Privacy Policy
You are reading a previous version (version 2026-10.2).
1. What this Privacy Policy is about
In this Privacy Policy, we, easyall GmbH, Stäffiserweg 13, 4500 Solothurn, Switzerland (“easyall”, “we”), explain how we process personal data when you use www.easyall.ch: the premium comparison for health insurance, the application form, your customer account, our AI assistants, the premium alert, the termination service and the cashback and referral programmes.
easyall is an untied insurance intermediary and is entered in the register of the Swiss Financial Market Supervisory Authority FINMA (register no. F01522147). You can find the legally required information on our intermediation activity in our Initial Information under Art. 45 of the Insurance Supervision Act (VAG).
This Privacy Policy is based on the Federal Act on Data Protection (DSG) and the Data Protection Ordinance (DSV). Our comparison and intermediation services are aimed only at persons resident in Switzerland.
The Privacy Policy also applies to persons whose data we receive in connection with an application, for example co-insured family members (section 3.5), and to doctors in our doctor search (section 3.15). The insurers' processing of your data is governed by their own privacy policies.
2. Controller and contact
For questions about data protection and to exercise your rights (section 16), you can reach us at info@easyall.ch or by post at the above address.
3. Which personal data we process
Which data we process depends on which functions you use. We receive most data from you yourself. We receive some from third parties, for example from insurers (section 3.16).
3.1 Visiting the website
Each time our website is accessed, we and our hosting provider Vercel (section 7) process technically necessary connection data:
- IP address
- date and time of access
- address accessed (URL) and referring page
- browser, operating system and device type
- language setting and other technical information about the connection
We need this data to deliver the website, to fix faults and to prevent misuse (section 11). The access logs of our hosting provider contain the full IP address and are automatically deleted after a short time (section 15). For web analytics and the measurement of our ads, see section 10; for cookies and browser storage, section 9.
3.2 Premium calculator, comparison and doctor search
For calculating and comparing premiums and for our recommendation, we process:
- postcode, municipality and canton
- for each person in the household: year of birth, gender, deductible, insurance model and accident cover
- selected insurance categories, filters and products
- your needs information (e.g. hospital ward and desired benefits), your priorities and the desired level of cover
- your search entries in the doctor search (e.g. place or name of a practice)
We store your entries in the calculator in your browser's session storage (section 9) and in the activity log under a pseudonymous session ID, without IP address (section 14.2). If no application follows, we delete this record after 90 days.
3.3 Customer account
When you open and use a customer account, we process:
- first name, last name, email address and telephone number (optional)
- your password, which we store only as an irreversible hash value (bcrypt)
- your own referral code and, where applicable, the information via whose referral link or referral code you registered (section 3.11)
- information that you add in your profile: date of birth, address and your bank details for payouts (section 3.8)
- your applications and drafts with status and documents, your cashback and referral transactions, your messages to us (section 3.12) and your subscription to the premium alert (section 3.13)
- your acceptance of the General Terms and Conditions (GTC) and your confirmation that you have taken note of this Privacy Policy, in each case with version, time and language
- technical information relating to registration and sign-in, e.g. whether and when you confirmed your email address
To confirm your email address and to reset your password, we send you links and codes; we store them only as hash values.
3.4 Insurance application
If you apply for basic or supplementary insurance through easyall, we process for each person in the application:
- Personal details: name, date of birth, gender, nationality, marital status, residence status, the date of entry in the case of a move to Switzerland, and whether the person is gainfully employed (relevant for accident cover)
- Address and contact details
- Choice of insurance: chosen insurers and products, model, deductible, accident cover, desired start of insurance, premiums and discounts, chosen family doctor or chosen practice; in addition, the check of family and combination discounts, from which information on the relationships within the household emerges
- Current insurance: insurer, policy numbers, termination dates and reason for termination, and your information on any outstanding premiums or cost-sharing
- Payment details for the insurer: payment frequency, payment method and, where applicable, bank details (section 3.8)
- Health information for supplementary insurance (section 3.6)
- Documents and signatures (section 3.9)
- Your confirmations and consents with time; the versions of the GTC, of this Privacy Policy and of the Initial Information that were presented to you with the application; the insurers' contract documents that were displayed to you and that you confirmed
- Processing status: status of your application, including the day on which we forwarded it to the insurer, feedback from the insurer, notes by our staff and the correspondence relating to the application
If you save an application as a draft, we store the details entered so far in your customer account, except for the health information (section 3.6). Two to three days after a draft is created, we remind you of it once by email if you have not yet submitted it. If documents are missing after submission, we ask you to upload them within 7 days and remind you of this by email. If they are still not available 30 days after submission, we close the application without forwarding it and inform you by email; you can submit a new application at any time.
3.5 Co-insured persons and minors
An application may cover several persons in a household. The applicant then also provides information about these persons, including health information. Please inform the persons concerned about this Privacy Policy.
Adult co-insured persons sign the application themselves and thereby make their own declarations, in particular the consent for their health information (section 3.6). With their signature, they also accept that the cashback for the entire application is paid out to the applicant (section 3.11). For minors, the applicant signs as legal representative and confirms in the application that they are entitled to do so. An application can also be submitted only for minor children; in that case, a parent submits and signs it as legal representative without being insured themselves, and we also process that parent's personal details, contact details and signature. We determine whether a person is of age on the basis of their full date of birth.
3.6 Health information
For supplementary insurance, the insurers require information about health. We do not ask any health questions for basic insurance. For supplementary insurance, we process:
- the answers to the insurer's health questionnaire, including follow-up questions (e.g. on diagnoses, treatments, medication or smoking)
- names and addresses of treating doctors, insofar as the questionnaire asks for them
- health documents that you upload, for example medical certificates, dental findings or decisions and rulings of the invalidity, accident or military insurance or of occupational pension schemes
Health data are sensitive personal data (Art. 5 let. c DSG). We process them on the basis of the express consent of the data subjects: your consent when submitting the application, the consent of each adult co-insured person when signing and, for minor children, the consent of the legal representative. We process them only for your application: to review it, to complete it, to forward it to the chosen insurer and to document the intermediation. We do not store any health information in drafts: we store it in our systems only when the application is submitted (for the interim state in your browser, see section 9.3). If you resume a saved draft, you answer the health questions again. Without these consents, we do not submit any application with health information.
