This privacy notice describes how Gallagher Risk and Reward Limited (trading as Arthur J. Gallagher (Employee Benefits) ('we', 'us', 'OUR') may collect, handle and process personal information in relation to your access to or use of the services.
This privacy notice applies to all of the services, websites and apps offered by Gallagher Risk and Reward Limited (trading As Arthur J. Gallagher (Employee Benefits) (collectively, the "Services"), but excludes Services which have separate privacy notices that do not incorporate this privacy notice.
1. Personal information we use
We may collect personal information about you from a variety of sources, including information we collect from you directly (e.g., when you contact us) and from other sources, described below.
Note that we may be required by law to collect certain personal information about you, or as a consequence of any contractual relationship we may have with you. Failure to provide this information may prevent or delay the fulfilment of these obligations. We will inform you at the time your information is collected if the provision of certain personal information is compulsory and the consequences of the failure to provide such personal information.
1.1 Information we collect directly from you
Depending on the service, website or app that you are using, the categories of information that we may collect directly from you include:
(a) personal details (e.g., name, date of birth);
(b) contact details (e.g., phone number, email address, postal address or mobile number);
(c) government issued identification details (e.g., and national insurance numbers, passport details);
(d) health and medical details (e.g., lifestyle and general health information);
(e) policy details (e.g., policy numbers and types);
(f) bank details (e.g., payment details, account numbers and sort codes);
(g) other information we receive from you on applications or required questionnaires (e.g., occupation, current employer); and
We do collect personal information about your online activities over time and across third party websites or online services. When we see a browser set to "do not track", signals transmitted from web browsers do not apply to our sites, and we do not alter any of our data collection and use practices upon receipt of such a signal.
1.2 Information we collect from other sources:
The categories of information that we may collect about you from other sources are:
(a) personal details (e.g., name, date of birth);
(b) contact details (e.g., phone number, email address, postal address or mobile number);
We may receive such information via other insurers, consumer-reporting agencies, our affiliated companies, or other third parties in the course of conducting our business.
1.3 Sensitive personal information
We may also collect certain information about you which is considered more sensitive under local applicable laws, such as:
(a) information about your race, ethnic origin, religious views and philosophical beliefs, membership of professional or trade associations, gender identity or sexual orientation for diversity and statutory monitoring purposes where appropriate; and
(b) health, biometric or disability information required to administer policies or process claims.
1.4 How we collect personal information
We may collect personal information in different ways, including:
(a) Data you give to us via face to face meetings
(b) When you talk to us on the phone
(c) In email communication and letters
(d) In application forms or insurance claims
(e) In financial reviews
(f) In customer surveys
2. How we use your personal information and the basis on which we use it
We may use your personal information to:
(a) provide, maintain, protect and personalise our services including our insurance products, consulting and broking services;
- deal with your enquiries and requests;
- perform system administration and to report aggregate statistical information to our advertisers;
- cooperate with regulators and law enforcement bodies;
- contact you with marketing and offers relating to products and services offered by us (unless you have opted out of marketing, or we are otherwise prevented by law from doing so);
- personalise the marketing messages we send you to make them more relevant and interesting and to customize and enhance your website or app experience;
- resolve complaints, as well as handle requests for data access or correction;
- protect your, our or others' rights and interests; and
- communicate with you regarding your account or changes to our policies, terms and conditions.
Some jurisdictions require a legal basis to use or process your personal information. In most cases the legal basis will be one of the following:
- to fulfil our contractual obligations to you in connection with your policy or contract with us, for example using your contact details to reply to your requests. Failure to provide this information may prevent or delay the fulfilment of these contractual obligations;
- in order to comply with our legal obligations, for example to keep records of the services we provide you with as required by applicable law or regulation, or to comply with any governmental, quasi-governmental or court orders or subpoenas;
- where there is a public interest in the processing, for example where it is necessary in order to prevent and detect fraud; and
- to meet our or a third party's legitimate interests, for example to understand how you use our services and to enable us to derive knowledge from that to develop new services, to protect our rights or the rights of third parties, or to resolve any disputes. When we process personal information to meet our legitimate interests, we put in place robust safeguards to help ensure that your privacy is protected and that our legitimate interests are not overridden by your interests or fundamental rights and freedoms.
