| Effective: 2024 February 1 | Privacy Hub |
Westfield Specialty, Ltd., its subsidiaries and affiliates ("Westfield Specialty Ltd" or "we," "us" or "our") respect your privacy. This Privacy Notice ("Privacy Notice") applies to all insurance customers of Westfield Specialty Ltd companies located in the United Kingdom (“UK”), the European Union (“EU”) and the United Arab Emirates ("UAE").
For the purposes of European data protection laws, Westfield Specialty Ltd is the controller of personal data processed via our websites or where you otherwise interact with us as a claimant, insurance applicant, policyholder or business partner.
This Privacy Notice explains how, when and why we collect and use your personal data, including but not limited to:
It is also important that you show this Privacy Notice to any other person whose personal data may be shared with us as a result of the provision of our services to you. This Privacy Notice is not intended to override the terms of any insurance policy or contract you have with us, nor rights you are afforded under applicable privacy and data protection laws.
When we use the term "personal data," we mean any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
We may collect and process the following personal data of applicants and policyholders:
In order to receive and process claims, we need to collect and process the following personal data about you:
We may collect and process the following personal data (of employees and representatives) of business partners:
We may collect and process the following personal data if you visit one of our websites:
If you do not provide the personal data listed above, we may not be able to provide our services to you including but not limited to providing insurance quotes, issue insurance policies, and administer your insurance, processing a claim or entering into an agreement. If you subsequently revoke or limit our use of your personal data by exercising your data subject rights as described in the section ‘Your Privacy Rights’ below, we may not be able to (continue to) provide or we may have to cancel our services or will not be able to (continue to) process your personal data for the other purposes described in the section ‘Purposes and Legal Bases Of Your Personal Data’.
We will collect your personal data:
We will collect your personal data:
We will collect your personal data:
We will collect your personal data:
We process personal data for the following purposes and legal bases:
| Category of Personal Data | Purpose of Processing | Legal Basis |
|---|---|---|
| Contact details, Identification Details, Financial and Anti-Fraud Data | To consider an application for an insurance policy, assess, evaluate, and manage risk, and where applicable, provide you with insurance coverage | The processing is necessary to perform a contract or enter into a contract with you (e.g., the insurance policy) (Article 6(1)(b), UK GDPR) |
| Contact Details, Identification Details, Financial and Anti-Fraud Data | For reinsurance purposes | The processing is necessary to support our legitimate interests in managing our business (or those of a third party), provided such interests are not overridden by your interests and rights (Article 6(1)(f), UK GDPR) |
| Contact details, Identification Details, Financial and Anti-Fraud Data, Other Information | To manage our relationship with you To grant access to Westfield systems and resources necessary for you to deliver the requested services |
The processing is necessary to perform a contract or enter into a contract with you (Article 6(1)(b), UK GDPR) The processing is necessary to support our legitimate interests in managing our business (or those of a third party), provided such interests are not overridden by your interests and rights (Article 6(1)(f), UK GDPR) |
| Sensitive Personal Data | ||
| Data Concerning Criminal Convictions and Offences | To confirm initial and continued eligibility for business transactions | Westfield Specialty Ltd has a legal obligation to ensure compliance with anti-moneylaundering and other financial crimes statutes and regulations (Article 6(1)(c), UK GDPR) |
| Category of Personal Data | Purpose of Processing | Legal Basis |
|---|---|---|
| Contact Details, Identification Details, Financial and Anti-Fraud Data, Claims Information | For claims processing, which includes assessing and evaluating the merits of a claim and, where relevant, paying a settlement | The processing is necessary to perform a contract or enter into a contract with you (e.g., the settlement agreement) (Article 6(1)(b), UK GDPR) The processing is necessary to support our legitimate interests in managing our business (or those of a third party), provided such interests are not overridden by your interests and rights (Article 6(1)(f), UK GDPR) Westfield Specialty Ltd may have a legal obligation to do so (Article 6(1)(c), UK GDPR) |
| Contact details, Identification Details, Financial and Anti-Fraud Data, Claims Information | For claims processing, which includes assessing and evaluating the merits of a claim and, where relevant, paying a settlement | The processing is necessary to perform a contract or enter into a contract with you (e.g., the insurance policy or settlement agreement) (Article 6(1)(b), UK GDPR) The processing is necessary to support our legitimate interests in managing our business (or those of a third party), provided such interests are not overridden by your interests and rights (Article 6(1)(f), UK GDPR) |
| Sensitive Personal Data | ||
| Data Concerning Criminal Convictions and Offences | To confirm initial and continued eligibility for business transactions | Westfield Specialty Ltd has a legal obligation to ensure compliance with anti-moneylaundering and other financial crimes statutes and regulations (Article 6(1)(c), UK GDPR) |