We create the health declaration from the answers. The insurer of the supplementary insurance receives the answers with the application (section 6). The advisory record only records that the health questions were answered, how many there were, for how many persons and according to which version of the questionnaire; it does not contain the answers themselves. Individual answers may mean that a chosen tariff is not possible, for example a non-smoker tariff (section 5).
Please provide health information only in the health questionnaire of the application, not in the chat, with easy or in messages (section 13).
3.7 AHV number
We do not ask for AHV numbers (Swiss social security numbers), neither yours nor those of co-insured persons, and we do not record them either. If the chosen insurer needs an AHV number, it obtains it itself, usually directly from you. If this changes, we will amend this Privacy Policy beforehand.
Please do not provide AHV numbers in the chat, with easy, in messages or in free-text fields either. On documents that you upload (e.g. a policy), you can cover the AHV number; we do not need it.
3.8 Bank details
We process bank details (IBAN) for two purposes:
- In the application: payment method and, where applicable, IBAN for paying the premium (e.g. by direct debit) or for refunds by the insurer. We pass these details on to the insurer with the application.
- In the customer account: your Swiss IBAN for the payout of cashback and referral bonuses; the account must be held in your name. Payouts are made exclusively by bank transfer to this account.
We additionally store bank details in encrypted form in our database (section 12).
3.9 Documents and signatures
- Copy of ID of each person and, if the person is already insured in Switzerland, a copy of their current policy, which you upload in the application form or later in the customer account. The insurers require a copy of an ID or policy with the application (health insurers' industry agreement, Branchenvereinbarung); we therefore forward the copies to the insurer. We also use the copy of the policy for three purposes: to check your existing cover, to prepare the termination letter (e.g. policy numbers and termination dates) and so that the new insurer can review your application.
- Health documents (section 3.6).
- Signatures: you and adult co-insured persons sign the application and, where applicable, the termination letter on the screen. We store the signature image and insert it into the signed application and into termination letters.
- Documents created by us: the signed application, the health declaration, termination letters and the advisory record.
We store documents in the document storage of our provider Amazon Web Services in Switzerland (Zurich region). We store files that you upload in the application form as soon as they are uploaded, even if you then do not submit the application (for deletion, see section 15).
3.10 Termination service
If you instruct us to terminate your current basic or supplementary insurance, we prepare a termination letter in your name. It contains the names, dates of birth and policy numbers of the persons concerned, your address, the termination date, where applicable the reason for termination, and the signatures. The letter states that easyall is sending it on your behalf, and asks the current insurer to send us a copy of the confirmation of cancellation.
Depending on the situation, we send the notice of termination electronically (by email or via an online portal of the insurer), by post (usually by registered mail) or deliver it by hand. We keep the letter sent and the date and method of dispatch as proof, where applicable with the tracking number or acknowledgement of receipt (section 15).
As a rule, we send the notice of termination for basic insurance only once the necessary documents are available (section 3.4) and the new basic insurer has accepted your application in writing. If documents are missing and time until the end of the notice period is running short (for a switch on 1 January, the notice of termination must reach the current insurer by 30 November at the latest), we will point this out to you; you can then also terminate yourself.
3.11 Cashback and referral programme
If supplementary insurance is concluded through easyall, you may be entitled to cashback under our GTC. For the calculation, the due date, the payout and any reclaim, we process:
- the supplementary insurance premiums as you applied for them and as stated in the policy, the cashback that was displayed to you before submission, and the intermediation compensation that we receive from the insurer for the supplementary insurance
- information from the insurer on acceptance, on the start of the supplementary insurance and on any dissolution within two years of the start, insofar as the insurer communicates it to us (e.g. with the commission statement), including the reason for the dissolution insofar as it is relevant for a reclaim (e.g. death or termination by the insurer)
- the day on which we forwarded your application to the insurer, and any revocation under Art. 2a of the Insurance Contract Act (VVG); both are relevant for the due date
- amount, status, due date, payout date and payment reference of each credit, as well as any reclaims, repayments and set-offs against other credit balances
- your bank details for the payout (section 3.8)
For an application covering several persons, we calculate the cashback on the supplementary insurance of all insured persons and pay it to the applicant. The applicant therefore sees in their customer account the cashback for the entire application and its status, including a reclaim that concerns a co-insured person.
In the customer account, you can retrieve a statement of the amounts paid out for each year.
For the referral programme, we store who referred whom. The attribution arises when the referred person registers with the referring person's link or code. We do not send invitations to third parties; you share your referral link yourself. If you registered via a referral, you accept the terms of the referral programme when submitting your application; we store this consent with your application.
If you registered with another person's link or code, that person sees your first name and the date of your registration in their customer account. In the customer account, they see everything else only in aggregated form across all persons they have referred, without attribution to individual persons: on the cashback page, the total of their pending referral bonuses and the total of their paid-out referral bonuses. In emails about the release or payout of an individual referral bonus, they can see its amount, but not your name.
The referring person does not see individually whether your application was accepted or cancelled, your insurer, your products, your premiums, your cashback or your health information. The referral bonus corresponds to a share of your cashback (depending on the insurer, a maximum of 10%). If the referring person has referred only a few persons, they can therefore tell from the totals or from these emails whether your application was accepted or cancelled and infer the amount of your cashback.
3.12 Support, contact form and emails
- Messages in the customer account: content, attachments and times of your messages and of our replies. We inform you of new replies by email.
- Contact form: name, email address, telephone number (optional), subject and message. The enquiry is delivered to us by email to info@easyall.ch via our email service provider; we do not store it in our database.
- Emails to us: content, sender and attachments; they are kept in our email mailbox (section 7).
- Emails from us: we send automatic emails such as confirmations, notifications on the status of your application, reminders and notifications about the cashback, some of them with attachments such as the advisory record or the insurer's contract documents, via our service provider Resend, or alternatively via Amazon Web Services (section 7). We send replies to your emails from our mailbox at Hostpoint (section 7). We send advertising emails only with your consent (premium alert, section 3.13).
