This privacy notice describes how Artex Risk Solutions group companies ('Artex', 'we', 'us') may collect, handle and process personal information in relation to the services which we provide to our clients.
This privacy notice applies to all of the services, websites and apps offered by Artex (collectively, the "Services"), but excludes Services which have separate privacy notices that do not incorporate this privacy notice.
The Artex Risk Solutions company, which provides each Service, is primarily responsible for the personal information collected and held in relation to that Service. A description of Artex Risk Solutions Services and contact details for us are available at www.artexrisk.com.
1. Personal information we use.
We may collect personal information about you from a variety of sources, including information we collect from you directly (e.g., when you contact us) and from other sources, described below.
Note that we may be required by law to collect certain personal information about you, or as a consequence of any contractual relationship we may have with you. Failure to provide this information may prevent or delay the fulfillment of these obligations. We will inform you at the time your information is collected if the provision of certain personal information is compulsory and the consequences of the failure to provide such personal information.
1.1 Information we collect directly from you
Depending on the service, website or app that you are using, the categories of information that we may collect directly from you include:
- Personal details (e.g., name, date of birth);
- Contact details (e.g., phone number, email address, postal address or mobile number)
- Government issued identification details (e.g., social security and national insurance numbers, passport details)
- Health and medical details (e.g., health certificates)
- Policy details (e.g., policy numbers and types)
- Bank details (e.g., payment details, account numbers and sort codes)
- Driving license details
- Online log-in information (e.g., username, password, answers to security questions)
- Information relating to any claims
- Other information we receive from you on applications or required questionnaires (e.g., occupation, current employer)
1.2 Information we collect from other sources
The categories of information that we may collect about you from other sources are:
- Personal details (e.g., name, date of birth)
- Contact details (e.g., phone number, email address, postal address or mobile number)
- Bank details (e.g., account numbers and sort codes)
- Financial information from consumer-reporting agencies for the purpose of ascertaining credit history
- Policy details (e.g., policy numbers and types)
- Personal details of various types received when we conduct anti money laundering, countering financing of terrorism, anti-bribery and corruption, and sanctions screening checks
We may receive such information via other insurers, consumer-reporting agencies, our affiliated companies, or other third parties, including compliance screening services, in the course of conducting our business.
1.3 Sensitive personal information
We may also collect certain information about you which is considered more sensitive under local applicable laws, such as:
- Information about your race, ethnic origin, religious views and philosophical beliefs, membership of professional or trade associations, gender identity or sexual orientation for diversity and statutory monitoring purposes where appropriate
- Health, biometric or disability information required to administer policies or process claims
1.4 Personal data relating to minors and other vulnerable people
We may also collect or receive personal data relating to minors (which might be defined differently in different jurisdictions), particularly but not exclusively when processing personal injury insurance claims. We recognise that personal data relating to minors and other vulnerable people is particularly sensitive, however we treat all personal and other confidential data as needing to be kept secure and confidential, accordingly all data is treated as needing appropriate protection.
We do not knowingly collect online information from children under the age of 13. Our services are marketed towards adults. If we are notified that we have collected personal information, as defined by the Children's Online Privacy Protection Act (COPPA), of a child under the age of 13, we will delete the information as expeditiously as possible.
2. How we use your personal information and the basis on which we use it.
We may use your personal information to:
- Provide, maintain, protect and personalize our services including our insurance products, consulting and client insurance management and other administration services
- Deal with your enquiries and requests
- Perform system administration and to report aggregate statistical information to our advertisers
- Cooperate with regulators and law enforcement bodies
- Contact you with marketing and offers relating to products and services offered by us (unless you have opted out of marketing, or we are otherwise prevented by law from doing so)
- Personalize the marketing messages we send you to make them more relevant and interesting and to customize and enhance your website or app experience
- Resolve complaints, as well as handle requests for data access or correction
- Protect your, our or others' rights and interests and
- Communicate with you regarding your account or changes to our policies, terms and conditions
Some jurisdictions require a legal basis to use or process your personal information. In most cases the legal basis will be one of the following:
- To fulfill our contractual obligations to you in connection with your policy or contract with us, for example using your contact details to reply to your requests. Failure to provide this information may prevent or delay the fulfillment of these contractual obligations
- To comply with our legal obligations, for example to keep records of the services we provide you with as required by applicable law or regulation, or to comply with any governmental, quasi-governmental or court orders or subpoenas
- Where there is a public interest in the processing, for example where it is necessary in order to prevent and detect fraud
- To meet our or a third party's legitimate interests, for example to understand how you use our services and to enable us to derive knowledge from that to develop new services, to protect our rights or the rights of third parties, or to resolve any disputes. When we process personal information to meet our legitimate interests, we put in place robust safeguards to help ensure that your privacy is protected and that our legitimate interests are not overridden by your interests or fundamental rights and freedoms.
