Privacy policy
1. About us
- Hiscox Syndicates Limited, company number 02590623, registered address: 1 Great St Helens, London EC3A 6HX.
- Hiscox Underwriting Services Limited, company number 03294530, registered address: 1 Great St Helens, London EC3A 6HX.
- Hiscox Underwriting Ltd, company number 02372789, registered address: 1 Great St Helens, London EC3A 6HX
- Hiscox Insurance Company Limited, company number 00070234, registered address: 1 Great St Helens, London EC3A 6HX.
- Hiscox Underwriting Group Services Limited, company number 04137419, registered address: 1 Great St Helens, London EC3A 6HX
2. About the insurance market
3. What personal information do we collect and use?
- General information such as your name, address, contact details, date of birth, gender and relationship to the policyholder (where you are not the policyholder).
- Identification information such as national insurance number, passport number or driving licence number.
- Information about your job including job title, your status as a director or partner, employment history, education history and professional accreditations.
- Information which is relevant to your insurance policy including details of previous insurance policies and claims history. This will depend on the type of policy you hold with us. For example, if you hold a household policy, we may collect and use information which relates to your property or if you hold a travel policy, we may collect and use information which relates to your travel plans.
- Information relevant to any claim or complaint you may make. This will depend on the type of claim or complaint you make. For example, if you make a claim following a road traffic accident, we may use personal information which relates to your vehicle and named drivers.
- Financial information such as your bank details, payment details and information obtained as a result of our credit checks. This may include details of any bankruptcy orders, individual voluntary arrangements or county court judgements.
- Information (including photographs) obtained as a result of carrying out checks of publically available sources such as newspapers and social media sites in the event that we suspect fraudulent activity.
- Information we obtain as a result of checking sanctions lists, such as those published by United Nations, European Union, UK Treasury, the U.S. Office of Foreign Assets Control (OFAC) and the U.S. Department of Commerce, Bureau of Industry and Security.
- Information such as IP address and browsing history obtained through our use of cookies. You can find more information about this in our cookies policy which can be found at https://www.hiscox.co.uk/cookies-privacy/cookie-policy.
- Information obtained during telephone recordings.
- Your marketing preferences and details of your customer experience with us.
- the named policyholder (where you are a beneficiary);
- third parties involved in the relevant insurance policy or claim (such as our business partners and representatives, brokers or other insurers, claimants, defendants or witnesses to an incident);
- third parties who provide a service in relation to the relevant insurance policy or claim (such as loss adjusters, claims handlers, and medical experts);
- publically available sources such as internet search engines, news articles and social media sites;
- other companies within the Hiscox Group;
- credit reference agencies;
- financial crime detection agencies and databases (such as for fraud prevention and checking against international sanctions) including the Claims Underwriting Exchange (known as ‘CUE’);
- third parties who provide sanctions checking services;
- government agencies such as the police, the National Crime Agency, the DVLA or HMRC;
- insurance industry bodies (including the Employers’ Liability Tracing Office and the Association of British Insurers);
- third parties who provide us with details of individuals who have expressed an interest in hearing about insurance products;
- in limited circumstances, private investigators;
- third-party data suppliers (for example in relation to flood modelling data and property surveys and valuations);
- third party administrators and suppliers we appoint to help us carry out our everyday business activities including IT suppliers, actuaries, auditors, lawyers, document management providers, outsourced business process management providers, our subcontractors and tax advisers;
- our own websites; and
- selected third parties in connection with any sale, transfer or disposal of our business.
- We need to use your personal information to enter into or perform a contract that we hold with you. For example, we need to use your personal information to provide you with a quote or to provide your insurance policy and other associated products (e.g. legal expenses cover). We will rely on this for activities such as assessing your application, managing your insurance policy, handling claims and providing other products to you.
- We have a legal or regulatory obligation to use such personal information. For example, our regulators require us to hold certain records of our dealings with you.
- We have an appropriate business need (sometimes referred to as a ‘legitimate interest’) to use your personal information. We will rely on this for activities such as maintaining our business records, training and quality assurance, and developing and improving our products and services.
- Such use is necessary to protect your vital interests. For example, in relation to a kidnap claim.
- You have provided your consent to our use of your personal information (e.g. in relation to your marketing preferences).
- We need to use your sensitive personal information for an insurance purpose and there is a substantial public interest in such use. Such purposes include assessing your insurance application, managing claims and preventing and detecting fraud.