3.13 Premium alert
With the premium alert, we inform you by email about the new health insurance premiums, usually once a year after their publication. For this purpose, we store your email address, the canton, the language and, if provided, year of birth, deductible and current insurer, in the case of a subscription in the customer account the link to your account, and the times of subscription, confirmation, dispatch and unsubscription.
- Without a customer account or with an email address other than that of your account, the subscription becomes active only when you confirm it via the link in our confirmation email (double opt-in).
- Signed in to the customer account and with the email address of your account (e.g. in the profile, in the application form, on the premium alert page or in the calculator), the subscription is active immediately; you then do not receive a confirmation email. In the application form, the checkbox for this is not preselected.
The email contains a link to the calculator in which the year of birth and deductible are included as parameters, so that the comparison is prefilled. You can unsubscribe at any time via the unsubscribe link in every email or in your customer account; after that, we will no longer send you any premium alert emails. For retention after unsubscription, see section 15.
3.14 AI functions
If you use the chat assistant, the companion easy or the policy analysis, we process your messages, the state of your entries in the calculator and uploaded policies as described in section 13.
3.15 Data of doctors (doctor search)
For the doctor search and for the choice of the family doctor's practice in the application, we use information from one health insurer's directory of doctors relating to its insurance models: name, title, gender, practice address, telephone number, language, location coordinates and information on network, tariff and status from the directory. In the doctor search, we display name, title, practice address, location and network; we do not display the telephone number. We pass on to the insurer the practice that you choose in the application. Doctors who wish to obtain access to, rectification or deletion of their information can reach us at info@easyall.ch.
3.16 Data we receive from third parties
- from the chosen insurer, insofar as it communicates them to us: acceptance or rejection, reservations, policy number, start of insurance, requests for further documents, premium changes, any dissolution of the contract and its reason, and statements and reclaims of our intermediation compensation. Reservations and reasons for a rejection or termination may be health data. If we receive such information, we process it with restricted access and only insofar as necessary for the intermediation or the cashback (section 15).
- from the current insurer: the confirmation of cancellation and feedback on the termination, for example on outstanding amounts
- from the applicant: information on co-insured persons (section 3.5)
- from one health insurer's directory: information on doctors (section 3.15)
- from public sources: premium data of the Federal Office of Public Health (FOPH); they do not contain any information about you
4. Purposes and grounds for justification
We process personal data for the following purposes. Under the DSG, not every processing requires a ground for justification. Where one is needed, for example for disclosing health data to third parties, we rely on the grounds stated in each case under Art. 31 DSG: your consent, the conclusion or performance of a contract with you (Art. 31 para. 2 let. a DSG), our overriding interest or a legal obligation.
- Operation of the website, premium calculator, comparison and doctor search: calculation and display of premiums, storage of your entries during the session. Ground: your request and pre-contractual measures; our overriding interest in a functioning service.
- Needs analysis and recommendation (section 5): Ground: pre-contractual measures and your intermediation mandate.
- Customer account: opening and management of your account. Ground: contract for the use of the account.
- Intermediation of your insurance: preparing, reviewing, completing and forwarding the application to the chosen insurer; handling the insurer's queries; informing you about the status. Ground: your intermediation mandate; for health data, additionally the express consent of the data subjects (Art. 6 para. 7 let. a DSG).
- Termination service: preparing, sending and tracking termination letters. Ground: your mandate.
- Documentation of the intermediation: Initial Information, advisory record, activity log and evidence (section 14). Ground: our information obligations as an insurance intermediary (Art. 45 VAG) and the documentation obligations under the health insurers' industry agreement, which the Federal Council has declared binding on the insurers and which the insurers impose on their intermediaries by contract; our overriding interest in having evidence in the event of complaints.
- Cashback and referral programme: calculation, payout and reclaim, statements. Ground: contract (GTC); statutory accounting obligations.
- Communication and support: answering your enquiries, notifications about account and application, reminders about drafts not submitted and about missing documents, notices about notice periods. Ground: contract and mandate; our overriding interest.
- Premium alert: Ground: your consent.
- AI functions (section 13): answering your questions and reading policies at your request. Ground: your request. Quality assurance of the answers: our overriding interest.
- Web analytics and measurement of our ads (section 10): Google Analytics, the Google Ads cookies and the transmission of your email address and phone number as a hash value: your consent. Measurement signals without cookies to Google Ads: our overriding interest in measuring the success of our advertising. Vercel Web Analytics: our overriding interest in aggregated usage statistics.
- Security, protection against misuse and troubleshooting (sections 11 and 12): Ground: our overriding interest in secure operation and in protecting our data; obligation to ensure data security (Art. 8 DSG).
- Compliance with legal obligations: accounting, supervision, information to authorities. Ground: law.
- Protection of our rights: assertion and defence of claims. Ground: our overriding interest.
We do not send third-party advertising, and we obtain your consent for our own advertising emails.
5. Needs analysis, recommendation and automated checks
From your information, the platform automatically calculates a recommendation for supplementary insurance according to fixed rules for which easyall is responsible. The following are taken into account: place of residence or premium region (via the premiums), age, gender, household, accident cover, desired benefits, your priorities and the desired level of cover, as well as premiums, benefits, our quality rating of the products and possible discounts. In the process, personal needs are evaluated; this may qualify as profiling within the meaning of Art. 5 let. f DSG. In our assessment, it is not high-risk profiling (Art. 5 let. g DSG), because we do not link any data from other sources for this purpose and do not assess any essential aspects of your personality. Your health information and our intermediation compensation are not factored into the recommendation. If you deviate from the recommendation, we record this with your confirmation.
The chat assistant and easy can answer questions about products and premiums and explain the recommendation. They do not decide on your application.
Before submission, the system automatically checks your application for completeness and consistency (e.g. premiums, documents and confirmations). An application cannot be submitted through easyall in particular:
- if the new insurer belongs to the same insurance group as your current one; insurers pay no intermediation compensation for this, and a switch directly with the insurer remains possible
- if your details exclude the chosen tariff, for example a non-smoker tariff
- if an insurer is temporarily not available through easyall
Only the insurer decides on admission to an insurance. You can state your point of view on an automated check and request that it be reviewed by a member of staff (info@easyall.ch). The calculation of the cashback, reminder emails and the protection against misuse (section 11) are also automated.
