Privacy Notice for Fleet Insurance Policies
Last Updated: 27 January 2023
About This Notice
This Privacy Notice sets out how Humn.ai (Humn, we, our, us) will process personal data in relation to our fleet insurance products and services, including Rideshur. This includes personal data relating to fleet managers and drivers of fleet vehicles.
Information for Drivers
There may be instances where we do not have a direct contractual relationship with you. Our contract may be with a third party, for example, a drivers employer, the insurer of a vehicle, the owner of the drivers vehicle or the broker placing the vehicle insurance policy with the insurer (The Contracting Entity).
The Contracting Entity will also be a Data Controller under data protection legislation.
The Contracting Entity will also be a Data Controller under data protection legislation.
It is very important that you read this Privacy Notice in conjunction with that offered by the relevant Contracting Entity in order to understand how your data is processed and the legal basis for onward transfer to us. This Privacy Notice only covers the processing performed by Humn and not those processes performed by The Contracting Entity.
If you are reading this having received an e-mail or a notification regarding Driver ID we have been provided with your details by The Contracting Entity in order to provide them with a Contract for Insurance. As part of this service we require to know who is driving which vehicle covered by that policy. We do so under the basis of legitimate interest. If you have any questions in relation to this please contact the Data Protection and Privacy Office on the details provided below.
How We Receive This Information
Where you provide personal data about other third-party individuals, such as drivers of vehicles, where appropriate, you should direct these individuals to this Notice to ensure they understand how we collect and use their personal data.
We collect personal information from a number of different sources. These include:
We collect personal information from a number of different sources. These include:
- Directly from you in person, by telephone, email or via our website and app;
- From third parties involved in the contractual chain of vehicle licensing - in the case of drivers for example this may be The Contracting Entity;
- From other third parties involved in your insurance policy or claim such as another insurer, claimants, defendants, or witnesses;
- From other third parties who provide a service in relation to your insurance policy or claim such as claims service providers, loss adjusters, claims handlers, medical experts, healthcare providers, emergency assistance personnel, legal counsel, and other professional service providers;
- From publicly available sources such as internet search engines and social media sites;
- From data contributors such as software houses and intermediaries;
- From risk analysis, fraud prevention, credit reference agencies and identity verification companies;
- From insurance industry fraud prevention and detection databases and sanctions screening tools;
- From providers of demographic and vehicle data;
- From call recordings when interacting with us;
- From our website and app including through the use of cookies and web analytics. Please see our Cookies Policy for further information;
- From third parties who we buy marketing lists from;
- From third parties who provide us with details of companies who have expressed an interest in hearing about our products and services such as when we receive data through introducer agreements;
- From third party telematics providers and OEM’s;
- From local authorities;
- From brokers and insurance intermediaries;
- From other insurers;
- From third parties in connection with any acquisition or merger of a business by us.
The Personal Information We Collect
We collect a range of different personal information in order to provide or offer our services to you. The information that we process will depend upon our relationship with you as set out above in the section “About this Notice”.
If you are providing information to us regarding a third party, such as when The Contracting Entity shares driver data with us, you agree to inform the individual of who we are, that we are a third-party Data Controller processing their information and give them an opportunity to view this Privacy Notice before submitting their data to us.
Basic Categories Data
- Biographical information such as your name, title, date of birth, age, occupation and years resident in the United Kingdom;
- Personal contact information such as home address, personal email address, telephone number, social media information;
- Professional contact information such as the name of your employer, work address, work e-mail and telephone number;
- Financial information such as bank details, payment details and information obtained as a result of credit checks;
- Online and transactional information such as details of your IP address and interactions that you have with our websites and digital platforms. Please see our Cookies Policy for more information;
- Telematics data such as GPS location, time and date, direction of travel, speed, accelerometer data, safety events as processed and detected by the telematics service provider, CAN bus data;
- Vehicle data such as registration, VIN, make and model;
- Driver licence related information such as related data such as type of licence held, licence date and licence number;
- Dashcam data such as images captured by the dashcam device(s);
- Diagnostic data such as vehicle fault codes, better health status etc;
- Your opinions and preferences in relation to your working conditions.
