 6 para. 1 lit. f GDPR.

  2. Registration, quote, application process: Within the scope of our Internet Service, we offer you the option to register. This is necessary in order to obtain a cost calculation for the desired insurance coverage and an offer to conclude an insurance contract. For this, we request your name,email address, and further details about you and in connection with the risk to be insured. This is necessary in order to establish insurability or, as applicable, the level of potential insurance premium for you. The processing of this data is necessary in each case in order to make the desired quote available to you for cost calculation and in order to be able to send you an appropriate offer by email, if necessary, with the provision of further information on the conclusion of an insurance contract. The processing therefore serves as preparation for entering into a possible insurance contract between us. Thus, the legal basis for the data collection and processing is Art. 6 para. 1 lit. b GDPR.

  3. Insurance contract including claims management: If you wish to accept the quote, you have the option to conclude the insurance contract with us directly online as further explained during the application procedure. In this context, you might, upon receipt of our legal offer, also transmit your payment details for the purpose of paying the insurance premiums due and accept our offer online and may ask for your phone number to contact you if needed in relation to your insurance policy. Following the conclusion of your insurance contract, you will be able to access further information on your account at any time – in particular in connection to the insurance taken out – and potentially include further information or, as applicable, ask to book add-ons to your insurance contract. We will subsequently send you the insurance policy by email. To access your account as well as regarding the administration of your insurance contract, e.g. for the purpose of invoicing or handling of claims, we may request entering data already given during the registration and/or application procedure once again (in particular for the purposes of identification). Furthermore, we will ask for additional personal information and supporting evidence of your claim to prevent fraudulent claims. You can submit your claim’s details through the app or by contacting us. The legal basis of conducting the insurance contract between you and us is Art. 6 para. 1 lit. b GDPR.

  4. Policy management: During the period in which your insurance policy is active with us, we might need to process policy changes, and for that, additional personal information might need to be collected.

  5. Contact after the registration process started: If you have already started to enter the details required for your quote, including your email address, but have not completed it, we may contact you to remind you to complete your application, provided you have consented to getting product updates and offers from us. The legal basis for this is therefore your consent according to Art. 6 para. 1 lit. a GDPR. You can always request to unsubscribe from further non-essential emails from us.

  6. Contact support: You can also contact us through the contact form on the website or by calling us. We collect all the data you provide and store it insofar as necessary to process your request. Calls may be recorded for quality and training purposes. If necessary, data will be stored longer after completion of processing for reasons of preservation of evidence. The legal basis is Art. 6 para. 1 lit. a, b, f GDPR.

  7. Fraud Prevention: In certain cases, we will store and process the personal data collected from interested parties even if no insurance contract is concluded. This is to detect and prevent fraud, attempted fraud, and/or other harmful and/or illegal activities. This serves to maintain our justified interests in the prevention of fraud, and illegal and harmful behavior. The legal basis is Art. 6 para. 1 lit. f GDPR.

  8. Blocking: In the event of a material breach of your legal or contractual obligations or where there are serious grounds for suspecting such a breach, in the event of serious or inappropriate behavior towards Lemonade’s personnel (e.g. repeated harassing contacts, abusive language, aggression etc.), in the event that you provide personal data or information required for the purposes of the insurance contract which is deliberately inaccurate, or in the event of fraud or attempted fraud, we or our service providers may use your personal data to prevent you from contacting us directly by telephone, email, or through our contact form on the Website. We process your data in this way in our legitimate interest, in particular for the purpose of protecting our employees working in the support services teams. The legal basis is Art. 6 para. 1 lit. f GDPR. You will be informed personally if you are accused of such behavior. You will then be given the opportunity, within a reasonable period of time, to comply with our requests, to cease the alleged conduct or to object to the proposed blocking measure. You may object to the processing of your data for this purpose if your interests outweigh our legitimate interests. Your data may be retained for blocking purposes for a period not exceeding two years.

  9. Advertising information by email: If you have agreed to receive product updates and offers from us, we will process your email address, and potentially, information included in your account based on your corresponding consent, in order to be able to send you information with regard to our services, offers, and activities in the areas of household and liability insurance. You can always request to unsubscribe from further non essential emails from us. Further, we might assess data collected during the delivery and retrieval of our emails for analytics purposes and to improve our communications. Your personal data in connection with an email subscription will not be disclosed to third parties for any purpose other than to allow us to technically send out communications and analyze the results of our communications through our technical providers. We will process your data exclusively for the selection of individualized content and for sending out product updates and offers within the scope of your consent granted. The legal basis is Art. 6 para. 1 lit. a GDPR.

  10. Statistical evaluations: Where necessary, we may assess your personal data for the purpose of evaluating your preferences to enable interest-orientated marketing, individual addressing, and a continuous optimization of our business processes in a statistical form. We do this in order to get a better understanding of what our customers expect from us. Further, these evaluations help us in the detection of fraud, and the revision and maintenance of security; we conduct this data processing in order to maintain our justified interests; the legal basis is Art. 6 para. 1 lit. f GDPR.

  11. Job Applications: If you apply for a job posting, we collect information necessary to process your application or to retain you as an employee. This may include, among other things, government identification numbers, contact information, and educational history. We have a legitimate interest in evaluating candidates for potential employment. Our processing is based on Art. 6 para. 1 lit b f GDPR.

  12. Social Plug-ins: On our Website, we may use plug-ins of social network sites that allow you to conduct activities with regard to content on our Internet Service (also "Social Plug-Ins"). If you are registered in the respective social network and logged in to it, you may communicate directly with the social network. You may also prevent the loading of Social Plug-Ins with add-ons for your browser e.g. with the script blocker "NoScript" (http://noscript.net/). The legal basis for the provision of social plug-ins on our Internet Service is in our justified interests regarding the design of our Internet Service, in accordance with the needs of our users, Art. 6 para. 1 lit. f GDPR.

    1. Facebook Social Plug-In: A Facebook plug-in might be integrated on our Website. Facebook is operated by Facebook, Inc. (1601 South California Avenue, Palo Alto, CA 94304, USA – "Facebook"). The Facebook plug-in can be recognized from the Facebook logo or the “like” or share button. Also, we as the operator of this Internet Service, do not have any knowledge of the data transmitted, or its usage by Facebook. Further information on the use of data by Facebook can be found in Facebook’s privacy policy.

    2. Twitter Social Plug-In: On this Website, Social Plug-Ins of the social network Twitter Inc., 795 Folsom St., Suite 600, San Francisco, CA 94107, USA (“Twitter”) might be integrated. Such buttons can be recognized through terms like "Twitter" or "Follow" in connection with a stylized blue bird on this Website. These Social Plug-Ins allow comments about web pages of our Website to be shared or us to be followed on Twitter. If you open a web page on our online presence that contains such a button, your browser will automatically establish a direct connection to Twitter's servers. Twitter will directly transmit the contents of the Twitter plug-in to your browser and this might allow Twitter to assign your visit to our web pages to your user account.. We would like to indicate that we, as the operator of this Website, do not have any knowledge of the data transmitted or its usage by Twitter. Further information on the use of data by Twitter can be found in Twitter's privacy policy.

    3. LinkedIn Social Plug-In: Furthermore, on this Website, Social Plug-Ins of the social network LinkedIn operated by the LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA ("LinkedIn") might be integrated. LinkedIn plugins can be recognized on our website through the LinkedIn logo or the "Recommend" button. These Social Plug-Ins allow recommendations about web pages of our Website to be shared or us to be followed on LinkedIn. This might allow LinkedIn to assign your visit to our web pages to your user account. If you visit a web page on our online presence that contains such a button, your browser will automatically establish a direct connection to LinkedIn's servers. LinkedIn will directly transmit the contents of its Social Plug-In to your browser. We would like to indicate that we, as the operator of this Website, do not have any knowledge of the data transmitted or its usage by LinkedIn. For further details on the collection of data (purpose, scope, further processing, use) and your rights and settings options, please see LinkedIn's privacy policy.

  13. Facebook Log-in: Further, we might offer you the possibility to register on our Internet Service via the "Facebook Log-in" functionality by Facebook in order to shorten the registration or log-in procedure for you. In order to log in, you are forwarded to the Facebook site, where you may log in with your user data, if you wish to do so. By this, your Facebook profile and our portal are linked. Through this, we receive the following information from Facebook: Facebook ID, name, email address. We use this data in order to identify you, to be able to provide the contracted services. If you use the Facebook log-in, Facebook will receive information on you, in particular the fact that you have visited our portal. Further information on Facebook-Connect and the privacy settings can be found in the Facebook privacy policy. The legal basis is your consent in the scope of the use of the Facebook log-ins (Art. 6 para. 1 lit. a GDPR) or, as applicable, our justified interests regarding the provision of this functionality in order to simplify the registration or log-in procedure (Art. 6 para. 1 lit. f GDPR).

  14. Facebook Page: In addition to our Internet Service, we maintain a presence on Facebook (“Corporate Site”) and our Internet Service may contain links to this Corporate Site. If you open the Corporate Site, Facebook will process personal data and potentially also while you are not logged on to Facebook while opening it. We receive statistics from Facebook which are detailed as to content, but exclusively based on aggregated information regarding the use of our Corporate Site on Facebook. From these statistics, it may be visible e.g. how often or, as applicable, how many visitors visited the Corporate Site or individual content on this site was clicked or e.g. assessed. Based on these statistics, it is not visible to us which exact persons have visited the Corporate Site, have clicked on individual content or have assessed these. On the Corporate Site – as it is commonly the case on Facebook – it is however visible which Facebook user has assessed or commented on content. Further information on the use of data by Facebook is provided by Facebook in its privacy policy.