6. Recipients of your personal data
We do not sell your personal data and do not pass it on to other insurance intermediaries or address dealers. For the measurement of our ads, Google receives the information described in section 10.3; we do not pass on personal data for other advertising purposes. We disclose personal data only to the following recipients and only insofar as necessary for the respective purpose:
- Chosen insurers: with your application, the insurer you have chosen receives the information and documents that it requires for the review, in particular the application details of all persons in the application, the copies of ID and policy, the chosen practice and the payment details, depending on the insurer also the signed application or the signatures and our advisory record or the insurer's record form with the information from the advice. Health information and health documents are received by the insurer with which you apply for supplementary insurance. If you apply for basic and supplementary insurance with different insurers, each receives the information on its application; if we enclose our advisory record, it lists all products in the application but does not contain any health information (section 14.1). We transmit your application and the documents to the insurer via its intermediary portal or by email. The insurers process the data as controllers in their own right in accordance with their privacy policies.
- Current insurers: if you instruct us to terminate, your current insurer receives the termination letter with the information under section 3.10. When sending by post, Swiss Post or a courier service is involved; when sending electronically, our email provider (section 7) or the insurer's online portal.
- Our bank: for payouts of cashback and referral bonuses, our bank receives your name, your IBAN, the amount and the payment reference.
- Referring person: if you registered with a referral link or referral code, the referring person sees the information under section 3.11.
- Applicant: for an application covering several persons, the applicant sees in their customer account the status of the entire application and the cashback for all insured persons (sections 3.5 and 3.11).
- Authorities, courts and industry bodies: for example FINMA, tax authorities, criminal prosecution authorities and courts, if we are legally obliged to do so or it is necessary to protect our rights; in addition, insurers or the competent industry body if we have to provide evidence under the industry agreement, for example on the origin of a customer contact in the event of a complaint or spot check.
- Advisers: for example lawyers or our fiduciary or audit firm, insofar as necessary and subject to confidentiality.
- Service providers (processors): see section 7.
Of our records, the insurer routinely receives at most the advisory record. We disclose extracts from the activity log only if we are obliged to do so, for example in the event of a complaint or spot check under the industry agreement, or if it is necessary to protect our rights (section 14.2).
7. Service providers (processors)
We use service providers that process personal data on our behalf and in accordance with our instructions (Art. 9 DSG). We have data processing agreements with them, usually on the respective provider's standard terms. The service providers in turn use sub-processors, for example data centres; they publish the lists of these on their websites.
- Amazon Web Services (contracting party: Amazon Web Services EMEA SARL, Luxembourg; group company Amazon Web Services, Inc., USA): database, document storage, key management and fallback route for sending emails. Data: account, application and health data, documents and activity logs. Location: Switzerland (Zurich region). Safeguards: storage in Switzerland; for any access from abroad, Luxembourg with adequate data protection or, for the USA, certification under the Swiss-U.S. Data Privacy Framework.
- Vercel Inc., USA: hosting of the website, execution of the server functions, delivery of the pages, cookie-free web statistics (Vercel Web Analytics) and bot protection (Vercel BotID). Data: connection and device data including IP address, the content transmitted via the website while it is being processed (including application data on its way to our database) and statistical data. Location: server functions in Frankfurt (Germany); delivery of the pages via a global network, with Vercel processing requests in the nearest data centre, for requests from Switzerland usually in an EU state, in the event of faults or for requests from abroad also in other states; platform data such as logs and statistics also in the USA. Safeguards: EU states with adequate data protection; USA: Swiss-U.S. Data Privacy Framework; other states: see section 8.
- Upstash, Inc., USA (obtained via Vercel): cache for rate limiting, for blocks and for security events (section 11). Data: IP addresses and, for sign-in and confirmation attempts, the email address or our internal customer ID in plain text, in each case only for the duration of the count and of any block (at most approximately 2 hours); hash values generated with a secret key and truncated IP addresses; technical characteristics of requests. Location: storage in the EU (Frankfurt, Germany). Safeguards: Germany with adequate data protection; for access from the USA, the Swiss-U.S. Data Privacy Framework.
- Resend (Plus Five Five, Inc.), USA: sending of our automatic emails to you as well as of the messages from the contact form and of internal notifications to our mailbox. Data: email address, name, content and attachments (e.g. advisory record, contract documents) and sending logs. Location: sending via Ireland; storage of account, log and email data in the USA. Safeguards: EU standard contractual clauses with the adaptations required for Switzerland; Resend is not certified under the Swiss-U.S. Data Privacy Framework.
- Anthropic (contracting party: Anthropic Ireland, Limited, Ireland; processing by Anthropic, PBC, USA): AI functions (section 13). Data: messages to the chat assistant and to easy, page context, uploaded policies. Location: USA; depending on load, also other states in which Anthropic uses data centres. Safeguards: Ireland with adequate data protection; USA and other states: EU standard contractual clauses with an addendum for Switzerland (section 8); Anthropic is not certified under the Swiss-U.S. Data Privacy Framework.
- Sentry (Functional Software, Inc.), USA: detection and fixing of technical errors. Data: technical error reports (e.g. browser, operating system, page concerned, error message, pseudonymous identifiers such as application or draft numbers) and the IP address of your browser when an error report is transmitted, which Sentry does not store according to our settings. We automatically remove email addresses, Swiss IBANs, signature images and similar information beforehand, insofar as our filter detects them. Location: storage in the EU (Frankfurt, Germany). Safeguards: Germany with adequate data protection; for access from the USA, the Swiss-U.S. Data Privacy Framework.
- Google (Google Ireland Limited, Ireland, and Google LLC, USA): web analytics with Google Analytics 4, only with your consent, and measurement of our ads with Google Ads (section 10). Data: usage data and measurement signals; with your consent, cookie identifiers and, for a submitted application, your email address and phone number as a hash value. Location: Google Analytics collects data via servers in Europe; Google also processes data in the USA and in other states in which Google operates data centres. Safeguards: Ireland with adequate data protection; USA: Swiss-U.S. Data Privacy Framework; other states: see section 8.
