Skip to Main Content

Privacy Notice for International Customers

Effective: 2024 February 1

Westfield Specialty, Ltd., its subsidiaries and affiliates ("Westfield Specialty Ltd" or "we," "us" or "our") respect your privacy. This Privacy Notice ("Privacy Notice") applies to all insurance customers of Westfield Specialty Ltd companies located in the United Kingdom (“UK”), the European Union (“EU”) and the United Arab Emirates ("UAE").

For the purposes of European data protection laws, Westfield Specialty Ltd is the controller of personal data processed via our websites or where you otherwise interact with us as a claimant, insurance applicant, policyholder or business partner.

Introduction

This Privacy Notice explains how, when and why we collect and use your personal data, including but not limited to:

  • When you access any of our websites , regardless of how you access or use the website, whether via personal computers, mobile devices or otherwise.
  • When you as a representative of a company, apply for or purchase an insurance policy underwritten by us.
  • When you or someone on your behalf submits or notifies us of a claim against any of our policies or policyholders.
  • When you purchase an insurance policy from a third-party insurance company that enters into a reinsurance arrangement with us, which is referred to as "reinsurance".

 

It is also important that you show this Privacy Notice to any other person whose personal data may be shared with us as a result of the provision of our services to you. This Privacy Notice is not intended to override the terms of any insurance policy or contract you have with us, nor rights you are afforded under applicable privacy and data protection laws.

What Personal Data Do We Collect?

What is personal data?

When we use the term "personal data," we mean any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Personal data we collect

Insurance applicants and policyholders

We may collect and process the following personal data of applicants and policyholders:

  • Contact Details – Name, address, phone number, email address.
  • Identification Details – Gender, marital status, date of birth, nationality, identification numbers issued by government bodies or agencies, including license numbers of covered drivers.
  • Financial and Anti-Fraud Data – Bank account details, credit history, and credit score.
  • Claims Information – Information about previous and current claims (including other unrelated insurances).
  • Other Information – Marketing preferences and other information you may provide to us.
  • Special Categories of Personal Data and Criminal Convictions Data –These categories include data concerning your health and background checks related to criminal offenses and convictions and anti-fraud databases to the extent permitted by law.

 

Claimants

In order to receive and process claims, we need to collect and process the following personal data about you:

  • Contact Details – Name, address, phone number, email address.
  • Identification Details – Gender, marital status, date of birth, nationality, identification numbers issued by government bodies or agencies, including your driver’s license number.
  • Financial and Anti-Fraud Data – Bank account details, credit history, credit score.
  • Claims Information – Information about previous and current claims (including other unrelated insurances).
  • Other Information – Other information you may provide to us.
  • Special Categories of Personal Data – These categories include personal data revealing racial or ethnic origin, data concerning health (e.g., injuries and relevant pre-existing conditions) and background checks related to criminal offenses and convictions, and anti-fraud databases to the extent permitted by law.

 

Business partners

We may collect and process the following personal data (of employees and representatives) of business partners:

  • Contact Information – Name, address, phone number, email address.
  • Financial Information – Bank account details.
  • Claims Information – Information about previous and current claims (including other unrelated insurances).
  • Other Information – Marketing preferences, employment information, and other information you or your employer may provide to us.

 

Website and mobile application users

We may collect and process the following personal data if you visit one of our websites:

  • Contact Information – Name and email address.
  • Other Information – Marketing preferences and other information you may provide to us.
  • Internet or Other Electronic Activity Information – IP address, your device and browser type, your browsing and search history on our websites, and information regarding your interaction with our websites and our advertisements.

 

Consequences of not providing personal data

If you do not provide the personal data listed above, we may not be able to provide our services to you including but not limited to providing insurance quotes, issue insurance policies, and administer your insurance, processing a claim or entering into an agreement. If you subsequently revoke or limit our use of your personal data by exercising your data subject rights as described in the section ‘Your Privacy Rights’ below, we may not be able to (continue to) provide or we may have to cancel our services or will not be able to (continue to) process your personal data for the other purposes described in the section ‘Purposes and Legal Bases Of Your Personal Data’.

