Privacy & Data Protection Policy
Howden is committed to protecting your privacy on-line. At Howden, we appreciate that you do not want the personal information you provide to us distributed indiscriminately. Here, we explain how we collect information and what we do with it.
Introduction
We, Howden Puri Insurance Brokers Limited (“we”, “us”, “our”), part of the Howden Group, need to collect, process and share information, including information which may identify individuals (‘personal data’), in order to provide our insurance broking services. This Privacy Notice applies to you in the event that we have collected personal data from or about you. It explains when, why and how we collect and process your personal data, the third parties with which we may share your personal data, what your rights are in the event we hold your personal data, and how you can enforce these rights.
We may amend this Privacy Notice from time to time in order to reflect any changes in how we process personal data, or to satisfy any new requirements under applicable data protection laws. If we make any significant changes, we will let you know directly.
Definitions
To be clear on what we mean in this Privacy Notice:
- “Applicable data protection law(s)” means applicable data protection laws in the United Republic of Tanzania including Personal Data Protection Act (the “PDPA”).
“Personal data” means any information that identifies or can be used to identify an individual;
“Sensitive data” means personal data concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, genetic data, biometric data, health data, sex life or sexual orientation, data relating to security criminal convictions and offenses and data that indicates that one or both of the individual’s parents are unknown;
“controller” means an organisation that decides why and how to collect and process personal data from or about an individual;
“processor” means an organisation that is engaged by a controller to process personal data on its behalf;
“The Howden Group” means Howden Group Holdings Limited and any company or organisation in which Howden Group Holdings Limited holds significant share capital. Howden is international insurance group that supports clients while using insurance as a tool to increase resilience for individuals, businesses, and communities.
“third-party” means someone who isn’t you, us, or a company in the Howden Group.
“PDPC” means the Personal Data Protection Commissioner.
Who does this Privacy Notice relate to
This Privacy Notice relates to the following types of individuals (“you”, “your”, “data subjects”) where we hold your personal data:
Directors, authorised personnel, beneficial owners, other associates of, or persons exercising control over, prospective, current and former clients or intermediaries that we do business with;
Individuals who contact us with a query, concern or complaint;
Individuals who request information from us or permit us to contact them for marketing purposes.
Our details
We are a data controller and data processors, and our offices are at I&M House @1046 Haile Selassie Rd, Dar es Salaam, Tanzania.
Should you have a data protection query, wish to enforce one of your rights or wish to make a data protection complaint, then please send an email to [email protected].
You can also raise a request/concern via the feedback section of the website.
What personal data do we collect
Depending on your relationship with us, we may collect the following types of personal data from or about you:
Identity and contact data: for example, your name, gender, date of birth, postal address, job title, telephone number and e-mail address. We may also collect identification details and documents to verify your identity;
Policy and claims information: for example, your policy number, insured amounts, premiums due, relationship to the policyholder, claims made via us or your previous claims history;
Payment and account data: for example, your bank account details, credit/debit card details if you are the payer of a premium or are receiving a claim;
Location data: for example, your residential or IP address, the location of any insured property, and in the event of a claim, where the incident occurred;
Correspondence data: for example, copies of letters and e-mails we send you or you send to us, and notes or call recordings of any telephone conversations
Information we obtain from other sources: for example information we obtain from credit agencies, anti-fraud and other financial crime prevention agencies when permitted to do so under applicable data protection laws;
Complaint data: for example, what the complaint was, how we investigated it and how we resolved it, including any contact with third-party adjudicator services;
Any other information provided to us in the course of your engagement with us
Sensitive data: in some cases it may be necessary for us to collect more sensitive types of information, for example health-related data, as part of responding to a claim, or it may be necessary for us to collect data relating to criminal convictions or offences as part of undertaking ‘know your customer’ checks which are required by our regulators.
How do we collect personal data
We may collect personal data from, or about, you at different times and through different channels depending on our relationship with you, for example if:
You request an insurance quotation from us, either directly or via an intermediary;
You purchase, change or cancel an insurance policy;
You are named on the insurance policy of our client;
We receive notification of a claim that is made against you or that you bring against one of our policyholders;
You are a client of a business that we acquire;
You contact us in writing or speak to us on the phone;
You visit one of our stands at a show or trade fair;
You give permission to other companies to share your information with us;
Your information is publicly available through sources such as regulatory or company registers, which we may need to consult in order to satisfy our due diligence processes for new and existing clients;
We are provided with your information from your employer or intermediary when they complete one of our proposal forms or questionnaires; or
We are provided with your personal data by other third parties including antifraud and crime-prevention agencies, credit reference and vetting agencies, and other data providers.