The provision of your telematics data allows us to track your vehicle in real-time, map and analyse your trips in order to calculate your risk score.
Special Categories Data
Special Categories data that we process include:
- Medical information such as your current or former physical or mental health and historic confirmed personal claims information;
- Information relating to criminal convictions and motoring offences such as endorsements on your licence;
- Your raw data and reports from psychometric questionnaires.
What We Use Your Data For
Whenever we process personal data we must have a legal basis in order to do so. Please refer to the sections below to find out more about our processing activities.
Contract
- In order to process any application you make for policy cover;
- Providing you with policy cover, including underwriting and claims handling;
- Administering and managing your motor insurance policy;
- Providing any additional services to you as agreed such as top up products. For example, policy checks for fleets;
- Providing you with risk management insights and driver behaviour data;
- Managing any disputes or complaints in relation to our contractual relationship with one another.
Legal or Regulatory Obligation
- To fulfil our obligations as an entity regulated by the Financial Conduct Authority (FCA) and The Financial Ombudsman Service;
- Contacting the insured/ policyholder during the renewals process;
- To fulfil your data rights under data privacy laws, handle complaints about data privacy or our insurance products and services and to comply with other legal requirements.
In this respect, please note that we may have to process your data to comply with other legal obligations such as requests from law enforcement agencies or other international and national governmental and regulatory bodies. This will be covered more fully in the section below regarding “Who we share your data with”.
Legitimate Interest
- In furtherance of our commercial activities such as to maintain and manage our business operations, management reporting information and internal process requirements;
- To develop and improve our products and services;
- To communicate with you regarding additional product offerings, awareness campaigns, research projects and surveys you may wish to participate in and to facilitate marketing campaigns and events;
- To carry out business to business to customer awareness campaigns such as driver safety;
- To monitor your use of our platform and subsequently provide you with any help or support in relation to our products and services;
- To send out promotional materials and/or gifts;
- To offer additional services to drivers such as our incentive programme and driver coaching;
- For the purposes of reinsuring and the insurance renewal process.
- In order to facilitate Driver ID so that we accurately identify the driver for any given trip in order to provide our products and services.
- To communicate with you regarding any queries you raise via the website.
- To send you (the driver) reports about your driving and training materials.
- To send reports about your driving to your employer.
Where we rely on this lawful basis, we conduct a balancing exercise to ensure that our interests are proportionate and do not override your rights and interests as a data subject. In some instances, you also have the right to object to this kind of use. If you wish to object to this type of processing please contact the Data Protection and Privacy Office details of which can be found below.
Establishment, Exercise or Defence of Legal Claims.
- We may process your personal information for the establishment, exercise, or defence of legal claims or if we proceed with a claim against you.
Substantial Public Interest
- We may use your personal information under Schedule 1 of the Data Protection Act 2018 in that doing so is necessary for insurance purposes.
Consent
- Where we have obtained consent to collect and process your data for a particular purpose. If we rely upon your consent you will be presented with a consent statement prior to you submitting your data to us. An example of this is our use of Cookies in order to monitor the usage of our app and websites to better understand our customer base and their use of our services. Please see our Cookies Policy for further information.
Please note that if consent is the legal basis upon which we process your personal data then you may withdraw your consent at any time. In order to affect this right please contact the Group Data Protection Officer whose details can be found below.
If you would like further details regarding our processing activities please contact the Data Protection and Privacy Office details of which can be found below.
If you would like further details regarding our processing activities please contact the Data Protection and Privacy Office details of which can be found below.
Automated Decision Making and Profiling for the Purposes of Underwriting
We may use personal data in processes that involve automated decision making and profiling for the purposes of assessing whether or not you meet our underwriting criteria, to determine premium pricing and assessing the risk of the policy as a whole.