  15. Referral program: Further, we might offer a refer-a-friend program. If you take part in such program as existing customer, you will receive a personal link which you can send to your contacts. We will register which contacts have successfully used your link and process any necessary information in order to perform the refer-a-friend program (including but not limited to the number of referrals generated via your personal link). If you use a refer-a-friend link sent to you by a Lemonade customer, we will process this information if you purchase an insurance policy with us in order to perform the refer-a-friend-program. The legal basis for this is therefore the performance of our agreement regarding the refer-a-friend program (in case you are a referrer) or our insurance agreement (if you are a new customer).

  16. Further justified interests: Where required, we may process your data beyond the purposes mentioned above, for the purpose of maintaining our justified interests or for the interests of third parties; this is based on Art. 6 para. 1 lit. f GDPR. Some of our justified interests are

    1. the assertion of legal claims and defence of legal disputes;

    2. the prevention and the solving of crimes;

    3. the steering and the further development of our business activities including risk management;

    4. the prevention of fraud;

    5. the ability to identify and resolve technical bugs in the system;

    6. the ability to provide customer support (which is also based on the customer's consent pursuant to Art. 6 para. 1 lit. a GDPR); and the possible sharing of information as part of a corporate transaction or merger;

    7. and the possible disclosure of information in the context of a corporate transaction or merger.

  17. Cookies: In order to make our services as user-friendly as possible, we use cookies during our Internet Service. Cookies are small text files which are stored in the internet browser used by you after accessing our Website and may be allocated to your computer . A Cookie contains a characteristic order of signs which allows for a clear identification of your browser during the repeated use of our Internet Service. Since cookies are stored on your computer or, as applicable, on your device, you are in control of their use. You may set your browser in a way that it informs you about the setting up of cookies. This way, the use of cookies is transparent to you. You may delete the stored cookies at any time (also in an automated manner). Further, you may deny the storage of cookies through your browser settings altogether.

    On our Website, we use short-term as well as permanent cookies.

    Short-term cookies, such as, in particular, so-called ‘session cookies’ are deleted in an automated manner upon leaving our Website. These store a so-called ‘session ID’ by which different requests may be allocated to the website. By this, your device will be recognized when you use our Website again. The session cookies will be deleted when you log off or close your browser.

    Permanent cookies will be deleted after a certain time in an automated manner, which may be different depending on the cookie. You may configure the settings of your operating system, to prevent e.g. the acceptance of third party cookies, or of all cookies.

    In our app, we may use different Software Development Kits ("SDKs") that provide us with data about your usage through our third parties providers. If you would like to avoid this data collection, you will need to close the app and use our website instead. In any case you can always contact our customer service through the website as an alternative to performing in app features.

    On the Website, you may prevent the use of third party cookies by way of other measures as explained below.

    Please note that if you have accessed other websites from the Lemonade Group operating outside of the EU or have agreed to accept cookies from this site in the past, you may have received cookies. If you wish to remove these cookies, please refer to the "manage cookies" section.

    Further information on the cookies used by us, their purpose, and legal basis have been compiled by us for you below. Please note that some cookies are necessary for the functioning of our website and therefore cannot be disabled (‘Essential Cookies’). Other cookies are used by us for analytics and marketing purposes and these may be disabled from our cookie banner when you first log into our website. Further information on online advertising cookies, and on how to prevent their use, can be found on the following websites:

    - http://www.youronlinechoices.eu/

    - http://www.aboutads.info/choices/ (only available in English)

    - http://www.networkadvertising.org/choices/ (only available in English)

  18. Analytics and range measurement, (re-)marketing: If you visit our Internet Service or interact with it, we or our authorized service-providers may use cookies, pixel or other similar technologies to offer you a better, faster, and more secure user experience, or in order to show you advertising as explained below.

    1. Advertising Networks: We may in particular use third party providers such as advertising networks and advertising exchange programs which enable us to include advertising for you on the sites of third parties. The operators of these external advertising networks and advertising exchange programs may, in the case of you consenting, use third party cookies, pixel or similar technologies in order to collect data (Art. 6 para. 1 lit. a GDPR). In some cases, we will place cookies or a pixel on our own site in order to identify cases where a user gets to our Website through advertising placed on another website and completes certain activities (e.g. registration, or application for a quote or conclusion of a contract), for the purpose of remuneration of the advertising partner, in which we have a justified interest (Art. 6 para. 1 lit. f GDPR).

    2. Google Analytics: We make use of the Google Analytics web analysis services from the company “Google Inc.”, 1600 Amphitheatre Parkway, Mountain View, 94043 CA, USA, ( “Google”). Google Analytics stores information on your use of these Websites (incl. your IP address) in cookies. (Information on cookies can be found above in this Privacy Policy). The information stored in cookies by Google Analytics will be transmitted to a Google server in the US, stored there, and evaluated. We would like to inform you of the fact that for our internet presence Google Analytics was extended to anonymize capturing of IP addresses (IP-masking) is ensured. The IP-addresses will normally be shortened/abbreviated prior to the storage or, as applicable, the transmittal into the US on servers of Google in member states of the European Union or, as applicable, treaty countries of the European Economic Area. A transmittal of the unshortened/full IP-address onto servers of Google in the US will be effected only in exceptional cases, whereby also in this case a shortening of the IP-address will be effected prior to the storage.

