Data Privacy Statement in connection with your use of our website, online services and guest Wi-Fi
In the following we provide you with specific information in connection with your use of our website, corporate presence in social media and online collaboration tools. In addition, we would refer to our General Data Privacy Statement pursuant to Articles 13 and 14 EU General Data Protection Regulation (GDPR).
1. Responsible data controller / Contact information for the Data Protection Officer
Hannover Rück SE
Karl-Wiechert-Allee 50
30625 Hannover
Phone +49 511 5604-0
Fax +49 511 5604-1188
www.hannover-re.com
Our Data Protection Officer can be reached by post at the aforementioned address (please include the additional address line "Data Protection Officer") or by e-mail via our data privacy group mailbox at privacy[at]hannover-re.com.
2. Purposes and legal bases of data processing
Data processing operations in connection with our website are intended primarily to enable you to visit our website without encountering any problems from a technical point of view and are also carried out for purposes of IT security and Web analytics.
Insofar as you have consented to data processing, the legal basis of the respective data processing operations is Art. 6 (1) a) GDPR (consent).
We would additionally make reference to Art. 6 (1) f) GDPR (legitimate interest) as a legal basis. It is our legitimate interest to process such data that are necessary during your visit for the smooth operation of our website and for purposes of IT security. Further information on the purposes and legal bases of individual data processing operations is provided in the corresponding sections below.
4. Source, collection and processing of your data
Only personal data technically transmitted to us by you in the context of your visit to our website is processed in connection with the operation of our website.
We collect your data in various ways:
Access data and server log files
In order to technically optimise the utilisation of our website, we require information about which technical tools are used to access which of our webpages. We store this data in so-called server log files. Unless otherwise required by law, the storage period is 12 months. The data does not include any personal information.
Subscription to our e-mail notification service
If you are a subscriber to our Notification Service, you receive e-mail notifications of the latest press releases that you can access under www.hannover-rueck.de or www.hannover-re.com. We use the data provided by you for this purpose solely for sending our e-mail notifications. You may choose to stop receiving these notifications at any time by sending an e-mail to privacy@hannover-re.com. In addition, each e-mail notification contains a link via which you can cancel the receipt of these e-mails.
In addition, we process your personal data, insofar as legally required, to validate the e-mail address you have provided by means of the so-called double opt-in procedure and to document the status (granting or revocation of consent).
Direct inquiries using contact forms or via e-mail
Inquiries that we receive via contact or order forms or which you send directly to a contact person at the Hannover Re Group are forwarded as necessary by us internally within the Group to the relevant responsible area.
We process the data contained therein in order to process your request and, if necessary, to contact you.
In fulfilment of the legal requirements, in particular the Whistleblower Protection Act (HGSchGE), Hannover Rück SE maintains an internal reporting office for whistleblowers. Personal data transmitted in this context is processed accordingly on the basis of Art. 6 (1) c) GDPR.
In view of our global presence, the responsible area may be located outside the European Economic Area (EEA). In this case too, however, your data is used solely to respond to your particular inquiry insofar as an adequate level of data protection has been confirmed by the EU Commission in the third country or other appropriate data protection guarantees (e.g. binding corporate data protection regulations or EU Standard Contractual Clauses) are in place.
All data that you transmit using the e-mail form on our website is encrypted to protect it against misuse by third parties. We currently use TLS (Transport Layer Security (formerly SSL, Secure Sockets Layer)) encryption as recommended by the Federal Office for Information Security (BSI). We cannot, however, guarantee the security of data transmitted to us over the Internet.
6. Nutzung von Videokonferenz- und Kollaborationswerkzeugen
6. Use of videoconferencing and collaboration tools
We use videoconferencing and collaboration applications, such as Microsoft Teams, for online collaboration within the Hannover Re Group and with external participants, including contractual partners, service providers, applicants, interested parties, guests and participants in online events.
Purposes of data processing
- Holding online meetings, conferences, telephone conferences and webinars using video, audio and chat functions
- Communication between individuals, within internal company groups and in groups comprising internal and external participants, such as project teams, departments or business units
- Project work and the sharing, presentation and collaborative editing of documents, files and other content
- Conducting job interviews
- Instructional and training measures
- Where required for the specific meeting: documenting, transcribing, summarising and recording the activities referred to above, including the provision of live captions, real-time translation and other accessibility functions. The meeting organiser will inform participants of any additional purpose before the relevant function is used.