Our purposes and lawful bases for processing
We are required to establish a lawful basis and purpose for collecting personal data. Generally, we collect personal data pursuant to the following lawful bases and purposes:
To comply with a legal obligation: for example, to fulfil your data rights under data privacy laws, handle complaints about data privacy or our financial products and services, and to comply with other legal requirements such as preventing money laundering and other financial crimes;
For our legitimate business interests: for example, to provide our client (who may be your employer) with a quote or broking services, to share data internally for administrative purposes, to improve our products and services, or carrying out analytics across our datasets. Where we rely on this lawful basis, we assess our business needs to ensure they are proportionate and do not affect your rights. In all cases, we will not rely on this lawful basis to process sensitive data;
For the implementation of a previous agreement to which you are a party;
With your consent: for example, if you consent to us processing your personal data for marketing purposes; and
To protect actual interests: in extreme or unusual circumstances, we may need to use your personal data to protect your moral or material interest.
The processing of sensitive data requires additional controls. If and where we collect this type of our data, these controls may include:
Your explicit consent, we will ask for your clear, written permission before collecting or using sensitive data.
The establishment, exercise, or defence of legal claims, we may process sensitive data if it is necessary to protect our legal rights or respond to legal proceedings.
Compliance with anti-money laundering (AML) or counter-terrorist financing (CTF) laws
Sensitive data may be processed to meet legal obligations under financial crime regulations.
Vital interests of the data subject
We may process sensitive data to protect your life or health when you are unable to give consent.
Medical diagnosis or health care services
Sensitive data may be processed under the supervision of a health professional for medical treatment or diagnosis.
Public interest or lawful functions of a public authority
Processing may be permitted if necessary for tasks carried out in the public interest or by a public authority.
Obtaining your explicit consent to process your sensitive personal data;
Not processing your sensitive personal data for marketing purposes;
Not collecting or processing your sensitive personal data for scientific, research, or statistical purposes without your explicit consent.
Restricting processing of any health data, including medical files, that we may hold on you for the purposes specified above to the minimum number of employees or workers required and granting access only to the extent necessary to enable the provision of any required health services; and
Restricting any health data processing procedures and operations to the minimum extent possible of employees and workers as necessary to enable the provision of health insurance services or to offer health insurance programs.
PLEASE NOTE – Collection of personal data is mandatory unless stated otherwise. Where you do not provide the requested personal data such as where our lawful basis of processing is your explicit consent, documentation that you need to complete will include a provision where you can indicate that consent. If you choose to withdraw your consent we will tell you more about the possible consequences, including that we may no longer be able to act as your broker of record or place or administer your policy and that you may have difficulties finding other cover. Further, we may not be able to support you in processing your claim.
We will not process your personal data in a manner that is inconsistent with the purpose for which we have collected the data or the basis on which we have relied to collect your personal data, unless we have your consent or a legal basis to process the personal data for an additional purpose.
Who do we share personal data with
Below are the categories of third parties we may share your personal data with for the purposes described under Section 7:
Other Howden Group companies;
Insurers, (Re)insurers and intermediaries including but not limited to other Insurance Brokers and Managing General Agencies;
Risk Management Assessors, Uninsured Loss Recovery Agencies and Third-Party Administrators who work with us to help manage the insurance process and administer our policies;
Service Providers who help manage our IT and back-office systems, or who provide platforms and portals for administering policies and member details;
Our regulators and law enforcement agencies (including authorities outside of the location which personal data has been collected);
Credit reference agencies, Premium Finance Providers, and organisations working to prevent fraud in financial services;
Solicitors (who may be legal representatives for you, us or a third-party claimant) and other professional services firms (including our auditors);
Marketing fulfilment, webinar and customer satisfaction service providers, acting on our behalf in facilitating online events, providing marketing communications and capturing feedback from our customers on our service levels;
Claims Experts who work with us to help manage the claims process;
Potential purchasers of our businesses.
A list of third parties with whom personal data is shared is available below.
Sharing data with the Howden Group
As stated in the previous section, we may share personal data with other companies within the wider Howden Group for the following purposes:
To receive administrative support from those companies, such as the receipt of IT, HR, Finance and Compliance services;
So that these companies can provide market insight to insurers on a confidential basis, but only where personal data has been aggregated or anonymised; and
So that we can offer you services that may be available from another company in the Howden Group, but only if permitted under marketing laws.
