About this Privacy Policy

Broker One Ltd takes your data privacy seriously. In order to provide you with our services we collect and use personal data which means that we are a ‘Data Controller’ and we are responsible for complying with Data Protection Laws and the General Data Protection Regulations (GDPR).

We collect and process information about you in order to arrange insurance policies and to process claims. Your information is also used for business purposes such as fraud prevention and detection and financial management. This may involve sharing your information with third parties such as insurers, reinsurers, other brokers, claims handlers, loss adjusters, credit reference agencies, service providers, professional advisors, our regulators, police and government agencies or fraud prevention agencies.

In this Privacy Notice, we want to inform you what information we collect, how we use it and what rights individuals have in relation to the collection and processing of their personal data.

If you are providing personal data of another individual to us, you must tell them you are providing their information to us and show them a copy of this notice.

Our Contact Details

If you have any questions in respect of this Privacy Notice or how we manage your personal data, please contact:

Broker One Ltd                             

Address: Avalon, 14 Castle View, Airth, FK2 8GE

Tel: 07809166442
Email: info@brokerone.co.uk

About Us

Broker One Ltd are an appointed representative of Arthur J Gallagher Insurance Brokers Ltd.  They are a joint data controller of any personal information you provide to us or personal information that has been provided to us by a third party.

For further details on your rights in relation to the information we may share with them, you can access their privacy notice here.

Why we do we collect your information?

Where we collect and process personal data, we identify both the purpose and legal basis for doing so.  The legal bases which are:

Consent – where we have consent from the individual to the processing of his or her personal data for one or more specific purpose

Contract – where the processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract

Legal Obligation – The processing is necessary for compliance with a legal obligation to which we are subject

Vital Interests – Where the processing is necessary in order to protect the vital interests of the data subject or another natural person

Public Interest – Where the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller

Legitimate Interests – Where the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal date, in particular where the data subject is a child.

Our Processing of Your Personal Information

 The information we collect and our lawful basis for processing it will depend on the type of service we provide for you.  Please review the section which is most applicable to our relationship with you.

  • Prospective Customers or Parties to be covered under an Insurance Policy
  • New or Existing Customers or parties covered under an Insurance Policy we have arranged
  • Third Party Claimants
  • Specialist Claims Experts
  • Employees
  • Potential Employees

What personal data we collect – select the option most suited to you

Where you have contacted us to enquire about, or arrange a quotation for insurance and / or our services, we can collect, store or use the following types of personal data:

  • General contact details such as, Name, Address, email address, Telephone number
  • General Identity Information such as Driving Licence Number, National Insurance Number
  • Business Activities of the person whose personal information we are processing
  • Details of previous insurance arrangements including claims history
  • Details of your demands and needs in relation to insurance
  • Full details of your insurance risks being reviewed
  • Sanctions information
  • Details of Services provided to you
  • Financial Details – such as credit history or payment or bank details
  • Information obtained through our use of cookies (please see our Cookie Policy)
  • Your marketing preferences

Special Categories of Personal Data that we collect:

  • Details relating to health or previous health insurance claims when arranging a travel insurance policy where it is relevant to the policy being arranged
  • Information relating to criminal sanctions (including offences and alleged offences and any caution, court sentence or criminal conviction), which can be established directly from you or as a result of carrying out sanctions checks.
  • Information relating to any professional disciplinary action you have been the subject of where it is relevant to the policy being arranged

How we collect your information

In most cases, we collect your data directly from you.  We collect data and process it when you

  • Complete an online ‘contact us’ form
  • Speak to us on the telephone to discuss or use our services
  • Email or write to us to enquire about or use our services
  • View our website via your browsers cookies (see our Cookie Policy)

Or Indirectly

We also receive your data indirectly from the following sources:

  • Social Media Sites such as LinkedIn or Facebook
  • Public sources – demographic data, Market Research, Local Directories

Our purpose and legal basis for the information we collect, and process allows us to:


Purpose

Lawful Basis

Lawful Basis for Any Special Category of Information

To understand your insurance requirements, needs and risk appetite prior to arranging quotes for you and entering into a contract of service with you

The processing is necessary for the performance of an anticipated Contract

It is necessary for an Insurance Purpose


To add you as a prospective client including carrying out credit, fraud, sanctions and anti money laundering checks

The processing is necessary to enter into a Contract.