3. Your rights over your personal information.
You may have certain rights regarding your personal information, subject to local law. These include rights in certain circumstances to:
- Access your personal information.
- Request proof of the authorization or previous consent given to us to perform the collection and processing of the personal information.
- Rectify the information we hold about you.
- Erase your personal information.
- Restrict our use or disclosure of your personal information.
- Object to our use or disclosure of your personal information.
- Request information about the use and processing of your personal information by us.
- Receive your personal information in a usable electronic format and transmit it to a third party (right to data portability).
- Revoke the consent given by you for the processing of your personal information.
- Lodge a complaint with your local data protection authority.
If you would like to discuss or exercise such rights, as applicable under local law, please contact us at the details below.
We encourage you to contact us to update or correct your information if it changes or if the personal information we hold about you is inaccurate.
We will contact you if we need additional information from you in order to honor your requests.
4. Automated decisions about you.
We may automatically process your personal information to make decisions or conduct 'profiling' about you. This may involve using software that is able to evaluate your personal aspects and predict risks or outcomes. We may carry out this automatic processing for general business purposes including, for example, advertising, risk assessment or fraud prevention. The processing may involve decisions about you that relate to products that we sponsor or your eligibility to use the Services. The significance of our actions in this connection is that is that it may have legal or similar effects for you, namely, availability of access to services. The logic involved may be related to our cookies policy, or it may be related to specific underwriting software, for example.
We will only make these kinds of automated decisions about you where:
- Such decisions are necessary for entering into a contract. For example, we may decide not to offer services to you, or we may decide on the types or amount of services that are suitable for you, or how much to charge you for our services based on your credit history and other financial or related information we have collected about you.
- Such decisions are required or authorized by law, for example for fraud prevention purposes.
- You give your consent to us carrying out automated decision-making.
Subject to local legal requirements and limitations, you can contact us to request further information about automated decision-making, object to our use of automated decision-making, or request an automated decision to be reviewed by a human being.
We also may make automated decisions about you based on your personal information in the circumstances such as: to select personalized offers, discounts or recommendations to send you based on your shopping history or browsing history, subject to any applicable laws or regulations.
These types of decisions will not have legal or similar effects for you, but you can still contact us for further information
5. Information sharing.
We may share your personal information with third parties for the purposes described in this privacy notice under the following circumstances:
- We may share your personal information with our insurance management and other administration clients and their business partners for the purpose of processing claims and other insurance and company administration purposes; including with insurance and reinsurance companies, brokers, lawyers, actuaries, loss adjusters, claims handlers etc.
- We may share your personal information with our service providers and business partners that perform marketing services and other business operations for us. For example, we may partner with other companies to process secure payments, fulfill orders, optimize our services, send newsletters and marketing emails, support email and messaging services and analyze information.
- We work closely with other businesses and companies that fall under the Artex Risk Solutions family of companies and our parent group. We may share your personal information with other group companies for marketing purposes (subject to applicable laws or regulations), internal reporting and other purposes as described in this privacy notice. A general description of the Artex Risk Solutions companies can be found here.
- Law enforcement agency, court, regulator, government or quasi-governmental authority or other third party. We may share your personal information with these parties where we believe this is necessary to comply with a legal or regulatory obligation, to enforce or apply any agreements between us and you, to resolve any disputes, or otherwise to protect our rights or the rights of any third party.
- Asset purchasers. We will not sell your personal information to third parties other than to the extent reasonably necessary to proceed with the consideration, negotiation, or completion of a merger, reorganization, or acquisition of our business, or a sale, liquidation, or transfer of some or all of our assets. Should such a sale or transfer occur, we will use reasonable efforts to try to ensure that the entity to which we transfer your personal information uses it in a manner that is consistent with this privacy notice.
- Online ad technology firms. We may transfer information about you to ad technology firms so that they may recognize your devices and deliver interest-based content and advertisements to you. The information may include your name, postal address, email, device ID, or other identifier in encrypted form. These firms may collect additional information from you, such as your IP address and information about your browser or operating system; may combine information about you with information from other companies in data sharing cooperatives in which we participate; and may place or recognize their own unique cookie on your browser.
Because we operate as part of a global business, the recipients referred to above may be located outside the jurisdiction in which you are located (or in which we provide the Services). See the section on "International Data Transfer" below for more information.
When required by applicable law, when we share personal information with corporate third parties we will ensure that such third parties maintain a comparable level of protection of the personal information as set out in this privacy notice by using contractual or other means. To the fullest extent permitted by applicable law, we exclude all liability arising from the use of your personal information by third parties.
