We are committed to protecting the privacy of all persons whose personal information we handle or process. The following notice outlines how we safeguard your personal information.
As used in this notice, terms such as “we”, “our”, “UMe” and “Company” refer to the UK operations of UnderwriteMe Limited and UnderwriteMe Technology Solutions Limited.
The Protection Platform is an online service that allows the comparison of protection insurance products offered by participating insurers. UMe facilitates the provision of fully underwritten quotes (i.e. quotes for insurance which can be immediately purchased without any further underwriting being required) on such products to customers and introduces interested customers to participating insurers.
Principally, UMe acts as a processor on behalf of other insurance intermediaries and, if a product is purchased, the insurer. However, when undertaking certain statistical analysis activities, UMe may act as a data controller in its own right.
Where we get information from
Depending on which services you have used, we may receive your personal information from:
- our Protection Platform service
- an independent financial advisor (IFA)
- an insurance provider which uses our technology to provide you with an accurate quote for your insurance
What information we collect
We may collect, store, and use the following kinds of personal information:
• basic details such as name, address, contact details and salary
• details of contact we have had with you such as referrals and quotes, and any other policies or cover you may have
• details of services you have received
• information about complaints and incidents
• notes and reports about your health and any treatment and care you have received or need, including about clinic and hospital visits and medicines administered
• Information relating regarding criminal offences, including alleged offences, criminal proceedings, outcomes and sentences
What your information is used for
The information we receive will only be used for the following legitimate purposes:
- to provide you with fully underwritten protection quotations; – this is necessary for UMe (as recipient), as well as the IFAs and insurance providers (as applicable, as disclosers), who have confirmed to UMe that processing of the information is necessary (a) for our respective legitimate interests (GDPR article 6.1(f)); or (b) for the purposes of the performance of the insurance contract or for taking steps towards entering into the insurance contract (GDPR article 6.1 (b))
- sharing within our company group for other business activities and operations relating to our underwriting business, e.g. statistical analysis (using de-personalised data) to refine our group’s services, this is within our legitimate interests under (a) GDPR article 6.1 (f) “necessary for the purposes of the legitimate interests”; and (b) GDPR article 9(2)(g) (substantial public interest), as it is necessary for (i) an insurance purpose; and (ii) reasons of substantial public interest.
- keeping data up to date and accurate, this is within our legitimate interests under GDPR article 5.1 (d) “Personal data shall be: (d) accurate and, where necessary, kept up to date)”
- the prevention and detection of fraud, which is within our legitimate interests under UK Data Protection Act 2018, Schedule 1 paragraph 14.1 (a) “necessary for the purposes of preventing fraud”
- sharing with other third parties where required by law, regulatory requirement or for the prevention or detection of a crime, this is within our legitimate interests under GDPR article 9.2 (f) “processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity”
When we handle, use and store any information about your physical or mental health or criminal convictions and this is necessary for the provision of our underwriting Protection Platform comparison services then we rely on our specific legal derogation to process this Special Category Information for insurance purposes under the UK Data Protection Act 2018, Schedule 1 paragraph 20 (1) (a) “processing is necessary for an insurance purpose”.
Who we share your information with
In order to provide prices and quotes for insurance products, UMe passes the information you supply to a selection of insurers who use it to calculate the quotation. A full list of the insurers with whom we share your information is available on request.
UMe also share information within our company group for statistical purposes to improve our group services, this information is de-personalised to protect your privacy and is never used to make decisions about you or any other individual person.
Finally, we are legally required to share your information with law enforcement agencies and the data protection regulator if requested.
How we keep your information secure
All the personal information we collect is only accessed by our staff in the UK, and is located on servers within the European Union. We make sure your information is stored and shared safely. Our safeguards include ensuring that your personal information is only held on secure servers, encryption, firewalls, access controls and separation of duties.
How long we keep information for
When an intermediary uses our Protection Platform service to identify products for you, or you provide information directly and you submit an application for an insurance policy, our retention periods for personal information are based on our legitimate interests listed above and legal requirements.
We retain your personal information for as long as is necessary for the processing purpose(s) for which the information was collected, and any other permissible, related purpose. For example, we retain information relating to your policy and correspondence for the life of the policy, keeping it updated as needed, including with information from your insurance provider, (for example with claims or changes to the policy), and thereafter until the time limit for claims arising from the transaction has expired (usually 6 years), or to comply with legal requirements regarding the retention of such information. After this period your personal data will be deleted.
Where you do not complete an application or decide not to purchase a policy, we keep your application record for 6 months to allow you to re-apply for changes to covers or provider, after which time your personal data is deleted.
Your rights regarding your personal information
Your right to access information
Subject to any relevant exemptions, you are entitled to see a copy of the personal information we hold about you and to request details of how we use your information, including any disclosures made. To exercise the rights to access your information, you should contact us at the address below. There will not usually be a charge for dealing with these requests.
Your right to rectification
Under certain conditions, you may also have the right to:
• request deletion of any of your information that we are no longer legally entitled to retain
• object to any processing of your information based on the legal ground of ‘legitimate interests’ unless our reason for undertaking that processing outweighs any prejudice to your data protection rights
• restrict how we use your information whilst a complaint is being investigated
Please note – In the current circumstances we may take longer than usual to comply with access requests as our offices are currently closed. We will inform you if the request will take longer than the permitted 30 days and provide an estimated date for completion.
Your right to complain to the Information Commissioners Office
If you are not happy with our use of your information, our response to any exercise of your rights set out above, or if you believe us to be in breach of our data protection obligations, then you have the right to complain to the Information Commissioner’s Office.
Ways to contact us
UnderwriteMe Limited is registered in England and Wales under registration number 07912813, and our registered office and principal place of business is at: Tower Bridge House, St Katharine’s Way, London, E1W 1BA.
Our Data Protection Officer’s contact details are: