Privacy
Achmea Bank respects your privacy. This means that we comply with privacy legislation and make every effort to protect your personal data. We believe it’s important for you to know how we use your personal data and what your rights are, so that you can be confident that your data is in good hands with us. This Privacy Statement provides information on how we handle your personal data.
The privacy statement applies to all personal data processed by Achmea Bank N.V. and its subsidiary Syntrus Achmea Hypotheekdiensten B.V. (hereinafter collectively referred to as: Achmea Bank). Syntrus Achmea Hypotheekdiensten B.V. provides services relating to mortgages. The privacy statement for the savings, investments and mortgages brands mentioned below provides more specific information regarding the processing of your personal data.
Achmea Bank has its registered office in The Hague (under Chamber of Commerce number 27154399). It holds a banking licence from De Nederlandsche Bank (DNB) and is listed in the register of the Dutch Authority for the Financial Markets under number 12000011. The following brands are part of Achmea Bank:
- Achmea Bank (savings products offered through Raisin)
- Centraal Beheer (savings products, PSD2 and investment services)
- Centraal Beheer (mortgages with lenders Achmea Bank N.V. and Achmea Hypotheken B.V.)
- Acier Financieringen (mortgages with lender Achmea Bank N.V.)
- Attens Hypotheken (mortgages with lender Attens Hypotheken B.V.)
- Other brands that have been outsourced to Syntrus Achmea Hypotheekdiensten B.V. (Tellius Hypotheken and Syntrus Achmea Hypotheken).
In this Privacy Statement, all brands and entities listed above, including Syntrus Achmea Hypotheekdiensten B.V., are collectively referred to as "Achmea Bank".
Achmea Bank is a subsidiary of Achmea B.V. Achmea Bank N.V. and Achmea B.V. are jointly responsible for processing your personal data correctly.
If you request a quotation, take out a savings or mortgage product, visit our website, subscribe to a newsletter, are already an existing or former customer, advisor, guardian, executor, (legal) representative or have been in contact with us by other means, then we require your personal data. We may also use personal data that we have previously received from you. This data often reveals something about you or can be linked to you as an individual in various ways. Usually, you provide us with your data yourself, for example when taking out a product and subscribing to a newsletter.
We usually ask for your name, address, e-mail address, telephone number and date of birth, but sometimes we also ask for additional information depending on the product you choose. Examples include your financial data and information about the collateral when you are taking out a mortgage, or your bank account number for the automatic deduction of the monthly mortgage payments.
We may also request data in order to verify your identity. This often occurs via iDIN or personal identification on-site by AMP.
We may sometimes receive your data by different means. For instance, if you have an independent consultant, they will provide us with your data. We can also request your data from external public and semi-public sources or registers, for example from the Credit Registration Office (BKR).
We may process the following categories of personal data relating to you.
|
Personal data category |
Example |
|
Account data |
Username and user ID |
|
Audiovisual data |
Camera and video recordings, recorded chat and telephone conversations |
|
Professional information |
Occupation, position, employer, company location |
|
Contact data |
Address, e-mail address, phone number |
|
Due Diligence data |
PEP, Sanctions list, IVR and EVR assessments |
|
Financial data |
Bank account number (IBAN), transactions, income, balance data, assets, loan information, payment arrears, debts/arrears, credit score |
|
Data concerning devices, operating systems, online behavior and preferences |
IP address, MAC address, operating system, device type, version and/or brand, and cookie settings |
|
Personal identification data |
Name, address, place of residence, postcode, date of birth, place of birth, citizen service number (BSN)/tax identification number (TIN), customer number and nationality |
|
Legal status |
Relationship status, marital status and family composition |
|
Collateral data |
Address of the collateral property, purchase and contract sum, market value, property's energy label |
|
Education data |
Education completed and level of education achieved |
|
Sensitive personal data |
Special personal data |
|
Criminal record data |
Criminal convictions and offences |
If you visit the website of one of our brands, such as centraalbeheer.nl, syntrusachmeahypotheken.nl, or acierfinancieringen.nl, you will find a cookie statement on that website explaining the use of cookies placed on the website or in the app.
