Alan - Privacy Policy
A privacy policy is often a big, intimidating block of text that is supposed to reassure you but that you don't read.
We have written ours to be as clear and accessible as possible, so that you understand exactly how your personal data is used by Alan.
Enjoy your reading.

Table of contents
In the course of its activity as a health insurer and as a health management services provider, Alan is required to process sensitive personal data. We attach the utmost importance to the security and confidentiality of the data of Alan's services’ users, whether on the alan.com website or on the mobile application made available to them.
The purpose of this privacy policy is to help you understand how we treat the personal data you provide us with, in accordance with the Personal Information Protection and Electronic Documents Act ("PIPEDA") and, where applicable, provincial privacy laws.
This privacy policy may be updated regularly, to enrich it, according to Alan's needs, circumstances or if required by law. We therefore invite you to check for updates on a regular basis, although we will always notify you of any significant changes affecting the way your data is processed.
Version dated February 18th 2026
Above all, we have set ourselves two key principles which are also included in our contracts:
Furthermore, in accordance with the regulations and particularly the PIPEDA and GDPR, we undertake to collect and process only the data that is strictly necessary for their purpose. Similarly, we undertake to ensure that the data collected is kept in a form that allows your identification for a period that does not exceed the time required for the purposes for which the data is collected and processed.
Alan requires your consent to collect, use, or disclose your personal data, except under the exceptions permitted by law. Please note that your consent may be either expressed (verbal or written) or implied (inferred from your actions).
You have the right to withdraw your consent at any time, subject to our legal, regulatory, or contractual obligations. However, this may limit your access to some of our services and products. To withdraw your consent, please contact our Data Protection Officer (DPO), the contact details are in the section below.
If you have any questions regarding security and personal data, or to exercise your rights of access, correction, deletion, withdrawal of consent, limitation of processing, opposition to processing or portability, you may contact us and our Data Protection Officer (DPO) at [email protected]. Alan will ensure that you receive a response promptly.
For any complaint concerning your personal data, you can either contact our DPO or contact:
For Canadian residents: the Office of the Privacy Commissioner of Canada directly at:
Office of the Privacy Commissioner of Canada
For Ontario residents, you can also contact the Information and Privacy Commissioner of Ontario at:
For Québec residents, you can also contact the Commission d’accès à l’information du Québec at:
This data is used for the electronic signature of the contract, any communication with the company's representatives, and for access to the account used to manage the contract. In the case of delegated contracts, this data is also received from the contract insurer.
The data is kept only for the duration necessary to achieve the purposes. Unless otherwise required by law or regulation, the usual retention periods are as follows:
From the Alan dashboard.
Only if the contract has not been signed. Otherwise we are required to keep the data.
The company contract administrators are led to send us data concerning their employees, including those who have left the company for less than a year ( as part of the portability of health insurance rights):
This is a legal obligation of the employer from which employees cannot escape, even when they do not wish to benefit from health coverage (exemption mechanism).
This data is used:
Contract administrators can do this directly from their Alan dashboard. In some cases, an intervention of our customer service is necessary (for example for certain retroactive modifications).
No, Alan has to keep this data.
Personal data is transmitted to us directly by or on behalf of the insured members with their explicit consent (e.g. to automate the retrieval of receipts from a third party site), in particular :
We also generate individual policy numbers.
We use this data mainly to process requests for reimbursement of expenses according to the guarantees of the contract which covers the insured members and any declared beneficiaries. In particular, this involves receiving and processing the health documents and information provided to justify the care received, determine coverage, generate payments and manage the recovery of undue payments. They are also used for :
The data is kept only for the duration necessary to achieve the purposes. Unless otherwise required by law or regulation, the usual retention periods are as follow:
No, because we are obliged to keep this data. However, you have the possibility to ask us not to use them for purposes other than the performance of your insurance contract and compliance with our legal and regulatory obligations, by sending an email to [email protected].
When the possibility is offered to him/her and an insured member declares a dependent (spouse or child) to his/her contract, he/she vouches that the beneficiary agrees to become a party to its insurance contract (or gives consent as a parent of a minor). Alan treats the personal data of the dependent in the same way as those of any other user insured member in this capacity.
Our insured members and their dependents share a single Alan account. By default, both the insured members and the dependents (if they are of legal age and choose to access Alan's online insurance or management services themselves) will be able to view all account information related to the insurance services, without separation. Members with an Alan account can also choose to restrict visibility of their care acts to other members covered under the same policy.
How can I have access to this privacy setting?
Through the "Privacy and security" section on your member profile.
We use personal data you provide us with in the context of our health insurance (including your health data) in order to detect and fight insurance fraud. We may also use the following connexion data to identify fraudulent behavior:
We use this data for the prevention of fraud, in particular to detext suspicious patterns or activities and to manage alerts and procedures following a case of fraud.
The data is kept only for the duration necessary to achieve the purposes. Unless otherwise required by law or regulation, the usual retention periods are as follows:
Data you provide us in the context of your health insurance serves multiple purposes. If there is a specific reason you would like to oppose Alan processing your personal data for the purpose of fraud fighting, you can send an email to [email protected], we will consider your request and balance your rights with Alan’s legitimate interest.
This data is used to authenticate members in order to provide them with travel assistance abroad.
The data is kept only for the duration necessary to achieve the purposes. Unless otherwise required by law or regulation, we keep this data 5 years after the end of the contract.
No, Alan must keep it for 5 years after the end of the coverage.
In order to answer questions or resolve problems raised by our members, admins or prospects when they contact Alan we collect the following information:
We may thus collect the following personal data:
We use your data to analyze and answer your questions, provide guidance, manage complaints and disputes, and improve our services and products. In order to do so we:
In addition, your data will also be anonymized to enable research and statistical learning.
The data is kept only for the duration necessary to achieve the purposes. Unless otherwise required by law or regulation, the usual retention periods are as follows:
We are obliged to keep the data relating to your insurance contract and demonstrating legal compliance. However, you can request the deletion of other data collected by emailing [email protected].
When you book or attend a session, we collect information needed to schedule, deliver, and administer the service, such as:
In some cases, we may also collect intake information you provide (for example, questionnaire responses) to support your care.
We do not record your calls. However, during your care, the practitioner may create clinical notes (for example, session notes or care summaries).
Depending on how the practitioner works, notes may be:
Where clinical notes and intake forms are stored in Alan’s platform:
For orientation call, if the member accepts, orientation psychologist will share the reason for consultation and situation with the psychologist booked. This information is deleted once shared.
Note that the Alan attributed e-mail address of the Practitioner is solely for communicating on administrative matters with you and/or your employer. This emailing address shall not contain any health related information.
To facilitate scheduling and coordination, we also process the practitioner’s identifying and professional data, as well as their calendar availability.
We use this information to:
For no longer than necessary for the purposes described above, including to meet applicable legal and professional record‑keeping requirements.
Yes, you can send a request to [email protected]. However, we may not be able to delete data that must be kept to comply with legal or professional record‑keeping requirements.
When you exchange messages with Alan health team members for a question relating to your health (excluding video consultation), we use the following data:
To delivered more personalized and contextualized care to members, health team members will also have access to:
Your messages and clinical information are accessible only to health professional of the Clinic involved in providing care, and to a limited set of authorized personnel as needed to operate and secure the Clinic (for example, to maintain the platform). We use role‑based access controls and other safeguards to protect confidentiality. Your health information is not used for insurance purposes.
We use this information to:
Alan respects medical secrecy: the content of your exchanges within the Alan Clinic is accessible only to members of the Alan medical team, they many not be consulted or used by anyone else at Alan.
In addition, when you have had an inspiring health experience with the Alan Clinic, we may contact you to create a fully anonymized educational health story for the benefit of as many people as possible. These health stories will only be created with your prior and specific consent, and in a non-identifying manner.
We retain messages and related records for as long as necessary to provide the service and to meet applicable legal and professional record‑keeping requirements.
You can request the erasure of messages from your interface, simply send a request to [email protected]. However, we we may need to keep a secure archived copy where required for legal, regulatory, or professional obligations.
We use the NPS to monitor our performance with our members, through the Metabase tool. In concrete terms, this allows us to identify factors of dissatisfaction that may allow us to improve our services or, conversely, things that need to be reinforced because they are highly appreciated.
We keep them for the time needed to carry out analyses and measure their evolution over several development cycles. We then anonymise or delete them.
Yes, simply send a request to [email protected].