3. Your rights over your personal information
You may have certain rights regarding your personal information, subject to local law. These include rights in certain circumstances to:
- access your personal information;
- request proof of the authorisation or previous consent given to us to perform the collection and processing of the personal information;
- rectify the information we hold about you;
- erase your personal information;
- restrict our use or disclosure of your personal information;
- object to our use or disclosure of your personal information for example you may object to direct marketing;
- request information about the use and processing of your personal information by [Gallagher Group];
- receive your personal information in a usable electronic format and transmit it to a third party (right to data portability);
- revoke the consent given by you for the processing of your personal information; or
- lodge a complaint with your local data protection authority.
If you would like to discuss or exercise such rights, as applicable under local law, please contact us at the details below.
We encourage you to contact us to update or correct your information if it changes or if the personal information we hold about you is inaccurate.
We will contact you if we need additional information from you in order to honour your requests.
4. Information sharing
We may share your personal information with third parties for the purposes described in this privacy notice under the following circumstances:
- Service providers and business partners. We may share your personal information with our service providers and business partners that perform marketing services and other business operations for us. For example, we may partner with other companies to process secure payments, fulfil orders, optimise our services, send newsletters and marketing emails, support email and messaging services and analyse information.
- Our group companies. We work closely with other businesses and companies that fall under [the Gallagher Group]. We may share your personal information with other [Gallagher Group] companies for marketing purposes (subject to applicable laws or regulations), internal reporting and other purposes as described in this privacy notice. A list of companies within our group can be found here: https://www.ajg.com/about-us/
- Law enforcement agency, court, regulator, government or quasi-governmental authority or other third party. We may share your personal information with these parties where we believe this is necessary to comply with a legal or regulatory obligation, to enforce or apply any agreements between us and you, to resolve any disputes, or otherwise to protect our rights or the rights of any third party.
- Asset purchasers. We will not sell your personal information to third parties other than to the extent reasonably necessary to proceed with the consideration, negotiation, or completion of a merger, reorganization, or acquisition of our business, or a sale, liquidation, or transfer of some or all of our assets. Should such a sale or transfer occur, we will use reasonable efforts to try to ensure that the entity to which we transfer your personal information uses it in a manner that is consistent with this privacy notice.
- Online ad technology firms. We may transfer information about you to ad technology firms so that they may recognise your devices and deliver interest-based content and advertisements to you. The information may include your name, postal address, email, device ID, or other identifier in encrypted form These firms may collect additional information from you, such as your IP address and information about your browser or operating system; may combine information about you with information from other companies in data sharing cooperatives in which we participate; and may place or recognise their own unique cookie on your browser.
Because we operate as part of a global business, the recipients referred to above may be located outside the jurisdiction in which you are located (or in which we provide the Services). See the section on "International Data Transfer" below for more information.
When required by applicable law, when we share personal information with corporate third parties we will ensure that such third parties maintain a comparable level of protection of the personal information as set out in this privacy notice by using contractual or other means. To the fullest extent permitted by applicable law, we exclude all liability arising from the use of your personal information by third parties. When required by applicable law, data transfers will be logged and documented, identifying the recipient of the data, the purpose of the transmission, and the type of data that was transmitted. Where required by law to do so, we can on request confirm the name of each third party that personal information is, or will be, transferred to.
5. Information security and storage
We implement technical, organisational, administrative and physical measures to help ensure a level of security appropriate to the risk to the personal information we collect, use, disclose and process. These measures are aimed at ensuring the on-going integrity and confidentiality of personal information. We evaluate these measures on a regular basis to help ensure the security of the processing. Please be aware that, despite our ongoing efforts, no security measures are perfect or impenetrable.