- We need to use your sensitive personal information to comply with or help someone else comply with a regulatory requirement relating to unlawful acts and dishonesty and there is a substantial public interest in such use.
- We need to use your sensitive personal information to establish, exercise or defend legal rights. This might happen when we are faced with legal proceedings or want to bring legal proceedings ourselves or when we are investigating a legal claim that a third party brings against you.
- We need to use your sensitive personal information to prevent or detect crime and there is a substantial public interest in such use. This might happen when we are investigating allegations of insurance fraud.
- Such use is necessary to protect your vital interests. For example, in relation to a kidnap claim.
- You have provided your explicit consent to our use of your sensitive personal information.
Purpose for processing | Legal grounds for using your personal information | Legal grounds for using your sensitive personal information |
To carry out fraud, credit and anti-money laundering checks. |
|
|
To evaluate your insurance application or renewal and provide you with a quote. |
|
|
To administer your insurance contract including taking payments and making changes where requested or necessary. |
|
|
To manage insurance claims. |
|
|
To prevent and investigate fraud and other crime. |
|
|
To communicate with you (including assessing whether you are a vulnerable person) and resolve any complaints that you might have. |
|
|
To comply with our legal or regulatory obligations. | We have a relevant legal or regulatory obligation. |
|
To provide improved quality, training and security (for example, through recorded or monitored phone calls to our contact numbers, or carrying out customer satisfaction surveys) | We have an appropriate business need (to develop and improve the products and services we offer). | You have given us your explicit consent. |
To enable us to manage our business operations, such as by maintaining accounting records, carrying out analysis of financial results, using information to meet internal audit requirements, and receiving professional advice (e.g. tax or legal advice) |
|
|
For insurance risk modelling and product and pricing refinement. | We have an appropriate business need (to develop and improve the products and services we offer). | You have given us your explicit consent. |
To apply for and claim on our insurance. | We have an appropriate business need (to ensure that we have appropriate insurance in place). |
|
To carry out marketing analysis, customer segmentation and campaign planning. |
|
Not applicable. |
To provide marketing information to you in accordance with preferences you have expressed. |
|
Not applicable. |
To buy or sell Group companies or to restructure our business. |
|
You have given us your explicit consent. |
- other companies in the Hiscox Group, including where:
- one of our Group companies is placing your insurance policy with another Group company;
- one of our Group companies is unable to provide you with an insurance policy but another might be able to assist you;
- we are arranging our own insurance;
- necessary for our business administration purposes;
- we are using information for the prevention or detection of fraud or other crime; or
- we need to report information within our Group of companies.
- our insurance and reinsurance partners such as brokers, other (re)insurers or other companies who act as (re)insurance distributors;
- other third parties who assist in the administration of your insurance policy or claim, such as loss adjusters, claims handlers, accountants, auditors, banks, lawyers and other experts including medical experts;
- companies who provide you with certain services such as home emergency cover and legal expenses cover;
- our regulators;
- other insurers;
- fraud detection agencies and other third parties who operate and maintain fraud detection registers (including the Motor Insurance Database) or undertake investigations in cases of suspected insurance fraud;
- the police and other third parties (such as banks or other insurance companies);
- other insurers who provide our own insurance;
- industry bodies (such as the Association of British Insurers, Lloyd’s Market Association or Employers’ Liability Tracing Office);
- credit referencing agencies and third parties who carry out sanctions checks on our behalf;
- our third party services providers, such as IT suppliers, actuaries, auditors, lawyers, document management providers, outsourced business process management providers and tax advisers;
- third parties who handle our direct marketing on our behalf (this includes, for example, inclusion or suppression of your personal information from our contact lists, sending marketing communications, and analysis of responses to our marketing communications);
- social media sites (such as Facebook) to carry out marketing;
- selected third parties in connection with any sale, transfer or disposal of our business; or
- where necessary, courts and other alternative dispute resolution providers (such as arbitrators, mediators and the Financial Ombudsman Service).
- General information such as your name, address, contact details, date of birth and gender.
- Identification information such as your national insurance number, passport number or driving licence number.
- Information about your job including job title, your status as a director or partner, employment history, education history and professional accreditations.
- Information relevant to your claim. This will depend on the type of claim you make. For example, if you make a claim following a road traffic accident, we may use personal information which relates to your vehicle and named drivers.
- Information relating to previous insurance policies or claims.
- Financial information such as your bank details and payment details.
