Privacy Policy
Privacy Policy
Client Privacy Policy
Client Privacy Policy
1. AOP's Commitment
For AOP – Corretor de Seguros, Lda, hereinafter referred to as AOP, the privacy and protection of the personal data of its clients and other parties involved is very important. AOP is committed to complying with all applicable legislation on privacy and personal data protection, GDPR – EU Regulation 2016/679 of 27 April 2016. Through this privacy policy, AOP intends to make public the protection mechanisms and data processing practices it undertakes to apply in relation to natural persons acting as applicants, policyholders, insured parties, insured persons, beneficiaries or in any other capacity.
2. AOP's Responsibility in Processing Personal Data
The controller responsible for processing personal data is AOP, which provides you with the service and offers products and, in that context, decides which data is collected, the means of processing and the purposes for which the data is used, in the cases identified in point 4 below.
In certain cases, AOP will act as a processor, processing your data on behalf of another entity acting as the controller. This will occur in particular with insurance companies, when AOP provides them with services relating to the management and performance of an insurance contract to which the data subject is a party (for example, for claims management purposes). In such cases, we recommend consulting the privacy policy and/or other information on the processing of your data provided by the controllers.
3. Key Concepts
3.1. What is personal data?
Personal data is any information, of whatever nature and in whatever form, relating to an identified natural person. A person may be identified, directly or indirectly, by an identifier such as name, legal number, location, genetic or mental data.
3.2. Who are the data subjects whose data is processed by AOP?
Data subjects are the natural persons to whom the personal data relates.
For example, as a controller, AOP may process personal data of its clients (natural persons) who take out AOP's services and products, its former clients and its prospective clients. As a processor, AOP may process personal data of policyholders, beneficiaries or insured persons under a given insurance contract, or of persons named as witnesses in the event of claims.
3.3. What types of personal data are processed?
1 – Identification data of the policyholder, insured persons, injured parties and beneficiaries, as necessary (for example: name, address, place of birth, nationality, dual nationality, citizen card, gender, date of birth, telephone contact, email, tax identification number, marital status, occupation);
2 – Life insurance claims records (for example: death registration, death certificate, deed of heirs, medical report, funeral home receipt, accident report, autopsy report and results of blood-alcohol and toxicology tests, payment order to be completed by the beneficiary, IBAN proof);
3 – Health insurance claims records (for example: the insured's health history, medical reports, documents supporting the resolution of a claim);
4 – Workplace accident insurance claims records (for example: policy activation date and description of the claim, salary, premiums, extras, bonuses, meal allowance, data supporting the resolution of the claim);
5 – Personal accident insurance claims records (for example: description of the claim, medical information, documentation supporting the claim, legal beneficiaries);
6 – Motor insurance claims records (for example: motor claim report data (DAA), identification of injured third parties, identification of witnesses);
7 – Claims records in other lines (for example: claim report data);
8 – Identification data of the insured object (for example: type of vehicle, type of aircraft, type of vessel, registration number, make, model, year of manufacture, chassis number, registration date, engine capacity, number of seats/power output, policy number, identification of other insured objects such as jewellery, works of art, home, home contents or animals);
9 – Payment data (for example: NIB/IBAN, bank, SWIFT, signature, account holder's name, address, policy number);
10 – Health data and lifestyle habits;
11 – Call recording data.
4. Processing of Personal Data
AOP, as controller of personal data, processes such data in the following situations:
1 – To enter into a contract or to carry out pre-contractual steps at your request.
As part of its service and product provision activity, AOP may need to process your personal data, namely:
For the recording and evidencing of commercial transactions and pre-contractual information, which includes (for example):
responses to requests for information made by clients or prospective clients;
simulation requests for the submission of insurance proposals;
For the monitoring of contract management and performance, which includes (for example):
submission of insurance proposals in line with the client's interests;
2 – Compliance with legal obligations
In carrying out its activity, AOP is subject to legal and regulatory obligations, compliance with which may require the processing of personal data for these purposes, such as:
Tax obligations – withholding, payment or declaration;
Legal obligations – requests from public authorities;
Prevention of and combat against money laundering and terrorist financing.