Similarly, if you have a product with us, you may receive e-mail messages. Our brands can also register your click behaviour in our e-mails. Specifically, we register whether you open an e-mail and click the links and articles. This enables us to make our e-mail messages more relevant to you. If you do not want us to do this, you can usually disable this registration activity through the online customer portal. You can also click the unsubscribe link in the newsletter if you wish.
We only process your data when we have a legal basis for doing so. We process your personal data on the basis of the following:
- entering into and performing a contract. For example, if you wish to open a savings account, take out a mortgage or when you already have a mortgage with us. We also use your personal data to continue providing these products and services during their term and to contact you when necessary.
- complying with a statutory obligation. Examples include performing our statutory duty of care (Financial Supervision Act, Wft), verifying your identity, preventing fraud, preventing tax evasion, preventing money laundering and terrorist financing (Money Laundering and Terrorist Financing (Prevention) Act, Wwft), or sharing your data with the (Dutch) Tax Administration or other regulatory authorities.
- if you have given explicit consent (you can withdraw consent at any time). An example is consent for forwarding your data to an external party or obtain it on your behalf through a service provider from government organisations, such as MijnOverheid and the Employee Insurance Agency (UWV).
- safeguarding our legitimate interests or those of a third party. This only applies when we determine after consideration that processing is necessary, there is no less intrusive way to achieve the objective, and our interests or those of a third party outweigh your privacy interest. Examples include cases such as the IBAN Name Check, conducting a test with the Credit Registration Office (BKR) during a mortgage application, developing and using credit risk models and risk analyses , identifying potential mortgage credit risks at an early stage, recording telephone calls for quality improvement purposes and to document what has been discussed, training employees and documenting interactions, helping to keep the financial sector secure through the use of internal and external registers, complying with our legal obligations relating to customer due diligence and integrity management, for which the KYC Centre may, where necessary, share data between Achmea entities with which you have a product, carrying out our administration efficiently (for example by maintaining a central overview of customer data), using a service provider that facilitates technical communication between advisers and lenders, providing you with relevant tips and offers or processing your personal data where a regulatory authority requires us to undertake the processing but this has not yet been enshrined in law.
We process certain personal data because we are required by law to do so, for example pursuant to the Money Laundering and Terrorist Financing (Prevention) Act (Wwft). In addition, we require data to enter into and perform an agreement with you; without the data, we will be unable to do these things.
We sometimes use data for a purpose other than the one for which we receive it. This is only permissible if there is a close correlation between both objectives.
We always process your data with a purpose, and only if your data is necessary to achieve that purpose. For instance, we may use your data to:
- enable you to perform an online calculation on our website. This data will then be used solely for that calculation, unless you decide to take out the product.
- maintain contact with you so we can answer your questions.
- keep records on how and when we contacted you.
- to assess whether the desired product is suitable. This may also be a credit score if that is necessary.
- offer you a suitable product (including, but not limited to relationship management, promotion and marketing). We may also use customer profiles.
- enter into and perform an agreement with you.
- identify your products at Achmea, as well as assess your needs, satisfaction and preferences.
- better align our products with your needs.
- develop and/or improve products.
- manage, administer, develop and test IT systems.
- monitor your visit to the website and app, where applicable and to secure.
- enable you to make use of your personal environment (such as Centraal Beheer and Acier Financieringen).
- provide you with account information services and payment initiation services (PSD2).
- perform financial and balance transactions.
- assess/estimate our financial and other risks in order to protect our financial position, including through our Advanced Internal Ratings-Based (AIRB) risk model for determining financial reserves and stress testing.
- enhance your financial resilience and avoid payment arrears, for example by using models to identify potential payment issues at an early stage.