- Information (including photographs) obtained as a result of carrying out checks of publically available sources such as newspapers and social media sites in the event that we suspect fraudulent activity.
- Information we obtain as a result of checking sanctions lists.
- Information such as IP address and browsing history obtained through our use of cookies. You can find more information about this in our cookies policy which can be found at https://www.hiscoxcollection.com/CookiePolicy.aspx.
- Information obtained during telephone recordings.
- Information relating to your criminal convictions (including offences and alleged offences and any court sentence or unspent criminal conviction).
- If relevant, details of your current or former health condition. For example, if you are injured whilst at a property insured by Hiscox, and the owner of the property makes a claim under their insurance policy in relation to your injury.
- In limited circumstances, we may process other sensitive personal information including details of your race; ethnicity; religious or philosophical beliefs; political opinions; trade union membership; genetic or biometric data; or data concerning your sex life or sexual orientation if relevant to your claim. For example, we may process information relating to your religious beliefs if relevant as part of your medical treatment.
- the policyholder;
- third parties involved in the relevant insurance policy or claim (such as our business partners and representatives, brokers or other insurers, claimants, defendants or witnesses to an incident);
- third parties who provide a service in relation to the relevant insurance policy or claim (such as loss adjusters, claims handlers, and medical experts);
- publically available sources such as internet search engines, news articles and social media sites;
- other companies within the Hiscox Group;
- credit reference agencies;
- financial crime detection agencies and databases (such as for fraud prevention and checking against international sanctions) including the Claims Underwriting Exchange (known as ‘CUE’);
- third parties who provide sanctions checking services;
- government agencies such as the police, the National Crime Agency, the DVLA or HMRC;
- insurance industry bodies (including the Employers’ Liability Tracing Office and the Association of British Insurers);
- in limited circumstances, private investigators;
- third party data suppliers (for example in relation to flood modelling data and property surveys and valuations);
- third-party administrators and suppliers we appoint to help us carry out our everyday business activities including IT suppliers, actuaries, auditors, lawyers, document management providers, outsourced business process management providers, our subcontractors and tax advisers;
- our own websites; and
- selected third parties in connection with any sale, transfer or disposal of our business.
- We have a legal or regulatory obligation to use such personal information. For example, our regulators require us to hold certain records of our dealings with you.
- We have an appropriate business need (sometimes referred to as a ‘legitimate interest’) to use your personal information. We will rely on this for activities such as maintaining our business records, training and quality assurance, and developing and improving our products and services.
- You have provided your consent to our use of your personal information.
- When the information that we process is classed as ‘sensitive personal information’, we must have an additional ‘legal ground’. We will rely on the following legal grounds when we process your ‘sensitive personal information’:
- We need to use your sensitive personal information for an insurance purpose and there is a substantial public interest in such use. Such purposes include managing claims and preventing and detecting fraud.
- We need to use your sensitive personal information to establish, exercise or defend legal rights. This might happen when we are faced with legal proceedings or want to bring legal proceedings ourselves or when we are investigating a legal claim that a third party brings against you.
- We need to use your sensitive personal information to prevent or detect crime and there is a substantial public interest in such use. This might happen when we are investigating allegations of insurance fraud.
- We need to use your sensitive personal information to comply with or help someone else comply with a regulatory requirement relating to unlawful acts and dishonesty and there is a substantial public interest in such use.
- You have provided your explicit consent to our use of your sensitive personal information.
Purpose for processing | Legal grounds for using your personal information | Legal grounds for using your sensitive personal information |
To administer claims. |
|
|
To carry out fraud, credit and anti-money laundering checks. |
|
|
To communicate with you (including assessing whether you are a vulnerable person) and resolve any complaints that you might have. |
|
|
To comply with our legal or regulatory obligations. |
|
|
To provide improved quality, training and security (for example, through recorded or monitored phone calls to our contact numbers, or carrying out customer satisfaction surveys) |
|
|
To enable us to manage our business operations, such as by maintaining accounting records, carrying out analysis of financial results, using information to meet internal audit requirements, and receiving professional advice (e.g. tax or legal advice) |
|
|
To prevent and investigate fraud and other crime. |
|
|
For insurance risk modelling and product and pricing refinement. |
|
|
To apply for and claim on our own insurance. |
|
|
To buy or sell Group companies or to restructure our business. |
|
|
- other companies in the Hiscox Group, including where:
- we are arranging our own insurance;
- necessary for our business administration purposes;
- we are using information for the prevention or detection of fraud or other crime; or
- we need to report information within our Group of companies.