3 – Promoting AOP's activity
With the aim of better serving its clients, AOP may use your personal data to improve and develop its activity and to defend its legal rights and interests, such as:
Maintaining and improving service quality;
Marketing and communication;
Complaints management and monitoring of legal proceedings.
4 – Commercial communication and promotion.
5. Processing Data as a Processor
When AOP acts on behalf of other entities, namely insurance companies, the processing of personal data will be determined by them, as the data controllers. AOP's obligation in these cases is to process the personal data in accordance with the controllers' instructions.
6. Processing Regime
The personal data collected by AOP is subject to lawful and transparent processing, in accordance with the applicable legislation.
Data may be processed by automated means.
Data processing is limited to what is strictly necessary and in line with the purpose that justified its collection.
In order for AOP to fulfil all its duties and provide you with the best possible service, it may need to communicate or grant access to your personal data to other entities. AOP will only communicate or grant access to your personal data to the following entities:
Service providers (for example, contracted services for data centre management);
The insurance and/or reinsurance companies with which the insurance or reinsurance contracts have been entered into;
Public authorities, such as the Tax Authorities or the Courts.
AOP will only communicate the personal data that is indispensable to the provision of the contracted services or to compliance with the legal obligations to which it is subject.
7. Purpose, Type and Retention Period of Data
AOP will only process your personal data for the purposes set out below and only for the period of time necessary to fulfil those purposes:
Recording and evidencing commercial transactions and pre-contractual information;
Monitoring contract management and performance;
Commercial prospecting;
Marketing and communication;
Complaints management and monitoring of legal proceedings;
Improving service quality;
Compliance with legal obligations.
You can consult the details of the type of data and retention periods here.
8. Data Subjects' Rights
In relation to the personal data collected and processed under this privacy policy, AOP provides data subjects with all the rights provided for, namely those set out in the GDPR:
8.1. Right to information and access
Whenever they request it, the data subject has the right to obtain and be informed, in a concise, clear and transparent manner, of the purposes of the processing, the recipients to whom the data will be disclosed, the data retention periods, the source (where it was not obtained directly) and other information provided for by law and by the GDPR.
8.2. Right to rectification
Whenever they find or consider that their personal data is incorrect or incomplete, the data subject may request its rectification or completion.
8.3. Right to erasure
Provided that the purpose which justified the collection of the personal data has been fulfilled or is no longer necessary, you may request the erasure of your personal data.
In such cases, AOP will erase your data, save for the exceptions provided for by law that prevent erasure:
exercise of the right to freedom of expression and information;
compliance with a legal obligation that requires processing and applies to AOP;
reasons of public interest in the area of public health;
archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, insofar as the exercise of the right to erasure is likely to seriously impair the achievement of the objectives of that processing; or
the establishment, exercise or defence of a right in legal proceedings.
8.4. Right to restriction of processing
In certain situations, you may request the restriction of access to personal data or the suspension of processing activities. For example, in cases where you contest the accuracy of your personal data, or in cases where you have objected to the processing, until it is verified whether AOP's legitimate interests override yours.
8.5. Right to data portability
In the cases provided for by law, you have the right to receive the personal data concerning you that you have provided to AOP in a structured, commonly used and machine-readable format.
You also have the right to request that AOP transmit that data to another controller, provided this is technically feasible.
8.6. Right to object
The data subject has the right to object to the processing of their personal data at any time, on grounds relating to their particular situation, where that processing is based on AOP's legitimate interest or where it is carried out for purposes other than those for which the data was collected but which are compatible with them.
In such cases, AOP will cease to process your personal data, unless there are legitimate grounds for that processing which override your interests.
You may also object, without the need for justification, to the processing of your data for direct marketing purposes.
8.7. Right to withdraw consent
In cases where data processing is based on your consent, you may withdraw your consent at any time.
Should you decide to withdraw your consent, your personal data will no longer be processed, except as provided for by law or on another basis, such as a contract or legitimate interest.
8.8. Right to lodge complaints with the supervisory authority
You have the right to lodge complaints with the competent supervisory authority regarding matters relating to the processing of your personal data.
In Portugal, the competent supervisory authority is the Comissão Nacional de Proteção de Dados (National Data Protection Commission).