The following personal data is processed
- Participant and account information: for example, first name, surname, display name, e-mail address, telephone number, profile picture, company, role or function and language preference
- Meeting and connection metadata: for example, subject and description, meeting ID, date and time, start and end time, participants, IP addresses, device and hardware information, operating system, browser information, location or country information and, depending on the type of dial-in, telephone numbers
- Content and interaction data: depending on the functions used, text entries in chats and polls, reactions, files and other content uploaded, presented or shared by participants, and information visible through screen sharing. If video or audio functions are used, video images, spoken contributions and technical information relating to the microphone and camera are processed for the duration of the meeting. Before joining a meeting, you can check and, where available, deactivate your microphone and camera. Please avoid displaying or sharing personal data that is not required for the purpose of the meeting.
- Use of recording, transcription and related functions: if a meeting is recorded, the recording may contain audio and video data, presentation content, shared screen content, chat messages and other contributions. If transcription, subtitles, real-time translation or automated summarisation functions are used, spoken contributions and other meeting content may also be converted into text, translated or summarised. Participants will be informed in advance about the intended function, its purpose and the intended recipients or authorised users. Consent is voluntary and may be withdrawn at any time with effect for the future; withdrawal does not affect the lawfulness of processing carried out before the withdrawal. Participants who do not consent will not suffer any disadvantage under employment law; where appropriate, an alternative means of participation or documentation will be offered. The application also displays a notification when recording or transcription is active.
- Telephone dial-in data: incoming and outgoing telephone numbers, country information, start and end time and, where applicable, further connection data such as the device IP address.
- Apps and additional functions: Microsoft Teams provides applications and functions supplied by Microsoft and, in individual cases, by third-party providers. The categories of data processed, purposes and recipients depend on the application or function selected. Additional information is provided in the relevant application under “About” or “Privacy Policy”.
Recordings and transcripts are automatically deleted by the system after 60 days, unless the person responsible for the meeting has specified a different retention and deletion period in an individual case. In that case, the criteria for the storage period set out in section 8 below apply.
Legal bases of data processing
- For the processing of employees' personal data, the legal basis is Section 26 (1) sentence 1 BDSG in conjunction with Art. 88 GDPR and Art. 6 (1) (b) GDPR, insofar as the processing is necessary for establishing, performing or terminating the employment relationship. Where processing is based on employees' consent, in particular for the use of the recording function, the legal basis is Art. 6 (1) a) GDPR in conjunction with Art. 7 GDPR and, where applicable, Section 26 (2) BDSG. If the processing is not necessary for the employment relationship and is not based on consent, Art. 6 (1) f) GDPR may serve as the legal basis. Our legitimate interests in such cases are the efficient conduct, documentation and follow-up of online meetings and the provision of accessible communication functions, provided that these interests are not overridden by the interests or fundamental rights and freedoms of the data subjects.
- If an online meeting is held in order to take steps at the request of a data subject prior to entering into a contract or to perform a contract with that data subject, the legal basis is Art. 6 (1) b) GDPR.
- For other participants, including external consultants and cooperation partners, the legal basis is Art. 6 (1) f) GDPR insofar as the processing is necessary for the technical provision of the service, communication, collaboration, documentation or accessibility. Our legitimate interests are the efficient conduct of online meetings and the traceable exchange of content for collaboration purposes. Where processing is based on consent, in particular for the use of the recording function, the legal basis is Art. 6 (1) a) GDPR in conjunction with Art. 7 GDPR.
- In individual cases, processing may also be based on Art. 6 (1) c) GDPR if it is necessary for compliance with a legal obligation, such as certain documentation obligations.
Withdrawal of consent:
- Participants who wish to withdraw their consent at a later date may request deletion or partial deletion by contacting the meeting chair or the person who started the recording.
- Participants may stop recording at any time from their own device: https://support.microsoft.com/en-us/teams/meetings/start-stop-and-find-meeting-recordings-in-microsoft-teams
- The meeting chair will help ensure that your contribution is appropriately reflected in the meeting documentation, for example through chat during the meeting or by email afterwards.
- For general information on data subject rights below (section 11), please refer to the relevant section.