- our insurance and reinsurance partners such as brokers, other (re)insurers or other companies who act as (re)insurance distributors;
- other third parties who assist in the administration of your insurance claim, such as loss adjusters, claims handlers, accountants, auditors, banks, lawyers and other experts including medical experts;
- companies who provide you with certain services such as home emergency cover and legal expenses cover;
- our regulators;
- other insurers;
- fraud detection agencies and other third parties who operate and maintain fraud detection registers (including the Motor Insurance Database) or undertake investigations in cases of suspected insurance fraud;
- the police and other third parties (such as banks or other insurance companies);
- other insurers who provide our own insurance;
- industry bodies (such as the Association of British Insurers, Lloyd’s Market Association or Employers’ Liability Tracing Office);
- credit referencing agencies and third parties who carry out sanctions checks on our behalf;
- our third-party services providers, such as IT suppliers, actuaries, auditors, lawyers, document management providers, outsourced business process management providers and tax advisers;
- selected third parties in connection with any sale, transfer or disposal of our business; or
- where necessary, courts and other alternative dispute resolution providers (such as arbitrators, mediators and the Financial Ombudsman Service).
- General information such as your name, address, contact details, date of birth and gender.
- Identification information such as your national insurance number, passport number or driving licence number.
- Information about your job including job title, your status as a director or partner, employment history, education history and professional accreditations.
- Information relevant to any claim made.
- Information relating to previous insurance policies or claims.
- Financial information such as your bank details and payment details.
- Information (including photographs) obtained as a result of carrying out checks of publically available sources such as newspapers and social media sites in the event that we suspect fraudulent activity.
- Information we obtain as a result of checking sanctions lists.
- Information such as IP address and browsing history obtained through our use of cookies. You can find more information about this in our cookies policy which can be found [here].
- Information obtained during telephone recordings.
- Information relating to your criminal convictions (including offences and alleged offences and any court sentence or unspent criminal conviction).
- If relevant, details of your current or former health condition. For example, if you are injured whilst at a property insured by Hiscox, and the owner of the property makes a claim under their insurance policy in relation to your injury.
- In limited circumstances, we may process other sensitive personal information including details of your race; ethnicity; religious or philosophical beliefs; political opinions; trade union membership; genetic or biometric data; or data concerning your sex life or sexual orientation if relevant to the policy. For example, we may process information relating to your religious beliefs if relevant as part of your medical treatment.
- the policyholder;
- third parties involved in the relevant insurance policy or claim (such as our business partners and representatives, brokers or other insurers, claimants, defendants or witnesses to an incident);
- third parties who provide a service in relation to the relevant insurance policy or claim (such as loss adjusters, claims handlers, and medical experts);
- publically available sources such as internet search engines, news articles and social media sites;
- other companies within the Hiscox Group;
- credit reference agencies;
- financial crime detection agencies and databases (such as for fraud prevention and checking against international sanctions) including the Claims Underwriting Exchange (known as ‘CUE’);
- third parties who provide sanctions checking services;
- government agencies such as the police, the National Crime Agency, the DVLA or HMRC;
- insurance industry bodies (including the Employers’ Liability Tracing Office and the Association of British Insurers);
- in limited circumstances, private investigators;
- third party data suppliers (for example in relation to flood modelling data and property surveys and valuations);
- third party administrators and suppliers we appoint to help us carry out our everyday business activities including IT suppliers, actuaries, auditors, lawyers, document management providers, outsourced business process management providers, our subcontractors and tax advisers;
- our own websites; and
- selected third parties in connection with any sale, transfer or disposal of our business.
- We have a legal or regulatory obligation to use such personal information. For example, our regulators require us to hold certain records of our dealings with you.
- We have an appropriate business need (sometimes referred to as a ‘legitimate interest’) to use your personal information. We will rely on this for activities such as maintaining our business records, training and quality assurance, and developing and improving our products and services.
- Such use is necessary to protect your vital interests. For example, in relation to a kidnap claim.
- You have provided your consent to our use of your personal information.
- We need to use your sensitive personal information for an insurance purpose and there is a substantial public interest in such use. Such purposes include assessing the insurance application, managing claims and preventing and detecting fraud.