      On our instruction, Google uses the transmitted data to evaluate your use of our internet presence, compile a report on the activities on the Website, as well as to render further services for us regarding the use of our Websites. (Therefore, there is a commissioned data processing agreement in place between us and Google). The use of Google Analytics therefore serves the purpose of continuously improving our internet presence and to optimise your user experience. These activities are in our justified interest regarding the data processing (Art. 6 para. 1 lit. f GDPR). Further, by clicking a button on our cookie banner on our Internet Service, you expressly agree to the processing of the collected data by Google in the manner, and for the purposes as described above (Art. 6 para. 1 lit. a GDPR).

      If you wish to deactivate or change Google Analytics only in respect of the presentation of content tailored to your interests, including advertising, this can be adjusted under “Google adverts on the web” in the settings for Google Adverts.

      Further information regarding the purpose and scope of the data collection as well as regarding the further processing and use by Google, including information on your rights or, as applicable, options for configuration for the protection of your personal data can be found under the following links: http://www.google.com/analytics/terms/de.html as well as under https://policies.google.com/privacy?hl=en-US.

    3. Google Tag Manager: We also use Google Tag Manager. With this service, website tags can be administered via an interface. Google Tag Manager solely implements tags. This means that Google Tag Manager does not place any cookies and no personal data is collected. Google Tag Manager triggers other tags that potentially collect data, but Google Tag Manager does not access this data. If, at domain or browser level, a deactivation of certain websites is affected (see details on the deactivation of cookies given above), this remains in place for all tracking tags to the extent that these are implemented with Google Tag Manager.

    4. Google AdWords / conversion tracking: On our Internet Service we also use, having gained your consent, (Art. 6 para. 1 lit. a GDPR) the online advertising program "Google AdWords,” and within the scope of this, its conversion tracking. With this, Google AdWords inserts a cookie or a pixel on your computer or, as applicable, on the storage of your mobile device, if you were directed to our Internet Service via a Google advert. These cookies are no longer applicable after 30 days. They do not serve for any personal identification. If the user visits certain pages of our Internet Service and the cookie is still active, both we as well as Google are able to see that you clicked on the advert and were forwarded to our site. We, as well as all other clients of Google-AdWords, receive different cookies. The cookies affected by our Google adverts can therefore not be followed beyond our Internet Service.

      The information obtained from the conversion tracking serves to compile statistics on the conversion for us. With this, we learn about the total number of users who clicked on an advert and were forwarded to a site provided with a conversion tracking tag. However, we do not receive any information that would allow your potential identification.

      If you do not wish to take part in conversion tracking, you may deactivate the conversion cookie in the settings of your browser. More information on this can be obtained from the Google Data Protection Statement. > von Google.

      You may also adjust your settings for Google Advertising in the Google settings for advertising.

    5. FinanceAds: In the event of your prior consent (Art. 6 para. 1 lit. a GDPR) we also use the conversion tracking program of financeAds GmbH & Co. KG ("financeAds"). financeAds inserts a cookie on your computer or your mobile device, if you were directed to our website via a financeAds advertising network partner (website or mobile app). These cookies are no longer applicable after 30 days and do not serve for any personal identification. The information obtained from the conversion tracking serves to compile statistics, whether you have been referred to our site by a financeAds partner and whether you have actually concluded an insurance agreement with us. This serves to enable us to pay advertising network partners of financeAds a so-called lead or sale commission on successful registrations or conclusion.

      For further details, please see financeAds’ privacy policy. A possibility to opt out of the conversion tracking by financeAds can be found here.

    6. Adform: If you agree, Adform cookies will be used on our website. Adform does not collect any personally identifiable information about you when you visit our website, other than information you voluntarily provide. According to Adform, in addition to the applicable data protection law, it observes certain provisions for the online market within the framework of self-regulation, such as the provisions of the World Wide Web (W3) Group, Privacy Preferences Projects (P3P), Internet Advertising Bureau (IAB) Good Practice Principles for Online Behavioural Advertising (OBA).