| Category of Personal Data | Purpose of Processing | Legal Basis |
|---|---|---|
| Contact Details, Identification details, Financial Information | To provide our services to you | The processing is necessary to perform a contract or enter into a contract with you (e.g., the insurance policy) (Article 6(1)(b), UK GDPR) |
| Contact Details, Identification Details, Financial Information, Other Information | To manage our relationship with you | The processing is necessary to perform a contract or enter into a contract with you (Article 6(1)(b), UK GDPR) The processing is necessary to support our legitimate interests in managing our business (or those of a third party), provided such interests are not overridden by your interests and rights (Article 6(1)(f), UK GDPR) |
You have a right to object to the processing of your personal data where that processing is carried out for our legitimate interests. Please note however that Westfield Specialty Ltd may not be able to fulfil this request in all instances.
We may share the personal data we have collected about you with our affiliates or third parties, as described below.
We may share your personal data with other Westfield group companies to assist in the delivery of services to you, and for other purposes authorized under this Privacy Notice.
We may disclose your personal data to intermediaries (e.g., brokers, managing general agents, third-party administrators) and other (re)insurers to assist us in managing our business.
We may use third-party processors, service providers and/or vendors to perform certain services on our behalf, such as technical support and back-office services, loss adjustors and claims experts, hosting services and website activity tracking and analytics. We may also disclose your personal data to our professional advisors (e.g., attorneys and other professional services firms).
We may disclose your personal data to judicial, regulatory and law enforcement bodies, for reasons including but not limited to: (1) satisfying any applicable law, regulation, governmental requests or legal process if in our good faith opinion, such disclosure is required or permitted by law; (2) protecting and/or defending our rights, property and/or interests (including the enforcement of the Terms and Conditions of any of our websites); (3) protecting the safety, rights, property or security of Westfield Specialty Ltd or any third party; and (4) detecting, preventing or otherwise addressing fraud, security or technical issues. Such disclosures may be carried out without notice to you to the extent permitted or required by law.
Subject to applicable law, we reserve the right to transfer some or all personal data in our possession to a potential successor organization in the event of a merger, acquisition, bankruptcy, or other sale or transfer of all or a portion of our assets. If any such transaction occurs, the purchaser / successor organization will be entitled to use and disclose the personal data collected by us in the same manner that we are able to, and the purchaser / successor organization will assume the rights and obligations regarding your personal data as described in this Privacy Notice.
You may have certain rights in relation to your personal data under applicable privacy and data protection law, which may be subject to certain limitations and restrictions:
| Right of access | You can ask us to confirm whether we are processing your personal data and request a copy of that personal data. |
| Right to rectification | You have the right to request that we correct any inaccuracies in the personal data we hold about you and to complete any personal data that is incomplete. |
| Right to erasure ("right to be forgotten") | You have the right to request that your personal data be deleted in certain circumstances. |
| Right to restrict processing | You can ask that we restrict the processing of your personal data (i.e., keep but not use it) in certain circumstances. |
| Right to data portability | Where you have provided personal data to us, you have a right to receive such personal data back in a structured, commonly used and machine-readable format. You may also have the right to have your personal data transmitted to a third-party data controller without hindrance in certain circumstances. |
| Right to object | You have a right to object where we are processing your personal data in reliance on our legitimate interests or for direct marketing purposes. |
| Automated decision-making | You have a right not to be subject to decisions based solely on automated processing when such decisions produce legal effects concerning you or similarly significantly affects you in certain circumstances. |
| Right to complain | If you are not satisfied with our use of your personal data or our response to any request made by you to exercise any of your rights, you have the right to lodge a complaint with the local data protection supervisory authority at any time. |
| Right to withdraw consent | If we are processing your personal data on the legal basis of consent, you are entitled to withdraw your consent at any time. |
To exercise any of your applicable rights, please contact us at the email listed below or visit Data Subject Rights Request to submit your request. You may also authorize someone to exercise the above rights on your behalf. We aim to respond to any valid requests within one month unless it is particularly complicated, or you have made repeated requests, in which case we aim to respond within three months. We will inform you of any such extension within one month of receipt of your request, together with the reasons for the delay.