From Whom Do We Collect Your Personal Data

Applicants and policyholders

We will collect your personal data:

  • Directly from you when you apply for an insurance policy.
  • From third parties such as intermediaries (e.g., an insurance broker), other third-party insurance companies (e.g., if you are a policyholder with an insurance company that has a reinsurance arrangement with a Westfield group company) or your employer where, for example, they apply for an insurance policy under which you will be covered.
  • From other sources (e.g., credit reference agencies and government agencies) and other public sources where necessary to, for example, comply with applicable sanctions and anti-money laundering laws.
  • Claimants

    We will collect your personal data:

    • When you or a third party notifies us of a claim either directly or through intermediaries (e.g., an insurance broker or third-party claims administrator) or other third-party insurance companies (e.g., if you are a policyholder with an insurance company that has a reinsurance arrangement with Westfield group company).
    • From other sources (e.g., credit reference agencies and government agencies) and other public sources where necessary to, for example, validate the claim or comply with applicable sanctions and anti-money laundering laws.
    • Business partners

      We will collect your personal data:

      • Where you (as an employee or representative of our business partner) or the business partner provide your contact or other information to us while working with us.
      • Where you attend meetings, events or conferences that we organize or sponsor.

           

          Website and mobile application users

          We will collect your personal data:

          • Where you visit and/or contact us one of our websites, for example through cookies and other related technologies.

           

          Purposes and Legal Bases Of Your Personal Data

          We process personal data for the following purposes and legal bases:

          Applicants and policyholders

          Category of Personal Data Purpose of Processing Legal Basis
          Contact details, Identification Details, Financial and Anti-Fraud Data To consider an application for an insurance policy, assess, evaluate, and manage risk, and where applicable, provide you with insurance coverage The processing is necessary to perform a contract or enter into a contract with you (e.g., the insurance policy) (Article 6(1)(b), UK GDPR)
          Contact Details, Identification Details, Financial and Anti-Fraud Data For reinsurance purposes The processing is necessary to support our legitimate interests in managing our business (or those of a third party), provided such interests are not overridden by your interests and rights (Article 6(1)(f), UK GDPR)
          Contact details, Identification Details, Financial and Anti-Fraud Data, Other Information To manage our relationship with you
          To grant access to Westfield systems and resources necessary for you to deliver the requested services
          The processing is necessary to perform a contract or enter into a contract with you (Article 6(1)(b), UK GDPR)
          The processing is necessary to support our legitimate interests in managing our business (or those of a third party), provided such interests are not overridden by your interests and rights (Article 6(1)(f), UK GDPR)
          Sensitive Personal Data
          Data Concerning Criminal Convictions and Offences To confirm initial and continued eligibility for business transactions Westfield Specialty Ltd has a legal obligation to ensure compliance with anti-moneylaundering and other financial crimes statutes and regulations (Article 6(1)(c), UK GDPR)

          Claimants

          Sensitive Personal Data
          Category of Personal Data Purpose of Processing Legal Basis
          Contact Details, Identification Details, Financial and Anti-Fraud Data, Claims Information For claims processing, which includes assessing and evaluating the merits of a claim and, where relevant, paying a settlement The processing is necessary to perform a contract or enter into a contract with you (e.g., the settlement agreement) (Article 6(1)(b), UK GDPR)
          The processing is necessary to support our legitimate interests in managing our business (or those of a third party), provided such interests are not overridden by your interests and rights (Article 6(1)(f), UK GDPR)
          Westfield Specialty Ltd may have a legal obligation to do so (Article 6(1)(c), UK GDPR)
          Contact details, Identification Details, Financial and Anti-Fraud Data, Claims Information For claims processing, which includes assessing and evaluating the merits of a claim and, where relevant, paying a settlement The processing is necessary to perform a contract or enter into a contract with you (e.g., the insurance policy or settlement agreement) (Article 6(1)(b), UK GDPR)
          The processing is necessary to support our legitimate interests in managing our business (or those of a third party), provided such interests are not overridden by your interests and rights (Article 6(1)(f), UK GDPR)
          Sensitive Personal Data
          Data Concerning Criminal Convictions and Offences To confirm initial and continued eligibility for business transactions Westfield Specialty Ltd has a legal obligation to ensure compliance with anti-moneylaundering and other financial crimes statutes and regulations (Article 6(1)(c), UK GDPR)

