Privacy Policy
COMPLETE INFORMATION ON THE DATA PRIVACY POLICY OF DYLSI AGENCIA DE SEGUROS, SL IN ITS ACTIVITY AS AN INSURANCE AGENT.
1. Data Controllers
Depending on the type of service or enquiry you make through this website, the entity responsible for processing your personal data will be:
A. AXA SEGUROS (AXA Seguros Generales, S.A. de Seguros y Reaseguros)
- Role: Primary data controller for personal data relating to requests for estimates, pricing, quotations, policy arrangements and the administrative management or claims handling of insurance policies offered through the agency.
- Address: Paseo de la Castellana, 259C, 28046 Madrid.
B. DYLSI AGENCIA DE SEGUROS SL (Exclusive AXA Agency)
- Role: Data controller for the administration of this website, its own contact forms, chatbot enquiries, management of the customer service channel and processing arising from commercial loyalty agreements with third party partners.
- Registered office: Calle Galileo Galilei, 2, Oficina 18, Edificio U. Parc Bit, 07121. Balearic Islands, Spain.
- NIF: B16846255
- Contact email: darryl@dylsi-seguros.es
2. Categories of Data Collected
- Browsing and device data: IP address, browser type and version, operating system, language, date and time of the request, referring URL and technical error logs.
- Data provided via forms and the chatbot: Name, email address, telephone number, postcode, date of birth and information required to calculate the premium or respond to your enquiry.
- Contract and billing details: Handled in my capacity as an AXA broker to arrange insurance policies.
- Commercial verification data (Agreement with VITA DOCTORS): First name, surname(s), National Identity Card (DNI)/Foreign Resident Identity Number (NIE) and the binary technical status parameter ‘Active DYLSI Customer: YES/NO’, processed solely for the purpose of verifying membership.
3. Purposes of Processing and Lawful Bases
3.1. 3.1. Processing carried out as an Exclusive AXA Insurance Agency (AXA Responsibility)
- Management of requests for information and quotations: Pricing of insurance products. (Lawful basis: Consent of the data subject or steps taken at the request of the data subject prior to entering into a contract, Art. 6.1.a and 6.1.b GDPR).
- Arrangement and performance of the insurance contract: Where an insurance policy is taken out. (Lawful basis: Performance of a contract, Art. 6.1.b GDPR).
3.2. 3.2. Processing carried out directly by DYLSI AGENCIA DE SEGUROS SL (DYLSI Responsibility)
- Website administration and security: To ensure the proper operation of the website, detect errors and prevent fraud. (Lawful basis: Legitimate interests, Art. 6.1.f GDPR).
- Handling enquiries and the Chatbot: To respond to enquiries received through the website and process conversations in order to improve the chatbot learning based on frequently asked questions. (Lawful basis: Consent and legitimate interests, Art. 6.1.a and 6.1.f GDPR).
- Validation of the VITA DOCTORS Loyalty Programme (Level 1 Membership): To enable automated technical verification in real time (in less than 30 seconds) when you visit the VITA DOCTORS MEDICAL & SKINCARE clinic or its membership sign up landing page, in order to verify whether you hold an active policy with DYLSI and assign the corresponding reduced rates.
(Lawful basis: Explicit consent of the data subject given by ticking the checkbox on the forms or when confirming registration at the clinic, Art. 6.1.a GDPR).
4. Strict Data Separation and Medical Confidentiality
Under the collaboration agreement between DYLSI and VITA DOCTORS, an enhanced privacy safeguard is established:
- No access to clinical data: DYLSI will never access, process or store data relating to your medical history, dermo aesthetic treatments, diagnoses or clinical information generated by VITA DOCTORS.
- Communication limit: Technical verification between the IT systems of both entities is strictly limited to returning the binary parameter (YES/NO) in response to the question of whether the DNI/NIE entered belongs to a client with an active policy with DYLSI.
5. Age and Legal Capacity
By using the website and its forms, you declare that you are of legal age and have the legal capacity required to be bound by this agreement and to use the website in accordance with its terms and conditions, which you fully understand and acknowledge. All information you provide before and during use of the Service must be true, complete and accurate.
6. Cookies and Similar Technologies
We use cookies and similar mechanisms stored on your device to operate and provide the Service, personalise content, understand how the website is used and remember your preferences.
- Technical and Necessary Cookies: These enable smooth browsing and the use of the different options or services available on the website.
- Analytics or Performance Cookies: These collect aggregated information about how users interact with the website in order to make improvements based on the analysis of usage data.
Non essential cookies are always used only after obtaining your informed consent through the settings banner. You can find further details in our Cookie Policy.