You will not be charged a fee to exercise any of your rights unless your request is clearly unfounded, repetitive or excessive, in which case we will charge a reasonable fee in the circumstances or will refuse to act on the request. To protect your privacy, Westfield Specialty Ltd may take steps to verify your identity before fulfilling your request.
The personal data we collect from you may be transferred to and stored at locations outside of the jurisdiction you are in, to locations where we and our third-party service providers have operations (including Bermuda, the UAE and the United States) for the purposes described above.
For intra-group transfers of personal data, Westfield Specialty Ltd has entered into an intra-group data transfer agreement. For cross-border transfers of personal data to other recipients, including our service providers, Westfield Specialty Ltd will put in place appropriate safeguards so that personal data is and remains protected. These may include implementing the Standard Contractual Clauses with the UK International Data Transfer Addendum or Binding Corporate Rules, or otherwise in reliance on a derogation for the transfer (e.g., where the transfer is necessary for the defence of legal claims).
If you would like further information about the safeguards we have implemented, please contact us using the contact details below.
We implement technical and organizational security measures designed to secure and protect personal data. Please note, however, that we cannot fully eliminate security risks associated with the storage and transmission of personal data.
We will retain your personal data for as long as is necessary to fulfil the purposes for which we obtained the personal data, including to provide our services, or for such longer period as may be required or permitted by applicable law. We will also retain your personal data as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements and policies. We use the following criteria to set our retention periods: (1) the duration of our relationship with you; (2) the purposes for processing your personal data and associated legal bases; (3) the existence of a legal obligation; (4) our contractual obligations; and (5) the advisability of retaining the data in light of our legal position (for example, in light of applicable statutes of limitations, litigation or regulatory investigations).
Our websites and services are not targeted at children, as defined by local law, and we do not knowingly collect any personal data from children. We will delete any personal data we determine to have been collected from a child as defined under applicable privacy and data protection laws. If you are a parent or guardian of a child and believe he or she has disclosed personal data to us, please contact us as described below.
Our websites may contain content that is supplied by a third party, and those third parties may collect usage information and your device identifier when webpages from the website are served to you. Our website may also contain links to third parties. This Privacy Notice does not apply to, and we are not responsible for the data collection and privacy practices employed by any of these third parties on their websites. We encourage you to review their privacy notices. Our websites may include social network sharing widgets that may provide information to their associated social networks or third parties about your interactions with our webpages that you visit, even if you do not click on or otherwise interact with the plug-in or widget. Information is transmitted from your browser and may include an identifier assigned by the social network or third party, information about your browser type, operating system, device type, IP address, and the URL of the webpage where the widget appears. If you use social network tools or visit social networking sites, we encourage you to read their privacy disclosures to learn what information they collect, use and share.
This Privacy Notice is reviewed and updated periodically. The most recent version of the Privacy Notice is reflected by the version date located at the top of this page. We encourage you to review this Privacy Notice often to stay informed of how we may process your information. If we make material changes to this Privacy Notice, we will notify individuals by email to their registered email address, by prominent posting on our website or through other appropriate communication channels.
Email: privacy@westfieldgrp.com.
Post:
Floor 36
22 Bishopsgate
London
EC2N 4BQ
United Kingdom