For more information, go to www.cnpd.pt.
9. How Can You Exercise Your Rights?
Through the following channels:
Email: you may exercise your rights by email, to the address [rgpd@aopseguros.pt].
Post: you may exercise your rights by letter addressed to AOP and sent to the address Rua Santa Maria 1740, 4535-400 Santa Maria de Lamas.
Exercising your rights is free of charge.
10. Indirect Collection of Your Personal Data
It is possible that AOP has collected your personal data through third parties or by other means, even if you are not an AOP client.
This will happen, for example, in cases where your contact details are provided by a family member or a third-party entity when you are the beneficiary of a given insurance policy.
At the first opportunity, AOP may provide you with this policy in person or refer you to the website, where this policy should be available.
11. Security, Technical and Organisational Measures
In order to guarantee the protection of the personal data made available to it, AOP has adopted various security, technical and organisational measures to protect personal data against unauthorised access, destruction, loss, manipulation, disclosure or any other form of unlawful processing.
In cases where AOP subcontracts the provision of services involving the transfer of personal data to other entities, those entities will be required to adopt the necessary technical and organisational measures to protect the personal data against destruction, loss, alteration, disclosure, unauthorised access or any other type of unlawful processing.
12. Responsibility for Services and Websites
We advise you to consult the rules on the use of cookies set out on AOP's website. You may also consult AOP's Cookie Policy here.
1. AOP's Commitment
For AOP – Corretor de Seguros, Lda, hereinafter referred to as AOP, the privacy and protection of the personal data of its clients and other parties involved is very important. AOP is committed to complying with all applicable legislation on privacy and personal data protection, GDPR – EU Regulation 2016/679 of 27 April 2016. Through this privacy policy, AOP intends to make public the protection mechanisms and data processing practices it undertakes to apply in relation to natural persons acting as applicants, policyholders, insured parties, insured persons, beneficiaries or in any other capacity.
2. AOP's Responsibility in Processing Personal Data
The controller responsible for processing personal data is AOP, which provides you with the service and offers products and, in that context, decides which data is collected, the means of processing and the purposes for which the data is used, in the cases identified in point 4 below.
In certain cases, AOP will act as a processor, processing your data on behalf of another entity acting as the controller. This will occur in particular with insurance companies, when AOP provides them with services relating to the management and performance of an insurance contract to which the data subject is a party (for example, for claims management purposes). In such cases, we recommend consulting the privacy policy and/or other information on the processing of your data provided by the controllers.
3. Key Concepts
3.1. What is personal data?
Personal data is any information, of whatever nature and in whatever form, relating to an identified natural person. A person may be identified, directly or indirectly, by an identifier such as name, legal number, location, genetic or mental data.
3.2. Who are the data subjects whose data is processed by AOP?
Data subjects are the natural persons to whom the personal data relates.
For example, as a controller, AOP may process personal data of its clients (natural persons) who take out AOP's services and products, its former clients and its prospective clients. As a processor, AOP may process personal data of policyholders, beneficiaries or insured persons under a given insurance contract, or of persons named as witnesses in the event of claims.
3.3. What types of personal data are processed?
1 – Identification data of the policyholder, insured persons, injured parties and beneficiaries, as necessary (for example: name, address, place of birth, nationality, dual nationality, citizen card, gender, date of birth, telephone contact, email, tax identification number, marital status, occupation);
2 – Life insurance claims records (for example: death registration, death certificate, deed of heirs, medical report, funeral home receipt, accident report, autopsy report and results of blood-alcohol and toxicology tests, payment order to be completed by the beneficiary, IBAN proof);
3 – Health insurance claims records (for example: the insured's health history, medical reports, documents supporting the resolution of a claim);
4 – Workplace accident insurance claims records (for example: policy activation date and description of the claim, salary, premiums, extras, bonuses, meal allowance, data supporting the resolution of the claim);
5 – Personal accident insurance claims records (for example: description of the claim, medical information, documentation supporting the claim, legal beneficiaries);
6 – Motor insurance claims records (for example: motor claim report data (DAA), identification of injured third parties, identification of witnesses);
7 – Claims records in other lines (for example: claim report data);
8 – Identification data of the insured object (for example: type of vehicle, type of aircraft, type of vessel, registration number, make, model, year of manufacture, chassis number, registration date, engine capacity, number of seats/power output, policy number, identification of other insured objects such as jewellery, works of art, home, home contents or animals);
9 – Payment data (for example: NIB/IBAN, bank, SWIFT, signature, account holder's name, address, policy number);
10 – Health data and lifestyle habits;
11 – Call recording data.
