Privacy and Data Protection Policy

 

 

EFFECTIVE DATE: This Privacy and Data Protection Policy was last revised on April 30, 2018
You have arrived at a website that is owned and/or operated by Watford Holdings Ltd. and its subsidiaries (collectively, “Watford” or “we,” “our” or “us”). The purpose of this Privacy and Data Protection Policy (this “Policy”) is to explain how, when and why we collect and use information that directly or indirectly identifies you (“personal data”) under the following circumstances:
  • When you access our website (the “Website”) regardless of how you access or use the Website, whether via personal computers, mobile devices or otherwise; or
  •  When you purchase an insurance policy underwritten directly by us or from a third party insurance company that enters into a reinsurance arrangement with us, which is referred to as “reinsurance”.
It is therefore important that you read this Policy and show it to any other person who is insured under your insurance policy. This Policy is not intended to override the terms of any insurance policy or contract you have with us, nor rights you are afforded under applicable privacy and data protection laws.
If you are located in the European Economic Area (“EEA”), it is important that when you read this Policy you refer in particular to Section 9.
Watford is a group of companies which writes insurance and reinsurance on a worldwide basis through its principal operations in Bermuda, the United States and Europe. Our insurance companies write policies either directly or in some cases through unaffiliated co-insurers or through other third parties known as managing general agencies. The company which was originally responsible for collecting information about you in connection with obtaining your Watford policy (whether one of the Watford companies, a co-insurer or a managing general agency) will be principally responsible for your personal data (the “data controller”). your policy will be with the particular Watford company named on the policythisy.
In addition, please review the Website’s Terms and Conditions of Use, which governs your use of the Website.
It is important that you read and understand the entire Policy before using the Website. Please click on the headings in the table of contents to go directly to the full explanation of a specific issue or point.

 

TABLE OF CONTENTS
1. What Personal Data do We Collect?
i. Prospective Insureds and Insureds
ii. Claimants
iii. Business Partners and Website Users
2. When do We Collect Your Personal Data?
i. Prospective Insureds and Insureds
ii. Claimants
iii. Business Partners and Website Users
3. How Do We Use the Personal Data Collected?
i. Prospective Insureds and Insureds
ii. Claimants
iii. Business Partners and Website Users
4. How and When Do We Disclose Personal Data to Third Parties?
5. Ads and Information About You
6. Do Not Track Disclosures
7. Does the Site include Third Party Content and Links to Third Party Websites?
8. How Do I Change My Information and Communications Preferences?
9. Additional information regarding individuals in the EEA
i. Legal basis for processing personal data or of individuals in the EEA.
ii. Legal basis for processing personal data (including usage information) relating to Website users in the EEA.
iii. Criminal Convictions and Offenses Data and Special Categories of Personal Data of Individuals in the EEA.
iv. What additional rights do you have if you are in the EEA?
v. Transfers of Personal Data out of the EEA.
10. Children’s Privacy
11. Security of Personal Data
12. How Long Do We Retain Your Personal Data?
13. Changes to Our Privacy Policy
14. Contact Us

 

1. What Personal Data do We Collect?
i. Prospective Insureds and Insureds
In order to provide insurance quotes and policies and administer your insurance, we need to collect and process certain personal data about you. If you do not provide the information we need, we also may not be able to offer you a quote or provide our services to you. We may have to cancel our services with you but in that case we will notify you and provide an explanation.
The types of personal data may include:

ii. Claimants
In order to deal with any claims, we need to collect and process certain personal data about you. If you do not provide the information we need, we may not be able to handle the claim.
The types of personal data may include:

iii. Business Partners and Website Users
  • Business Partners: If you are a business partner, we will collect your business contact details. We may also collect information about your professional expertise and experience.
  • Website Users: If you are a Website user:
• You may voluntarily provide us with personal data where you voluntarily provide this to us (e.g., to contact us, or for us to contact you). You can visit the Website without revealing who you are or providing any personal data about yourself. However, there will be times, such as when you request information or a publication from us through the Website, when we will need to obtain personal data from you or about you. We may collect this personal data through various forms and in various places on the Website, including application forms, "Contact Us" forms or when you otherwise interact with the Website. Additionally, we may also make certain online services available, such as an online portal, that permits our customer account holders to access their business accounts.
• We and our third-party service providers may use a variety of technologies that automatically (or passively) store or collect certain information whenever you visit or interact with the Website based on your use of the Website (“usage information”). This usage information may be stored or accessed using a variety of technologies that may be downloaded to your personal computer, browser, laptop, tablet, mobile phone or other device whenever you visit or interact with our Website. You may have other options regarding tracking and/or targeting. Please see our Cookies Policy for further information.
• We may, from time to time, supplement the information we collect directly from you on the Website with outside records from third parties for various purposes, including to enhance our ability to serve you, to tailor our content to you and to offer you opportunities that may be of interest to you. We will apply this Policy to such supplemental information and where such supplemental information amounts to personal data (and/or the combined information amounts to personal data), it will be treated as personal data.
2. When do we Collect your Personal Data?
i. Prospective Insureds and Insureds
We will collect your personal data: (1) directly from you when you apply for an insurance policy; (2) from third parties, such as an intermediary (e.g., an insurance broker or managing general agency), or other third party insurance companies (e.g., if you are a policyholder with an insurance company which (i) is a co-insurer with a Watford company or (ii) has a reinsurance arrangement with a Watford company) or your employer where, for example, they apply for an insurance policy under which you will be a beneficiary; and (3) from other sources (e.g., credit reference agencies and government agencies) and other public sources where necessary to, for example, comply with applicable sanctions and anti-money laundering laws.
ii. Claimants
We will collect your personal data: (1) when you or a third party (e.g., your employer or attorney) notify us of a claim either directly or through an intermediary (e.g., an insurance broker or managing general agency) or other third party insurance companies (e.g., if you are a policyholder with an insurance company which has a co-insurance or reinsurance arrangement with a Watford company); and (2) from other sources (e.g., credit reference agencies and government agencies) and other public sources where necessary, for example, to validate the claim or comply with applicable anti-money laundering laws and sanctions.
iii. Business Partners and Website Users
We will collect your personal data: (1) where you or your employer provides your contact or other information to us in the course of working with us, either directly as a business partner or as a representative of your company; (2) where you attend meetings, events or conferences that we organize or sponsor; and (3) where you visit and/or contact us through the Website or one of our online portals. For more information on how we collect technical data about your device and browsing activities, see our Cookie Policy.
3. How Do We Use the Personal Data Collected?
i. Prospective Insureds and Insureds
In order to provide insurance quotes and policies and administer your insurance we may use your personal data for the following purposes:
  • To consider an application for an insurance policy, assess and evaluate risk, and where applicable, provide you with insurance cover;
  • To manage and administer your insurance policies with you or your employer (including dealing with your queries);
  • For reinsurance purposes;
  • To improve our insurance products and services, to carry out market research, to perform data analytics, for general risk modelling purposes, for transferring books of business, company sales and reorganizations, and for statistical analyses; and
  • For the prevention and detection of fraud, money laundering or other crimes; and
  • For direct marketing.
Additional information concerning the legal basis for processing personal data of individuals in the EEA is provided in Section 9 below.
ii. Claimants
In order to deal with any claims, we may process your personal data for the following purposes:
  • For claims processing including assessing and evaluating the merits of a claim and to pay a settlement;
  • For statistical analyses; and
  • For the prevention and detection of fraud, money laundering or other crimes.
Additional information concerning the legal basis for processing personal data of individuals in the EEA is provided in Section 9 below.
iii. Business Partners and Website Users
Business Partners
As part of our business activities, we may process your personal data for the following purposes:
  • To manage our relationship with you and to, for example, invite you to events; and
  • To administer our contract with you or your employer.
Website Users:
As part of our business activities, we may process your personal data for the following purposes:
  • To improve the Website or our services, to customize your experience on the Website, or to serve you specific content that is relevant to you;
  • To contact you with regard to your use of the website and, in our discretion, changes to the website or the website policies;
  • For internal business purposes, including to help us understand how our Website is navigated and used;
  • For direct marketing; and
  • Where you submit personal data in connection with a career opening or by submitting a resume through the Website, we will use that information only for the purpose of evaluating your qualifications in order to allow us to make an informed decision about whether to proceed with your application.
4. How and When Do We Disclose Personal Data to Third Parties?
We may share Website usage data, such as aggregated user statistics, with third parties. In addition, we may share with third parties the information we have collected about you, including personal data, to provide our services and comply with legal obligations. We do not share your personal data with third parties for their marketing purposes unless you have consented to such sharing.