We have a legal or regulatory obligation

We have a legitimate business need to prevent fraud or illegal activity

The prevention of fraud is in the substantial public interest.

It is necessary for an insurance purpose

It is necessary to establish, exercise our legal rights

To comply with our legal or regulatory obligations (such as our requirements to report to the FCA)

We have a legal or regulatory obligation

It is necessary for an Insurance Purpose

It is necessary to establish and exercise our legal rights.

To communicate with you, respond to your queries and notify you about changes to our service

It is in our Legitimate Interests to use your personal information to keep you informed about any changes that may affect you

It is necessary for an insurance purpose

It in necessary to establish, exercise and defend our legal rights

For electronic Marketing of services to new customers

We rely on Consent for direct electronic marketing to individuals


For Direct Marketing to Businesses

It is in our Legitimate Interests to market our services to other businesses which can include personal business email addresses


Managing our Business operations such as maintaining accounting records, analysing financial results, complying with internal audit requirements and receiving professional advice (e.g. tax or legal advice)

It is in our Legitimate Interests to manage and improve our business operations and activities.



Where we rely on your consent you have the right to withdraw this consent at any time by contacting our Data Protection Officer.  Contact details can be found at the beginning of this policy.

Legitimate Interests

Where the processing of personal data is based on our Legitimate Interests, it is to improve on our service, security and prevent fraud or illegal activity in favour of the wellbeing of our customers and shareholders. 

Where you have arranged an insurance policy and / or entered into a contract for our services, we can collect, store or use the following types of personal data which is regularly reviewed throughout the lifespan of your relationship with us:

  • General contact details such as, Name, Address, email address, Telephone number
  • General Identity Information such as Driving Licence Number, National Insurance Number
  • Business Activities of the person who’s personal information we are processing
  • Details of previous insurance arrangements including claims history
  • Details of your demands and needs in relation to insurance
  • Full details of your insurance risks where cover has been arranged by us
  • Details of other insurance risks not managed by us
  • Sanctions information
  • Details of policies purchased and Services provided to you
  • Financial Details – such as credit history or payment or bank details
  • Information obtained through our use of cookies (please see our Cookie Policy)
  • Your marketing preferences

Special Categories of Personal Data that we collect

New or Existing Customers or parties covered under an Insurance Policy we have arranged:

  • Details relating to health or previous health insurance claims when arranging a travel insurance policy where it is relevant to the policy being arranged
  • Information relating to criminal sanctions (including offences and alleged offences and any caution, court sentence or criminal conviction), which can be established directly from you or as a result of carrying out sanctions checks.
  • Information relating to any professional disciplinary action you have been the subject of where it is relevant to the policy being arranged
  • The following special category information offered by you in the course of your discussions with us relating to race, ethnicity, religious or philosophical beliefs, political opinions, trade union memberships or data concerning your sex life or sexual orientation. We will only process such information to the extent necessary in the connection with a claim or where in connection with legal proceedings.  Any further processing will only be with your explicit consent.

How we collect your information

In most cases, we collect your data directly from you.  We collect data and process it when you

  • Complete an online ‘contact us’ form
  • Speak to us on the telephone to discuss or use our services
  • Email or write to us to enquire about or use our services
  • View our website via your browsers cookies (see our Cookie Policy)

Or Indirectly

We also receive your data indirectly from the following sources:

  • Social Media Sites such as LinkedIn or Facebook
  • Public sources – demographic data, Market Research, Local Directories

Purpose

Lawful Basis

Lawful Basis for Any Special Category of Information

To understand your insurance requirements, needs and risk appetite on an ongoing basis to obtain regular quotes and terms for you as part of an ongoing contract of service with you

The processing is necessary for the performance of our ongoing contract with you.

It is necessary for an insurance purpose

To provide documentation and assist with any ongoing claims made under an insurance policy we have arranged

The processing is necessary for the performance of our ongoing contract with you.

It is necessary for an Insurance Purpose

To assist with any renewals, mid-term adjustments of your insurance policy or cancellations.

The processing is necessary for the performance of our ongoing contract with you.

It is necessary for an Insurance Purpose

To hold you on our records as a client including carrying out annual credit, fraud, sanctions and anti money laundering checks

The processing is necessary to enter into a Contract.

We have a legal or regulatory obligation

We have a legitimate business need to prevent fraud or illegal activity

The prevention of fraud is in the substantial public interest.

It is necessary for an insurance purpose

It is necessary to establish, exercise our legal rights

To comply with our legal or regulatory obligations (such as our requirements to report to the FCA)

We have a legal or regulatory obligation

It is necessary for an Insurance Purpose

It is necessary to establish and exercise our legal rights.

To communicate with you, respond to your queries and notify you about changes to our service

It is in our Legitimate Interests to use your personal information to keep you informed about any changes that may affect you

It is necessary for an insurance purpose

It is necessary to establish, exercise and defend our legal rights

Prevention, detection and investigating and prosecuting fraud.  This can include sharing personal data information with third parties including the police, and other insurance and financial providers

The processing is necessary for the performance of our ongoing contract with you.

It is in our Legitimate Interests to ensure that we take all necessary steps to prevent fraud.

The prevention and detection of fraud is in the substantial public interest.

It is necessary for an insurance purpose.

It is necessary to establish, exercise and defend our legal rights.

For Marketing of similar services to existing customers

It is in our legitimate interests to use your personal information for marketing purposes where the services being marketed are relevant to you.


For electronic Marketing of services to new customers

We rely on Consent for direct electronic marketing to individuals


For Direct Marketing to Businesses

It is in our Legitimate Interests to market our services to other businesses which can include personal business email addresses


To identify and prevent fraud

It is in our Legitimate Interests to act as a responsible business


Managing our Business operations such as maintaining accounting records, analysing financial results, complying with internal audit requirements and receiving professional advice (e.g. tax or legal advice)

It is in our Legitimate Interests to manage and improve our business operations and activities.



Legitimate Interests

Where the processing of personal data is based on our Legitimate Interests, it is to improve on our service, security and prevent fraud or illegal activity in favour of the wellbeing of our customers and shareholders. 

Where you contact us in relation to a claim you may have against one of our contractual clients, we can collect, store or use the following types of personal data:

  • General contact details such as, Name, Address, email address, Telephone number
  • General Identity Information such as Driving Licence Number, National Insurance Number
  • Job title where relevant

If Relevant to your claim, we can also collect:

  • Business Activities of the person who’s personal information we are processing
  • Details of your claim
  • Details of your own insurance arrangements
  • Details of all discussions in relation to the claim
  • Sanctions information
  • Financial Details – such as payment or bank details
  • Information obtained through our use of cookies (please see our Cookie Policy)

Special Categories of Personal Data that we collect:

We may collect the following information, only where it is relevant to your claim:

  • Information relating to health / medical history or previous claims
  • Information relating to criminal sanctions (including offences and alleged offences and any caution, court sentence or criminal conviction), which can be established directly from you or as a result of carrying out sanctions checks.
  • The following special category information offered by you in the course of your discussions with us relating to race, ethnicity, religious or philosophical beliefs, political opinions, trade union memberships or data concerning your sex life or sexual orientation. We will only process such information to the extent necessary in the connection with your claim or where in connection with legal proceedings.  Any further processing will only be with your explicit consent.