If you feel that the outcome of this processing has been unfair you have the right to contest any decision produced by a solely automated means and request for human intervention. In order to affect this right please contact the Data Protection and Privacy Office details of which can be found below.
If you feel that the outcome of this processing has been unfair you have the right to contest any decision produced by a solely automated means and request for human intervention. In order to affect this right please contact the Data Protection and Privacy Office details of which can be found below.
Automated Decision Making and Profiling for the Purpose of Driver Behaviour Scores
Humn.ai systems including Rideshur allow Driver Behaviour Scores to be calculated based on recorded telematics data and other publicly available data such as speed limits. The calculation of Driver Behaviour Scores is a form of profiling under Data Protection Legislation.
Driver Behaviour Scores are calculated using a combination of recorded telematics data, speed limit or similar data and system thresholds that may be defined within our systems by The Contracting Entity. These thresholds typically relate to legal speed limits (speeding events), acceleration rates (harsh acceleration events), deceleration rates (harsh braking events) or other driving behaviours (such as harsh cornering).
Humn.ai uses the Driver Behaviour Score profiling as key metrics in automated decision-making processes to calculate dynamic insurance premium prices on behalf of The Contracting Entity.
Calculated Driver Behaviour Scores are passed directly from Humn.ai to The Contracting Entity for their subsequent processing and use.
Humn.ai do not control the use of Driver Behaviour Score data by The Contracting Entity and you should contact The Contracting Entity directly for further information on their use of this data.
You have the right to contest any decision produced by a solely automated means and request for human intervention. In order to affect this right please contact the Data Protection and Privacy Office details of which can be found below.
Driver Behaviour Scores are calculated using a combination of recorded telematics data, speed limit or similar data and system thresholds that may be defined within our systems by The Contracting Entity. These thresholds typically relate to legal speed limits (speeding events), acceleration rates (harsh acceleration events), deceleration rates (harsh braking events) or other driving behaviours (such as harsh cornering).
Humn.ai uses the Driver Behaviour Score profiling as key metrics in automated decision-making processes to calculate dynamic insurance premium prices on behalf of The Contracting Entity.
Calculated Driver Behaviour Scores are passed directly from Humn.ai to The Contracting Entity for their subsequent processing and use.
Humn.ai do not control the use of Driver Behaviour Score data by The Contracting Entity and you should contact The Contracting Entity directly for further information on their use of this data.
You have the right to contest any decision produced by a solely automated means and request for human intervention. In order to affect this right please contact the Data Protection and Privacy Office details of which can be found below.
Data Sharing
- In the case of drivers, The Contracting Entity that you have a primary relationship with;
- For those drivers that wish to work with Uber we will share your data with Uber via our established Instadoc verification mechanism in order to confirm your status as an insured driver;
- Our insurance partners and reinsurers. If you require further details regarding these companies then please contact us directly on the details provided below;
- Other insurers who provide us with our own insurance;
- Other third parties who assist in the administration of insurance policies such as loss adjusters, first notification of loss providers, claims handlers, accountants, auditors, lawyers and other experts;
- Where you have opted to pay your insurance by instalments with our Finance Partners;
- Fraud detection agencies and other third parties who operate and maintain fraud detection registers including but not limited to the Claims and Underwriting Exchange, Insurance Fraud Register, Motor Insurance Anti-Fraud and Theft Register and other centralised insurance industry applications/databases investigative firms we ask to look into claims on our behalf in relation to suspected fraud;
- Motor Insurance Database managed by the Motor Insurance Bureau;
- Regulators who govern how we operate, including the FCA, PRA, FOS, HMRC, ICO and the Advertising Standards Authority;
- The police, courts and other third parties or law enforcement agencies where reasonably necessary for the prevention or detection of crime;
- Government agencies and regulatory bodies including the DVLA, DVA, DVSA, DWP and the Motor Insurance Bureau;
- Any personal representatives appointed by you to act on your behalf;
- Industry bodies;
- Debt collection, credit reference and fraud prevention agencies or any organisations we instruct to commence legal proceedings against you;
- Legal advisers, accountants, auditors, financial institutions and professional service firms who act on our or your behalf, or who represent a third-party claimant;
- Our third-party services providers such as IT suppliers, actuaries, auditors, marketing agencies, providers of market research services, including customer feedback surveys, referral administrators, document management providers and tax advisers;
- Third parties in connection with any sale, transfer, or disposal of our business;
- We may also disclose your personal information to other third parties where the disclosure is required by law or by a regulator with authority over us on the grounds of substantial public interest.