- protect your interests and ours from fraud and other types of crime.
- ensure the security of our customers, ourselves and the financial sector by reducing risks and detecting and preventing fraud. For this purpose, we conduct a customer survey prior to and during the customer relationship, and we monitor your transactions using data that you have provided, or by consulting data held by external sources. We may use analyses, risk parameters, risk profiles or other indicators for this purpose. We can also make use of our incident management system and the internal reference register, as well as the incident registration system and the external reference register (EVR) in the context of the Financial Institutions Incident Warning System (PIFI) protocol. You can find more information later on in this statement under ‘incident management/incident registration system/IVR/EVR’.
- fulfil our gatekeeper function and to combat money laundering and the financing of terrorism.
- map the sustainability and climate risks of the properties we have financed for internal purposes and regulators/regulatory reports, or to offer assistance to customers or to make offers with respect to improving the sustainability of financed collateral properties.
- be able to handle complaints and disputes.
- settle a product after the death of a customer.
- enter into and perform contracts and agreements with suppliers and other parties with whom we collaborate.
- provide to the government or regulatory authorities, if we are required to do so.
- support our internal management and control processes and make adjustments where necessary.
- be able to conduct audits, accountancy controls and investigations, or have them conducted.
- conduct material, formal checks and horizontal monitoring.
- conduct market, scientific or historical research, research for statistical purposes, and archiving.
- implement and improve business processes and their quality control.
- prepare management reports.
- for the development and validation of risk and other models.
- be able to train, coach, develop and assess our employees.
- determine our general strategy and policy.
- for benchmarking purposes (for example, making a comparison with other organisations).
- process your job application.
- for the electronic signing of documents.
- facilitate the transfer of receivables, mergers, acquisitions, and the sale or transfer of businesses or parts of businesses.
- comply with the legislation and regulations.
If you request another product from us, then we can also take into account information about other products you have with us when assessing your application.
We will record the agreements with you and use our contact with you to improve our communication. The following are some examples of contact with you that we document:
- letters and e-mail messages that we send to and receive from you.
- telephone calls, e-mail messages, and chat messages.
- what you view and do on our websites and apps, depending on your cookie and tracking pixel preferences.
- the occasions you log into the online customer portal or use the mortgage check module.
- during an investigation (including a personal investigation), if there is good reason to do so, we may also use data obtained from camera footage, information we find about you on the internet, and telephone conversations or chat/video chat conversations with our colleagues.
- the contact we have with you through social media, such as WhatsApp.
Because many social media providers are located outside the European Economic Area (EEA), personal data may not be adequately protected. We therefore recommend that you always read the privacy policies of those social media channels carefully before using them, so that you know what happens to your data.
Achmea Bank has no influence over the manner in which these social media providers secure and use your personal data and is therefore not responsible for the content that social media providers post or how they handle personal data.
Usually, you provide us with your data yourself, but sometimes we receive your data by different means. In addition, we sometimes share your data or verify it with other companies, depending on the product you choose. We do not sell your personal data.
We may received and/or exchange data with the following:
- other Achmea entities, components and brands, such as Centraal Beheer and the Achmea KYC Centre, for example:
- systems in which relevant customer information from different products is made centrally available where this is necessary for operational purposes.
- carrying out customer due diligence in accordance with the Wet ter voorkoming van witwassen en financieren van terrorisme (Wwft), the Wet op het financieel toezicht (Wft), and the Sanctiewet (Sw).
- other financial institutions, in relation to:
- processing domestic and international payment transactions.
- a financial/balance transaction or in the context of combating fraud, terrorism, or money laundering.
- individual savings and investment transactions of customers.
- our suppliers and business partners, such as:
- Quion and Stater for processing mortgage administration.
- Topicus for processing savings and investment administration.
- Equens the European Payments Initiative (EPI), including Wero (formerly iDEAL), and SWIFT for the settlement of online payment transactions.