We will only share the minimum amount of personal data required to achieve these purposes, ensuring that we have a lawful basis to share personal data and that any processing undertaken on our behalf is governed by a data processing agreement.
International data transfers
In line with one of the legal bases identified in Section 7 above and in line with applicable data protection law, we may need to transfer, or allow access to, your personal data to parties based outside of the United Republic of Tanzania. Where we do this, we will ensure that your personal data is transferred in accordance with the applicable data protection law’s requirements.
You have the right to ask us for more information about the safeguards we have put in place as mentioned above.
Retaining personal data
We will retain your personal data only for as long as is necessary to fulfil the purpose as set out in Section 7, or as required by applicable data protection laws. In most cases this will be for ten (10) years following the end of our relationship with you however, in some circumstances we may retain your personal data for longer periods of time, for instance;
Where we are required to do so in accordance with legal, regulatory or accounting rules;
So that we have an accurate record of your dealings with us in the event of any complaints or challenges;
If we reasonably believe there is a prospect of litigation relating to your personal dealings.
We maintain a data retention policy which we apply to records in our care. Where your personal data is no longer required we will ensure it is either securely deleted or stored in a way which means it will no longer be used by the business.
Security
We are committed to protecting the personal data you provide us. We have implemented security policies, rules and technical measures to protect the personal data that we have under our control, in accordance with applicable data protection laws. The security measures are designed to prevent unauthorised access, improper use or disclosure, unauthorised modification and unlawful destruction or accidental loss. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
Automated decision-making
Please note we do not undertake any automated decision-making or profiling with your personal data.
Your rights
Data protection law gives you rights relating to your personal data. Should you wish to enforce a right (generally at no cost to you), or make a data protection complaint, please contact [email protected]
1. Right to Be Informed
You have the right to be informed about the collection and use of your personal data, including the purpose, legal basis, and recipients of the data.
2. Right of Access
You may request access to your personal data held by a data controller, including confirmation of whether your data is being processed and details of such processing. You have a right to request a copy of the personal data that we hold on you in a readable and clear format, along with meaningful information on how it is used and who we share it with, however there are some instances where we may not be able to provide you with some or all of the information we hold. Where this is the case, we will explain to you why when we respond to your request, unless the relevant applicable data protection laws or regulations prevent us from doing so.
3. Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data to ensure it is up to date and accurate. You have a right to ask us to correct inaccurate or incomplete personal data that we hold about you. We will either confirm to you that this has been done, or if there is a valid reason that this cannot be done, we will let you know why. This is subject to any supporting documents or evidence which may be required to verify such request.
4. Right to Erasure ("Right to be Forgotten")
You may request the deletion of your personal data where it is no longer necessary for the purpose for which it was collected, or where processing is unlawful. You can request that we delete your personal data in certain circumstances, for example if we no longer need the personal data for the purpose(s) for which we collected it. We will either confirm to you that this has been done, or if we are unable to delete it due to a compelling overriding reason, we will let you know why.
5. Right to Restrict Processing
You can request that the processing of your personal data be restricted in certain circumstances, such as when the accuracy of the data is contested or processing is unlawful. You can ask us to restrict the processing of your personal data in certain circumstances. If you do so, we will either confirm that this has been done, or if we are unable to do so, we will let you know why.
6. Right to Object
You have the right to object to the processing of your personal data, particularly where it is used for direct marketing or profiling.
7. Right to Data Portability
You may request to receive your personal data in a structured, commonly used, and machine-readable format, and have the right to transmit that data to another controller. In certain circumstances you have the right to request that your personal data be transferred to yourself or a nominated third party in a common, machine-readable format. If you request this, we will either act upon your instruction and confirm to you that we have done so, or if there is a valid reason that this cannot be done, we will tell you why.
8. Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, which may significantly affect you.
9. Right to Lodge a Complaint
You may file a complaint with the Personal Data Protection Commission if you believe your personal data has been mishandled or your rights have been infringed.
10. Right to Appeal
If you are dissatisfied with the decision of the Commission, you have the right to appeal to a competent court.
Your acceptance of these terms
If we change our privacy policy in any way, we will post these changes on this page.
Any questions, concerns or comments you have about this policy, please complete the feedback form or write to us at:
Howden Puri Insurance Broker,
I&M House @1046 Haile Selassie Rd, Dar es Salaam, Tanzania.