Privacy Policy

Last Updated: 21 July 2026

1. Overview

This Privacy Policy (“Privacy Policy”) sets out our (discoveric marketplace Ag, all its subsidiaries and all the entities under discovermarket brand) basis for the collection, use, disclosure, or processing of any personal data of following parties in accordance with the requirements of applicable privacy laws and other related personal data protection laws regulating the handling of personal data (“Privacy Laws”):

  • Visitors to our website at discovermarket.com and related digital properties
  • Insurance carriers, distributors, fintech companies, and other business partners who use the discovermarket Platform (DCMP)
  • End consumers and insurance policyholders whose insurance products are arranged, distributed, or processed through DCMP
  • Individuals who apply for employment or engage with discovermarket’s recruitment process

“Personal information” means any information that identifies or can reasonably identify you as a specific individual, whether alone or in combination with other data. This includes your name, email address, contact details, financial data, insurance policy information, and technical identifiers associated with your device.

Please read this Policy carefully. By accessing or using our services, website, or platform, you acknowledge that you have read and understood this Policy.

Applicable frameworks: GDPR / EU  ·  PDPA / Singapore  ·  LGPD / Brazil  ·  OJK / BNM / SEA  ·  Global

This Policy is designed to comply with applicable data protection and privacy laws across our operating jurisdictions, including the EU General Data Protection Regulation (GDPR), the UK GDPR, Singapore’s Personal Data Protection Act (PDPA), Brazil’s Lei Geral de Proteção de Dados (LGPD), Indonesia’s OJK regulations, and Malaysia’s PDPA.

2. Who We Are

For the visitors of our website and individuals who apply for employment or engage with discovermarket’s recruitment process, we act as Data Controller. The data controller responsible for your personal information under this Policy is:

discoveric marketplace Ag

Headquarters Switzerland
Group offices Singapore (Asia Hub), Vietnam, Portugal, Brazil
DPO Contact dpo@discovermarket.com

Where discovermarket operates as a data processor on behalf of an insurance carrier, distributor, or fintech partner (our “Partners”), that Partner is the data controller for end-consumer personal information, and discovermarket processes that information only on their instructions. In those cases, the Partner’s own privacy policy will also apply to end consumers. discovermarket requires all Partners to maintain their own lawful basis for data processing under applicable law.

For context on the embedded insurance industry: discovermarket operates the DCMP platform — a MACH-architecture (Microservices, API-first, Cloud-native, Headless) embedded insurance platform enabling Partners to distribute and administer insurance products within their own digital channels. As a regulated technology intermediary in the insurtech space, we are committed to the highest standards of data stewardship.

3. Personal Information We Collect
3.1 Website Visitors

When you visit discovermarket.com or interact with our digital properties, we may collect:

  • Identity & contact data: name, email address, company name, job title (if submitted via contact or demo request forms)
  • Technical data: IP address, browser type and version, operating system, device identifiers, time zone settings
  • Usage data: pages visited, referral URLs, session duration, clicks, scroll depth, and interaction events
  • Cookie & tracking data: persistent and session cookies, pixel tags, and similar technologies (see Section 10)
3.2 DCMP Platform Users & Business Partners

When insurance carriers, distributors, fintechs, or other business entities use the DCMP platform, we may collect:

  • Business contact data: names, email addresses, phone numbers, job titles, and business addresses of authorised users
  • Organisational data: company name, registration number, regulatory licences, and corporate structure information
  • API & integration data: API keys, technical logs, request/response metadata, and system authentication credentials
  • Commercial & contractual data: agreement details, billing information, and transaction records
  • KYC / due diligence data: identity verification documents and regulatory onboarding information for Partner entities and their authorised representatives
  • Platform usage & performance data: feature utilisation, error logs, audit trails, and operational metrics
3.3 Insurance Policyholders & End Consumers

Where discovermarket processes data relating to end consumers whose insurance is arranged through DCMP-powered Partner channels, the categories of personal information may include:

Category Examples Sensitivity
Identity Full name, date of birth, national ID, passport number Standard
Contact Email, phone number, residential address Standard
Financial Payment card details (tokenised), bank account references, premium payment history Sensitive
Health / Medical Medical history, pre-existing conditions (for health or life insurance products) Special Category
Insurance Policy Policy number, coverage type, sum insured, inception/expiry dates, endorsements Standard
Claims Claims ID, incident description, supporting documentation, claims outcome Sensitive
Behavioural / Telematics Device usage data (for device insurance), location data (where applicable) Sensitive

Special Category Data: Where we process health, medical, or other special category data (as defined under GDPR Article 9), we do so only with your explicit consent, where necessary for insurance purposes under applicable insurance regulations, or on another lawful basis as required by law.

3.4 Job Applicants

If you apply for a position at discovermarket, we collect information contained in your CV, cover letter, application form, professional references, and assessments. This data is retained for recruitment purposes and, where you consent, for future suitable vacancies.

3.5 Sources of Personal Information

We collect personal information directly from you, from our Partners (on behalf of their end consumers), from third-party KYC and identity verification providers, from public registers and regulatory databases, and automatically through your use of our website and platform.

4. How We Use Personal Information
4.1 Platform Operations & Service Delivery
  • Configuring, operating, and maintaining the discovermarket Platform (DCMP)
  • Processing insurance applications, policy issuance, renewals, and cancellations on behalf of Partners
  • Facilitating claims intake, assessment, and settlement processing through our Claims AI engine
  • Delivering API-based integrations and ensuring platform uptime and performance
  • Providing technical support and customer success services to Partners
4.2 Regulatory Compliance & Risk Management
  • Conducting Know Your Customer (KYC) and Anti-Money Laundering (AML) checks for Partner onboarding
  • Meeting regulatory reporting obligations under applicable insurance and financial services regulations
  • Maintaining required records for audit, supervisory, and legal purposes
  • Detecting and preventing fraud, money laundering, and other financial crime
  • Managing insurance and operational risk in compliance with our contractual obligations to insurers and reinsurers
4.3 Product Development & AI Improvement
  • Analysing platform usage patterns to improve product features, reliability, and user experience
  • Training and evaluating our AI and machine learning models (using anonymised or aggregated data where possible)
  • Conducting internal research and analytics for insurtech product innovation
4.4 Marketing & Business Development
  • Sending product updates, newsletters, and thought leadership content to business contacts who have opted in or with whom we have an existing business relationship
  • Personalising content on our website and communications
  • Conducting surveys and gathering feedback about our platform and services
4.5 Legal, Safety & Security
  • Enforcing our Terms of Service and contractual agreements with Partners
  • Protecting the security and integrity of our platform and infrastructure
  • Responding to legal process, court orders, or lawful governmental requests
  • Exercising or defending legal claims in any jurisdiction
5. AI based processing and Automated Decision Making
5.1 How We Use AI & Automated Processing

We use artificial intelligence (AI), machine-learning models and other automated tools to process personal information in order to operate and improve our insurance services. This includes, but not limited to, assessing and processing claims, supporting underwriting and pricing decisions, detecting and preventing fraud, generating product recommendations, and powering virtual assistants and customer-support tools.

5.2 Legal Basis for AI Processing

We rely on the following legal bases for AI processing: performance of your insurance contract (to assess and settle claims and to price and issue cover); your consent (for certain solely automated decisions and for optional personalisation); our legitimate interests (fraud prevention, security, analytics and improving our models), balanced against your rights; and compliance with legal and regulatory obligations. Where required, we obtain your explicit consent before using sensitive information or making a solely automated decision that significantly affects you.

6. Legal Basis for Processing

Where GDPR, UK GDPR, or equivalent laws apply, we rely on the following legal bases for processing your personal information:

Legal Basis When We Rely on It
Contract performance Processing necessary to perform our contracts with Partners and, where applicable, with end consumers directly
Legal obligation Complying with insurance regulations, financial crime laws, tax requirements, and regulatory reporting duties
Legitimate interests Platform security, fraud prevention, product improvement, and business-to-business marketing, where not overridden by your interests or rights
Consent Marketing communications to individuals; collection of special category health data where required; use of non-essential cookies
Vital interests Where necessary to protect life in emergency insurance scenarios
Insurance purposes (GDPR Art. 9(2)(a)/(g)) Processing special category data necessary for insurance underwriting, risk assessment, and claims management

Where we rely on legitimate interests, we conduct a balancing test to ensure your rights are not overridden. You may request information about these assessments by contacting our DPO at dpo@discovermarket.com.

Singapore PDPA

Under Singapore’s Personal Data Protection Act 2012, we collect, use, and disclose personal data with your consent, or where we have a legitimate business purpose recognised under PDPA, or where required by law.

Brazil LGPD

Under Brazil’s Lei Geral de Proteção de Dados Pessoais (Law 13,709/2018), we process personal data on the basis of consent, contract performance, legitimate interest, regulatory compliance, or other applicable LGPD legal hypotheses. Brazilian data subjects have all rights set out in Article 18 of the LGPD.

Indonesia & Malaysia

For activities subject to OJK (Indonesia) or BNM (Malaysia) regulation, we process personal data in compliance with applicable financial services and data protection requirements in those jurisdictions, including sector-specific rules applicable to insurance intermediaries and technology providers.

7. How We Share Personal Information
7.1 Insurance Carriers & Underwriters

In order to arrange and administer insurance products, we share relevant personal data (including policyholder identity, risk, and claims information) with licensed insurance carriers, underwriters, and reinsurers. Such sharing is necessary for the performance of insurance contracts and is subject to applicable regulatory requirements.

7.2 Partner Distributors & Platforms

Where a Partner (e.g., a fintech, bank, or e-commerce platform) has embedded insurance via DCMP, we may share relevant policyholder data with that Partner to the extent required to fulfil the insurance product or comply with their regulatory obligations as a distribution intermediary.

7.3 Technology & Service Providers

We engage trusted third-party service providers who process personal information on our behalf, subject to contractual data processing agreements. These include cloud infrastructure providers (Azure, AWS), database services (MongoDB Atlas), analytics platforms, payment processors, KYC/identity verification services, and communications providers. All such providers are required to process personal information only on our instructions and to implement appropriate security measures.

7.4 Regulatory & Law Enforcement Bodies

We may disclose personal information to regulatory authorities (including insurance supervisors, financial intelligence units, and data protection authorities), law enforcement agencies, or courts where required by law, a court order, or regulatory direction, or where we believe in good faith that disclosure is necessary to protect rights, prevent fraud, or comply with applicable legal obligations.

7.5 Business Transactions

In the event of a merger, acquisition, joint venture, corporate restructuring, financing, or sale of all or part of our business, personal information may be shared with the acquiring or merging entity as part of due diligence or post-transaction integration. We will notify you of any material change in data controller or processing purposes arising from such a transaction.

7.6 With Your Consent

We may share your personal information with other third parties where you have given explicit consent to such disclosure.

We do not sell your personal information to third parties for their own commercial marketing purposes. We may use analytics tools for targeted advertising on our own marketing properties, and under certain privacy laws this may constitute “sharing” for advertising purposes. You have the right to opt out of this — please see Section 11.

8. International Data Transfers

discovermarket operates globally, with offices and infrastructure in Singapore, Switzerland, Vietnam, and Portugal. Personal information we collect may be stored and processed in any country where we or our service providers operate, including countries that may not offer the same level of data protection as your home jurisdiction.

Where we transfer personal information from the European Economic Area (EEA), the United Kingdom, or Switzerland to countries without an adequacy decision, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission for controller-to-controller and controller-to-processor transfers
  • UK International Data Transfer Agreements (IDTAs) for transfers from the UK
  • Binding Corporate Rules (BCRs) or other approved transfer mechanisms, as applicable
  • Adequacy decisions, where applicable (e.g., EU-Singapore data flows)

For transfers of Singapore personal data internationally, we ensure adequate levels of protection consistent with the PDPA’s data transfer obligations under the ASEAN Framework on Personal Data Protection.

You may request a copy of the transfer safeguards applicable to your personal information by contacting our DPO at dpo@discovermarket.com.

9. Data Retention

We retain and process your personal data only for as long as is necessary for the purposes for which the information is collected. In addition, we will retain and use your personal data to the extent necessary to comply with our legal obligations and exercise our legal rights (for example, if we are required to retain your data to comply with applicable laws), resolve disputes and enforce our legal agreements and policies.

When we no longer need to use your personal data or retain it pursuant to legal obligations in order to exercise our legal rights, we will remove it from our systems and records or take steps to anonymise it so that you can no longer be identified from it in accordance with relevant Privacy Laws. Anonymised or aggregated data (which can no longer reasonably identify you) may be retained indefinitely for analytics and product development purposes.

10. Cookies & Tracking Technologies

Our website uses cookies and similar tracking technologies (such as pixel tags and local storage) to provide functionality, analyse usage, and support marketing activities. We categorise these as follows:

Cookie Type Purpose Consent Required?
Strictly Necessary Essential to operate the website and platform (e.g., security, authentication, session management) No
Functional Remember your preferences and settings to improve your experience Yes
Analytics Understand how visitors use our website; aggregate usage statistics (e.g., Google Analytics) Yes
Marketing Serve relevant advertising and track campaign performance across channels Yes

You can manage your cookie preferences through our Cookie Consent Manager, which is presented when you first visit our website. You may also control cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our website.