- Hostpoint AG, Rapperswil-Jona, Switzerland: our email mailbox info@easyall.ch. Data: emails to us and replies from our mailbox, contact enquiries and internal notifications (e.g. on new applications and security events, some with the full IP address, section 11), and emails that we send to insurers, for example with applications, documents or terminations. Location: Switzerland.
8. Disclosure abroad
We store our database and our documents in Switzerland. Some service providers under section 7 process data abroad, in particular in Germany, Ireland, Luxembourg and the USA. Vercel temporarily processes connection data and requests in the data centre closest to you, for requests from Switzerland usually in an EU state, in the event of faults or for requests from abroad also in other states; Vercel publishes the locations at vercel.com/docs/regions. Google may also process data in other states in which Google operates data centres. For computing AI responses, including the automatic topic check, Anthropic may, depending on load, also use data centres in other states. We disclose personal data abroad only if one of the following safeguards is in place:
- States with adequate data protection: Germany, Ireland, Luxembourg and the other EU states (Art. 16 para. 1 DSG and Annex 1 DSV).
- USA, certified companies: Vercel, Amazon Web Services, Upstash, Sentry and Google LLC are certified under the Swiss-U.S. Data Privacy Framework. For such companies, data protection in the USA is deemed adequate (Annex 1 DSV).
- USA, non-certified companies: for Resend and Anthropic, we rely on the European Commission's standard contractual clauses with the adaptations required for Switzerland, which the Federal Data Protection and Information Commissioner (FDPIC) has recognised (Art. 16 para. 2 let. d DSG).
- Other states: if Vercel or Google process data in other states, we rely on their data protection agreements with us and on their certification under the Swiss-U.S. Data Privacy Framework, which also governs onward transfers within the group and to sub-processors. If Anthropic uses data centres in other states, the standard contractual clauses apply to this (Art. 16 para. 2 let. d DSG).
Even with these safeguards, authorities in the USA may, under certain circumstances, access data under the law applicable there. Information on the safeguards, for example a copy of the standard contractual clauses, is available on request at info@easyall.ch.
9. Cookies and storage in the browser
Our website stores information on your device: in cookies, in local storage and in the session storage of your browser. We use technically necessary storage without consent. We set Google Analytics and Google Ads cookies only with your consent (section 10). We do not use any cookies for personalised advertising or remarketing.
9.1 Cookies
- Login cookie: keeps you signed in after login, for up to 30 days. In addition, there are security cookies for login (protection against forged requests, redirection after login), which end with the browser session.
- Language cookie: stores the chosen language, 1 year.
- Google Analytics analytics cookies: only after your consent, up to 2 years from your last visit (section 10).
- Google Ads cookies (e.g. _gcl_au, _gcl_aw): only after your consent, 90 days; they link a click on one of our ads with a later calculation or application (section 10.3). Google may additionally set cookies on its own domains for this purpose, such as doubleclick.net.
9.2 Local storage
These entries remain stored until they are replaced or you delete them:
- your choice in the cookie banner
- a security token for the premium calculator; it is valid for 12 hours and contains a hash value of your IP address (section 11)
- display settings of the chat assistant and of easy
- in the customer account, the time at which you last read your messages
9.3 Session storage
Session storage applies per browser tab and is generally deleted when you close the tab. We store there:
- a pseudonymous session ID for the activity log, as soon as you use the calculator, the chat assistant, easy, the registration or the application form (section 14.2)
- your entries in the calculator, your needs information, the recommendation and the selection that you transfer to the application form
- the history of the chat assistant and of easy
- the interim state of the application form
We store the interim state so that your entries are not lost if the page is reloaded. It includes the fields of the form, for example names, addresses and insurance details. Passwords, signatures and uploaded files are not stored in it; health information and bank details are included in the interim state. The interim state is deleted as soon as you save or submit the application; if a tab is restored or duplicated, it may be retained. Therefore, if possible, do not use a third-party or shared device for an application, or close the browser window afterwards.
This storage is necessary for the respective functions, the session ID for documenting the intermediation (advisory record and proof of the origin of the customer contact under the health insurers' industry agreement; section 14). You can delete or block cookies and website data in your browser at any time; sign-in, the calculator or the application form may then not work or may work only to a limited extent.
10. Web analytics and measurement of our ads
10.1 Vercel Web Analytics
We use Vercel Web Analytics from our hosting provider Vercel to understand how our website is used. The service does not set any cookies. For each page view, the time, the address accessed, the referring page, the approximate location (country, region, city), the operating system, the browser and the device type are recorded. We transmit addresses without parameters that could allow conclusions to be drawn about you, such as confirmation or draft identifiers. To count visits, Vercel generates a hash value from the request, which Vercel discards after 24 hours. We see only aggregated statistics. Ground: our overriding interest in improving our services.
10.2 Google Analytics 4
We load Google Analytics only if you choose “Accept” in the cookie banner. Before that, and if you choose “Decline”, we do not transmit any data to Google Analytics (for the measurement signals of Google Ads, see section 10.3). Even after your consent, we transmit the address of the page accessed without parameters and fragments (the part from “?” or “#” onwards), so that confirmation or draft identifiers, for example, do not reach Google; only the click identifier that Google appends to the address when you click on one of our ads is kept (gclid, gbraid or wbraid).
With your consent, Google Analytics sets cookies that recognise your browser pseudonymously. In particular, the pages accessed and times, the referring page, interactions on the website, the device, browser, operating system and approximate location are recorded. According to Google, it uses your IP address only to determine the approximate location and does not log or store it for users from Switzerland. Advertising features such as ad personalisation are deactivated in our implementation. We use the data only for aggregated statistics. According to our settings, Google retains the event data for 2 months.
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; data may be transferred to Google LLC in the USA (sections 7 and 8).
You can withdraw your consent at any time via the “Cookie settings” link at the bottom of the pages of our website, for example on the home page, in the calculator or on this page. After that, we no longer transmit any data to Google Analytics and delete the analytics cookies. If you decline or withdraw consent, you can use the website without restriction.
10.3 Google Ads
We run ads on Google and measure whether they lead to calculations in the premium calculator and to submitted applications (conversion measurement). For this purpose, the Google tag of Google Ads is embedded on all pages of our website, regardless of your choice in the cookie banner.