- iDIN for identification and verification of new and existing customers and the use of Secure Login (2FA) on the online customer portal.
- AMP Group for identification and verification of new and existing customers on-site (in person).
- Ockto(ID) or I-Wise for providing us with information or documents for the purpose of a mortgage application (including identification).
- SurePay for verification of account/contra account holder names (IBAN Name Check).
- I-Tek for security matters and preventive and special management.
- Calcasa for the valuation of collateral.
- DM Interface – Impress B.V., Koninklijke Kampert and Helm Rotaform B.V. and PostNL for the printing and mailing of postal items.
- Raisin, if you have taken out a product with us through the Raisin platform.
- investors in our mortgage portfolios (such as pension funds).
- cloud providers and IT service providers.
- public and/or external registers, such as:
- the Credit Registration Office (BKR, Stichting Bureau Krediet Registratie) for matters such as access to or registration (if applicable) in your BKR/credit registrations (Central Credit Information System), the BKR score, and the joint fraud prevention system known as the external reference register (EVR, Externe Verwijzingsregister) for identifying and reporting fraudsters with other Dutch financial institutions. This is done through the databases of the Foundation for the Combating of Mortgage Fraud (SFH, Stichting Fraudebestrijding Hypotheken) and the External Referral Register (EVR).
- Foundation for the Combating of Mortgage Fraud (SFH, Stichting Fraudebestrijding Hypotheken).
- Verification Identification System via the Dutch Credit Registration Office (BKR) for checking the validity of an identity document.
- The banking information reference portal, for the automated provision of data requested by investigative authorities or the Tax Administration (Verwijzingsportaal Bankgegevens).
- Valuation of Immovable Property Act (WOZ) register (Ministry of Finance).
- The Land Registry, for consulting collateral data (Kadaster).
- the Dutch Banking Association sector organisation (NVB, Nederlandse Vereniging van Banken) and the Dutch Association of Insurers (VvV, Verbond van Verzekeraars).
- Chamber of Commerce (KVK, Kamer van Koophandel) for the general KVK register (Commercial Register) and UBO register.
- the Central Register of Wills (Centraal Testamentenregister) for checks relating to registered wills.
- PostNL's Verhuisdatabase to identify your new address if postal mail is returned as undeliverable.
- Professional parties, such as:
- intermediaries, (mortgage) consultants and intermediaries, service providers, appraisers, brokers, legal service providers, administrators, bailiffs, collection agencies, credit intermediaries, notaries and/or trustees.
- Tax Administration (Belastingdienst).
- In certain cases, we are required to share your data with a foreign tax administration. We are obliged to do this under the International Assistance (Levying of Taxes) Act (WIBB) or the Foreign Account Tax Compliance Act (FATCA). In this event, your account details will be sent to the Dutch tax administration, which will then forward them to the relevant foreign tax administration. For more information, visit the WIB or FATCA sites.
- investigative authorities, such as the police, the Public Prosecution Service, Financial Intelligence Unit Nederland (FIU) and intelligence services.
- regulatory authorities for example, to verify that we comply with applicable laws and regulations, such as:
- the Dutch Authority for the Financial Markets (AFM, Autoriteit Financiële Markten).
- De Nederlandsche Bank (DNB).
- the European Central Bank (ECB).
- the Netherlands Authority for Consumers and Markets (ACM, Autoriteit Consument en Markt).
- the Dutch Data Protection Authority (AP, Autoriteit Persoonsgegevens).
- complaint bodies, such as the Financial Services Complaints Tribunal (Kifid), Banking Disciplinary Board (Stichting Tuchtrecht Banken) and judicial authorities or lawyers in the context of a dispute.
- our internal and external accountant(s) and auditors.
- Homeownership Guarantee Fund (WEW, Stichting Waarborgfonds Eigen Woningen), for mortgages with a National Mortgage Guarantee (NHG) in connection with the National Mortgage Guarantee scheme. We may also share data to assess the affordability of your mortgage following a major life event. This may also apply to mortgages without an NHG guarantee.