      You have the possibility to object to the storage of cookies on your computer when ads are displayed by the Adform Ad Server system. Adform uses a cookie mechanism to decide which ads to place, such as ads on similar products a visitor has already seen before, but only on an anonymous basis. This means that Adform does not store any personal information such as e-mail addresses, names or addresses in the cookie or cookie-based profile. The cookie does not collect any names, addresses, telephone numbers, e-mail addresses or other data that personally identify the user. Instead, the cookie contains a random identification number, ways to accept or decline it, or information about campaigns/advertising activities on an advertiser's website. Ad-form collects and stores information such as the operating system, browser version, geographical location, URLs on which Adform displays advertisements, or facts about interactions with advertisements (e.g. number of clicks or views) in cookie-based profiles using random cookie identification numbers. During web requests on Adform's web servers, IP addresses of Internet users are accessible to our system. Adform does not share this data with third parties and uses the data exclusively for the purposes of analysis on our behalf.

      Further information on Adform data protection and the possibility of opting out can be found at https://site.adform.com/datenschutz-opt-out.

    7. Awin: We work with Awin, which helps us to carry out these affiliate marketing campaigns. You can find the Awin privacy policy at https://www.awin.com/gb/privacy, which includes information on your rights in respect of their data processing.

      In some instances, Awin may maintain a limited profile which relates to you, but which does not reveal your identity, online behaviour or other personal characteristics. This profile is only used to understand whether a referral is commenced on one device and completed on another device. In some cases, Awin and the referrers of potential customers may receive and process your personal data for the purposes of carrying out affiliate marketing campaigns with us.

      We also receive personal data from Awin and the referrers of potential customers, which can be categorised as: cookie data, data relating to the website, app or other technology from which a potential customer was referred to and technical information relating to your device or an ID individually assigned to your transaction, which Awin can assign to the aforementioned data in its system.

      These activities are in our legitimate interest regarding the data processing (Art. 6 para. 1 lit. f GDPR) in carrying on an online advertising campaign, paid for on a performance basis.

    8. MCANISM / Conversion Tracking: We are using the conversion tracking from MCANISM Technology GmbH (“Mcanism”) on our website. As soon as you access our website through a Mcanism advertising partner (a website or a mobile app), a cookie will be placed on your computer or mobile device. This cookie is no longer applicable after the cookie duration has ended. The cookie duration for this campaign can be found at https://mcanism.com at the campaign category. We do not save any personal identifications. This information obtained from the conversion tracking serves to compile statistics, whether you have been referred to our side by a Mcanism partner and whether you have completed an action with this partner. This enables us to pay our advertising network partners. More information about our tracking can be found here: https://mcanism.com/en/datenschutz/.

    9. AduP Technology: Our website uses AdUps tracking - a technology- and service provider of Axel Springer Teaser Ad GmbH (Axel-Springer-Straße 65, 10969 Berlin). By collecting anonymous and/or pseudonymous data, AdUp can then display advertising on websites for a certain period of time in accordance with the users’ interests. AdUp is using cookies in order to provide advertisers with so-called conversion tracking, which determines the effectiveness of their ads and keywords. Further information on data protection at Axel Springer Teaser Ad GmbH can be found at https://www.adup-tech.com/datenschutz/.

    10. Facebook Pixel: After gaining your consent, our Website has a re-marketing pixel from Facebook. Via this pixel, a direct connection to the servers of Facebook is provided during your visit to our Website. Through this, it is transmitted to the Facebook server that you have visited this Website and Facebook will assign this information to your personal Facebook user account.

      Further information on the collection and use of the data by Facebook as well as your corresponding rights and options to protect your privacy can be found in the privacy policy of Facebook. Alternatively, you may deactivate or adjust these functionalities here. The legal basis for this data processing is in each case Art. 6 para. 1 lit. a GDPR.

    11. Mixpanel: We also use the web analytics service Mixpanel, in order to obtain data on the use of our Website for internal purposes, operated by Mixpanel, Inc., 405 Howard St, Floor 2, San Francisco, CA 94105, USA ("Mixpanel"). Mixpanel is obliged to maintain appropriate data protection levels. In the event of your consent (Art. 6 para. 1 lit. a GDPR), Mixpanel will insert a cookie on your device which also logs your user behaviour on the Website (retrieval of pages and activities on pages). This data is then analyzed by Mixpanel and forwarded to us.

      If you want to prevent this, you may do so via the function "Do Not Track" by setting an opt-out-cookie. Please note, that by setting this cookie, only the currently-used browser is affected. The collection and use of your data in other browsers remains possible, until you have deactivated Mixpanel on these as well. Further, the collection of user data is possible again if you delete the opt-out-cookie. Further information on the use of data by Mixpanel can be found in the privacy policy of Mixpanel.

    12. Bing: On our Website pixels of the Bing Ads are implemented. Data is collected and stored from which anonymous usage profiles are created. This is a service of Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. This service enables us to track the activities of users on our Website when they arrive at our Website through ads from Bing Ads. If you enter our website via such an ad, a pixel is placed on your computer and a Bing UET tag (Universal Event Tracking tag) is integrated into our website. This is a code that is used in conjunction with the pixel to store some non-personal information about your use of the site.