Without your consent – before you choose and if you choose “Decline” – the Google tag neither sets nor reads cookies. It sends Google measurement signals without cookies: the time, the address accessed, information on your browser and device, your choice in the cookie banner and the event, such as a page view, a calculation or a submitted application. As with any connection, Google receives your IP address. Google removes the click identifier of an ad from these signals. According to Google, it uses them to estimate the number of applications resulting from our ads. Reason: our overriding interest in measuring the success of our advertising.
With your consent, the Google tag sets cookies that link a click on one of our ads with a later calculation or application (section 9.1). If you submit an application, we additionally transmit the email address and phone number of your customer account to Google as a hash value (SHA-256), so that Google can attribute the application to your ad click even when cookies are missing, for example after a change of device (enhanced conversions). For this purpose, Google matches the hash value against the information in Google accounts. We create the hash value on our server. We do not transmit names, addresses, health information or any other information from the application to Google. Personalised advertising and remarketing are deactivated in our integration. Reason: your consent.
In both cases, the Google tag also automatically records interactions such as page changes, scrolling, clicks on links to other websites, file downloads and the submission of forms, without the content of the form fields. As with Google Analytics, we transmit addresses without parameters and fragments (section 10.2).
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; data may be transferred to Google LLC in the USA (sections 7 and 8). Google processes the ad measurement data partly under its own responsibility in accordance with its privacy policy (policies.google.com/privacy) and retains it in accordance with its own periods.
You can withdraw your consent at any time via the “Cookie settings” link. After that, we no longer set Google Ads cookies, delete the existing ones on our website and no longer transmit an email address and phone number; Google Ads then only receives measurement signals without cookies. You can prevent these by blocking connections to Google in your browser, for example with an ad blocker; the website keeps working without any restrictions even then.
11. Protection against misuse
We protect our platform and our premium data against automated bulk queries, overload and other misuse. To this end, we use the following measures:
- Rate limiting: for individual functions (e.g. calculator, chat, registration, sign-in, contact form, premium alert), we count the requests per IP address, and for sign-in and confirmation attempts and when saving applications also per email address or customer account. For this purpose, our service provider Upstash stores the IP address and, where applicable, the email address or our internal customer ID in plain text, in each case only for the duration of the count and of any block (at most approximately 2 hours). If Upstash cannot be reached, the server temporarily counts in its own memory; these entries expire when the server instance is terminated.
- Calculator security token: the calculator receives a token that is valid for 12 hours and bound to a hash value of your IP address (section 9.2).
- Vercel BotID bot protection: when premiums are retrieved, a test in your browser that is invisible to you checks whether the request comes from a human or from an automated program.
- Honeypot links: our pages contain links that are invisible to humans. If an automated program follows such a link, we detect this.
- Blocks and test data: if misuse is suspected, we automatically block access to the premium query for 1 to 72 hours, delay responses or deliver test data to automated programs with a marker derived from the hash value of the IP address.
- Characteristics recorded: for such events, instead of the IP address we store a hash value generated with a secret key and a truncated IP address (e.g. 203.0.x.x), the function accessed and technical characteristics of the request: browser identifier, language and other technical information from the browser, characteristics of the encrypted connection, approximate location (country, region, city), time zone and network operator.
- Notification of our team: in the event of a block or suspected misuse, our team receives an email with the full IP address and the technical characteristics, at most one email per occasion, IP address and day. The daily report to our team contains only hash values and truncated IP addresses.
Hash values remain personal data for us because we can recalculate them with our key. We rely on our overriding interest in the secure operation of the platform and in protecting our data collection against unauthorised exploitation (Art. 31 para. 1 DSG). For retention, see section 15. If you believe you have been blocked wrongly, please contact us at info@easyall.ch.
12. Data security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss and misuse (Art. 8 DSG). These include in particular:
- encrypted transmission (TLS) across the entire website
- storage of passwords only as a hash value (bcrypt), never in plain text
- additional encryption of particularly sensitive fields in the database (AES-256-GCM): health information, signature images, bank details and the list of health documents; we manage the key via the key service of Amazon Web Services in the Zurich region
- storage of the database and documents in Switzerland; the documents are encrypted server-side by the storage provider (AES-256)
- access only for authorised staff based on roles, separate login for the admin area and time-limited download links for documents
- filtering of error reports before transmission (section 7)
- regular security updates
No one can guarantee complete security in the transmission and storage of data. If a breach of data security occurs, we proceed in accordance with Art. 24 DSG: we report it to the FDPIC if it is likely to result in a high risk, and inform you if this is necessary for your protection.
13. AI functions
13.1 Overview and provider
The chat assistant and the companion easy are AI systems; there, you are not communicating with a human. The policy analysis reads uploaded policies using AI.
For these functions, we use Anthropic's application programming interface (API) under its standard commercial terms, including the data processing agreement. There is no special agreement, for example on immediate deletion. The contracting party is Anthropic Ireland, Limited; processing is carried out by Anthropic, PBC in the USA and, depending on load, also in other states (sections 7 and 8).
Under its contractual terms, Anthropic may not use content from our use to train its models. According to Anthropic, it automatically deletes inputs and outputs within 30 days. If Anthropic classifies content as a violation of its usage policies, it may retain that content for up to 2 years and the associated safety assessments for up to 7 years.
13.2 Chat assistant and easy
- What we transmit: your messages and the previous conversation history. As a rule, we first automatically check messages to the chat assistant as to whether they concern an insurance topic; this check also runs via Anthropic. For easy, we additionally transmit the current state of your entries: page and step, type of insurance, postcode, municipality and canton, for each person year of birth, gender, deductible, model, accident cover and needs information, the products displayed and selected and the recommendation. We do not transmit names, health answers or bank details from the application form in this process.
- Health information: if our system detects health information in a message, we replace the affected passages with a placeholder before transmission to Anthropic; in our chat log, we replace the entire message. This detection does not succeed in every case. We do not remove names, email addresses, telephone numbers or other information that you type in yourself. Please therefore do not enter any health information, AHV numbers or bank details, and if possible no names or contact details, in the chat or with easy.