- Statistics Netherlands (CBS, Centraal Bureau voor de Statistiek) for statistical analyses and activities.
- Foundation Central Information System (CIS, Stichting Centraal Informatiesysteem) for PEP and sanctions list checks.
- public sources, such as public registers, newspapers, the internet, and public social media.
For example, to prevent fraud, protect the bank, and comply with applicable laws and regulations. - municipalities, in connection with payment arrears (Early Warning Pilot). We are participating in a national pilot in which lenders and municipalities collaborate to identify mortgage payment arrears at an early stage. The aim is to prevent arrears from developing into problematic debts, and to provide timely support. We can provide limited information to your municipality. This data does not concern other financial products or your complete financial situation. You will be informed in advance about this provision of data, and may object to it at that time if you wish.
- members of the Association for Debt Counselling and Social Banking (NVVK) in the context of debt assistance regarding residual debt on mortgages.
- companies, for the purpose of benchmarking
- heirs and executors who succeed you in your rights and obligations in the event of your death.
- other parties to whom you have granted consent, such as service providers from Centraal Beheer Climate Store (Klimaatwinkel).
When you transfer money from an Achmea Bank product to a payment or other account at another financial institution, this financial institution will also receive your data.
These databases are subject to strict security measures. We therefore only conduct business with reliable service providers, we encrypt our data wherever possible, and in principle, we only store your data in databases within the European Economic Area (EEA) or share this data only with parties within the EEA. Since the EEA and the Netherlands are subject to the same privacy regulations, we can ensure that your privacy is protected effectively.
In exceptional situations, it may be necessary for your data to be stored or shared outside the EEA. In this event, we will do so very carefully. We and our processor(s) make an assessment in advance and ensure that appropriate agreements are made in order to protect your privacy. We can also perform a Data Transfer Impact Assessment. Examples of such agreements include the adoption of a model agreement approved by the European Commission (Standard Contractual Clauses) and the EU-US Data Privacy Framework.
For this purpose, we consistently implement appropriate technical and organisational security measures to prevent the loss or unlawful processing of your data. This enables us to monitor the security of our data traffic 24 hours a day. We also have an information security policy, and we take your privacy and the security of your data into account when developing new products and processes. One example is that your data is only accessible to those employees who need to work with it. Our employees have also received clear instructions on how to handle your data, and they are all subject to a duty of confidentiality.
If you happen to discover a vulnerability in our internet services, then you can report it through Achmea's Responsible Disclosure page. We would appreciate it if you would inform us of this so that we can take appropriate measures and work together to improve the security of our data and systems.
Sensitive personal data includes the following:
- Your citizen service number (BSN)
- When you become our customer, we are required by law to verify your identity. We therefore sometimes ask you for a copy of your identification, upon which your BSN also appears.
- We are also required by law to provide information annually about your financial product (for example, your savings account) to the Tax Administration. In order to do so, we need to use your BSN (Articles 47b and 53 of the State Taxes Act (AWR). The Tax Administration uses your BSN as a unique identification number in order to effectively and accurately utilise information during the implementation and monitoring process.
- For those Achmea Bank products coming under the Dutch deposit guarantee, we are obliged to communicate your BSN to De Nederlandsche Bank (Article 3:17 Financial Supervision Act (Wft).
- If you have a Dutch IBAN account with us, we are required to share your data in certain situations in the context of the banking information reference portal. We may make use of your BSN for this purpose (Article 3:267i Financial Supervision Act (Wft).
- Your banking information (including debts and payment arrears)
- Your creditworthiness check
- We are also required to check your creditworthiness when you apply for a loan.
- Criminal law data
- When assessing the risk relating to a financial product, we may inquire whether you have a criminal record.