4. Processing of Personal Data
AOP, as controller of personal data, processes such data in the following situations:
1 – To enter into a contract or to carry out pre-contractual steps at your request.
As part of its service and product provision activity, AOP may need to process your personal data, namely:
For the recording and evidencing of commercial transactions and pre-contractual information, which includes (for example):
responses to requests for information made by clients or prospective clients;
simulation requests for the submission of insurance proposals;
For the monitoring of contract management and performance, which includes (for example):
submission of insurance proposals in line with the client's interests;
2 – Compliance with legal obligations
In carrying out its activity, AOP is subject to legal and regulatory obligations, compliance with which may require the processing of personal data for these purposes, such as:
Tax obligations – withholding, payment or declaration;
Legal obligations – requests from public authorities;
Prevention of and combat against money laundering and terrorist financing.
3 – Promoting AOP's activity
With the aim of better serving its clients, AOP may use your personal data to improve and develop its activity and to defend its legal rights and interests, such as:
Maintaining and improving service quality;
Marketing and communication;
Complaints management and monitoring of legal proceedings.
4 – Commercial communication and promotion.
5. Processing Data as a Processor
When AOP acts on behalf of other entities, namely insurance companies, the processing of personal data will be determined by them, as the data controllers. AOP's obligation in these cases is to process the personal data in accordance with the controllers' instructions.
6. Processing Regime
The personal data collected by AOP is subject to lawful and transparent processing, in accordance with the applicable legislation.
Data may be processed by automated means.
Data processing is limited to what is strictly necessary and in line with the purpose that justified its collection.
In order for AOP to fulfil all its duties and provide you with the best possible service, it may need to communicate or grant access to your personal data to other entities. AOP will only communicate or grant access to your personal data to the following entities:
Service providers (for example, contracted services for data centre management);
The insurance and/or reinsurance companies with which the insurance or reinsurance contracts have been entered into;
Public authorities, such as the Tax Authorities or the Courts.
AOP will only communicate the personal data that is indispensable to the provision of the contracted services or to compliance with the legal obligations to which it is subject.
7. Purpose, Type and Retention Period of Data
AOP will only process your personal data for the purposes set out below and only for the period of time necessary to fulfil those purposes:
Recording and evidencing commercial transactions and pre-contractual information;
Monitoring contract management and performance;
Commercial prospecting;
Marketing and communication;
Complaints management and monitoring of legal proceedings;
Improving service quality;
Compliance with legal obligations.
You can consult the details of the type of data and retention periods here.
8. Data Subjects' Rights
In relation to the personal data collected and processed under this privacy policy, AOP provides data subjects with all the rights provided for, namely those set out in the GDPR:
8.1. Right to information and access
Whenever they request it, the data subject has the right to obtain and be informed, in a concise, clear and transparent manner, of the purposes of the processing, the recipients to whom the data will be disclosed, the data retention periods, the source (where it was not obtained directly) and other information provided for by law and by the GDPR.
8.2. Right to rectification
Whenever they find or consider that their personal data is incorrect or incomplete, the data subject may request its rectification or completion.
8.3. Right to erasure
Provided that the purpose which justified the collection of the personal data has been fulfilled or is no longer necessary, you may request the erasure of your personal data.
In such cases, AOP will erase your data, save for the exceptions provided for by law that prevent erasure:
exercise of the right to freedom of expression and information;
compliance with a legal obligation that requires processing and applies to AOP;
reasons of public interest in the area of public health;
archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, insofar as the exercise of the right to erasure is likely to seriously impair the achievement of the objectives of that processing; or
the establishment, exercise or defence of a right in legal proceedings.