          Business partners

          Category of Personal Data Purpose of Processing Legal Basis
          Contact Details, Identification details, Financial Information To provide our services to you The processing is necessary to perform a contract or enter into a contract with you (e.g., the insurance policy) (Article 6(1)(b), UK GDPR)
          Contact Details, Identification Details, Financial Information, Other Information To manage our relationship with you The processing is necessary to perform a contract or enter into a contract with you (Article 6(1)(b), UK GDPR)
          The processing is necessary to support our legitimate interests in managing our business (or those of a third party), provided such interests are not overridden by your interests and rights (Article 6(1)(f), UK GDPR)

          Website and mobile application users

          Category of Personal Data Purpose of Processing Legal Basis Contact Details, Other Information, Internet or Other Electronic Activity Information To improve the website or our services, to customize your experience on the website, or to serve you specific content that is relevant to you. The processing is necessary to support our legitimate interests in managing our business (or those of a third party), provided such interests are not overridden by your interests and rights Contact Details, Other Information. To contact you regarding changes to the website or the website policies. The processing is necessary to support our legitimate interests in managing our business (or those of a third party), provided such interests are not overridden by your interests and rights Contact Details, Other Information, Internet or Other Electronic Activity Information. For internal business purposes, including to help us understand how our website is navigated and used. The processing is necessary to support our legitimate interests in managing our business (or those of a third party), provided such interests are not overridden by your interests and rights

          Applicable to all

          Category of Personal Data Purpose of Processing. Legal Basis Contact Details, Identification Details, Other Information For statistical analysis The processing is necessary to support our legitimate interests in managing our business (or those of a third party), provided such interests are not overridden by your interests and rights (Article 6(1)(f), UK GDPR) Contact Details, Identification Details, Other Information To improve our insurance products and services, to carry out market research, to perform data analytics and for statistical analyses The processing is necessary to support our legitimate interests in managing our business (or those of a third party), provided such interests are not overridden by your interests and rights (Article 6(1)(f), UK GDPR) Contact details, Identification Details, Financial and Anti-Fraud Data / Financial Information, Other Information For the prevention and detection of fraud, money laundering or other crimes The processing is necessary for us to comply with legal and regulatory obligations or as authorized by applicable law (Article 6(1)(c), UK GDPR) Contact Details, Other Information For direct marketing, to organize meetings, events or conferences You have given consent to the processing of your personal data for direct marketing, which you may withdraw at any time using the opt-out instructions contained in the email or by contacting us as described on our website (Article 6(1)(a), UK GDPR)
          The processing is necessary to support our legitimate interests in managing our business (or those of a third party), provided such interests are not overridden by your interests and rights (Article 6(1)(f), UK GDPR) Contact Details, Identification Details, Financial and Anti-Fraud Data / Financial Information, Other Information Preparing for and acting in relation to inquiries, investigations or proceedings, by governmental, administrative, judicial or regulatory authorities, including civil litigation The processing is necessary to support our legitimate interests in managing our business (or those of a third party) and to ensure that all investigations and proceedings are managed efficiently and effectively , provided such interests are not overridden by your interests and rights (Article 6(1)(f), UK GDPR)
          Westfield Specialty Ltd may have a legal obligation to do so (Article 6(1)(c), UK GDPR) Contact Details, Identification Details, Financial and Anti-Fraud Data / Financial Information, Other Information If Westfield Specialty Ltd is involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another entity The processing is necessary to support our legitimate interests in managing our business (or those of a third party), provided such interests are not overridden by your interests and rights (Article 6(1)(f), UK GDPR)

          You have a right to object to the processing of your personal data where that processing is carried out for our legitimate interests. Please note however that Westfield Specialty Ltd may not be able to fulfil this request in all instances.