When required by applicable law, data transfers will be logged and documented, identifying the recipient of the data, the purpose of the transmission, and the type of data that was transmitted. Where required by law to do so, we can on request confirm the name of each third party that personal information is, or will be, transferred to.
6. Information security and storage.
We implement technical, organizational, administrative and physical measures to help ensure a level of security appropriate to the risk to the personal information we collect, use, disclose and process. These measures are aimed at ensuring the on-going integrity and confidentiality of personal information. We evaluate these measures on a regular basis to help ensure the security of the processing. Please be aware that, despite our ongoing efforts, no security measures are perfect or impenetrable.
We restrict access to your personal information to those who require access to such information for legitimate, relevant business purposes.
We will keep your personal information for as long as we have a relationship with you. Once our relationship with you has come to an end, we will retain your personal information for a period of time that enables us to:
- Maintain business records for analysis and/or audit purposes
- Comply with record retention requirements under the law
- Defend or bring any existing or potential legal claims
- Deal with any complaints regarding the services
We will delete your personal information when it is no longer required for these purposes. If there is any information that we are unable, for technical reasons, to delete entirely from our systems, we will put in place appropriate measures to prevent any further processing or use of the personal information.
6.1 Secure communications
Live chat sessions on our site are encrypted to encode information that you share with our operators. By contrast, be aware that e-mail messages sent in clear text over the public internet can be observed by an unintended third party. Non-encrypted Internet e-mail communications may be accessed and viewed by other internet users without your knowledge and permission while in transit to us. If you wish to keep your information private, please do not use electronic mail to communicate information to us or request information from us that you consider to be confidential and/or proprietary. If you wish, you may contact us instead via telephone at the phone number provided:
6.2 Third-party vendors
For certain services on our website, such as live chat or webcasts, we will ask for information about you such as your name, business, and e-mail address. In cases where we use a third-party vendor to provide online services, the vendor has agreed to keep your information confidential. For example, transcripts of live chat sessions may be archived in a database by our vendor for review by our operators.
7. Links to other sites.
We may provide links to other websites not owned or controlled by us that we think might be useful or of interest to you. We are not, however, responsible for the privacy practices used by other website owners or the content or accuracy contained on those other websites. Links to other websites do not constitute or imply endorsement by us of those web sites, any products or services described on those websites or any other material contained in them. We advise that you contact any third party websites directly for their individual privacy policies.
8. International data transfer
We may transfer certain personal information across geographical borders to our group companies or service providers (working in conjunction with us or on our behalf) worldwide. Such transfers are made in accordance with applicable law.
Where you are based outside of the European Union, you should be aware that your personal information may be transferred to, stored, and processed in a jurisdiction that is not your home jurisdiction. Where relevant you consent to the transfer, disclosure, storage and/or processing of your personal information outside the jurisdiction in which the information was originally collected, in other circumstances this might be done in order to meet our legal obligations, in other circumstances this might be done in order to meet our legal obligations.
Where you are based in the European Union you should be aware that your personal information may be transferred to, stored, and processed in a country that is not regarded as ensuring an adequate level of protection for personal information under European Union law. We have therefore put in place appropriate alternative safeguards (such as contractual commitments) in accordance with applicable legal requirements to ensure that your personal information is adequately protected.
9. Contact us.
The Artex Risk Solutions company which provides each Service is primarily responsible for the personal information collected in relation to that Service. A general description of Artex Risk Solutions capabilities and their contact information is available here.
- Our North American Data Protection team can be contacted at firstname.lastname@example.org.
- Our International Data Protection team can be contacted at DPO@artexrisk.com.
We are committed to working with you to obtain a fair resolution of any complaint or concern about privacy. If, however, you believe that we have not been able to assist with your complaint or concern, you may have the right to make a complaint to the data protection authority in your country of residence.
10. Changes to the privacy notice.
You may request a copy of this privacy notice from us using the contact details set out above.
Where changes to this privacy notice will have a fundamental impact on the nature of our processing of your personal information or otherwise have a substantial impact on you, we will give you sufficient advance notice so that you have the opportunity to exercise any rights you may have under applicable law (e.g. to object to the processing).
Annex A: Cookies policy.
- We may obtain information about your general internet usage by using a 'cookie' file which is stored on the hard drive of your computer. Cookies contain information that is transferred to your computer's hard drive. They help us to improve our site and to deliver a better and more personalized service. They enable us to:
- Estimate our audience size and usage pattern
- Store information about your preferences, and so allow us to customize our site according to your individual interests
- Speed up your searches
- Recognize you when you return to our site