8.4. Right to restriction of processing
In certain situations, you may request the restriction of access to personal data or the suspension of processing activities. For example, in cases where you contest the accuracy of your personal data, or in cases where you have objected to the processing, until it is verified whether AOP's legitimate interests override yours.
8.5. Right to data portability
In the cases provided for by law, you have the right to receive the personal data concerning you that you have provided to AOP in a structured, commonly used and machine-readable format.
You also have the right to request that AOP transmit that data to another controller, provided this is technically feasible.
8.6. Right to object
The data subject has the right to object to the processing of their personal data at any time, on grounds relating to their particular situation, where that processing is based on AOP's legitimate interest or where it is carried out for purposes other than those for which the data was collected but which are compatible with them.
In such cases, AOP will cease to process your personal data, unless there are legitimate grounds for that processing which override your interests.
You may also object, without the need for justification, to the processing of your data for direct marketing purposes.
8.7. Right to withdraw consent
In cases where data processing is based on your consent, you may withdraw your consent at any time.
Should you decide to withdraw your consent, your personal data will no longer be processed, except as provided for by law or on another basis, such as a contract or legitimate interest.
8.8. Right to lodge complaints with the supervisory authority
You have the right to lodge complaints with the competent supervisory authority regarding matters relating to the processing of your personal data.
In Portugal, the competent supervisory authority is the Comissão Nacional de Proteção de Dados (National Data Protection Commission).
For more information, go to www.cnpd.pt.
9. How Can You Exercise Your Rights?
Through the following channels:
Email: you may exercise your rights by email, to the address [rgpd@aopseguros.pt].
Post: you may exercise your rights by letter addressed to AOP and sent to the address Rua Santa Maria 1740, 4535-400 Santa Maria de Lamas.
Exercising your rights is free of charge.
10. Indirect Collection of Your Personal Data
It is possible that AOP has collected your personal data through third parties or by other means, even if you are not an AOP client.
This will happen, for example, in cases where your contact details are provided by a family member or a third-party entity when you are the beneficiary of a given insurance policy.
At the first opportunity, AOP may provide you with this policy in person or refer you to the website, where this policy should be available.
11. Security, Technical and Organisational Measures
In order to guarantee the protection of the personal data made available to it, AOP has adopted various security, technical and organisational measures to protect personal data against unauthorised access, destruction, loss, manipulation, disclosure or any other form of unlawful processing.
In cases where AOP subcontracts the provision of services involving the transfer of personal data to other entities, those entities will be required to adopt the necessary technical and organisational measures to protect the personal data against destruction, loss, alteration, disclosure, unauthorised access or any other type of unlawful processing.
12. Responsibility for Services and Websites
We advise you to consult the rules on the use of cookies set out on AOP's website. You may also consult AOP's Cookie Policy here.
Insurance Broker registered on 27-01-2007 with the ASF – Autoridade de Supervisão de Seguros e Fundos de Pensões, under the category of Insurance Broker, registration no. 607145230, authorised for Life and Non-Life branches, verifiable at www.asf.com.pt © 2026 Aop
Insurance Broker registered on 27-01-2007 with the ASF – Autoridade de Supervisão de Seguros e Fundos de Pensões, under the category of Insurance Broker, registration no. 607145230, authorised for Life and Non-Life branches, verifiable at www.asf.com.pt © 2026 Aop
Insurance Broker registered on 27-01-2007 with the ASF – Autoridade de Supervisão de Seguros e Fundos de Pensões, under the category of Insurance Broker, registration no. 607145230, authorised for Life and Non-Life branches, verifiable at www.asf.com.pt © 2026 Aop
Insurance Broker registered on 27-01-2007 with the ASF – Autoridade de Supervisão de Seguros e Fundos de Pensões, under the category of Insurance Broker, registration no. 607145230, authorised for Life and Non-Life branches, verifiable at www.asf.com.pt © 2026 Aop
Insurance Broker registered on 27-01-2007 with the ASF – Autoridade de Supervisão de Seguros e Fundos de Pensões, under the category of Insurance Broker, registration no. 607145230, authorised for Life and Non-Life branches, verifiable at www.asf.com.pt © 2026 Aop
