Alan - Privacy Policy
A privacy policy is often a big, intimidating block of text that is supposed to reassure you but you don't read.
We have written ours to be as clear and accessible as possible, so that you understand exactly how your personal data is used by Alan.
Enjoy your reading.

Resumen
In the course of its activity as an health insurer and as a health partner services provider, Alan is required to process your personal data, including sensitive data. We attach the utmost importance to the security and confidentiality of the data of Alan's services’ users, whether on the alan.com website or on the mobile application made available to them.
The purpose of this privacy policy is to be transparent and help you understand how we treat the personal data you provide us with, in accordance with the GDPR.
This privacy policy may be updated regularly, to enrich it, according to Alan's needs, circumstances or if required by law. We therefore invite you to check for updates on a regular basis, although we will always notify you of any significant changes affecting the way your data is processed.
Version dated February 18th, 2026
Above all, we have set ourselves two key principles which are also included in our contracts:
Furthermore, in accordance with the regulations and particularly the GDPR, we undertake to collect and process only the data that is strictly necessary for their purpose. Similarly, we ensure that the data collected is stored in a way that allows your identification for a period of time that does not exceed the time required for the purposes for which the data is collected and processed.
Alan, including all of its affiliates (Alan Insurance, Alan Services, Alan Tech, Alan CA, Marmot BE and Marmot Iberia) is a health insurer and does not mainly act as a data processor for our clients but as a data controller in the sense of article 4 of the GDPR on all operations relating to its insurance and health services described in this policy :
However, Alan can also process personal data on behalf of its client companies, within the scope of certain services provided on the Alan platform, in particular administrative management assistance services for human resources. Alan acts as a "data processor" of the company, and the processing of personal data is done under the responsibility of the company, which then acts as the data controller. The General Conditions governing the relationship between Alan and the client companies include a data processing agreement (DPA) reflecting this distribution. You can take a look at the privacy policies of the client companies directly for more details on how they process your personal data.
If you have any questions regarding security and personal data, or to exercise your rights of access, correction, deletion, withdrawal of consent, limitation of processing, opposition to processing or portability, you may contact us and our Data Protection Officer (DPO) at [email protected]. Alan will ensure that you receive a response promptly.
For any complaint concerning your personal data, you can either contact our DPO or contact the Commission Nationale Informatique et Liberté (CNIL) directly at https://www.cnil.fr.
Insurance services
Care and support
Health services
Alan features
Statistic and performance
Pre-contractual measures and performance of the insurance contract as well as, in the absence of a signature, Alan's legitimate interest in following his prospects.
This data is used for the electronic signature of the contract, any communication with the company's representatives, and for access to the account used to manage the contract.
From the Alan dashboard.
Only if the contract has not been signed. Otherwise we are required to keep the data.
The company contract administrators are led to send us data concerning their employees:
Alan processes this data on the basis of pre-contractual measures and the execution of the insurance contract between Alan and its members.
This data is used in order to invite (by email) employees to register on alan.com or on our mobile application.
Contract administrators can do this directly from their Alan dashboard. In some cases, an intervention of our customer service is necessary (for example for certain retroactive modifications).
No, Alan has to keep it for 5 years after the end of the cover.
Pre-contractual measures and execution of the contract binding them to Alan, as well as, in the absence of a signature, Alan's legitimate interest in following his prospects.
This data is used for the electronic signature of the contract, any communication with the contract holder, and for access to the account allowing to manage the contract.
From the Alan Dashboard.
Only if the contract has not been signed. Otherwise we are obliged to keep the data.
Personal data is transmitted to us directly by or on behalf of the insured members with their explicit consent (e.g. to automate the retrieval of receipts from a third party site), in particular :
We also generate individual policy numbers.
This data is required for the execution of the contract concluded with Alan, either by your employer or by you as an insured member. They are therefore not subject to prior consent. We also have a legal obligation to ask you for this information in order to comply with the regulations that apply to our insurance activities and to our health and management service providers activities.
In addition, we use it for some of the secondary purposes listed below on the basis of our legitimate interest in managing our insurance activities.