How we collect your information

In most cases, we collect your data directly from you.  We collect data and process it when you

  • Complete an online ‘contact us’ form
  • Speak to us on the telephone to discuss or use our services
  • Email or write to us to enquire about or use our services
  • View our website via your browsers cookies (see our Cookie Policy)

Or Indirectly

We also receive your data indirectly from the following sources:

  • Social Media Sites such as LinkedIn or Facebook
  • Public sources – demographic data, Market Research, Local Directories

Purpose

Lawful Basis

Lawful Basis for Any Special Category of Information

To assist in any claims made under an insurance policy we have arranged

It is in our legitimate interests to assist in any claims which have been made under an insurance policy we have arranged

It is necessary for an insurance purpose

To comply with our legal or regulatory obligations (such as our requirements to report to the FCA)

We have a legal or regulatory obligation

It is necessary for an Insurance Purpose

It is necessary to establish and exercise our legal rights.

Prevention, detection and investigating and prosecuting fraud.  This can include sharing personal data information with third parties including the police, and other insurance and financial providers

The processing is necessary for the performance of our ongoing contract with you.

It is in our Legitimate Interests to ensure that we take all necessary steps to prevent fraud.

The prevention and detection of fraud is in the substantial public interest.

It is necessary for an insurance purpose.

It is necessary to establish, exercise and defend our legal rights.

Managing our Business operations such as maintaining accounting records, analysing financial results, complying with internal audit requirements and receiving professional advice (e.g. tax or legal advice)

It is in our Legitimate Interests to manage and improve our business operations and activities.



Where we work with you as a specialist claims expert, we can collect, store or use the following types of personal data:

  • General contact details such as, Name, Address, email address, Telephone number
  • General Identity Information such as Driving Licence Number, National Insurance Number
  • Information about your business, job title and role

How we collect your information

In most cases, we collect your data directly from you.  We collect data and process it when you

  • Complete an online ‘contact us’ form
  • Speak to us on the telephone to discuss or use our services
  • Email or write to us to enquire about or use our services
  • View our website via your browsers cookies (see our Cookie Policy)

Or Indirectly

We also receive your data indirectly from the following sources:

  • Social Media Sites such as LinkedIn or Facebook
  • Public sources – demographic data, Market Research, Local Directories

Purpose

Lawful Basis

Lawful Basis for Any Special Category of Information

To assist in any claims made under an insurance policy we have arranged

It is in our legitimate interests to assist clients in any claims which have been made under an insurance policy we have arranged

It is necessary for an insurance purpose

Prevention, detection and investigating and prosecuting fraud.  This can include sharing personal data information with third parties including the police, and other insurance and financial providers

The processing is necessary for the performance of our ongoing contract with you.

It is in our Legitimate Interests to ensure that we take all necessary steps to prevent fraud.

The prevention and detection of fraud is in the substantial public interest.

It is necessary for an insurance purpose.

It is necessary to establish, exercise and defend our legal rights.

Managing our Business operations such as maintaining accounting records, analysing financial results, complying with internal audit requirements and receiving professional advice (e.g. tax or legal advice)

It is in our Legitimate Interests to manage and improve our business operations and activities.


Where you are an employee of Broker One Ltd, we will collect, hold and process the following personal data:

  • General contact details such as, Name, Address, email address, Telephone number
  • General Identity Information such as Driving Licence Number, National Insurance Number
  • Bank, Tax and Pension Details
  • Salary Details
  • Annual Leave details
  • Employment History

Special Categories of Personal Data that we collect:

New or Existing Customers or parties covered under an Insurance Policy we have arranged:

  • Absense and Sickness Details
  • Performance Details

How we collect your information

In most cases, we collect your data directly from you.  We collect data and process it when you

  • Complete an application or employee form
  • Provide information during a meeting or 121 review
  • Email or write to us in relation to your employment
  • Telephone discussions related to your employment

Or Indirectly

We also receive your data indirectly from the following sources:

  • Social Media Sites such as LinkedIn or Facebook
  • Public sources – demographic data, Market Research, Local Directories


Purpose

Lawful Basis

Lawful Basis for Any Special Category of Information

To hold your information on our records as an employee

The processing is necessary to enter into a Contract.