- We need to use your sensitive personal information to establish, exercise or defend legal rights. This might happen when we are faced with legal proceedings or want to bring legal proceedings ourselves or when we are investigating a legal claim that a third party brings against you.
- We need to use your sensitive personal information to prevent or detect crime and there is a substantial public interest in such use. This might happen when we are investigating allegations of insurance fraud.
- We need to use your sensitive personal information to comply with or help someone else comply with a regulatory requirement relating to unlawful acts and dishonesty and there is a substantial public interest in such use.
- Such use is necessary to protect your vital interests. For example, in relation to a kidnap claim.
- You have provided your explicit consent to our use of your sensitive personal information.
Purpose for processing | Legal grounds for using your personal information | Legal grounds for using your sensitive personal information |
To carry out fraud, credit and anti-money laundering checks. |
|
|
To manage any claims you make under the relevant Hiscox insurance policy. |
|
|
To comply with our legal or regulatory obligations. |
|
|
To communicate with you (including assessing whether you are a vulnerable person) and resolve any complaints that you might have. |
|
|
To prevent and investigate fraud and other crime. |
|
|
To provide improved quality, training and security (for example, through recorded or monitored phone calls to our contact numbers). |
|
|
To enable us to manage our business operations, such as by maintaining accounting records, carrying out analysis of financial results, using information to meet internal audit requirements, and receiving professional advice (e.g. tax or legal advice). |
|
|
For insurance risk modelling and product and pricing refinement. |
|
|
To buy or sell Group companies or to restructure our business. |
|
|
- other companies in the Hiscox Group, including where:
- one of our Group companies is placing the insurance policy with another Group company;
- one of our Group companies is unable to provide the insurance policy but another might be able to assist;
- we are arranging our own insurance;
- necessary for our business administration purposes;
- we are using information for the prevention or detection of fraud or other crime; or
- we need to report information within our Group of companies.
- our insurance and reinsurance partners such as brokers, other (re)insurers or other companies who act as (re)insurance distributors;
- other third parties who assist in the administration of the insurance policy or claim, such as loss adjusters, claims handlers, accountants, auditors, banks, lawyers and other experts including medical experts;
- our regulators;
- other insurers;
- fraud detection agencies and other third parties who operate and maintain fraud detection registers (including the Motor Insurance Database) or undertake investigations in cases of suspected insurance fraud;
- the police and other third parties (such as banks or other insurance companies);
- other insurers who provide our own insurance;
- industry bodies (such as the Association of British Insurers, Lloyd’s Market Association or Employers’ Liability Tracing Office);
- credit referencing agencies and third parties who carry out sanctions checks on our behalf;
- our third party services providers, such as IT suppliers, actuaries, auditors, lawyers, document management providers, outsourced business process management providers and tax advisers;
- selected third parties in connection with any sale, transfer or disposal of our business; or
- where necessary, courts and other alternative dispute resolution providers (such as arbitrators, mediators and the Financial Ombudsman Service).
- General information such as your name, address, contact details, date of birth and gender.
- Identification information such as your national insurance number, passport number or driving licence number.
- Information relevant to the incident that you have witnessed.
- Depending on the nature of the incident you have witnessed, and only if relevant, we may collect information relating to your criminal convictions (including offences and alleged offences and any court sentence or unspent criminal conviction) or details of your current or former physical or mental health condition.
- In limited circumstances, we may process other sensitive personal information including details of your race; ethnicity; religious or philosophical beliefs; political opinions; trade union membership; genetic or biometric data; or data concerning your sex life or sexual orientation if relevant to the your role as a witness.
- third parties involved in the incident you witnessed (such as brokers or other insurers, claimants, defendants or other witnesses);
- other third parties who provide a service in relation to the claim which relates to the incident you witnessed (such as loss adjusters, claims handlers, and experts);
- publically available sources such as the electoral roll, court judgments, insolvency registers, insurance industry databases, internet search engines, news articles and social media sites; and
- other companies within the Hiscox Group.
- We have a legal or regulatory obligation to use such personal information. For example, our regulators require us to hold certain records of our dealings with you.
- We have an appropriate business need (sometimes referred to as a ‘legitimate interest’) to use your personal information. We will rely on this for activities such as maintaining our business records, training and quality assurance, and developing and improving our products and services.
- You have provided your consent to our use of your personal information.
- We need to use your sensitive personal information for an insurance purpose and there is a substantial public interest in such use. Such purposes include assessing your insurance application, managing claims and preventing and detecting fraud.