      These pixels are stored on the basis of Art. 6 para. 1 lit. f GDPR and on the basis of your respective consent (Art. 6 para. 1 lit. a GDPR). The website operator has a legitimate interest in analysing user behaviour in order to optimise both its website and its advertising. In addition, Microsoft may use so-called cross-device tracking to track your usage patterns across several of your electronic devices and is thus able to display personalised advertising on or in Microsoft websites and apps. Microsoft is obliged to maintain appropriate data protection levels.

      You may, at any time, opt out of Bing's analysis of your usage patterns and the display of interest-based recommendations here. Furthermore, you can adjust your Microsoft ad settings here. For more information about the processing of your personal data through Microsoft, please see Microsoft's privacy policy.

    13. Twitter: On the Website, we use a marketing tool from Twitter in case of your consent (legal basis Art. 6 para. 1 lit. a) GDPR) to present you with interest-related advertisements ("Twitter Ads") as part of your visit to the social network Twitter. For this purpose, a Twitter pixel was implemented on the Website. This pixel establishes a direct connection to the Twitter servers when you visit the Website. The Twitter server is informed that you have visited our Website and Twitter assigns this information to your personal Twitter user account. In order to protect your privacy, we do not use the so-called "tailor-made target group" function, in which this information could be enriched with further personal data (e.g. email address). More information about Twitter Pixel can be found here. For the collection and use of data by Twitter as well as your related rights and options for protecting your privacy, please refer to Twitter's privacy policy. Alternatively, you can deactivate this in the settings of your Twitter account. To do this, you must be logged in to Twitter.

    14. Yahoo: Furthermore, we use a marketing tool provided by Oath, 701 First Avenue, Sunnyvale, CA 94089, USA ("Yahoo") in case of your consent (legal basis Art. 6 para. 1 lit. a GDPR to present you with interest-related advertisements. For this purpose, a pixel was implemented on the Website. This pixel establishes a direct connection to Yahoo servers when you visit the Website. More information about the Yahoo pixel can be found here: For the collection and use of data by Yahoo as well as your related rights and options for protecting your privacy, please refer to Yahoo's privacy policy. Furthermore, you might adjust your Yahoo ad settings here.

    15. Amazon: Furthermore, in the event of your consent (legal basis Art. 6 para. 1 lit. a) GDPR), this Website uses the Amazon Conversion Pixel and Amazon Remarketing Pixel web analytics services of Amazon Digital UK Limited of 1 Principal Place, Worship Street, London, EC2A 2FA, UK, ("Amazon"), a company affiliated with Amazon.com, Inc., 410 Terry Ave. North, Seattle, WA, USA.

      When you visit the Amazon.de website, Amazon receives information that you have previously visited our Website or other websites and may associate this with any Amazon account you might have, provided that you are logged in at the same time as your Amazon account. In addition, Amazon receives information about any successful conclusion of a contract with us or any visit of our Websites by means of an advertisement on Amazon.de. Your IP address may also be transmitted.

      Amazon can recognize you on other websites, in apps and within other Amazon services and can display personalized advertising. You can prevent your data from being processed by Amazon in your ad preferences settings.

      An opt-out cookie will then be set in your browser to prevent the future collection of your information by Amazon pixels when you visit our Website. Your opt-out is valid as long as you do not delete the opt-out cookie.

      More information from Amazon about data processing in connection with online advertising can be found here. We are not aware of the full extent of the data processing. This data may be stored by Amazon.com, Inc. You can find more information about data processing by Amazon in Amazon's privacy policy.

    16. AppsFlyer SDK: We will also analyze your session and interaction data during the use of our App through a service by AppsFlyer Inc. (111 New Montgomery Street, San Francisco, California 94105, USA). AppsFlyer is obliged to maintain appropriate data protection levels. The session and interaction data is never processed in person-related form, but pseudonymised. Further information on the data processing by AppsFlyer can be found in the privacy policy of the service provider here.

      You may object to the use of AppsFlyer at any time and also with future effect by clicking here.

      Alternatively, you will need to close the app and use our website instead. In any case you can always contact our customer service through the website as an alternative to performing in app features.

    17. TikTok Pixel: After gaining your consent, our Website has a remarketing pixel from TikTok. Via this pixel, a direct connection to the servers of TikTok is provided during your visit to our Website. Through this, it is transmitted to the TikTok server that you have visited this Website and TikTok will assign this information to your personal user account.

      Further information on the collection and use of the data by TikTok as well as your corresponding rights and options to protect your privacy can be found in the privacy policy of TikTok. Alternatively, you may deactivate or adjust these functionalities here. The legal basis for this data processing is in each case Art. 6 para. 1 lit. a GDPR.

    18. Adroll Retargeting: Through our advertising partner AdRoll Advertising Limited, Level 6, 1, Burlington Plaza, Burlington Road, Dublin 4, Ireland, we advertise this website in search results and on third party websites. If you have given us your consent for this according to Art. 6 Para. 1 S. 1 lit. a DSGVO, a cookie from these providers or from their partners will be automatically set when you visit our website. The cookie enables interest-based advertising through a pseudonymous cookie ID and based on the pages you visit. The collected data will get deleted immediately after we finished using AdRoll Retargeting for the intended purpose and at the end of its deployment.