We use this data mainly to process health services requests according to the guarantees of the contract which covers the insured members and any declared beneficiaries. In particular, this involves receiving and processing the health documents and information provided to justify the care received, determine coverage, generate payments and manage the recovery of undue payments. We share this information as required with our network partner (currently DKV).
They are also used for:
No, because we are obliged to keep this data. However, you have the possibility to ask us not to use them for purposes based on our legitimate interest, by sending an email to [email protected].
When the possibility is offered to him/her and an insured member declares a dependent (spouse or child) to his/her contract, he/she vouches that the beneficiary agrees to become a party to its insurance contract (or gives consent as a parent of a minor). Alan treats the personal data of the dependents in the same way as those of any other user insured member in this capacity.
Our insured members and their dependents share a single Alan account. Both the insured members and the dependents (if they are of legal age and choose to access Alan's online insurance or management services themselves) will be able to view all account information related to the insurance services, without separation. Information about health services (such as private chat as part of Alan Clinic) is not shared.
On the basis of pre-contractual measures or the execution of the healthy benefits contract between Alan and its members. We also have a legal obligation to ask you for this information in order to comply with the regulations that apply to payment services.
We use this data mainly to enroll member in our heatlhy benefits program. In particular, your data is collected to provide access to our payment card and services, to process payments and reimbursments, send our members the physical cards and manage benefits contracts with companies and members.
We share this information as required with our payment service provider partner (currently Adyen).
They are also used for:
No, because we are obliged to keep this data. However, you have the possibility to ask us not to use them for purposes based on our legitimate interest, by sending an email to [email protected].
On the basis of our legitimate interest in preventing and fighting against fraud.
We use this data for the prevention of fraud, in particular to detext suspicious patterns or activities and to manage alerts and procedures following a case of fraud.
Data you provide us in the context of your health insurance serves multiple purposes. If there is a specific reason you would like to oppose Alan processing your personal data for the purpose of fraud fighting, you can send an email to [email protected], we will consider your request and balance your rights with Alan’s legitimate interest.
To provide travel assistance and allow you to be covered in case of problems while traveling abroad, we transmit the following information to our partner EuropAssistance :
On the basis of the contract between us and the insured (you ask us to provide a service, which we pay for) as well as on the basis of our legitimate interest in measuring the use of this service
This data is used to authenticate members to provide them with travel assistance abroad.
2 years.
Absolutely, just send a request to [email protected]m. However, in that case, you will not be able to use this service anymore.
On the basis of the contract between us and the insured (you ask us to provide a service, which we pay for) as well as on the basis of our legitimate interest in measuring the use of this service
This data is used to authenticate members to provide them with access to a dental network.
2 years.
Absolutely, just send a request to [email protected]. However, in that case, you will not be able to use this service anymore.
In order to answer questions or resolve problems raised by our members, admins or prospects when they contact Alan we collect the following information:
We may thus collect the following personal data:
We use it on the basis of the performance of the contract entered into with Alan, either by your employer or by you as an insured member, or pre-contractual steps to enter it. We also have a legal obligation to store this information in order to comply with the regulations that apply to our insurance and health and management service providers activities.
In addition, we use it on the basis of our legitimate interest in assessing and improving the quality of our customer and support services.
We use your data to analyze and answer your questions, provide guidance, manage complaints and disputes, and improve our services and products. In order to do so we:
In addition, your data will also be anonymized to enable research and statistical learning.
We are obliged to keep the data relating to your insurance contract and demonstrating legal compliance. However, you can request the deletion of data collected for our legitimate interest by emailing [email protected].
In the context of a consultation with a therapist, we collect information such as:
For sessions with our psychologists we also collect information regarding your time zone, the name of the consulted expert, your country location and your language preferences. We never collect your communication with the Practitioner. We have implemented safeguards, such as end-to-end encryption to fully secure your communication and ensure your privacy is respected.
For orientation call, if the member accepts, orientation psychologist will share the reason for consultation and situation with the psychologist booked. This information is deleted once shared.
We also offer the possibility to members to fill out a survey about their mental health. Your responses to this questionnaire are only accessible to the therapist that will attend the orientation call, and are deleted after this session.