- We need to use your sensitive personal information to establish, exercise or defend legal rights. This might happen when we are faced with legal proceedings or want to bring legal proceedings ourselves or when we are investigating a legal claim that a third party brings against you.
- We need to use your sensitive personal information to prevent or detect crime and there is a substantial public interest in such use. This might happen when we are investigating allegations of insurance fraud.
- We need to use your sensitive personal information to comply with or help someone else comply with a regulatory requirement relating to unlawful acts and dishonesty and there is a substantial public interest in such use.
- You have provided your explicit consent to our use of your sensitive personal information.
Purpose for processing | Legal grounds for using your personal information | Legal grounds for using your sensitive personal information |
To investigate and manage claims made under an insurance policy. |
|
|
To enable us to manage our business operations, such as by maintaining accounting records, carrying out analysis of financial results, using information to meet internal audit requirements, and receiving professional advice (e.g. tax or legal advice) |
|
|
To comply with our legal or regulatory obligations. |
|
|
To prevent and investigate fraud and other crime. |
|
|
To communicate with you (including assessing whether you are a vulnerable person) and resolve any complaints that you might have. |
|
|
To provide improved quality, training and security (for example, through recorded or monitored phone calls to our contact numbers). |
|
|
To buy or sell Group companies or to restructure our business. |
|
|
- other companies in the Hiscox Group, including where:
- we are arranging our own insurance;
- necessary for our business administration purposes;
- we are using information for the prevention or detection of fraud or other crime; or
- we need to report information within our Group of companies.
- our insurance and reinsurance partners such as brokers, other (re)insurers or other companies who act as (re)insurance distributors;
- other third parties who assist in the administration of the insurance policy or claim, such as loss adjusters, claims handlers, accountants, auditors, banks, lawyers and other experts including medical experts;
- our regulators;
- other insurers;
- fraud detection agencies and other third parties who operate and maintain fraud detection registers (including the Motor Insurance Database) or undertake investigations in cases of suspected insurance fraud;
- the police and other third parties (such as banks or other insurance companies);
- other insurers who provide our own insurance;
- industry bodies (such as the Association of British Insurers, Lloyd’s Market Association or Employers’ Liability Tracing Office);
- credit referencing agencies and third parties who carry out sanctions checks on our behalf;
- our third-party services providers, such as IT suppliers, actuaries, auditors, lawyers, document management providers, outsourced business process management providers and tax advisers;
- selected third parties in connection with any sale, transfer or disposal of our business; or
- where necessary, courts and other alternative dispute resolution providers (such as arbitrators, mediators and the Financial Ombudsman Service)
- General information such as your name, address, contact details, date of birth and gender.
- Information about your job such as job title, your status as a director or partner, employment history, education history and professional accreditations.
- Information which we obtain as part of checking sanctions lists.
- Other information (including publically available information) obtained as part of our due diligence checks.
- Information relating to your criminal convictions (including offences and alleged offences and any court sentence or unspent criminal conviction).
- Invoices, contracts, policies, correspondence and business cards.
- Other Hiscox Group companies.
- Publically available sources such as internet search engines.
- From service providers who carry out sanctions checks.
- We have a legal or regulatory obligation to use such personal information. For example, our regulators require us to hold certain records of our dealings with you.
- We have an appropriate business need (sometimes referred to as a ‘legitimate interest’) to use your personal information. We will rely on this for activities such as maintaining our business records, training and quality assurance, and developing and improving our products and services.
- You have provided your consent to our use of your personal information.
- We need to use your sensitive personal information for an insurance purpose and there is a substantial public interest in such use. Such purposes include assessing your insurance application, managing claims and preventing and detecting fraud.
- We need to use your sensitive personal information to establish, exercise or defend legal rights. This might happen when we are faced with legal proceedings or want to bring legal proceedings ourselves.
- We need to use your sensitive personal information to prevent or detect crime and there is a substantial public interest in such use. This might happen when we are investigating allegations of insurance fraud.
- We need to use your sensitive personal information to comply with or help someone else comply with a regulatory requirement relating to unlawful acts and dishonesty and there is a substantial public interest in such use.