          How We Share Your Personal Data

          We may share the personal data we have collected about you with our affiliates or third parties, as described below.

          Westfield companies

          We may share your personal data with other Westfield group companies to assist in the delivery of services to you, and for other purposes authorized under this Privacy Notice.

          Third-party intermediaries

          We may disclose your personal data to intermediaries (e.g., brokers, managing general agents, third-party administrators) and other (re)insurers to assist us in managing our business.

          Third parties providing services on our behalf

          We may use third-party processors, service providers and/or vendors to perform certain services on our behalf, such as technical support and back-office services, loss adjustors and claims experts, hosting services and website activity tracking and analytics. We may also disclose your personal data to our professional advisors (e.g., attorneys and other professional services firms).

          Judicial, regulatory and law enforcement bodies

          We may disclose your personal data to judicial, regulatory and law enforcement bodies, for reasons including but not limited to: (1) satisfying any applicable law, regulation, governmental requests or legal process if in our good faith opinion, such disclosure is required or permitted by law; (2) protecting and/or defending our rights, property and/or interests (including the enforcement of the Terms and Conditions of any of our websites); (3) protecting the safety, rights, property or security of Westfield Specialty Ltd or any third party; and (4) detecting, preventing or otherwise addressing fraud, security or technical issues. Such disclosures may be carried out without notice to you to the extent permitted or required by law.

          Corporate transactions

          Subject to applicable law, we reserve the right to transfer some or all personal data in our possession to a potential successor organization in the event of a merger, acquisition, bankruptcy, or other sale or transfer of all or a portion of our assets. If any such transaction occurs, the purchaser / successor organization will be entitled to use and disclose the personal data collected by us in the same manner that we are able to, and the purchaser / successor organization will assume the rights and obligations regarding your personal data as described in this Privacy Notice.

          Your Privacy Rights

          You may have certain rights in relation to your personal data under applicable privacy and data protection law, which may be subject to certain limitations and restrictions:

          Right of access You can ask us to confirm whether we are processing your personal data and request a copy of that personal data.
          Right to rectification You have the right to request that we correct any inaccuracies in the personal data we hold about you and to complete any personal data that is incomplete.
          Right to erasure ("right to be forgotten") You have the right to request that your personal data be deleted in certain circumstances.
          Right to restrict processing You can ask that we restrict the processing of your personal data (i.e., keep but not use it) in certain circumstances.
          Right to data portability Where you have provided personal data to us, you have a right to receive such personal data back in a structured, commonly used and machine-readable format. You may also have the right to have your personal data transmitted to a third-party data controller without hindrance in certain circumstances.
          Right to object You have a right to object where we are processing your personal data in reliance on our legitimate interests or for direct marketing purposes.
          Automated decision-making You have a right not to be subject to decisions based solely on automated processing when such decisions produce legal effects concerning you or similarly significantly affects you in certain circumstances.
          Right to complain If you are not satisfied with our use of your personal data or our response to any request made by you to exercise any of your rights, you have the right to lodge a complaint with the local data protection supervisory authority at any time.
          Right to withdraw consent If we are processing your personal data on the legal basis of consent, you are entitled to withdraw your consent at any time.