7. Recipients and Service Providers
- Insurance Company (AXA): Transmission of pricing requests, management of premium receipts and contractual data.
- Technology Providers (Data Processors): Hosting services, chatbot platforms, statistics monitoring, corporate email management, communication plugins (such as the WhatsApp widget) and website design and marketing services. These providers are prohibited from using the information for any other purpose.
- Transmission to VITA DOCTORS MEDICAL & SKINCARE S.L.: Automated technical verification of active client status is enabled for users who have given their consent.
- Legal Compliance: DYLSI may disclose data to competent authorities, law enforcement bodies or public authorities where strictly required by law or legal proceedings.
8. Are International Data Transfers Carried Out?
We inform you that AXA has approved Binding Corporate Rules (BCR), an internationally recognised standard that provides an appropriate level of protection for the management of personal data within a multinational company. These rules have been approved by 16 European data protection authorities, including the Spanish Data Protection Agency (AEPD). More specifically, the rules establish equivalent measures for protecting personal data obtained in the course of business where such data must be transferred within companies in the Group. AXA has also adopted commitments concerning data protection.
Your personal data may be disclosed to recipients located in countries outside the European Economic Area (EEA), including countries that do not provide a level of data protection equivalent to that of the European Union. In such cases, however, the data will be processed in strict compliance with European and Spanish legislation and the safeguards set out below will be implemented:
Recipient category | Country | Safeguard |
AXA Group entities (for example, AXA Business Services Pvt. Ltd.) | India | Binding Corporate Rules (BCR) |
Technology and marketing service providers | USA | Standard Contractual Clauses, adopted by the European Commission on 4 June 2021 (Text with EEA relevance) (2021/914/EU). |
(Information note regarding VITA DOCTORS: The technical operations for automated membership verification with VITA DOCTORS MEDICAL & SKINCARE S.L. are carried out entirely within Spain and the EEA and therefore do not involve any additional international transfer of data).
9. Data Retention Periods
- AXA quotation data: Retained for 120 days from the simulation date (or for 2 years if you authorised AXA to send commercial information).
- Client and policy data: Retained for the duration of the contract and subsequently for the applicable limitation periods for legal actions (5 years under Art. 1964 of the Spanish Civil Code and 6 years under Art. 30 of the Spanish Commercial Code).
- Website enquiry data, Chatbot sessions and history: Retained for a maximum period of 12 months (unless the user manually deletes the chatbot history).
- Data associated with VITA DOCTORS verification: Processed for as long as the insurance business relationship and active membership remain in force. The Active Client: YES parameter will be deactivated when the client ceases to hold an active policy with DYLSI.
10. Security Measures
DYLSI adopts all necessary technical and organisational measures to protect the security and integrity of the personal and non personal information collected, both against unauthorised access and against alteration, loss or accidental destruction. All data transmitted through standard forms and the chatbot available on the website is encrypted using the TLS protocol. However, as absolute IT security does not exist on the Internet, users are advised to exercise appropriate caution.
11. Disclaimer of Liability
To the extent permitted by law, DYLSI accepts no liability for: a) any errors or omissions that may exist in the website’s content; b) the temporary unavailability of the information portal; or c) the transmission of malicious software via the content, despite having taken all reasonable technical measures to prevent this.
12. Exercise of Rights
You may exercise your rights of access, rectification, erasure, restriction of processing, objection and data portability:
- For processing for which DYLSI is responsible (Website, Chatbot, VITA DOCTORS Verification): By sending an email with a copy of your DNI or identity document to darryl@dylsi-seguros.es or by post to Calle Galileo Galilei, 2, Oficina 18, Edificio U. Parc Bit, 07121. Balearic Islands, Spain.
- For processing for which AXA is responsible (Quotations and Policies): Through the specific AXA Spain data protection channels indicated in its corporate policy terms and conditions.
If you believe there is an issue with the way we are handling your data, you may lodge a complaint with the Spanish Data Protection Agency (AEPD) (www.aepd.es).
13. Amendments to the Terms
DYLSI reserves the right to make any changes it considers appropriate to its website without prior notice, including changing, removing or adding content and services. Amendments to the privacy terms will take effect from the time they are published.
14. Contact Details
If you have any questions about these terms of use or the privacy policy, you can contact us at:
- Email: darryl@dylsi-seguros.es
- Postal address: DYLSI Agencia de Seguros, Calle Galileo Galilei, 2, Oficina 18, Edificio U. Parc Bit, 07121. Balearic Islands, Spain.
Last updated: July 2026