We restrict access to your personal information to those who require access to such information for legitimate, relevant business purposes.
We will keep your personal information for as long as we have a relationship with you. Once our relationship with you has come to an end, we will retain your personal information for a period of time that enables us to:
- maintain business records for analysis and/or audit purposes;
- comply with record retention requirements under the law;
- defend or bring any existing or potential legal claims;
- deal with any complaints regarding the Services;
We will delete your personal information when it is no longer required for these purposes. If there is any information that we are unable, for technical reasons, to delete entirely from our systems, we will put in place appropriate measures to prevent any further processing or use of the personal information.
5.1 Secure communications
Please be aware that e-mail messages sent in clear text over the public internet can be observed by an unintended third party. Non-encrypted Internet e-mail communications may be accessed and viewed by other internet users without your knowledge and permission while in transit to us. If you wish to keep your information private, please do not use electronic mail to communicate information to us or request information from us that you consider to be confidential and/or proprietary. If you wish, you may contact us instead via telephone at the phone number provided www.gallaghereb.com/ContactUs/Pages/default.aspx
5.2 Third-party vendors
For certain services on our website, such as live chat or webcasts, we will ask for information about you such as your name, business, and e-mail address. In cases where we use a third-party vendor to provide online services, the vendor has agreed to keep your information confidential. For example, transcripts of live chat sessions may be archived in a database by our vendor for review by our operators.
6. Links to other sites
We may provide links to other websites not owned or controlled by us that we think might be useful or of interest to you. We are not, however, responsible for the privacy practices used by other website owners or the content or accuracy contained on those other websites. Links to other websites do not constitute or imply endorsement by us of those web sites, any products or services described on those websites or any other material contained in them. We advise that you contact any third party websites directly for their individual privacy policies.
7. International data transfer
We may transfer certain personal information across geographical borders to our subsidiaries or service providers (working in conjunction with us or on our behalf) worldwide. Such transfers are made in accordance with applicable law.
Where you are based in the European Union you should be aware that your personal information may be transferred to, stored, and processed in a country that is not regarded as ensuring an adequate level of protection for personal information under European Union law.
Where you are based outside of the European Union, you should be aware that your personal information may be transferred to, stored, and processed in a jurisdiction that is not your home jurisdiction. You consent to the transfer, disclosure, storage and/or processing of your personal information outside the jurisdiction in which the information was originally collected.
We have put in place appropriate safeguards (such as contractual commitments) in accordance with applicable legal requirements to ensure that your personal information is adequately protected. For more information on the appropriate safeguards in place, please contact us at the details below.
8. Contact us
If you wish to exercise any of your rights detailed in section 3, our Data Protection Officer can be contacted at UK_GDPR@ajg.com.
We are committed to working with you to obtain a fair resolution of any complaint or concern about privacy. If, however, you believe that we have not been able to assist with your complaint or concern, you may have the right to make a complaint to the data protection authority in your country of residence.
9. Changes to the privacy notice
You may request a copy of this privacy notice from us using the contact details set out above. We may modify or update this privacy notice from time to time, under applicable local laws.
Where changes to this privacy notice will have a fundamental impact on the nature of our processing of your personal information or otherwise have a substantial impact on you, we will give you sufficient advance notice so that you have the opportunity to exercise any rights you may have under applicable law (e.g. to object to the processing).
25th May 2018
- We may obtain information about your general internet usage by using a cookie file which is stored on the hard drive of your computer. Cookies contain information that is transferred to your computer's hard drive. They help us to improve our site and to deliver a better and more personalised service. They enable us to:
- estimate our audience size and usage pattern;
- store information about your preferences, and so allow us to customise our site according to your individual interests;
- speed up your searches; and
- recognise you when you return to our site.