These third parties may include:
  • Other Companies. We may share your personal data with other companies in the Watford group of companies. We also reserve the right to disclose and transfer such information: (1) to a subsequent owner, co-owner or operator of the Website; or (2) in connection with a merger, consolidation, restructuring, the sale of substantially all of our interests and/or assets or other corporate change, including, during the course of any due diligence process.
  • Third Party Intermediaries. We may disclose your personal data to intermediaries (e.g., brokers, managing general agents, third party administrators) and other (re)insurers.
  • Third Parties Providing Services on our Behalf. We may use third party vendors to perform certain services on our behalf, such as technical support and back-office services, loss adjustors and claims experts, hosting services and Website activity tracking and analytics. We may also disclose your personal data to our advisors (e.g., attorneys and other professional services firms).
  • Judicial, Regulatory and Law Enforcement Bodies. We may disclose your personal data to judicial, regulatory and law enforcement bodies, including, but not limited to: (1) satisfy any applicable law, regulation, subpoenas, governmental requests or legal process if in our good faith opinion such disclosure is required or permitted by law; (2) protect and/or defend our rights, property and/or interests (including, the Website’s Terms and Conditions of Use or other policies applicable to the Site) and investigation of potential violations thereof; (3) protect the safety, rights, property or security of Watford or any third party where we are legally required or advised to do so; and (4) detect, prevent or otherwise address fraud, security or technical issues. Further, we may use Website usage information or device identifiers to identify users, on our own or in cooperation with third parties and/or law enforcement agencies, including disclosing such information to third parties, all in our discretion and subject to applicable law. Such disclosures may be carried out without notice to you.
5. Ads and Information About You
In accordance with our Cookie Policy, data about your online activity may be collected on our Website for use in providing advertising tailored to your individual interests. This process also helps us track the effectiveness of our marketing efforts. We may also use tracking technologies, such as our own cookies, to provide you with further information about your interests. The information collected may include information about your visits to our Website, such as the pages you have viewed. These third-party tracking technologies may be set to, among other things: (1) help deliver advertisements to you that you might be interested in; (2) prevent you from seeing the same advertisements too many times; and (3) understand the usefulness to you of the advertisements that have been delivered to you. Note that any images (or any other parts of content) served by third parties in association with third-party ads or other content may act as web beacons, which enable third parties to carry out the previously described activities.
We are not responsible for effectiveness of or compliance with any third-parties’ opt-out options. Third-party tracking technologies are not controlled by us, even if they use our technology to help store or collect data. Statements regarding our practices do not apply to the methods for collecting information used by these third-party advertisers and others or the use of the information that such third parties collect. The relevant third party’s terms of service, privacy policy, permissions, notices and choices should be reviewed regarding their collection, storage and sharing practices. We make no representations regarding the policies or practices of third-party advertisers or advertising networks or exchanges or related third parties.
Our Cookie Policy provides additional details and explains how you can limit the collection of this information through adjusting the settings on your browser.
6. "Do Not Track" Disclosures
Various third parties are developing or have developed signals or other mechanisms for the expression of consumer choice regarding the collection of information about an individual consumer’s online activities over time and across third-party websites or online services (e.g., browser "do not track" signals). Currently, we do not monitor or take any action with respect to these signals or other mechanisms.
7. Does the Website include Third Party Content and Links to Third Party Websites?
The Websiteite may contain content that is supplied by a third party, and those third parties may collect usage information and your device identifier when web pages from the Website are served to you. In addition, when you are on the Website you may be directed to other websites that are operated and controlled by third parties. We are not responsible for the data collection and privacy practices employed by any of these third parties or their webites. For example, if you “click” on a link, you may be directed away from our Website to a different website. These other websites may associate their tracking technologies with you, and independently collect data about you, including personal data. We encourage you to note when you leave our Website and to review the third party privacy policies and exercise caution in connection with them.
8. How Do I Change My Information and Communications Preferences?
i. You are responsible for maintaining the accuracy of the information you submit to us, such as your contact information provided through the Website. If you wish to access, update or review your data, please email: WatfordDPO@WatfordHoldings.com.
ii. You may cancel or modify the email marketing communications you receive from us by following the instructions contained in our promotional emails or in some cases by logging into your Website account and changing your communication preferences. This will not affect subsequent subscriptions and you may limit your opt-out to certain types of emails.
iii. Please note that we reserve the right to send you certain communications relating to your account or use of the Website, such as administrative and services announcements and you will continue to receive these transactional communications if you opt-out from receiving marketing communications.
9. Additional information regarding individuals in the EEA
i. Legal basis for processing personal data or of individuals in the EEA.
We will only use your personal data for the purposes for which we collect such personal data, as outlined below and in Section 3 above, unless we need to use it at a later date for another purpose that is compatible with the original purpose. If we need to further process your personal data for a purpose that is not compatible with the original purpose for collection, we will notify you and provide an explanation of the legal basis which allows us to do so. Please note that we may process your personal data without your knowledge or consent, in compliance with the applicable data protection laws.