We have a legal or regulatory obligation

We have a legitimate business need to prevent fraud or illegal activity


To comply with our legal or regulatory obligations (such as our requirements to report to the HMRC)

We have a legal or regulatory obligation


Managing our Business operations such as maintaining adequate resource to provide our services.

It is in our Legitimate Interests to manage and improve our business operations and activities.


To communicate with you, respond to your queries and notify you about changes to our business

It is in our Legitimate Interests to use your personal information to keep you informed about any changes that may affect you


To manage performance and provide training and development on an ongoing basis

The processing is necessary for the performance of our ongoing Contract with you.

It is in our Legitimate Interests to ensure that we take all necessary steps to ensure we are measuring the adequacy of our service to clients.

It is necessary to establish, exercise and defend our legal rights.

To support, manage and investigate absense and wellbeing within our workplace

It is in our Legitimate Interests to ensure that we support our employees in relation to health and wellbeing.

It is necessary to exercise, defend and establish out legal rights.


Legitimate Interests

Where the processing of personal data is based on our Legitimate Interests, it is to improve on our service, security and prevent fraud or illegal activity in favour of the wellbeing of our employees, customers and shareholders. 

Where you provide us with information (e.g. a CV) in relation to potential recruitment at Broker One Ltd, we will collect, hold and process the following personal data:

  • General contact details such as, Name, Address, email address, Telephone number
  • General Identity Information such as Driving Licence Number, National Insurance Number
  • Employment History
  • Education History
  • Salary and Benefits History

Special Categories of Personal Data that we can collect:

  • Trade Union Memberships

How we collect your information

In most cases, we collect your data directly from you.  We collect data and process it when you

  • Send us a CV
  • Complete an application form
  • Provide information during an Interview
  • Email or write to us in relation to potential employment
  • Telephone us to enquire about potential employment

Or Indirectly

We also receive your data indirectly from the following sources:

  • Social Media Sites such as LinkedIn or Facebook
  • Public sources – demographic data, Market Research, Local Directories

Purpose

Lawful Basis

Lawful Basis for Any Special Category of Information

To hold your information during a recruitment process

The processing is necessary to consider entering into a Contract.



To contact potential candidates during a recruitment process

It is in our Legitimate Interest to use your personal information to keep you informed about potential vacancies where you have expressed an interest in such previously



Legitimate Interests 

Where the processing of personal data is based on our Legitimate Interests, it is to improve on our service, security and prevent fraud or illegal activity in favour of the wellbeing of our (Potential) employees, customers and shareholders. 

Who we share your information with?

From time to time we may share your personal information with third parties for the various purposes set out above.  These are:

  • Our Principle Arthur J Gallagher Insurance Brokers Ltd
  • Other brokers who also act for you
  • Industry bodies
  • Accountants
  • Payment Services Providers
  • Regulators or Auditors
  • Service Providers such as Software Providers (I.T. Suppliers, Insurance Software providers, Cloud Services)
  • Lawyers
  • Specialist Claims Experts, Loss Adjusters
  • Fraud detection Agencies
  • Police and Law Enforcement agencies where reasonably necessary for the prevention or detection of crime
  • Debt Collection Agencies
  • Credit Reference Agencies
  • Selected Third Parties in connection with the sale, transfer or disposal of our business

International data transfers

Sometimes we (or third parties acting on our behalf) will transfer personal information that we collect about you to countries outside of the European Economic Area (EEA).  Our regular transfers include transfers to India to assist with our back office functions.  As a safeguard to protect your information, our principle has an intra group data transfer agreement in place (utilising Standard Contractual Clauses (Controller to Processor)).

Automated decision-making or Profiling

We do not use automated means to make decisions about your insurance, however insurers can do so when providing us with a quotation.  They consider the information provided (for example, details of your cover required, local crime rates, claim rates, flood registers) to determine whether your application for insurance can be accepted and the premium.  All of such decisions are however reviewed by us and you can request that the decision be made by an individual decision maker.