Alan may keep a fully anonymized version of responses (with no identifying information) for research and service improvement.
Note that the Alan attributed e-mail address of the Practitioner is solely for communicating on administrative matters with you and/or your employer. This emailing address shall not contain any health related information.
We collect the full name, photo, specialty details of the health expert as well as access to their Google calendar, in order to facilitate communication with you.
On the basis of the contract we have with you (you ask us to provide a service, which we pay for) as well as on the basis of our legitimate interest in measuring the use of these services or for as long as the health expert is employed with Alan.
This data is used to enable the processing of reimbursements related to the consultations as well as improving the service. It is also used to schedule and enable sessions with our therapists, as well as improving the service.
For as long as you benefit from Alan services and meet legal retention requirements for health professionals for mental health sessions.
Absolutely, on the part based on legitimate interest. You just have to send a request to [email protected].
On the basis of the contract between us and the insured (you ask us to provide a service, which we pay for) as well as on the basis of our legitimate interest in measuring the use of this service
This data is used to authenticate members to allow them to use the Meetingdoctors app.
2 years.
Absolutely, just send a request to [email protected]. However, in that case, you will not be able to use this service anymore.
When you exchange messages with Alan health team members for a question relating to your health (excluding video consultation), we use the following data:
To delivered more personalized and contextualized care to members, health team members will also have access to:
Health team members will not have your full name or access to your history as an insured member without your consent.
Your consent is collected before the access to the service from the Alan mobile app.
Alan respects medical secrecy: the content of your exchanges within the Alan Clinic is accessible only to members of the Alan medical team, they many not be consulted or used by anyone else at Alan.
The Alan medical team is composed of the health professionals and employees of Alan strictly necessary for the proper running of the Clinic, in accordance with the recommendations of the French Medical Council (and other applicable codes of ethics). Alan medical team’s access is specific, dedicated and segregated from the usual access of Alan's employees to our tools.
Medical conversations and documents are encrypted under the sole control of health professionals, who are the only ones with access to the content of encrypted information. This enables us to guarantee that medical confidentiality is respected where applicable, and that Alan will never re-use this information for its health insurance services.
In addition, when you have had an inspiring health experience with the Alan Clinic, we may contact you to create a fully anonymized educational health story for the benefit of as many people as possible. These health stories will only be created with your prior and specific consent, and in a non-identifying manner.
During the duration of the limitation period for medical responsibility of health professionals.
You can request the erasure of messages from your interface, simply send a request to [email protected]. This will erase the messages for your messaging space. However, we will keep a secure archive of them on our side, in accordance with the recommendations of the French Medical Council (Conseil de l'Ordre des Médecins).
We ask for your consent to process your health data to book your appointment.
This data used for the following purposes:
Appointment data is deleted as soon as the reminder is sent to the member.
Yes, you can simply make a request to [email protected].
Workshops are interactive training sessions on a specific mental health topic, involving one of our psychologists and administrators and/or managers. Alan collects information gathered during a pre-workshop briefing held between the psychologist and administrator. Alan later sends invites to administrators and/or managers. After the workshop, Alan sends feedback forms as well as related follow-up content to the participants.
Participants may consent to participating in the workshop or be obliged to participate in the context of mandatory workshops organized by their employer.
This allows us to tailor the workshops as much as possible to the company’s needs and to send feedback forms to the participants.
For as long as you benefit from Alan services.
Yes, you just have to send a request to [email protected]
The Alan Play feature uses your data to allow participation in healthy games and activities like daily step counts, challenges and leaderboards with your friends and colleagues, meditation and mindful breathing exercises as well as health events. Based on your participation data, you earn berries that can be exchanged on the Alan app for charitable donations, discount vouchers for the Alan shop, avatars and streak freeze.
We may therefore collect the following data:
More information on the how Alan Plays works can be found in the Rules of Play.
Your consent is requested:
You data is required to allow you to participate in these healthy games and activities as displayed in the Rules of Play.
Alan also processes this data to pursue its legitimate interests to monitor the performance of this feature and conduct statistical study and research.
This allows us to:
We may also draw statistics from anonymized and aggregated usage data (including on past step data), and share these non-identifying usage statistics with employers to measure Alan Play’s success in improving their employee well-being.
Your data is retained for 6 months from the termination of the service usage (withdrawal of your consent or termination of your participation).
Aggregated and anonymized usage data may be retained longer for statistical study and research purposes.
Yes, you just have to send a request to [email protected]
It is in Alan's legitimate interest to improve its services based on member satisfaction.
We use the NPS to monitor our performance with our members, through the Metabase tool. In concrete terms, this allows us to identify factors of dissatisfaction that may allow us to improve our services or, conversely, things that need to be reinforced because they are highly appreciated.
We keep them for the time needed to carry out analyses and measure their evolution over several development cycles. We then anonymise or delete them.
Yes, simply send a request to [email protected].
On the basis of Alan’s legitimate interest to assess and improve our products based on product usage analysis and feedback.
We track and analyze user interactions with our products to understand user usage and identify improvements.
We collect and assess user and member feedback to manage opinions or recommendations for improvement of the products, services or contents shared on our app and website.
We keep them for two years. We then anonymize or delete them.
Yes, by sending a message at [email protected].
Certain data is collected automatically when you visit alan.com (including other websites published by Alan such as blog.alan.com and map.alan.com) and when you use our mobile app. The data collected includes :
Where applicable, the collection is subject to the explicit consent of the user (cookie banner on our website). This consent is valid for 13 months from the date of registration.
Otherwise, it is in our legitimate interest to analyse the use of our site and mobile app in order to improve it or strictly required to provide our services.
This data is used for the following purposes:
Absolutely (with the exception of data collected in the framework of a legal obligation or strictly required to provide our services), simply make a request to [email protected].
To build our audience and client basis, Alan may reach out to prospects by emails and organize online advertising campaigns before sending them mails or emails. In this context, Alan handles email addresses available online (such as on Linkedin) but also from providers already used by Alan for audience-building purposes on social networks.
On the basis of Alan legitimate interests to fulfill our marketing and growth needs, in compliance with direct marketing regulatory requirements.
We are reaching prospects via online ads before sending mails or emails. To do so, we import prospects database into the audience of different platforms. The email addresses is the only data import on the ads platform.
We import only prospect data and we do not bring in any customer data or leads who have unsubscribed from any previous campaign. To do so, we ensure and remove our customers data in our ads audience before any data import.
In addition, users can opt-out and unsubscride from seeing Alan’s ads directly on the ads platform.
When reaching out by email, Alan provides easy-way to opt-out notably through unsubscription links in each communication and honor prospects opt-out in the future.
We keep this data for 2 years, in line with CNIL’s recommendation. A purge of the database to remove any inaccurate is carried out on a monthly basis.
Yes, you can opt-out from marketing communications at any time. You can exercize any of your rights simply in making a request to [email protected].
Data collected by Alan in the performance of our services, may be further used in a way compatible with the original purpose for which it was collected. Only aggregated and/or anonymized data may become subject to scientific research and/or for statistical studies, including for statistical learning. It could for instance be used in the selection and creation of relevant health stories to improve our services and Members' health, create aggregated usage reports or to streamline and improve the management of exchanges with Alan medical team.
We record the call only when you do not object to it. We process this data on the basis of our legitimate interests for training and quality purposes.
This data is used for the following purposes:
Records are kept for up to six months.
Yes, just send a request to [email protected].
Data security is an extremely important issue for Alan: we do our utmost to be worthy of the trust you place in us. Here are a few examples of the measures we have taken. If you have any questions on a specific point, we will be happy to answer them at [email protected].
Alan achieved ISO27001:2022 certification with SGS (certification body), validating our information security management system and our data protection measures. This certification covers all of Alan’s activities.
We use Datadog App Security to detect and block in real time attacks such as XSS, SQL injection, account theft, etc.
We also use Cloudflare to protect us from Distributed Denial of Service (DDoS) attacks.
All HTTP traffic to and from alan.com and api.alan.com is encrypted (HTTPS / TLS). You can evaluate our configuration here.
The first time a user logs on, we tell their browser (via the HSTS mechanism) that all subsequent connections must be encrypted (HTTPS), including when a link to alan.com starts with http:// instead of https://.
Your health conversations to our doctors, the answers and the attached documents are encrypted end-to-end: no one at Alan other than the doctors answering you has technically the possibility to see these discussions.
We use PostgreSQL databases. The data is encrypted using the AES-256 standard and the encryption keys are managed by AWS.
The backup archives are also encrypted.
We use the open-source zxcvbn-ts library to let users know the strength of the password they choose. The minimum size is 16 characters, including alphanumeric characters and symbols, and the minimum score is 4.
We do not store these passwords: we only store a non-reversible hash calculated by the open-source bcrypt library, with the following parameters :
All Alan employees receive mandatory training in security (including social engineering) and data privacy. They use complex and unique passwords and strong authentication (2FA) whenever possible. The use of a password manager such as 1Password is also mandatory.
Our computers are automatically updated and have their hard disk encrypted (in case of theft). Our screens lock automatically.
Access to our internal administration tools requires individual access from an authorised IP address and all data modifications (by an Alan employee or by a user himself) are audited.
We organise intrusion tests by independent companies.
All Alan services and applications are developed in-house. Our code is validated by automated tools (static analysis, security, etc.) and manually by a second pair of eyes.
In order to protect your data on your computer or mobile phone, you can take a few simple measures:
You can also consult the official recommendations on good IT security practices.
The data collected may be communicated as required to Alan's partners, reinsurers, subcontractors, legal and financial advisors, and service providers. These data transfers are carried out solely within the framework of the operations mentioned above and to the extent necessary for the performance of the tasks we entrust to third parties. These third parties are fully informed by Alan of the confidentiality of the data communicated to them in this context, and these partners have an obligation to ensure the protection of this data. They are also bound by their own confidentiality and privacy policies, which can be consulted on their websites. When the nature of the operation carried out allows it, the data is subject to prior anonymisation before being communicated to third parties.
We maintain a list of the main persons and tools that receive the data in the context of our processing operations through this link.
Furthermore, in order to meet legal and regulatory obligations, we may be required to communicate personal information to administrative or judicial authorities at their request. In this case, we ensure that only the data strictly required by the authorities is transmitted.
In order to fulfill all the purposes for which we collect your data, we may transfer some of your data to third parties, who host it in data centers located outside the European Union. In this case, we make sure that hosting is subject to European data protection standards (for example, by including standard contractual clauses in our contracts with such third parties).
You will find a summary of potential data transfers through this link.
In addition to being a delicious biscuit, a cookie is a file on your device that contains data we may collect when you visit our website. We obtain your consent before using cookies where it is required. You can delete or limit the storage of these files at any time in the settings of your internet browser (see below).
Third-party cookies used only on our public website based on user choice:
Third-party cookies used on our public website and dashboard (member and administrator) based on user choice:
Third-party cookies when viewing or interacting with third-party content embedded on our public site, based on the user’s choice:

You can find more information about the data collected by Alan via these third-party cookies through this link.
Of course you can! During your first visit on our website (or if you use your browser's private or incognito browsing), a banner (called a cookie banner) will be displayed asking you for permission to use cookies. Simply refuse and no cookies (other than those we need to operate the site and allow you to use our online chat) will be set. If you accept, your consent will be valid for 13 months from the date of registration.
Simply put, no.
You will receive emails from us, but in the vast majority of cases it will be in the context of the execution of our contract, for example to invite you to register, to ask you for additional information to enable a refund or to inform you of contractual modifications or changes related to your account. There is no escaping this, but it is for your own good.
A small minority of emails are not directly related to our contract with you or your employer, but are still for a legitimate interest (e.g. to offer to sponsor a relative with a financial reward, to send you a quote, or to announce new services similar to those you currently enjoy).
If you are an administrator, you may also receive commercial offers from us. In these cases, you always have the possibility of unsubscribing from this type of message by following the link in each of our emails (opt-out).
You can also choose to subscribe to our newsletter or to our waiting lists to be notified of the availability of our new services (opt-in).
As for push notifications, we will ask for your permission directly in the mobile application and you will be able to deactivate or reactivate them from your phone.
Resumen
Únete ahora a Alan


Preview