- Other entities within the Humn Group.
Motor Insurance Database
In order to comply with our legal obligations, we will add details about the insurance policy to the Motor Insurance Database (MID) via Motor Data Solutions (MDS). The MID is managed by the Motor Insurers’ Bureau (MIB) and we upload policies via MDS. The MID and the data stored on it may be used by the Police, the DVLA, the DVANI, the Insurance Fraud Bureau and other bodies permitted by law for purposes not limited to but including:
- electronic licensing
- continuous insurance enforcement
- law enforcement (prevention, detection, apprehension and/or prosecution of offenders)
- the provisions of government services and/or other services aimed at reducing uninsured driving
If you are involved in a road traffic accident (either in the UK or abroad), insurers and/or the MIB may search the MID to obtain relevant information. Other persons (including their appointed representatives) pursuing a claim in respect of a road traffic accident (including foreign citizens) may also obtain relevant information held on the MID.
It is important that the MID holds the correct vehicle registration number. If it is incorrectly shown on the MID you are at risk of having your vehicle seized by the police and/or a fixed penalty notice. You can check your current registration number with the MID at www.askmid.com.
MIB are an Independent Data Controller and you should contact them for further information about the use of your information.
If you would like further details in relation to how we share your information and with whom please contact the Data Protection and Privacy Office details of which can be found below.
It is important that the MID holds the correct vehicle registration number. If it is incorrectly shown on the MID you are at risk of having your vehicle seized by the police and/or a fixed penalty notice. You can check your current registration number with the MID at www.askmid.com.
MIB are an Independent Data Controller and you should contact them for further information about the use of your information.
If you would like further details in relation to how we share your information and with whom please contact the Data Protection and Privacy Office details of which can be found below.
Transferring Data Internationally
Data protection law places restrictions on transferring personal data outside of the United Kingdom (UK) and the European Economic Area (EEA).
There may be circumstances where we transfer information to our service providers in countries outside the UK and the EEA. If we do so, then your personal data will only be transferred on one of the following bases:
There may be circumstances where we transfer information to our service providers in countries outside the UK and the EEA. If we do so, then your personal data will only be transferred on one of the following bases:
- where the transfer is subject to one or more of the "appropriate safeguards" for international transfers prescribed by applicable law (e.g. Data Transfer Assessments and Standard Contract Clauses adopted by the European Commission and/or the UK IDTA and UK Addendum as adopted by the UK Government);
- a European Commission or UK Government decision provides that the country or territory to which the transfer is made ensures an adequate level of protection; or
- there exists another situation where the transfer is permitted under applicable law (for example, where we have your explicit consent).
Marketing Activities
We will only send you marketing information regarding:
- our own products and services;
- industry related insights and news;
- advice for fleet and risk management;
- third party marketing information that you have expressed an interest in receiving.
You have the right to stop the use of your personal data for direct marketing activity. Please contact us if you no longer wish to receive marketing communications.
If you do choose to stop receiving marketing communications from us, we will ensure that you do not receive such material going forward unless you specifically request it in the future.
Please note even although you have opted out of receiving marketing communication from us, we will still continue to send you any necessary information regarding any products of services you continue to have with us or communications we are required to issue in order to fulfil or legal and regulatory obligations.
