Privacy Notice for Business Contacts
Last Updated: 20 October 2022
About This Notice
How We Receive This Information
- Directly from you in person, by telephone, email, surveys or via our website and app;
- From publicly available sources such as internet search engines and social media sites;
- From call recordings when interacting with us;
- From third parties who we buy marketing lists from;
- From third parties who provide us with details of companies who have expressed an interest in hearing about our products and services such as when we receive data through introducer agreements;
- From other third party companies such as brokers and insurance intermediaries;
- From third parties in connection with any acquisition or merger of a business by us.
The Personal Information We Collect
Basic Categories Data
- Biographical information such as your name, title, date of birth, age, occupation and years resident in the United Kingdom;
- Personal contact information such as home address, personal email address, telephone number, social media information;
- Professional contact information such as the name of your employer, work address, work e-mail and telephone number.
What We Use Your Data For
- In order to carry out our responsibilities resulting from any business or commercial agreements that are entered into with us;
- Managing any disputes or complaints in relation to any business or commercial agreements that are entered into with us.
Legal or Regulatory Obligation
- To fulfil our obligations as an entity regulated by the Financial Conduct Authority (FCA) and The Financial Ombudsman Service;
- To fulfil your data rights under data privacy laws, handle complaints about data privacy or our insurance products and services and to comply with other legal requirements.
- In furtherance of our commercial activities such as to maintain and manage our business operations, management reporting information and internal process requirements;
- To develop and improve our products and services;
- To communicate with you regarding additional product offerings, awareness campaigns, research projects and surveys you may wish to participate in and to facilitate marketing campaigns and events;
- To carry out business to business to customer awareness campaigns such as driver safety;
- To communicate with you regarding any queries you raise via the website.
Establishment, Exercise or Defence of Legal Claims.
- We may process your personal information for the establishment, exercise, or defence of legal claims or if we proceed with a claim against you.
- Regulators who govern how we operate, including the FCA, PRA, FOS, HMRC, ICO and the Advertising Standards Authority;
- The police, courts and other third parties or law enforcement agencies where reasonably necessary for the prevention or detection of crime;
- Any personal representatives appointed by you to act on your behalf;
- Debt collection, credit reference and fraud prevention agencies or any organisations we instruct to commence legal proceedings against you;
- Legal advisers, accountants, auditors, financial institutions and professional service firms who act on our or your behalf, or who represent a third-party claimant;
- Our third-party services providers such as IT suppliers, actuaries, auditors, marketing agencies, providers of market research services, including customer feedback surveys, referral administrators, document management providers and tax advisers;
- Third parties in connection with any sale, transfer, or disposal of our business;
- We may also disclose your personal information to other third parties where the disclosure is required by law or by a regulator with authority over us on the grounds of substantial public interest.
Transferring Data Internationally
There may be circumstances where we transfer information to our service providers in countries outside the UK and the EEA. If we do so, then your personal data will only be transferred on one of the following bases:
- where the transfer is subject to one or more of the "appropriate safeguards" for international transfers prescribed by applicable law (e.g. Data Transfer Assessments and Standard Contract Clauses adopted by the European Commission and/or the UK IDTA and UK Addendum as adopted by the UK Government);
- a European Commission or UK Government decision provides that the country or territory to which the transfer is made ensures an adequate level of protection; or
- there exists another situation where the transfer is permitted under applicable law (for example, where we have your explicit consent).
- our own products and services;
- industry related insights and news;
- advice for fleet and risk management;
- third party marketing information that you have expressed an interest in receiving.
If you do choose to stop receiving marketing communications from us, we will ensure that you do not receive such material going forward unless you specifically request it in the future.
- Identity and Access Management, based on strong Authentication (SSO and a Zero Trust Model) and Role-Based-Access-Control to enforce granular access to data;
- Data Loss Prevention, through Backup & Recovery standards as well as Business Continuity & Disaster Recovery procedures;
- Encryption and Anonymisation, leveraging AES-256 based data encryption at rest and TLS v1.3 for data in-transit, whilst utilising SHA256 for PII hashing.
How Long We Keep Your Data For
Your Rights Under The Law
- The right to be informed – We are required to provide individuals with clear and precise transparency information regarding who we are and what we do with your data. This Privacy Notice along with other transparency information gives effect to this right;
- The right of access – Individuals have the right to access and receive copies of their personal data alongside other supplementary information as required. If you wish to affect this right please contact the Group Data Protection Officer on the details provided below;
- The right to rectification – Individuals have the right to ensure that the information that we hold about them is accurate. If you believe that the personal information that we hold about you is inaccurate or incomplete, then please contact us to request that we amend or update our records;
- The right to erasure – You have the right to request that all data pertaining to you be erased from our systems. Please note that there are certain circumstances where this request may not be possible. If we are unable to comply, we will issue you with meaningful information regarding why this is the case;
- The right to restriction of processing – There may be circumstances where we will restrict the processing of your data. For example, if we are investigating a claim that your personal information is no longer accurate or you object to the processing taking place;
- The right to data portability - You have the right to request that your information be compiled into a common, machine-readable format and either provided directly to you or sent by us to a third-party you nominate. If this is not possible, we will issue you with information setting out why this cannot be done;
- The right to object – You have the right to object to us processing your data or a category of data that we hold about you. If we are unable to comply with your request, we will issue you with meaningful information regarding why this is the case;
- Rights in relation to automated decision making and profiling – As set out above you have the right to request human intervention into any process involving automated decision - making or profiling where that processing results in legal or similarly significant effects. Please note that this right would not apply to underwriting decisions as this automated decision-making is required for entering into the insurance contract however, we would be happy to review your case and provide you with further information regarding the process and your case.
The Data Protection and Privacy Office
184 Shepherds Bush Road
Changes To This Notice