MileProtection AG is the data controller for personal data processed through the MileProtection platform. We are domiciled in Zurich, Switzerland.
For any privacy questions: welcome@mileprotection.com. We respond within 30 days.
This policy complies with the EU General Data Protection Regulation (GDPR), UK GDPR (Data Protection Act 2018), and the Swiss Federal Act on Data Protection (nFADP, SR 235.1).
This policy applies to personal data — information that identifies or could identify you as an individual.
It does not apply to aggregated or anonymized data. The MP Index, program-level statistics, and portfolio analytics derived from member data are MileProtection's proprietary intellectual property. Once data is aggregated or anonymized so that no individual can be identified, it falls outside this policy. MileProtection may use, publish, license, or commercialise such data freely.
| Category | What we collect | Legal basis | How long we keep it |
|---|---|---|---|
| Account | Name, email address, country of residence, currency and language preference | Art. 6(1)(b) — contract performance | Membership + 7 years |
| Contract | Enrolled programs, coverage threshold, enrolled amount, enrollment dates, fee | Art. 6(1)(b) — contract performance | Membership + 7 years |
| Identity verification | Government ID, date of birth, proof of address — only where required by our anti-money laundering obligations | Art. 6(1)(c) — legal obligation (Swiss AMLA) | 10 years from end of membership |
| Payment | Last 4 digits of card, card type, billing country. Full card numbers are never stored — our payment processor handles all card data. | Art. 6(1)(b) — contract performance | Membership + 7 years |
| Payouts | Trigger date, index reading, payout amount, bank details for disbursement | Art. 6(1)(b) — contract; Art. 6(1)(c) — AMLA | 10 years from payout date |
| Platform usage | Login timestamps, features accessed, notification preferences | Art. 6(1)(f) — legitimate interests: security, fraud prevention, service improvement | 2 years |
| Marketing | Email address for newsletters — only if you opt in | Art. 6(1)(a) — consent, withdrawable at any time | Until you unsubscribe |
We share personal data only as necessary to operate the platform — with our hosting, payment, and email delivery providers, all of whom process data on our behalf under contractual confidentiality obligations. Where these providers are based outside Switzerland or the EEA, we ensure appropriate transfer safeguards are in place (EU Standard Contractual Clauses or equivalent).
We may also share data with Swiss authorities where required by law, including anti-money laundering reporting obligations. We do not sell your personal data.
Under GDPR Art. 15–22, you have the following rights. Email welcome@mileprotection.com to exercise any of them.
| Right | What it means |
|---|---|
| Access (Art. 15) | Request a copy of all personal data we hold about you |
| Rectification (Art. 16) | Ask us to correct inaccurate or incomplete data |
| Erasure (Art. 17) | Ask us to delete your data. Some data must be retained to meet legal obligations — we will explain what we can and cannot delete. |
| Restriction (Art. 18) | Ask us to pause processing your data while a dispute is resolved |
| Portability (Art. 20) | Receive your data in a structured, machine-readable format |
| Object (Art. 21) | Object to processing based on legitimate interests |
| Withdraw consent | Withdraw marketing consent at any time via the unsubscribe link in any email or by contacting us |
| Complain | Lodge a complaint with your local supervisory authority: Switzerland — FDPIC (edoeb.admin.ch) · EU — your national DPA · UK — ICO (ico.org.uk) |
We use industry-standard encryption to protect your data in transit and at rest. Access to personal data is restricted to personnel who need it to operate the platform.
We may update this policy. Material changes will be notified by email at least 30 days before taking effect. Where we introduce new purposes for processing your personal data, we will seek your consent where GDPR requires it.
For members in the United Kingdom: your data is processed in accordance with UK GDPR. Complaints may be directed to the Information Commissioner's Office at ico.org.uk or 0303 123 1113.