- Storage at easyall: we store conversations in our database under a pseudonymous conversation ID, without IP address and without a direct link to your customer account, together with page, language and technical information (e.g. response time). We delete them automatically after 90 days. The messages and replies also appear in the activity log (section 14): if no application follows, we delete it after 90 days; if an application follows, we retain it with the application, and the conversation can thus be attributed to your application. Authorised easyall staff may view stored conversations for quality assurance. In your browser, the history remains in session storage (section 9.3).
- Use: we do not automatically transfer information from the chat into your application. Suggestions from easy change your entries in the calculator only when you tap them; links to the calculator offered by the chat assistant or easy may contain your information from the conversation as pre-filled values. You can transfer what you then select in the calculator to the application form. We do not routinely pass on information from the chat to insurers. AI answers may be incomplete or incorrect and are not legal, tax or medical advice; the insurance conditions, the policy and the advisory record are authoritative.
13.3 Policy analysis
If you upload your current policy in the calculator (up to four files), we transmit the files to Anthropic in order to extract the insurer, products, premiums and information on the insured persons (e.g. name, date of birth, model, deductible). easyall processes the files only in memory and does not store them; the result is returned to your browser. In the activity log, we record a summary without names (e.g. insurer, years of birth, models, deductibles, products and premiums, and your corrections). At Anthropic, the periods under section 13.1 apply.
Policies may contain health information, for example reservations. Cover such passages before uploading, or upload only the pages with products and premiums.
This must be distinguished from the copies of ID and policy that you upload in the application form. We store these with your application (section 3.9).
14. Advisory record and activity log
14.1 Advisory record
For each application, we create an advisory record as required by the health insurers' industry agreement. It contains in particular your personal details, the products chosen, the confirmation of the Initial Information, the versions of the documents accepted, the contract documents and the time of your signature. It does not contain any health information, only the number of questions answered and of persons and the version of the questionnaire. You approve the advisory record digitally before submission, will then find it in your customer account and receive it by email, provided the file size permits. Depending on the insurer, we enclose it with your application, and in the case of several insurers with each of them (section 6). If a person registered with FINMA reviews your application, they may supplement the record with an addendum.
14.2 Activity log
To document the intermediation, we record your entries and interactions as soon as you use the premium calculator, the chat assistant, easy, the registration or the application form: for example steps accessed, entries in the calculator, products chosen, results of the policy analysis, messages to the chat assistant and to easy together with their replies, steps in the application form, and notices and contract documents displayed and confirmed. This is done under a pseudonymous session ID and without IP address. We do not record answers to health questions, only that questions were answered and how many; nor do we record passwords and bank details from the application form. The restriction in section 13.2 applies to texts that you type in the chat or with easy. We store the records in Switzerland (Amazon Web Services, Zurich region).
If no application follows, we delete the record after 90 days. If you submit an application, we assign to it the records of your last sessions (at most five) and create the internal activity log from them. It also contains the premiums, discounts and the expected cashback at the time of the application. For retention, see section 15.
We do not routinely pass the activity log on to insurers. We may disclose extracts from it if we are obliged to do so (e.g. proof of the origin of a customer contact in the event of a complaint or spot check under the industry agreement, requests from FINMA or from courts) or if it is necessary to protect our rights. If you have submitted an application, you can request the activity log for it at any time at info@easyall.ch.
15. Retention period
We retain personal data only for as long as is necessary for the purpose, as a legal obligation exists or as we need it as evidence to protect our rights. After that, we delete or anonymise it (Art. 6 para. 4 DSG). We use data that we retain only for these reasons solely for this purpose. If proceedings, a complaint or an official request are pending, we retain the data concerned until they are concluded.
The intermediation of an application is completed with the last action or transaction relating to it: with the insurer's decision or the closing of the application, the dispatch of the notice of termination or the last cashback or referral transaction including a reclaim, whichever occurs last.
The periods in detail:
- Calculator, chat and easy histories without an application: 90 days. We delete the chat log in our database after 90 days in any case; if an application has followed, the history is retained in the activity log.
- Draft applications not submitted, including uploaded documents (transitional arrangement): as long as you can still continue the application; we are currently setting up automatic deletion 2 years after the last change. At your request, we delete a draft earlier.
- Uploaded files not assigned to any draft or application (transitional arrangement): until we have assigned them to a draft or application or established that they are no longer needed; we are currently setting up automatic deletion 7 days after upload.
- Submitted applications (evidence of the intermediation): personal details, products chosen, status and history, consents and confirmations, Initial Information, advisory record (section 14.1) and activity log (section 14.2), signed application, termination letters with the evidence of the date and method of dispatch, and evidence of which documents were transmitted when (e.g. checksums): 10 years after the end of the year in which the intermediation was completed. If no contract results from an application, for example because the insurer rejects it or the application is withdrawn, revoked or closed, we retain this evidence for 7 years after the end of that year. Reason: proof for claims arising from the intermediation (limitation under Art. 127 and 130 of the Code of Obligations, OR) and of compliance with our information obligations, breaches of which can be prosecuted for up to seven years (Art. 86 VAG, Art. 52 of the Financial Market Supervision Act, FINMAG).
- Health information (transitional arrangement): we retain the answers in the questionnaire, uploaded health documents and the health declaration for your application until the insurer has decided, the notice of termination has been sent and any queries have been dealt with; we are currently setting up automatic deletion 90 days after the insurer's decision or the closing of the application. After that, only the evidence of which documents were transmitted when remains. If the supplementary insurance has been concluded, we retain the health declaration with restricted access together with the evidence of the intermediation; otherwise we also delete it after this period and keep only its checksum.
- Health-related feedback from the insurer (e.g. reservations or reasons for a rejection or termination): with restricted access, together with the evidence of the intermediation.
- Copies of ID and policies (transitional arrangement): until the insurer has decided, the notice of termination has been sent and any queries have been dealt with; we are currently setting up automatic deletion 6 months after the insurer's decision or after the completion of the termination, whichever is later. After that, only the evidence of which documents were transmitted when remains.
- Signature images (transitional arrangement): until the insurer has decided, the notice of termination has been sent and any queries have been dealt with; we are currently setting up automatic deletion 90 days after the insurer's decision or the closing of the application, but not before the notice of termination has been sent. The signed documents remain with the evidence of the intermediation.