      You can revoke your consent at any time with future effect by deactivating the retargeting cookie and clicking the following link:

      https://app.adroll.com/optout/

      Alternatively, you can disable third-party use of cookies by going to the Network Advertising Initiative Disable page.

    19. Snapchat: On the Website, we use a marketing tool from Snapchat, with your consent (legal basis Art. 6. Para 1 lit. a GDPR), to provide you with advertisements tailored to your interests. This pixel establishes a direct connection to the Snapchat servers when you visit the Website. The Snapchat server is informed that you visited our Website, and Snapchat assigns this information to your personal Snapchat account. More information about Snapchat’s collection and use of data can be found in their privacy policy.

IV. Are you obliged to provide us with your data?

The details required for the conclusion of an insurance contract, as well as the registration for information by email, are in the respective areas of the Internet Service (e.g. in an online form) and marked as mandatory information; without providing the mandatory details, we are unable to allow you the use of the respective functionality.

V. Who will receive your data?

Depending on the type of personal data that is processed by our company, only certain departments / organizational units have access to your personal data. These include, in particular, our expert departments concerned with the provision of our services and our IT department. Based on the concept of roles and entitlements, the access is, within our company, limited to those functionalities and such scope as is required for the respective purpose of processing.

We may also transfer your personal data within the legally-allowed scope to third parties outside of our company. These external recipients may include, in particular

affiliated companies (in particular Lemonade, Inc. in the USA and Lemonade Agency B.V. in the Netherlands), to which we transfer personal data for internal administrative purposes, management and servicing of our insurance product, data analytics, recruiting, marketing, backoffice, the provision of hosting services and IT services required for the operation of this Website;

the service providers instructed by us (as well as the sub-contractors of our service providers instructed with our consent), such as e.g. in the areas of marketing or promotion of our services, as insurance intermediaries, customer service, IT (in particular hosting or disaster recovery), or payment administration who provide services to us on a specific contractual basis, which may include the processing of personal data (in particular we utilise services of our affiliate Lemonade Agency B.V. and payment services of the Hyperwallet group for outgoing payments and payment services of the Stripe group for incoming payments. The Hyperwallet group and the Stripe group have establishments outside the EU / EEA, in particular in the USA, you may find more information in regard to the processing of your personal data under https://www.hyperwallet.com/agreements-privacy/ and https://stripe.com/de/privacy); and

non-public and public agencies to the extent that we have legal obligations to transmit your personal data.

Reinsurance companies ("reinsurers") that reinsure us. In order for our reinsurers to be able to insure us, it may be necessary to provide our reinsurers with information relating to your insurance contract and your claims.

Companies that we partner with to conduct investigations and damages estimations during the claims process.

Information system of the German insurance industry (HIS). The insurance industry uses the information system HIS (Hinweis- und Informationssystem) of informa HIS GmbH to clarify the facts of the case in the processing of claims and checking of benefits, as well as to prevent and combat insurance fraud. This requires an exchange of certain personal data with the HIS. For further information, please refer the HIS data protection information at https://www.informa-his.de/

Information on data protection according to EU-DSGVO. Our organisation regularly checks your credit-worthiness when signing a contract and in certain cases for which a legitimate interest exists. This also applies to existing customers. In order to do so, we cooperate with Creditreform Boniversum GmbH, Hammfelddamm 13, 41460 Neuss, from whom we receive the required data. For this purpose, we transmit your name, and your contact details to Creditreform Boniversum GmbH. You can find the information pursuant to Art. 14 of the EU General Data Protection Regulation on the data processing carried out by Creditreform Boniversum GmbH here: http://www.boniversum.de/eu-dsgvo/.

In order to provide you with an Amazon.de voucher in the context of your participation in our refer-a-friend program or in the context of our marketing campaigns (where applicable), we provide Amazon.de with your e-mail address and name. We do this to have Amazon.de provide you with the voucher directly.

Other parties: we may share your information with other unaffiliated third parties who are not described elsewhere in this Policy with your consent.

We will transfer your data to external recipients only insofar as this processing is necessary for purposes as permitted by law.

VI. Will an automated-decision making process be used?

We utilize automated decision-making in connection with the provision of our Internet Service. Automated decision-making, as defined in Article 22 of GDPR, may include profiling, which is any kind of automated processing that utilizes personal data in order to evaluate certain aspects of a natural person. The automated decision-making is based, in addition to other factors, on the information you provide during the quote process. We will use automated decision-making to evaluate the information you provide to us to calculate your individual risk profile in order to determine whether we can extend insurance coverage to you, and if so, what your insurance coverage limits and premiums will be, or to process claims you submit.