We may determine later that another necessary purpose which is compatible with the original purpose. If you wish to obtain information as to how the processing for the new purpose is compatible with our original purpose, please contact us or email: WatfordDPO@WatfordHoldings.com.
If we need to use your personal data for an unrelated purpose, we will notify you and provide an explanation of the legal basis which allows us to do so.
ii. Legal basis for processing personal data (including usage Information) relating to Website users in the EEA.


iii. Criminal Offenses and Convictions Data and Special Categories of Personal Data of Individuals in the EEA
  • Criminal Offenses and Convictions Data: We will only process personal data relating to criminal offenses and convictions for the following purposes: (i) in order to underwrite risk appropriately, calculate a quote or policy renewal in the context of motor insurance, to risk-assess any person who will be driving the insured vehicle (e.g. a risk assessment), (ii) for fraud detection or prevention or (iii) where required for claims handling. We will only carry out such processing where it is authorized by applicable law.
  • Special Categories of Personal Data: Where we process your special categories of personal data (e.g., health data) for any of the above purposes, we will only do so where: (1) you have given explicit consent to the processing of your special categories of personal data for these purposes – which you may withdraw at any time; (2) the processing is necessary to protect your vital interests (or those of a third party); (3) you have manifestly made your special categories of personal data public; (4) the processing is necessary for the establishment, exercise or defense of legal claims; or (5) the processing is necessary for reasons of substantial public interest on the basis of applicable law.
iv. What additional rights do you have if you are in the EEA?
If you are located in the EEA, you have several rights in relation to your personal data under applicable privacy and data protection law, which may be subject to certain limitations and restrictions. We aim to respond to any valid requests within one month unless it is particularly complicated or you have made repeated requests in which case we aim to respond within three months. We will inform you of any such extension within one month of receipt of your request, together with the reasons for the delay. You will not be charged a fee to exercise any of your rights unless your request is clearly unfounded, repetitive or excessive, in which case we will charge a reasonable fee in the circumstances or refuse to act on the request. If you wish to exercise any of these rights, please contact us using the contact details set out in Section 14 below. We may request proof of identification to verify your request.




v. Transfers of Personal Data out of the EEA
If you are located in the EEA, the personal data we collect from you may be transferred to, and stored at, a destination outside of the EEA (including Bermuda, Switzerland and the United States) for the purposes described above.. The recipients may be located in countries which do not provide a similar or adequate level of protection to that provided by countries in the EEA.
Transfers within the Watford group will be covered by data transfer agreements designed to ensure the protection of your personal data when it is transferred outside of the EEA, in accordance with Article 46(2) (c) of the General Data Protection Regulation [(EU) 2016/679] ("GDPR") ("Model Clauses").
Transfers to service providers and other third parties will comply with applicable data protection laws (e.g., under Model Clauses or the EU/Swiss - U.S. Privacy Shield in accordance with Article 45 of the GDPR).
The Website is hosted in the US.
You may withdraw your consent at any time.
We may also transfer your personal data outside of the EEA when required by law (e.g., if we receive a request from a foreign judicial, regulatory or law enforcement body). Such transfers will be made in accordance with applicable data protection laws.
If you would like further information about the safeguards we have implemented please contact us using the contact details set forth in Section 14 below.
10. Children’s Privacy
The Website is not targeted at children, as defined by local law, and we do not knowingly collect any personal data from children. We will delete any personal data we determine to have been collected from a child or user under the applicable age of consent. If you are a parent or guardian of a child under the relevant digital age of consent and believe he or she has disclosed personal data to us, please contact us at WatfordDPO@WatfordHoldings.com.
11. Security of Personal Data
We implement appropriate technical and organizational measures against unauthorized or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.
Although we take appropriate measures to protect the security of the information communicated through the Website, no Internet-connected computer system can be made absolutely secure from intrusion. We, therefore, cannot and do not guarantee that information communicated by you to us via the Website will be received or that it will not be altered before or after its transmission to us. If you elect to use the Website to communicate with us or provide us with information, you do so at your own risk.
12. How Long Do We Retain Your Personal Data?
We retain your personal data only for as long as necessary in accordance with our document retention policy and in accordance with legal, regulatory, tax or accounting requirements, or for dealing with complaints, legal challenges or prospective litigation.
13. Changes to Our Privacy Policy
We reserve the right to change, update and/or modify this Policy at any time without notice to you. Any changes will be effective immediately upon the posting of the revised Policy. However, if we make material changes to this Policy we will notify you by means of a prominent notice on the Website prior to the change becoming effective. Please review the Policy whenever you access or use this Website.
To the extent any provision of this Policy is found by a competent tribunal to be invalid, illegal or unenforceable, such provision shall be deemed to be severed to the extent necessary, but the remainder shall be valid and enforceable.
14. Contact Us
If you have any questions about our Policy or practices described in it, you should contact us in the following ways:
    • Postal Mail: Watford Data Protection Officer, Watford Holdings Ltd., 100 Pitts Bay Road, Hamilton HM-08 Bermuda.
    • By e-mail: WatfordDPO@WatfordHoldings.com.