Privacy Notice

1. WHO WE ARE

Your personal information is collected by United Risk Global, LLC, a Delaware limited liability company, and its subsidiaries. We respect your privacy and are committed to protecting your personal information. This notice will inform you as to how we look after your personal data when you visit our website (regardless of where you visit it from) and tell you about your privacy rights and how the law protects you.


Data Protection Officer and Privacy Officer


We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this privacy notice and our compliance with UK and EU data protection law. The same appointee acts as our Privacy Officer for the purposes of the Bermuda Personal Information Protection Act 2016 (PIPA). You can contact our DPO and Privacy Officer using the details below:


Name: The DPO Centre Ltd

Email: dataprotectionofficer@unitedrisk.global


If you have any questions about this privacy notice, including any request to exercise your legal rights, please contact our DPO and Privacy Officer in the first instance. You also have the right to complain to a supervisory authority at any time (see section 10 below).


Third-party links

Our websites may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements.


Children

While our website is designed for a general audience, we will not knowingly collect any data from children under the age of 13 or sell products to children.

2. INFORMATION WE COLLECT ABOUT YOU

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).


We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:


  • Identity Data includes first name, last name, username or similar identifier, title, role.
  • Contact Data includes billing address, delivery address, email address and telephone numbers.
  • Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
  • Usage Data includes information about how you use our website, products, and services.
  • Insurance Data includes policies, coverage, quotes, items and products insured, premium types and values, limits covered, taxes, details of claims, bordereaux, and policyholder details (of clients, prospects and policyholders).
  • Financial Data includes bank account details, account details, payments, invoice and accounting details, and costs.
  • Employment Data includes employee names, roles, training records, basic salary details, pension details, purchases and salary reductions, employment history, CVs/resumes and professional history (including of underwriters), and information regarding the signing of documents.
  • Health Data includes health insurance package details.
  • IT and Security Data includes IT logs and history, IT usage and issues, access rights, security measures, and internet/fibre infrastructure usage.
  • Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.


If you fail to provide personal information

Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with goods or services). In this case, we may have to cancel a product or service you have with us, but we will notify you at the time if this is the case.


Special categories of personal information

Some personal information is treated as falling into a special category. This includes information about health, disability, race, ethnicity, political opinions, biometrics or religion. We do not anticipate we will collect any special categories of personal information from you, but will let you know if we do.

3. HOW WE COLLECT YOUR INFORMATION

We use different methods to collect data from and about you including through:


  • Direct interactions. You may give us your Identity, Contact and Financial Data by filling in forms or by corresponding with us by phone, email, post or otherwise. This includes personal data you provide when you:
  • apply for our products or services;
  • request marketing to be sent to you; or
  • contact or liaise with us.
4. HOW WE USE YOUR PERSONAL INFORMATION

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:


  • Where we need to perform the contract, we are about to enter into or have entered into with you.
  • Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
  • Where we need to comply with a legal obligation.


Generally, we do not rely on consent as a legal basis for processing your personal data although we will get your consent before sending third party direct marketing communications to you via email or text message. You have the right to withdraw consent to marketing at any time by contacting us.


Purposes for which we will use your personal data


We have set out below, a description of all the ways we plan to use your data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.


Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground we are relying on to process your personal data, where more than one ground has been set out in the table below.


The lawful bases set out in the table below are those recognised under UK and EU data protection law. Where our use of your personal information is subject to the Bermuda Personal Information Protection Act 2016 (PIPA), we rely on the equivalent conditions for the use of personal information permitted under that Act.

Purpose/ActivityType of dataLawful basis for processing including basis of legitimate interest
To assess, underwrite and price risk and provide quotes, and to place cover. Most personal data is received from brokers and intermediaries rather than directly from the insured.


(a) Identity

(b) Contact

(c) Insurance

(d) Financial

(a) Necessary for our legitimate interests (to underwrite, assess and price risk and run our underwriting business) (b) Performance of a contract (with the broker/intermediary, or where we are party to the insurance contract) (c) Necessary to comply with a legal obligation

To issue, administer and renew policies and to manage premiums, costs and payments.


(a) Identity

(b) Contact

(c) Insurance

(d) Financial

(a) Necessary for our legitimate interests (administering insurance) (b) Necessary to comply with a legal obligation


To assess, investigate and manage claims, including with carriers and other third parties.

(a) Identity

(b) Contact

(c) Insurance

(d) Financial

(a) Necessary for our legitimate interests (handling claims) (b) Necessary to comply with a legal obligation (c) Where relevant, the establishment/exercise/defence of legal claims
To manage and develop our relationships with brokers, intermediaries, carriers, markets (e.g. Lloyd's) and prospects, including business communications and marketing to business contacts.

(a) Identity

(b) Contact

(c) Marketing and Communications

(a) Performance of a contract (b) Necessary for our legitimate interests (to manage and grow our business) (c) Consent (for certain marketing)
To carry out fraud, sanctions, anti-money-laundering and other financial-crime and due-diligence checks, including via screening providers.

(a) Identity

(b) Contact

(c) Insurance

(d) Financial

(a) Necessary to comply with a legal obligation (b) Necessary for our legitimate interests (to prevent and detect fraud and financial crime) (c) For any criminal-offence data: the relevant substantial public interest condition (DPA 2018)
To administer and protect our business and systems (IT support, troubleshooting, data analysis, testing, system maintenance, network security, access control, reporting and hosting).

(a) Identity

(b) Contact

(c) Technical

(d) IT and Security

(a) Necessary for our legitimate interests (running our business, provision of IT services, network security, to prevent fraud, and in the context of a business reorganisation or group restructuring) (b) Necessary to comply with a legal obligation
To comply with our legal and regulatory obligations and the codes we follow (e.g. FCA, PRA, Lloyd's), to respond to regulators and authorities, and to establish or defend legal claims.