          To exercise any of your applicable rights, please contact us at the email listed below or visit Data Subject Rights Request to submit your request. You may also authorize someone to exercise the above rights on your behalf. We aim to respond to any valid requests within one month unless it is particularly complicated, or you have made repeated requests, in which case we aim to respond within three months. We will inform you of any such extension within one month of receipt of your request, together with the reasons for the delay.

          You will not be charged a fee to exercise any of your rights unless your request is clearly unfounded, repetitive or excessive, in which case we will charge a reasonable fee in the circumstances or will refuse to act on the request. To protect your privacy, Westfield Specialty Ltd may take steps to verify your identity before fulfilling your request.

          Transfers of personal data

          The personal data we collect from you may be transferred to and stored at locations outside of the jurisdiction you are in, to locations where we and our third-party service providers have operations (including Bermuda, the UAE and the United States) for the purposes described above.

          For intra-group transfers of personal data, Westfield Specialty Ltd has entered into an intra-group data transfer agreement. For cross-border transfers of personal data to other recipients, including our service providers, Westfield Specialty Ltd will put in place appropriate safeguards so that personal data is and remains protected. These may include implementing the Standard Contractual Clauses with the UK International Data Transfer Addendum or Binding Corporate Rules, or otherwise in reliance on a derogation for the transfer (e.g., where the transfer is necessary for the defense of legal claims).

          If you would like further information about the safeguards we have implemented, please contact us using the contact details below.

          Protecting Your Personal Data

          We implement technical and organizational security measures designed to secure and protect personal data. Please note, however, that we cannot fully eliminate security risks associated with the storage and transmission of personal data.

          Retaining Your Personal Data

          We will retain your personal data for as long as is necessary to fulfil the purposes for which we obtained the personal data, including to provide our services, or for such longer period as may be required or permitted by applicable law. We will also retain your personal data as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements and policies. We use the following criteria to set our retention periods: (1) the duration of our relationship with you; (2) the purposes for processing your personal data and associated legal bases; (3) the existence of a legal obligation; (4) our contractual obligations; and (5) the advisability of retaining the data in light of our legal position (for example, in light of applicable statutes of limitations, litigation or regulatory investigations).

          Other Important Information

          Children’s privacy

          Our websites and services are not targeted at children, as defined by local law, and we do not knowingly collect any personal data from children. We will delete any personal data we determine to have been collected from a child as defined under applicable privacy and data protection laws. If you are a parent or guardian of a child and believe he or she has disclosed personal data to us, please contact us as described below.

          Third-party content and links to third-party websites

          Our websites may contain content that is supplied by a third party, and those third parties may collect usage information and your device identifier when webpages from the website are served to you. Our website may also contain links to third parties. This Privacy Notice does not apply to, and we are not responsible for the data collection and privacy practices employed by any of these third parties on their websites. We encourage you to review their privacy notices. Our websites may include social network sharing widgets that may provide information to their associated social networks or third parties about your interactions with our webpages that you visit, even if you do not click on or otherwise interact with the plug-in or widget. Information is transmitted from your browser and may include an identifier assigned by the social network or third party, information about your browser type, operating system, device type, IP address, and the URL of the webpage where the widget appears. If you use social network tools or visit social networking sites, we encourage you to read their privacy disclosures to learn what information they collect, use and share.

          Updates to Privacy Notice

          This Privacy Notice is reviewed and updated periodically. The most recent version of the Privacy Notice is reflected by the version date located at the top of this page. We encourage you to review this Privacy Notice often to stay informed of how we may process your information. If we make material changes to this Privacy Notice, we will notify individuals by email to their registered email address, by prominent posting on our website or through other appropriate communication channels.

          Contact Us

          If you have any question about this Privacy Notice or the practices described in it, or would like to contact us about any rights you may have with regard to your personal data, you can contact us via the Data Subject Rights Request listed above, email, or postal mail as follows:

           

          Email: privacy@westfieldgrp.com.

          Post:
          Floor 36
          22 Bishopsgate
          London
          EC2N 4BQ
          United Kingdom