Categories of recipients of personal data and further information on data protection
Recipients may include the participants in the relevant meeting, authorised persons within the Hannover Re Group who require access for the stated purposes, providers operating the videoconferencing and collaboration platforms, and providers of applications or functions made available through those platforms. Content is made available to additional internal or external recipients only where this is intended for the stated purpose or otherwise necessary and legally permissible. Access to recordings, transcripts and summaries is restricted to the persons authorised for the relevant purpose.
- Further information on Microsoft Teams privacy and security: https://learn.microsoft.com/en-us/microsoftteams/teams-privacy
- Further information on applications from third-party providers in Microsoft Teams is available in the relevant application under “About” or “Privacy Policy”.
7. Guest Wi-Fi (HR WiFi)
We provide guests (including employees) at our sites with a guest Wi-Fi service (HR WiFi). In connection with the provision and use of this Wi-Fi service, we process personal data to the extent necessary to ensure the technical operation, IT security and proper use of the network.
7.1 Data Processed
The following data is processed in particular when Wi-Fi services are being used:
- Internal IP address
- MAC address of the end device (usually a randomly generated MAC address)
- Date and time of WiFi usage
- Transmission speed
- Operating system and operating system version of the end device
7.2 Purpose of Processing
The processing is carried out for the following purposes:
- Provision and technical operation of the guest Wi-Fi
- Ensuring network and information security
- Detection, analysis and prevention of disruptions, malfunctions or security-related incidents
- Ensuring stable and efficient network operation
7.3 Legal basis
The processing of data is carried out on the basis of Article 6(1)(f) of the GDPR (legitimate interest). Our legitimate interest lies in particular in the secure, functional and abuse-free provision of the guest Wi-Fi, as well as in the protection of our IT infrastructure.
7.4 Categories of recipients of personal data
The data is generally processed only by internal departments responsible for the operation and security of the IT infrastructure. Where external service providers are engaged, this is done on the basis of data processing agreements in accordance with Article 28 of the GDPR.
7.5 Retention period
The processed data is stored only for as long as is necessary for the purposes set out above and is subsequently deleted or anonymised in accordance with the applicable deletion and retention periods.
8. Period of data storage
The connection and device data is stored in log files for a period of 12 months. It may otherwise be noted that we erase your personal data as soon as they are no longer required for the aforementioned purposes. It may occur that personal data is stored for the period in which claims can be asserted against our company (statutory limitation period of three or up to thirty years). In addition, we store your personal data to the extent required by law.
9. Data transfer to a third country
If we transfer personal data to companies / service providers and/or authorities outside the European Economic Area (EEA), such transfer will only take place if the third country has been confirmed by the European Commission as having an appropriate level of data protection or if other appropriate data protection guarantees (e.g. mandatory internal corporate data protection rules or EU standard contract wordings) are in place. Detailed information in this regard and concerning the level of data protection at our service providers in third countries can be requested from the aforementioned contact information.
10. Automated decision-making and profiling
We process your data on a partially automated basis in order to support our employees' decision-making in certain situations. Should we fully automate these operations in the future we shall inform you accordingly in advance in order to enable you to exercise your rights.
11. Rights of data subjects
You can request information about the data stored on your person from the aforementioned address. Under certain conditions, you can also request that your data be rectified or erased. You may also have the right to restrict the processing of your data and to have the data that you made available provided to you in a structured, commonly used and machine-readable format. Consent that has been given may be withdrawn at any time with future effect.
12. Right to object
If we process your data to protect legitimate interests, you may register your objection to this processing with our Data Protection Officer at the aforementioned address if there are reasons associated with your particular situation that oppose such data processing. We shall then no longer process your personal information unless we can demonstrate compelling legitimate grounds for processing which outweigh your interests, rights and freedoms, or if the intention of processing is to assert, exercise or defend legal claims.
13. Right to complain
You may address a complaint to our Data Protection Officer (contact information as above) or a competent data protection supervisory authority.
The data protection supervisory authority responsible for our company is:
Der Landesbeauftragte für den Datenschutz Niedersachsen (Data Protection Commissioner for Lower Saxony)
Prinzenstraße 5
30159 Hannover
Phone: +49 (0511) 120 45 00
Fax: +49 (0511) 120 45 99
E-mail: poststelle@lfd.niedersachsen.de
14. Reservation of right of modification
We reserve the right to modify these data privacy rules at any time within the limits set by applicable laws.
Information valid as of May 2026