(a) Identity

(b) Contact

(c) Insurance

(d) Financial

(a) Necessary to comply with a legal obligation (b) Necessary for our legitimate interests (c) Where relevant, the establishment/exercise/defence of legal claims

Marketing

We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising.


Third-party marketing - we will not share your information with any third parties for the purposes of direct marketing.


Opting out - you can ask us to stop sending you marketing messages at any time by following the opt-out links on any marketing message sent to you.

5. WHO WE SHARE YOUR INFORMATION WITH

Your personal information may be transferred to other third-party organisations in certain scenarios:

  • to insurers, carriers, brokers and insurance markets (for example Lloyd's) where this is necessary to obtain quotes, place or administer your cover, or handle a claim.
  • to service providers who process information on our behalf to deliver our services to you.
  • to carry out fraud, sanctions, anti-money-laundering and other financial-crime checks, including via screening providers.
  • if we discuss selling or transferring part or all of our business, the information may be transferred to prospective purchasers under suitable terms as to confidentiality.
  • if we are reorganised or sold, information may be transferred to a buyer who can continue to provide services to you.
  • if we are required to by law, or under any regulatory code or practice we follow, or if we are asked by any public or regulatory authority, for example the Police, or insurance regulators such as the FCA, PRA or Lloyd's.
  • if we are defending a legal claim your information may be transferred as required in connection with defending such claim.
  • if there is an emergency which requires us to share your data to protect the health and safety of our website's or app's users or the general public.

Our suppliers and service providers will be required to meet our standards on processing information and security. The information we provide them will only be provided in connection with the performance of their function. They will not be permitted to use your information for any purposes other than those outlined in this privacy notice.

If we are not able to share your information with these third parties, you will not be able to receive our services.

Your personal data may also be shared with third parties if it is made anonymous and aggregated. In such circumstances the information will cease to be personal data.

6. INTERNATIONAL TRANSFERS

We share your personal data with our suppliers and service providers, which were described above. This will involve transferring your data outside the United Kingdom (UK) and the European Economic Area (EEA). Many of our external third parties are based outside the UK and the EEA, including in the United States, so their processing of your personal data will involve a transfer of data outside the UK and the EEA.


Where a transfer is subject to PIPA, we assess whether the law applying to the overseas recipient gives a level of protection comparable to PIPA. If we cannot reasonably conclude that it does, we put in place contractual clauses or other appropriate measures, or rely on an exception permitted under PIPA. We remain responsible for your personal information after we transfer it.


Whenever we transfer your information out of the UK or the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:


  • We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission or, for transfers from the UK, by the UK Government under UK ‘adequacy’ regulations. For further details, see European Commission: Adequacy of the protection of personal data in non-EU countries.
  • Where we use certain service providers, we may use specific contracts approved by the European Commission (the EU standard contractual clauses), together with the UK International Data Transfer Addendum to those clauses issued by the Information Commissioner’s Office (ICO) where the transfer is from the UK, which give personal data the same protection it has in the UK and Europe. For further details, see European Commission: Model contracts for the transfer of personal data to third countries.
7. HOW WE PROTECT YOUR INFORMATION

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.


We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

8. DATA RETENTION

How long will you use my personal information for?

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for.


To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.


By law we have to keep basic information about our customers (including Contact, Identity, Financial and Transaction Data) for 6 years after they cease being customers for tax purposes.

9. YOUR RIGHTS

Under certain circumstances, you have rights under data protection laws in relation to your personal data.


We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex. In this case, we will notify you and keep you updated.


If you wish to exercise any of the rights set out below please contact us by emailing dataprotectionofficer@unitedrisk.global.


You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.


We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights).


Your Rights in Detail

Depending on your jurisdiction and based on the applicable laws, you may have the right to:


Request access to your personal data (commonly known as a "data subject access request"). This enables you to receive a copy of the personal data we hold about you.


Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected.


Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons.


Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) or where we are processing your personal data for direct marketing purposes.


Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:

  • If you want us to establish the data's accuracy.
  • Where our use of the data is unlawful, but you do not want us to erase it.
  • Where you need us to hold the data even if we no longer require it.
  • You have objected to our use of your data, so we need to verify our legitimate interests.


Request the transfer of your personal data to you or to a third party. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.


Withdraw consent at any time where we are relying on consent to process your personal data.


Right to Data Portability: Subject to applicable law, you may have the right to receive certain personal information that you have provided to us in a structured, commonly used, and machine-readable format. Where technically feasible, you may also request that we transmit this information to another organization.


Rights to Contest Automated Decision-Making and Profiling: Where we make decisions about you based solely on automated processing, as permitted by applicable law, you may have the right to request information about the decision, obtain human review, express your point of view, and contest the decision.


Right to opt-out of Targeted Advertising, Sharing and Sales: United Risk does not sell your personal information.


Non-discrimination: United Risk will not discriminate individuals for exercising their rights.


Right to Unsubscribe: You may unsubscribe or Opt-out of receiving marketing or promotions communications.

10. HOW TO CONTACT US OR MAKE A COMPLAINT

If you have any questions about this privacy notice or our privacy practices, please contact our Data Protection Officer at dataprotectionofficer@unitedrisk.global.


You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK regulator for data protection issues (www.ico.org.uk) or the relevant Supervisory Authority in the European Union (You can find the Supervisory Authority in the country in which you live at: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en), the Office of the Privacy Commissioner for Bermuda (PrivCom) at www.privacy.bm where our use of your personal information is subject to PIPA, or the applicable privacy or data protection authority in your country of residence . We would, however, appreciate the chance to deal with your concerns before you approach a Supervisory Authority, so please contact us in the first instance.