Under certain applicable laws, you may have the right to certain safeguards as they relate to automated decision-making. Specifically, you may be able to request that the result of the automated decision-making process is recalculated by a human, to express your views related to or contest the result of the automated decision-making process, and receive notification of the contestation outcome. In order to exercise these rights, or for more information about automated decision-making, please contact us at the information provided below. By applying for insurance, you acknowledge that you understand that automated decision-making or profiling may be used as described in this policy and you consent to Lemonade’s use of those methods.

VII. Is data transmitted to countries outside the EU / EEA?

In certain cases, there may be a transmission of information to recipients in so-called “Third Countries.” Third Countries are countries outside of the EU or the EEA, and it cannot automatically be assumed that their data protection levels are in line with those in the European Union.

To the extent the transmitted information includes personal data, and we are not required to perform such transmission due to a legal obligation, we secure prior to such transmission that in the respective Third Country or by the recipient in the Third Country, the required appropriate data protection level is met. This may result, in particular, from a so-called “adequacy decision” by the European Commission, by which an appropriate data protection level is determined for a Third Country as a whole. Alternatively, we may base the transmittal of data on the so-called "EU Standard Contractual Clauses". Prior to July 16, 2020, Lemonade transferred personal data about people in the E.E.A. to its U.S. affiliate, Lemonade, Inc., pursuant to Lemonade, Inc.’s participation in the EU/US Privacy Shield. After the Privacy Shield program was invalidated, as of July 16, 2020, Lemonade Insurance N.V. and Lemonade, Inc. executed Standard Contractual Clauses to govern transfers of EU personal data. Lemonade Insurance N.V. additionally has taken steps to obtain additional assurance from Lemonade, Inc. that the personal data will be subject to adequate protections. We will be happy to provide further information on the suitable and appropriate guaranties of our compliance to an appropriate data protection level to you on request; the contact details can be found at the beginning of this Privacy Policy. Information on the EU Standard Contractual Clauses can further be found here: http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2010:039:0005:0018:DE:PDF and Information on the adequacy decisions here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protection-personal-data-non-eu-countries_en#dataprotectionincountriesoutsidetheeu.

You can request a copy of the relevant standard contractual clauses by contacting us at [email protected].

VIII. How long will your data be stored?

In general, we will store your personal data only as long as we have a justified interest in this storage, and your interests in discontinuation do not overtake the justified interest.

Additionally, without any justified interest, we may continue to store your data where we are statutorily obliged to do so (e.g. for the purpose of fulfilling archiving requirements). We will delete your personal data without any action from your side, as soon as access to the data is no longer necessary to fulfil the purpose of processing, or the storage is otherwise illegal.

The personal data we need to store for the purpose of compliance with retention duties will be stored until the end of the corresponding retention period. Where we store personal data exclusively for the purpose of fulfilling archiving duties, it is normally blocked so that access is only possible where this is required with regard to the purpose of the retention duty.

IX. What are your rights?

  1. Right to object according to Article 21 GDPR:

    You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you, based on Article 6 para. 1 lit. e or f GDPR, including profiling according to Art. 22 GDPR based on those provisions. In the event of your objection, we will no longer process the personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or where the processing serves for the establishment, exercise or defence of legal claims.

    Where we process your personal data for direct marketing purposes, you have the right to object at any time to processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing. Where you object to processing for direct marketing purposes, the concerned personal data shall no longer be processed for such purposes.

    You have the possibility, in the context of the use of information society services, and notwithstanding Directive 2002/58/EC, to exercise your right to object by automated means using technical specifications.

  2. Withdrawal of consents: Where you have granted consent to us (e.g. in connection to receiving information by email), you may withdraw such consent at any time with effect for the future. Our email information normally contains a corresponding link in each of our non essential communications. You are also able to contact us by other means, e.g. by post, or email via one of the contact means specified on the first page of this Privacy Policy.

  3. Further rights of affected persons: Based on the following provisions, you as a data subject have the right

    to obtain information on your personal data which is stored, Art. 15 GDPR;

    to have incorrect or incomplete data corrected, Art. 16 GDPR;

    to deletion of personal data, Art 17 GDPR;

    to a restriction of the processing, Art 18 GDPR;

    to data portability, Art. 20 GDPR.

    These rights are subject to the conditions appearing in this Privacy Policy and any regulatory instructions in the context of specific processing and data retention.

    To assert these rights you may, at any times, e.g. via one of the contact means specified at the beginning of this Privacy Policy, contact us.

    Further, you are entitled at any time to file a complaint with the responsible supervisory authority for data protection, Art. 77 GDPR.

X. Privacy of Minors

Our services are not aimed at persons under the age of 16 years and their use is not intended for use by such persons. We do not collect personal data from people we know to be under the age of 16.

XI. Changes to Privacy Policy

We may change this Privacy Policy at any time by posting the revised Privacy Policy on this Website and indicating the effective date of the revised Privacy Policy.

Help