Purpose for processing | Legal grounds for using your personal information | Legal grounds for using your sensitive personal information |
To comply with our legal or regulatory obligations. |
|
|
To write insurance policies and for claims handling. |
|
|
For relationship and business development purposes. |
|
|
To provide improved quality, training and security (for example, through recorded or monitored phone calls to our contact numbers). |
|
|
To manage and handle any queries you may have. |
|
|
- Other companies in the Hiscox Group including where:
- we are arranging our own insurance;
- necessary for our business administration purposes;
- we are using information for the prevention or detection of fraud or other crime; or
- we need to report information within our Group of companies.
- our other insurance and reinsurance partners such as brokers, other (re)insurers or other companies who act as (re)insurance distributors;
- our regulators;
- fraud detection agencies and other third parties who operate and maintain fraud detection registers (including the Motor Insurance Database) or undertake investigations in cases of suspected insurance fraud;
- the police and other third parties (such as banks or other insurance companies) where reasonably necessary for the prevention or detection of crime;
- other insurers who provide our own insurance;
- industry bodies (such as the Association of British Insurers, Lloyd’s Market Association or Employers’ Liability Tracing Office);
- credit referencing agencies and third parties who carry out sanctions checks on our behalf;
- our third party services providers, such as IT suppliers, actuaries, auditors, lawyers, document management providers, outsourced business process management providers and tax advisers; or
- third parties who handle our direct marketing on our behalf (this includes, for example, inclusion or suppression of your personal information from our contact lists, sending marketing communications, and analysis of responses to our marketing communications).
4. What marketing activities do we carry out?
5. How long do we keep personal information for?
6. International data transfers
7. How do we protect your information?
- physical security measures such as on-site security and CCTV;
- network security measures such as intrusion detection systems;
- access controls such as password protection and user logging; and
- virus and malware controls on our systems.
7. How do we protect your information?
- physical security measures such as on-site security and CCTV;
- network security measures such as intrusion detection systems;
- access controls such as password protection and user logging; and
- virus and malware controls on our systems.
8. Profiling and automatic decision making
Profiling
The provision of insurance is often based on profiling the likelihood of the insured event occurring. For example, we will use the information you provide in conjunction with the information provided by third party sources to assess the likelihood of a claim being made and how much it might cost and use that assessment to decide whether or not to offer you insurance and at what price.
Insurance application
For certain policy types we use an automated underwriting engine to process the personal information you provide to us for your insurance application, together with information obtained from third party sources (such as flood risk information for home insurance policies) to determine your policy premium. Other information may also be used to calculate your premium, such as the use of any specialist devices we may have provided to you as a benefit of your policy, as well as any policy history you have with us. This information is required in order to provide you with an appropriate policy premium.
Fraud prevention
We may use profiling to assess the probability that claims may be fraudulent or inaccurate. We use your personal information to evaluate and predict risks and outcomes. We do not make automated decisions based on these profiles.
Marketing
We may use profiling to provide you with information about our products and benefits that are most appropriate to you. We may also use your personal information and profile to help us to improve our marketing materials, targeting and customer journeys.
We analyse our customers to determine common characteristics and preferences. We do this by considering various types of information which may include: your location, demographic information (such as age or job title) alongside additional policy information. These characteristics and preferences enable us to understand our customers as well as to send you appropriate communications, and information which is most relevant to you.
Automated decision-making
Like many insurers, sometimes we make decisions using solely automated means. This automated process is often used in order to assist us predict the likelihood of events such a claim being made, its value and potential fraud. This helps us efficiently set premium prices which are appropriate for the insurance being provided. For example, an automated process may provide a home insurance policy price based on your postcode, risk of flooding and local crime rate.
The majority of automated decisions we make will be necessary to enter into or perform your insurance contract or necessary for insurance purposes. If not, we will ask for your consent before making any automated decisions which have a legal or substantially similar effect.
Where we make an automated decision which has a legal or substantially similar effect, you may request a review of that decision by a member of our team. We will take into account your comments and assess whether the decision was made correctly.
9. Your rights
- the rights set out below do not apply in all circumstances;
- in some cases we may not be able to comply with your request (for example, where there is a conflict with our own obligations to comply with other legal or regulatory requirements). However, we will always respond to any request you make and if we can't comply with your request, we will tell you why.
- in some circumstances exercising some of these rights (such as the right to erasure or the right to restrict processing) will mean we are unable to continue providing you with insurance and may therefore result in its cancellation. You will therefore lose the right to bring any claim or receive any benefit, including in relation to any event that occurred before you exercised your right of erasure, if our ability to handle the claim has been prejudiced. Your policy terms and conditions set out what will happen in the event your policy is cancelled.