- We may also process your criminal records in the context of fraud prevention, integrity investigations, sanctions legislation, customer due diligence (KYC), or the Financial Institutions Incident Warning System Protocol (PIFI).
- Your health data
- In general, we do not process health data. We process your health data only when it is necessary to do so, and with your consent.
In principle, we do not process special categories of personal data. If processing such data is necessary, we will only do so where there is a valid legal basis for doing so.
In specific situations, we may retain personal and other data for longer periods than the retention period we have established. An example is if the regulator requests this from us in the context of risk models or the development and review thereof, risk management, a complaint you have submitted that necessitates the retention of the underlying data for a longer period, or for legal proceedings. We may also retain it for historical or scientific research or statistical purposes.
If personal data is retained for a longer period, we take measures to ensure that the data is only used for the purposes for which a longer retention period is necessary.
In certain cases, we use automated decision-making. These are decisions about you that are made without human involvement and are based entirely on automated processing. We may also create a profile of you based on the data we have about you (profiling). You can read more about this below.
What if you take out a savings product or investment service directly online (through one of our brands)?
In this case, we will automatically process your personal data in order to evaluate certain personal aspects. We use this information to automatically assess whether or not you meet our acceptance criteria, which may directly result in automated rejection. We also obtain data from external sources or registers. We will then examine matters such as whether the information you provided about yourself is accurate and whether you are not registered externally (for example in sanctions lists). We also check for fraud indicators and make a risk assessment based on your data and other public sources and registers. This risk assessment can have repercussions for acceptance. In this regard, we can make use of profiling, which involves analysing some of your personal aspects such as your preferences, behaviour or financial situation. After you have applied for a product, the acceptance may take place automatically without human intervention. Before we decide not to offer you a product, at least one employee will conduct a substantive assessment, after which the employee will make the actual decision.
What happens if you submit a mortgage application through your consultant?
In this event, we are required to make an accurate and up-to-date assessment of your credit risk; in other words, we have to assess whether a mortgage is suitable for you and whether you will be capable of consistently repaying a mortgage in the long term. We do this based on data we have received from you and from external public sources and registers (such as the Credit Registration Office, BKR). Based on this information, we will endeavour to make a risk assessment in order to determine whether we can offer you a mortgage. This also involves the use of risk and other models, which automatically assess a risk and assign you a credit score. We may make use of profiling for this purpose. The credit score is merely an indication for us. The final assessment or the decision is always made by at least one authorised employee, so that there is always human intervention involved that ensures a wise, fair and unbiased decision. In this process, only profiling is involved - we do not use automated decision-making for this. If the assessment appears to reveal that you are at a higher risk, we may decide not to grant you a mortgage.
Are you a customer with us?
If so, then we are required to take measures to prevent fraud, money laundering, and the financing of terrorism (just as we do if you apply for a product). We are also required by law to know our customers well and regularly check that the information is still current. We want to be certain about who our customers are and prevent our products from being misused for fraud, money laundering or other illegal activities. For example, we monitor payment transactions and repayments in an automated manner. To ensure effectiveness, we also create risk profiles (profiling) relating to our customers, which we maintain periodically. If there is suspicion of an unusual transaction or if there is a possibility that your information is no longer up to date, our employees may contact you. In the event of a suspicion of fraud, we must report this immediately to the authorities. We also check periodically whether you are on a sanctions list. No automated decisions are ever made about you in this regard.
We also utilise profiling to tailor our marketing communications to suit your personal preferences, behaviour and interactions on our website. We process things such as your personal data, click behaviour and stated interests for this purpose. We do this on the basis of legitimate interest in order to provide you with more relevant offers and to improve our services. You can always unsubscribe from a marketing message.
If you have a mortgage with us, our risk and other models can automatically assess the risk relating to your loan and the likelihood of you experiencing a payment default. We may make use of profiling for this purpose. The reason for this is to identify and mitigate any risks for you and us as early as possible. To minimise this risk as effectively as possible, a staff member from Preventive and Special Management may assess the situation and contact you.
