Last updated: 10 September 2026
This Privacy Policy explains how GENERAL BROKER CLUB Ltd. handles personal data of visitors to bg.euromedins.com, customers, insured persons and people acting for a child. It covers insurance orders, payments, policy delivery and support by email or messenger.
1. Controller and contacts
The controller for the website, order administration and insurance-broker services described in this Policy is GENERAL BROKER CLUB Ltd., UIC 201044795, registered address: Lulin 2 district, block 279, Sofia, Bulgaria. Privacy contact: [email protected], +359 988 358 940.
The insurance company that issues a policy processes the data it needs for underwriting, issuance, administration and claims under its own privacy information. Where required to arrange the policy, we send the necessary data to that insurer.
2. Data we process
We collect data relevant to the requested service. This may include:
- Identity and policy data: name, date of birth, nationality, passport or other identity-document data, address and, where needed for a policy, information about the insured person or persons.
- Contact and delivery data: email address, telephone number, postal address, preferred delivery method and your messages to us.
- Order and payment data: selected insurance product, insurer, cover period, premium, invoice and payment status. For card payments, ePay.bg processes card details in its payment interface; we do not receive or store full card details.
- Insurance-related documents: documents required by an insurer or by law, such as a copy of an identity document and, for a newborn where required by the insurer, a copy of the birth certificate.
- Special-category data: only where needed for a particular insurance product or claim-support request, for example health information contained in documents you choose to provide.
- Technical and cookie data: IP address, browser and device information, pages viewed, approximate location inferred from IP, cookie preferences and security logs.
We normally receive data directly from you. If someone orders insurance for another person, that customer must have authority to provide the relevant data and must give the insured person this Policy. We may also receive limited status or correction information from an insurer, a payment provider or a delivery provider where it is necessary to fulfil the order or resolve an issue.
3. Why we use data and the legal basis
| Purpose | Examples | Legal basis |
|---|---|---|
| Providing the requested service | Quotes; policy issue, delivery or replacement; support; cancellations and refunds. | Performance of a contract or steps at your request before a contract (Art. 6(1)(b) GDPR). |
| Meeting legal and regulatory duties | Accounting and tax records; insurance-distribution duties; responding to competent authorities; preventing or reporting fraud where required by law. | Legal obligation (Art. 6(1)(c) GDPR). |
| Operating and protecting the service | Keeping the website secure; preventing misuse; maintaining records needed to handle complaints or legal claims; improving our ordering process. | Legitimate interests (Art. 6(1)(f) GDPR), balanced against your rights and expectations. |
| Health data where a product requires it | Transmitting health information or related documents to the insurer when you ask us to arrange a product or assist with an insurance matter. | Your explicit consent where required (Art. 9(2)(a) GDPR), or another specific condition permitted by applicable insurance and data-protection law. |
| Optional marketing and non-essential cookies | Sending marketing only when you opt in; measuring traffic or advertising only where consent is required. | Consent (Art. 6(1)(a) GDPR). You may withdraw it at any time. |
4. When providing data is necessary
The minimum identity, contact and policy data requested at checkout or by our operator is necessary to prepare and arrange insurance. If you do not provide data required by the insurer, payment provider, delivery provider or applicable law, we may be unable to issue the policy, take payment, deliver an original document or provide the requested service. Data for marketing and non-essential cookies is optional.
5. Who receives data
We do not sell personal data. We share it only where necessary for the purposes above, with:
- the insurer selected for your policy, including its assistance and claims partners where the insurer requires this to issue or service the insurance;
- ePay.bg, which processes card payments, and the banking providers used for the payment method you choose;
- courier and postal operators when you request an original paper policy or other delivery;
- hosting, email, technical support and security providers that operate our systems under appropriate contractual safeguards;
- accountants, lawyers, auditors and professional advisers where needed; and
- competent public authorities, courts or regulators where disclosure is required by law or necessary to establish, exercise or defend legal claims.
Our staff access customer data only when their duties require it. Service providers process data only under instructions or their own legal duties, as applicable.
6. International transfers
Some service providers, insurers or delivery partners may process data outside the European Economic Area. When this happens, we use a transfer mechanism permitted by the GDPR, such as an adequacy decision or the European Commission’s standard contractual clauses, and apply supplementary safeguards where appropriate. You can request information about the relevant safeguard by contacting us.
7. How long we retain data
- Order and policy records are normally kept for three years after the insurance period ends so that we can provide support, send a copy from the original order email, handle complaints and meet applicable duties.
- Accounting and tax records are kept for the period required by Bulgarian law, which may be up to ten years.
- Correspondence and complaint records are retained for as long as needed to resolve the matter and protect legal rights. If a dispute, investigation or legal claim is ongoing, relevant data may be kept until it is finally resolved.
- Cookie-consent records and technical security logs are kept for the period necessary for their purpose and in line with our cookie settings.
After the applicable period, we delete or irreversibly anonymise the data unless a longer retention period is required or permitted by law.
8. Cookies and analytics
We use essential cookies to make the site work, including keeping the shopping basket, protecting the checkout and recording your cookie choice. Essential cookies do not require consent. We ask for your consent before placing non-essential analytics or advertising cookies where the law requires it. You can accept, refuse or change non-essential choices through the cookie settings available on the site. The cookie banner provides the current list of cookies, their providers and retention periods.
9. Automated tools
The calculator may use the information you enter, such as age, insurance period, selected product and delivery option, to display available products and prices. It does not make a decision based solely on automated processing that produces legal or similarly significant effects for you. The insurer may apply its own underwriting rules and will provide its own information where required.
10. Security
We use appropriate technical and organisational measures to protect data against accidental or unlawful loss, alteration, unauthorised disclosure or access. No internet service can guarantee absolute security; please use a secure connection and do not send unnecessary sensitive information by ordinary email or messenger.
11. Your rights
Subject to the conditions and limits in the GDPR, you may request access to your data, correction of inaccurate data, deletion, restriction of processing, portability where applicable, and information about recipients. You may object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time; this does not affect processing already carried out lawfully before withdrawal.
To exercise a right, email [email protected] and identify the request sufficiently for us to verify your identity and locate the relevant order. You also have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria, or with the supervisory authority in your country of habitual residence, work or the place of the alleged infringement.
12. Changes to this Policy
We may update this Policy when our services, data practices or legal obligations change. The current version and its last-updated date are published on bg.euromedins.com.