- Bank details in the application (transitional arrangement): until the insurer has decided, the notice of termination has been sent and any queries have been dealt with; we are currently setting up automatic deletion 90 days after the insurer's decision or the closing of the application.
- AHV number: we do not ask for it or record it (section 3.7).
- Bank details for payouts: until you remove them in the customer account or your account is deleted, provided that no payout is still outstanding.
- Accounting-relevant data (intermediation compensation, cashback and referral transactions including reclaims and set-offs, payout receipts, statements): 10 years from the end of the financial year. Reason: statutory retention obligation (Art. 958f OR, Art. 126 para. 3 of the Federal Act on Direct Federal Taxation, DBG).
- Customer account (transitional arrangement): until deletion, which you can request at any time (section 16). We retain unconfirmed accounts and accounts without a submitted application as long as you use your account; we are currently setting up automatic deletion, namely for unconfirmed accounts without applications and without referrals after 30 days and for accounts without a submitted application, together with any drafts, after 24 months without sign-in, with notice by email 30 days in advance. This does not apply as long as a credit balance is outstanding or a bonus may still arise from a referral. If an account is deleted, we retain only the data that we must retain for longer under this section, and block it for all other purposes (section 16).
- Premium alert (transitional arrangement): until you unsubscribe or your customer account is deleted; after that, as long as necessary as proof of your consent. We are currently setting up automatic deletion, namely for the canton, year of birth, deductible and insurer within 30 days after the unsubscription, for your email address and the times of subscription and unsubscription (proof of your consent) 3 years after the unsubscription or the last email, whichever is later, and for unconfirmed subscriptions after 30 days.
- Information in the referral overview: if the referred person's account is deleted, we remove their first name from the referring person's overview; we retain the transactions as accounting-relevant data.
- Messages in the customer account, including attachments (transitional arrangement): messages relating to an application together with its evidence; other messages as long as necessary for handling your requests and as proof of your instructions; we are currently setting up automatic deletion of other messages 2 years after the last message. Contact enquiries and emails in our mailbox: as long as necessary for handling your request and as proof of our correspondence.
- Logs of our staff's activities in the admin area (transitional arrangement) (they may contain information on your account or application): as long as necessary to trace access; we are currently setting up automatic deletion after 2 years.
- Protection against misuse: counters at most approximately 2 hours (counters per calculator token up to 12 hours, lock against duplicate notifications 24 hours); blocks until they expire (at most 72 hours), the associated block record until the next daily clean-up; repeat counters with hashed IP address 30 days; security events as long as necessary to defend against misuse (transitional arrangement; we are currently setting up automatic deletion after 30 days); alerts to our team as long as necessary to defend against misuse.
- Logs and data at our service providers: server, error and sending logs of Vercel, Sentry and Resend, depending on the service, a few hours to 90 days; the visitor hash value of Vercel Web Analytics 24 hours; Anthropic in accordance with section 13.1; Google Analytics in accordance with section 10.2; Google Ads in accordance with Google's periods (section 10.3).
- Backups: deleted data may remain in backups until these are overwritten or deleted.
Transitional arrangement: for the data categories marked in this way, we are currently setting up automatic deletion. Until then, we retain these data only as long as necessary according to the criteria stated and review our holdings at least monthly. On request to info@easyall.ch, we will tell you which data we retain and for how long.
16. Your rights
Under the DSG, you have in particular the following rights:
- Access (Art. 25 DSG): you can request information as to whether and which personal data we process about you, including the purpose, the retention period or the criteria for determining it, the origin, the recipients including the states abroad, and any automated individual decisions together with their logic. Access is generally free of charge and is provided within 30 days; if we need longer, we will tell you. In the case of disproportionate effort, we may request a contribution to costs of at most CHF 300; we will inform you beforehand (Art. 19 DSV).
- Delivery and transfer (Art. 28 DSG): you receive data that you have disclosed to us or that we have collected about you during your use of the platform in a commonly used electronic format, insofar as we process it by automated means and on the basis of your consent or for the performance of a contract with you. At your request, we transfer it to another controller if this does not involve disproportionate effort.
- Rectification: you can request that we rectify incorrect data. You can also change your profile details yourself in the customer account.
- Deletion and restriction: you can request that we delete data or no longer process it, insofar as no retention obligation and no overriding interest prevent this (section 15). We use data that we must retain only for that purpose. You can request the deletion of your customer account by email to info@easyall.ch; we generally delete it within 30 days and confirm the deletion to you. If you have submitted applications, we anonymise your login data. We do not delete data that we must retain under section 15, but block it: we use it only for the purpose for which we retain it.
- Objection: you can object to processing that we base on our overriding interest (Art. 30 para. 2 let. b DSG). We will then examine whether legal obligations, the performance of your mandates or overriding interests, such as protection against misuse or the preservation of evidence, stand in the way.
- Withdrawal of consents: you can withdraw consents at any time with effect for the future: for Google Analytics and Google Ads via the “Cookie settings” link (sections 10.2 and 10.3), for the premium alert via the unsubscribe link or in the customer account, for health data by email to info@easyall.ch. If you withdraw the consent to health data before we have forwarded your application, we cannot forward it. After forwarding, the processing by the insurer remains unaffected, and we retain the evidence in accordance with section 15.
- Automated individual decisions: you can state your point of view and request that an automated decision be reviewed by a person (Art. 21 DSG, section 5).
Send your request in writing or by email to info@easyall.ch. To prevent misuse, we may request proof of your identity. In the cases provided for by law, we may restrict, defer or refuse access (Art. 26 DSG); we will give reasons for this. You can also assert your rights in court (Art. 32 DSG).
17. Report to the FDPIC
If you believe that we are not processing your personal data lawfully, please contact us first. You can also file a report with the Federal Data Protection and Information Commissioner (FDPIC) (Art. 49 DSG): FDPIC, Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch.
18. Changes and versions
We amend this Privacy Policy when our processing or the law changes. The version published on www.easyall.ch at the relevant time is authoritative; the version and date are stated at the end of this page. For an application, we store which version was presented to you. We will inform you in an appropriate form, for example by email or at the next contact, about material changes that affect an ongoing mandate or your customer account. Earlier versions are available on request.
This version (version 2026-10.2) replaces version 2026-10.1.