Provision of information in automated decision-making
We always inform you prior to an automated decision being made. If you disagree with an automated decision, you may always inquire about it or submit an objection or to request human intervention if you believe that an automated decision affects you. You may also inquire about the reasons and ask us to make a new decision. For security reasons, we may not be able to provide all or any further details regarding the manner in which we conduct the aforementioned investigations.
If an incident meets the conditions specified in the Financial Institutions Incident Warning System Protocol (PIFI), Achmea Bank records the relevant personal data in an incident registration system (IR), and if necessary, a limited amount of personal data in the external reference register (EVR). Other Dutch financial institutions may also access the EVR under very strict conditions as outlined in the PIFI protocol.
By placing your data in these registers, we and sometimes other Achmea entities or other Dutch financial institutions may use it for matters such as verifying whether you have ever committed fraud or attempted to do so.
You will receive a message if your data is included in one of the registers. In most cases, this occurs before your data is entered into the registers, unless disclosure would compromise the investigation. In that event, after the conclusion of the investigation, you will receive notification that we will proceed with registering you in the IVR, IR or EVR. If your data has been registered by us and you disagree with this registration, you may request a review and ask us to reassess the decision.
Achmea Bank has received a permit from the Dutch Data Protection Authority for the processing of criminal personal data in the context of the PIFI protocol.
Decisions regarding the acceptance of mortgage, savings or investment products are not made solely by AI and always involve human review and decision-making.
When we process your personal data, our intention is to do so transparently. To this end, you may make use of your legal rights, which are as follows:
- the right to request your personal data from us or view it.
- This enables you to check your personal data.
- the right to correct your personal data if it is inaccurate.
- You can ask us to amend or supplement your personal data when it is incorrect or incomplete.
- the right to have your personal data deleted.
- Bear in mind we may often be unable to delete your personal data, either because we still require it, or because we are required to retain it in compliance with a law.
- the right to object to certain use of your personal data.
- For example, you may no longer wish to receive e-mails from us with offers. You can use the unsubscribe link in our e-mails to unsubscribe, or you can call us.
- You may also prefer that we do not share your personal data with SurePay for the purpose of the IBAN Name Check. Please note that we do this so that you can check whether you have entered the correct account number when transferring to your savings account.
- Whatever the situation, you should always clearly indicate the reasons for your objection so that we can assess it properly.
- the right to withdraw your consent.
- If you gave us consent to use your personal data? You may withdraw your consent at a later date. We will no longer use your personal data from that moment on for the purpose for which you provided your consent.
- the right to have your personal data transferred.
- If you have provided us with personal, you can ask us to transfer your personal data to another organisation or to you.
- the right to have the use to stop your personal data temporarily.
- An example is if you have objected to the use of your personal data. We will always assess this on its merits.
We may not always be able to comply with your request, or we may require more information to fulfil your request. In either case, we will contact you.
We will respond within one month of receiving your e-mail or letter. In some cases, we may ask you to provide further details for your request or we may extend our response time to a maximum of three months.
You can view or change many of your details through the personal online customer environment you have with the brand concerned.
If you choose to send an e-mail, please do so by means of a secure method.
You can also send a letter to:
Achmea B.V.
Attn. AVG-Loket
Postbus 9150
7300 HZ Apeldoorn
You can also send a letter to:
Achmea B.V.
Attn. Privacy Manager
Postbus 866
3700 AW Zeist
These include:
- The General Data Protection Regulation (GDPR).
- The General Data Protection Regulation (Implementation) Act (GDPR Implementation Act).
- The Telecommunications Act (Tw).
- The Financial Institutions Incident Warning System Protocol.
- The Code of Conduct for Personal Investigations.
This latest version is dated 29 September 2026. You will always find the latest version on our website. We recommend that you regularly review this privacy statement when visiting our website.