How Long do we keep personal data for?

We will retain personal data in accordance with legal and regulatory requirements and for no longer than is necessary to fulfil the purposes set out in this privacy policy.  We maintain and review a detailed retention policy which documents how long we will hold different types of data.  The time period will depend on the purpose for which we collected the information and is never on an indefinite basis.  Subsequently, we will delete your personal data in accordance with our data retention and deletion policy or take steps to properly render the data anonymous, unless we are legally obliged to keep your personal data longer (e.g. for tax, accounting or auditing purposes).

The following details the criteria used to establish the retention period set out within our policy.

Where it is still necessary for the provision of our Services

This includes the duration of any contract for services we have with you and for a period of 12 months after the end of any contract with a view to maintaining and improving the performance of our products, keeping our systems secure, and maintaining appropriate business and financial records. Most of our retention periods are determined on the basis of this general rule.

Where required by Statutory, contractual or other similar obligations

Corresponding storage obligations may arise, for example, from laws or regulation, for example depending on the type of insurance policy we arranged for you.  It may also be necessary to store personal data with regard to pending or future legal disputes. Personal data contained in contracts, notifications and business letters may be subject to statutory storage obligations depending on national law.

Your Rights as a data subject

As a data subject, you have rights in relation to your personal data.  These are:

The Right to Access – You have the right to request details of personal information held or processed and to copies of this data.  We do not usually charge for this service.

The Right to Rectification – You have the right to request that any information be corrected that you believe is inaccurate or to complete any information that you believe is incomplete.

The Right to Erasure – You have the right to request that we erase your personal information under certain conditions

The Right to Restrict Processing – You have the right to request that we restrict the processing of your personal data under certain circumstances

The Right to Object to Processing – You have the right to object to our processing of your data, under certain conditions.

The Right to Data Portability – You have the right to request that we transfer the data that we have collected to another organisation or directly to you, under certain conditions.

As previously detailed, you also have the Right to Withdraw Consent where you have previously provided this at any time.

To exercise any of these rights or wish to make a complaint to us in respect of those rights, please contact:

Broker One Ltd                                                                                         

Address: Avalon, 14 Castle View, Airth, FK2 8GE
Telephone: 01324 751041
Email:  info@brokerone.co.uk

You also have the right to complain to the Supervisory Authority.  Where you wish to report a complaint or feel that we have not addressed your concern in a satisfactory manner, you may contact the Information Commissioner’s Office at:

Information Commissioners Office

Wycliffe House

Water Lane

Wilmslow

Cheshire

SK9 5AF

Helpline: 0303 123 1113

Contractual Obligations and Consequences

In some circumstances, the provision of personal data is partly required by law (for example, tax regulations, legal obligations) or can also result from contractual provisions such as payment details.  This means that it may sometimes be necessary to conclude or fulfil a contract, that the personal data be provided.  In those circumstances where the data is not provided or where certain rights are exercised below, (Erasure, Object) there is a possible consequence that the contract could not be fulfilled or concluded and may be cancelled.

Cookies & similar technologies

When you visit our Website, we use cookies and similar technologies to provide you with a better, faster and safer user experience or to show you personalised advertising. Cookies are small text files that are automatically created by your browser and stored on your device when you visit or use the Website.   For full details please see our separate Cookie Policy.

How we keep your Personal Data Secure

We protect your personal data through technical and organisational security measures to minimise risks associated with data loss, misuse, unauthorised access and unauthorised disclosure and alteration.

We store your data in in files within Insurance Software, Office 365 and use firewalls, antivirus, malware protection and encryption.  We have a full data protection policy which includes a records management policy which includes access, password security and clear desk restrictions.

Changes to our Privacy Notice

All businesses and their operations change from time to time.  Broker One Ltd consider and embed data privacy prior to making any such changes.  We keep our Privacy Notice under regular review to ensure that any changes are captured, and you are kept informed.

This Privacy Notice was last updated on 4th November 2019.