Security Measures
The safety and security of your data is important to us. As such we are committed to applying the appropriate technical and organisational security measures to meet our legal and regulatory obligations. Our Data Protection Policy and Protocols ensure the principles of Confidentiality, Integrity and Availability form the core structure of our service offering. Our security controls include the following:
- Identity and Access Management, based on strong Authentication (SSO and a Zero Trust Model) and Role-Based-Access-Control to enforce granular access to data;
- Data Loss Prevention, through Backup & Recovery standards as well as Business Continuity & Disaster Recovery procedures;
- Encryption and Anonymisation, leveraging AES-256 based data encryption at rest and TLS v1.3 for data in-transit, whilst utilising SHA256 for PII hashing.
How Long We Keep Your Data For
We will retain your Personal Data for as long as is reasonably necessary for the purposes explained in this Notice. In most cases this will be a maximum of 7 years from the expiry of an insurance contract. In some circumstances we may retain your Personal Data for longer periods of time, for instance where we are required to do so in accordance with legal, regulatory, tax or accounting requirements.
In some cases we may also retain your Personal Data for longer periods of time so that we have an accurate record of your dealings with us in the event of any complaints or challenges, or if we reasonably believe there is a prospect of litigation relating to your relationship with us. Where your Personal Data is no longer required we will ensure it is either securely deleted or stored in a way that no longer identifies you.
If you would like further details regarding our records retention then please contact the Data Protection and Privacy Office details of which can be found below.
Your Rights Under The Law
Under data protection legislation you have the following rights:
- The right to be informed – We are required to provide individuals with clear and precise transparency information regarding who we are and what we do with your data. This Privacy Notice along with other transparency information gives effect to this right;
- The right of access – Individuals have the right to access and receive copies of their personal data alongside other supplementary information as required. If you wish to affect this right please contact the Group Data Protection Officer on the details provided below;
- The right to rectification – Individuals have the right to ensure that the information that we hold about them is accurate. If you believe that the personal information that we hold about you is inaccurate or incomplete, then please contact us to request that we amend or update our records;
- The right to erasure – You have the right to request that all data pertaining to you be erased from our systems. Please note that there are certain circumstances where this request may not be possible. If we are unable to comply, we will issue you with meaningful information regarding why this is the case;
- The right to restriction of processing – There may be circumstances where we will restrict the processing of your data. For example, if we are investigating a claim that your personal information is no longer accurate or you object to the processing taking place;
- The right to data portability - You have the right to request that your information be compiled into a common, machine-readable format and either provided directly to you or sent by us to a third-party you nominate. If this is not possible, we will issue you with information setting out why this cannot be done;
- The right to object – You have the right to object to us processing your data or a category of data that we hold about you. If we are unable to comply with your request, we will issue you with meaningful information regarding why this is the case;
- Rights in relation to automated decision making and profiling – As set out above you have the right to request human intervention into any process involving automated decision - making or profiling where that processing results in legal or similarly significant effects. Please note that this right would not apply to underwriting decisions as this automated decision-making is required for entering into the insurance contract however, we would be happy to review your case and provide you with further information regarding the process and your case.
Please note that the above rights are not absolute and requests may be refused where exemptions apply. You can find out more about your rights at www.ico.org.uk
Contact Humn
If you would like further information regarding this Privacy Notice or you would like to exercise any of your data rights, you can contact the Data Protection and Privacy Office by email at privacy@humn.ai or in writing to:
FAO The Group Data Protection Officer
The Data Protection and Privacy Office
Humn.ai Ltd
184 Shepherds Bush Road
London
W6 7NL
The Data Protection and Privacy Office
Humn.ai Ltd
184 Shepherds Bush Road
London
W6 7NL
Changes To This Notice
Humn reserve the right to amend this policy at any time without notice in response to changes in data protection legislation and our legal and regulatory obligations. We recommend that you check our privacy page on a regular basis to ensure that you are aware of any changes which may affect you.