We use Google Analytics and may use other analytics services. You can opt out of Google Analytics by installing the Google Analytics opt-out browser add-on or by adjusting your cookie preferences. Certain U.S. state privacy laws characterise the use of analytics cookies as “sharing” or “selling” personal information for advertising purposes; you have the right to opt out as detailed in Section 11.

Our website may respond to browser-based Global Privacy Control (GPC) signals where technically feasible. We are monitoring the evolving landscape of browser-based privacy signals and will update our practices accordingly.

11. Your Privacy Rights

Depending on your location and the applicable law, you may have some or all of the following rights regarding your personal information:

Access Request a copy of the personal information we hold about you
Rectification Correct inaccurate or incomplete personal information
Erasure Request deletion of your personal information (subject to legal obligations)
Restriction Ask us to limit processing of your data in certain circumstances
Portability Receive your data in a structured, machine-readable format
Object Object to processing based on legitimate interests or for direct marketing
Automated Decisions Request human review of solely automated decisions with significant impact
Withdraw Consent Withdraw consent at any time where processing is consent-based
How to Submit a Request

To exercise any of these rights, please contact our Data Protection Officer at dpo@discovermarket.com with a description of your request. We will respond within the timeframes required by applicable law (typically 30 days under GDPR; 30 days under Singapore PDPA; 15 business days under LGPD).

We may need to verify your identity before processing your request. If you use an authorised agent or representative to submit a request on your behalf, we may require written evidence of their authority.

We will not discriminate against you for exercising your privacy rights. We will not deny you access to our services, charge different prices, or provide a different level of service solely because you exercised a privacy right.

11.1 EU, UK & Swiss Residents (GDPR)

If you are located in the EEA, UK, or Switzerland and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local supervisory authority. In Singapore, unresolved complaints may be directed to the Personal Data Protection Commission (PDPC) at pdpc.gov.sg.

11.2 Brazil Residents (LGPD)

Brazilian residents may exercise all rights under LGPD Article 18 by contacting our DPO. If your request cannot be resolved satisfactorily, you may lodge a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.

11.4 Singapore Residents (PDPA)

Singapore residents may withdraw consent for collection, use, or disclosure of personal data at any time, subject to legal or contractual restrictions. Note that withdrawal of consent may affect our ability to provide certain services to you or your insurance policy.

12. Security

discovermarket implements a comprehensive security programme aligned with industry best practices and applicable information security standards. Our measures include:

  • Encryption: Data is encrypted in transit (TLS 1.2/1.3) and at rest using AES-256 or equivalent standards
  • Access controls: Role-based access control (RBAC), multi-factor authentication, and principle of least privilege for all systems containing personal data
  • Infrastructure security: Cloud-native security controls on Azure and AWS, including network segmentation, intrusion detection, and vulnerability management
  • Monitoring & incident response: 24/7 security monitoring, automated threat detection, and a documented incident response plan with defined notification timelines
  • DevSecOps: Security integrated throughout our software development lifecycle, including regular code reviews, penetration testing, and dependency scanning
  • Vendor security: Due diligence and contractual security requirements for all third-party service providers with access to personal data

Data Breach Notification: In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware (as required by GDPR) and will inform affected individuals without undue delay where required by law. We maintain a breach register and response procedures aligned with PDPA, LGPD, and other applicable breach notification requirements.

No method of electronic transmission or storage is completely secure. While we use commercially reasonable efforts to protect your personal information, we cannot guarantee absolute security. If you have concerns about the security of your data, please contact our DPO immediately at dpo@discovermarket.com.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or regulatory guidance. When we make material changes, we will:

  • Post the updated Policy on our website with a revised “Last Updated” date
  • Notify registered Platform users and business Partners via email or in-platform notification at least 14 days prior to the change taking effect (for material changes)
  • Where required by law, seek renewed consent for material changes to the processing of your personal information

Your continued use of our website or platform after the effective date of any updated Policy constitutes your acceptance of the changes. If you disagree with a material change, please contact our DPO to discuss your options.

We recommend you review this Policy periodically. All previous versions of this Policy are available upon request from dpo@discovermarket.com.

14. Contact Us

For any questions, requests, or concerns about this Privacy Policy or our data practices, please contact our Data Protection Officer:

Data Protection Officer

Email dpo@discovermarket.com
Entity discoveric marketplace Ag and all its subsidiaries
Website discovermarket.com

If you are an insurance policyholder whose data is processed through a Partner’s platform powered by DCMP, please first contact the relevant Partner’s customer service or privacy team. Where the Partner is unable to resolve your concern, you may escalate to our DPO.