Certain data is collected automatically when you visit alan.com (including other websites published by Alan such as blog.alan.com and map.alan.com) and when you use our mobile app. The data collected includes :
This data is used for the following purposes:
The data is kept only for the duration necessary to achieve the purposes. Unless otherwise required by law or regulation, the usual retention periods are as follows:
Absolutely (with the exception of data collected in the framework of a legal obligation or strictly required to provide our services), simply make a request to [email protected].
To build our audience and client basis, Alan may reach out to prospects by emails and organize online advertising campaigns before sending them mails or emails. In this context, Alan handles email addresses available online (such as on Linkedin) but also from providers already used by Alan (Societeinfo.com, Kaspr) for audience-building purposes on social networks.
We are reaching prospects via online ads before sending mails or emails. To do so, we import prospects database into the audience of different platforms. The email addresses is the only data import on the ads platform. We import only prospect data and we do not bring in any customer data or leads who have unsubscribed from any previous campagin. To do so, we ensure and remove our customers data in our ads audience before any data import. In addition, users can opt-out and unsubscride from seeing Alan’s ads directly on the ads platform.
When reaching out by email, Alan provides easy-way to opt-out notably through unsubscription links in each communication and honor prospects opt-out in the future.
We keep this data for 2 years, in line with CNIL’s recommendation.
A purge of the database to remove any inaccurate is carried out on a monthly basis.
Yes, you can opt-out from marketing communications at any time. You can exercise any of your rights simply in making a request to [email protected].
Data collected by Alan in the performance of our services, may be further used in a way compatible with the original purpose for which it was collected. Only aggregated and/or anonymized data may become subject to scientific research and/or for statistical studies, including for statistical learning. It could for instance be used in the selection and creation of relevant health stories to improve our services and Members' health, create aggregated usage reports or to streamline and improve the management of exchanges with Alan medical team.
Data security is an extremely important issue for Alan: we do our utmost to be worthy of the trust you place in us. Here are a few examples of the measures we have taken. If you have any questions on a specific point, we will be happy to answer them at [email protected].
Alan achieved ISO27001:2022 certification with SGS (certification body), validating our information security management system and our data protection measures. This certification covers all of Alan’s activities.
We use Datadog App Security to detect and block in real time attacks such as XSS, SQL injection, account theft, etc.
We also use Cloudflare to protect us from Distributed Denial of Service (DDoS) attacks.
All HTTP traffic to and from alan.com and api.alan.com is encrypted (HTTPS / TLS). You can evaluate our configuration here.
The first time a user logs on, we tell their browser (via the HSTS mechanism) that all subsequent connections must be encrypted (HTTPS), including when a link to alan.com starts with http:// instead of https://.
When using the Alan Clinic services, your questions to our medical team, answers and attached documents are secured by an additional layer of application encryption entirely and exclusively under the control of our medical team. No one other than the Alan medical team is technically able to consult these exchanges.
For data hosting and processing, Alan uses AWS, which is HDS-certified. Our entire infrastructure is located in the Frankfurt region, in Germany. In order to fulfill all the purposes for which we collect your data, we may transfer some of your data to third parties, who host it in data centers located within and outside the European Union. When data is hosted outside the European Union, we make sure that hosting is subject to European data protection standards (for example, by including standard contractual clauses in our contracts with such third parties). You can find more information on data privacy with AWS security here, and our blog post on the subject here.
We use PostgreSQL databases. The data is encrypted using the AES-256 standard and the encryption keys are managed by AWS.
The backup archives are also encrypted.
We use the open-source zxcvbn-ts library to let users know the strength of the password they choose. The minimum size is 16 characters, including alphanumerical characters and symbols, and the minimum score is 4.
We do not store these passwords: we only store a non-reversible hash calculated by the open-source bcrypt library, with the following parameters :
All Alan employees receive mandatory training in security (including social engineering) and data privacy. They use complex and unique passwords and strong authentication (2FA) whenever possible. The use of a password manager such as 1Password is also mandatory.
Our computers are automatically updated and have their hard disk encrypted (in case of theft). Our screens lock automatically.
Access to our internal administration tools requires individual access from an authorised IP address and all data modifications (by an Alan employee or by a user himself) are audited.
We organise intrusion tests by independent companies.
All Alan services and applications are developed in-house. Our code is validated by automated tools (static analysis, security, etc.) and manually by a second pair of eyes.
In order to protect your data on your computer or mobile phone, you can take a few simple measures:
You can also consult the official recommendations on good IT security practices.
The data collected may be communicated as required to Alan's partners, reinsurers, subcontractors, legal and financial advisors, and service providers. These data transfers are carried out solely within the framework of the operations mentioned above and to the extent necessary for the performance of the tasks we entrust to third parties. These third parties are fully informed by Alan of the confidentiality of the data communicated to them in this context, and these partners have an obligation to ensure the protection of this data. They are also bound by their own confidentiality and privacy policies, which can be consulted on their websites. When the nature of the operation carried out allows it, the data is subject to prior anonymisation before being communicated to third parties.
The main persons and tools that receive the data in the context of our processing operations include:
Amazon Web Services (hosting and storage) Stripe.com (payment) Revolut.com (refunds) Intercom.com (online chat and customer service) Google Vision (document recognition) Sendgrid.com (emails) Sentry (error management) Linear (ticket management) Customer.Io (emails) Hubspot (CRM) Outreach (CRM) Salesforce (CRM) Snowflake Datadog Scale Studio (document annotation) Microsoft Azure (Azure OpenAI for document parsing) Xodus (travel insurance partner) OmbudService for Life & Health Insurance or the Financial Services Regulatory Authority of Ontario (external review of complaints) Telus (claims processing) Northbridge (travel insurance) Programmed Insurance Brokers (life & disability insurance) RWAM Insurance Inc. (life & disability insurance)
Audience and usage measurement data
Segment.com (audience analysis) Amplitude.com (audience analysis) Google Ads (targeted advertising) Google Optimize (AB testing) Google Speech-To-Text (voice recognition) Google Calendar (calendar) Meta Pixel (audience analysis and targeted advertising) X Ads (targeted advertising) LinkedIn Insights (targeted advertising) Customer.io (e-mails) Bing (audience analysis and targeted advertising) Datadog App Security (security) Cloudflare.com (network, security and audience analysis) Hubspot (Audience analysis and CRM) Piwik (audience analysis) Hotjar (user survey and navigation analysis) Calendly (scheduling tool for meetings)
Furthermore, in order to meet legal and regulatory obligations, we may be required to communicate personal information to administrative or judicial authorities at their request. In this case, we ensure that only the data strictly required by the authorities is transmitted.
In order to fulfill all the purposes for which we collect your data, we may transfer some of your data to third parties, who host them in data centers located in:
In this case, we ensure that the hosting is subject to applicable data protection standards:
To obtain more information about our data transfer practices, please contact our data protection officer at [email protected].
In addition to being a delicious biscuit, a cookie is a file on your device that contains data. We obtain your consent before using cookies where it is required. You can delete or limit the storage of these files at any time in the settings of your internet browser (see below).
Third-party cookies used only on our public website based on user choice:
Third-party cookies used on our public website and dashboard (member and administrator) based on user choice:

You can find more information about the data collected by Alan via these third-party cookies through this link.
Of course you can! During your first visit (or if you use your browser's private or incognito browsing), a banner (called a cookie banner) will be displayed asking you for permission to use cookies. Simply refuse and no cookies (other than those we need to operate the site and allow you to use our online chat) will be set. If you accept, your consent will be valid for 13 months from the date of registration.
Simply put, no.
You will receive emails from us, but in the vast majority of cases it will be in the context of the execution of our contract, for example to invite you to register, to ask you for additional information to enable a refund or to inform you of contractual modifications or changes related to your account. There is no escaping this, but it is for your own good.
A small minority of emails are not directly related to our contract with you or your employer, but are still for a legitimate interest (e.g. to offer to sponsor a relative with a financial reward, to send you a quote, or to announce new services similar to those you currently enjoy).
If you are an administrator, you may also receive commercial offers from us. In these cases, you always have the possibility of unsubscribing from this type of message by following the link in each of our emails (opt-out).
You can also choose to subscribe to our newsletter or to our waiting lists to be notified of the availability of our new services (opt-in).
As for push notifications, we will ask for your permission directly in the mobile application and you will be able to deactivate or reactivate them from your phone.
Table of contents
Get started with Alan now


Preview