https://ensigninsuranceltd.com/
This Privacy Policy explains how Ensign Insurance Brokers Limited ("Ensign Insurance", "we", "us" or "our") collects, uses, shares, stores and protects personal data when you visit our website,
request an insurance quotation, enquire about our insurance and risk-management services, submit information for placement or administration of insurance, or otherwise interact with us through our digital channels.
This policy is intended to be read together with any service-specific terms, consent notices, cookie notice or other privacy information presented at the point where personal data is collected.
This policy applies to personal data processed through https://ensigninsuranceltd.com/ and related online interactions controlled by Ensign Insurance Brokers Limited. It also applies where information submitted through the website is subsequently used to provide or administer the relevant services.
For purposes of applicable privacy and data-protection laws, the entity determining the purposes and means of processing personal data will ordinarily act as the data controller (or equivalent role under applicable law). Service providers may act as processors or service providers on our instructions, while certain regulated or independent recipients may act as separate controllers.
We may also collect information from publicly available sources, regulators, service providers, business partners or other persons where this is lawful and relevant to the service or interaction.
Depending on your interaction with us, we process personal data to:
We process personal data in accordance with the privacy and data-protection laws that apply to the relevant individual, processing activity and jurisdiction. Where a law requires a specific lawful basis, we rely on the basis appropriate to the circumstances. Depending on the jurisdiction, this may include:
Where we process sensitive personal data, we will also rely on an additional condition permitted by law, such as explicit consent, legal/regulatory necessity, establishment or defence of legal claims, or another applicable statutory basis.
Insurance can require the processing of sensitive personal data, particularly health and medical information. We limit such processing to what is relevant to the requested cover, underwriting, policy administration or claims handling, apply enhanced access controls, and disclose it only to parties that require it for those purposes or as required by law.
We do not sell personal data. We may disclose personal data, on a need-to-know basis and subject to appropriate legal and contractual safeguards, to:
Where a third party processes personal data on our instructions, we require it to process the data only for authorised purposes, keep it secure and comply with applicable data-protection obligations. Independent recipients remain responsible for their own lawful processing.
Because our websites and services may be accessed internationally, personal data may be transferred to, stored in or accessed from countries other than the country in which you are located. Where applicable law regulates such transfers, we use a legally recognised transfer mechanism or safeguard, which may include adequacy decisions, standard contractual clauses, binding corporate rules, contractual safeguards, consent where valid, or another permitted mechanism. We apply additional safeguards to sensitive or special-category data where required.
Our website may use cookies, pixels, local storage and similar technologies to operate essential functions, remember preferences, maintain security, understand website performance and, where permitted, support analytics or marketing. Non-essential cookies should be used in accordance with applicable consent requirements. You can also manage cookies through your browser settings, although disabling essential cookies may affect website functionality.
Where permitted by law, we may use your contact details to send information about relevant products, services, offers or updates. We will provide an appropriate opportunity to opt out of direct marketing. You may withdraw your marketing consent or object to direct marketing at any time using the unsubscribe mechanism provided or by contacting us through the website. Service, security, regulatory and transactional communications are not marketing and may still be sent where necessary.
We use reasonable administrative, organisational, physical and technical measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include access controls, authentication, encryption where appropriate, secure configurations, backups, monitoring, staff confidentiality obligations, vendor controls and incident-response procedures. No internet transmission or storage system can be guaranteed to be completely secure.
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including service delivery, legal and regulatory compliance, tax and accounting, fraud prevention, audit, dispute resolution and the establishment, exercise or defence of legal claims. Retention periods vary depending on the type of information, the relationship and applicable sector requirements. When information is no longer required, we will delete, anonymise or securely dispose of it, subject to lawful exceptions.
Depending on where you are located and the law applicable to our processing, you may have some or all of the following rights, subject to lawful limitations and exemptions:
| Right | What it means |
|---|---|
| Be informed | receive clear information about how and why your personal data is processed. |
| Access | request confirmation whether we process your personal data and obtain a copy, subject to lawful limitations. |
| Rectification | ask us to correct inaccurate or incomplete personal data. |
| Erasure | request deletion of personal data where there is no lawful reason for continued processing, subject to legal and regulatory retention duties. |
| Restriction | request restriction of processing in circumstances permitted by law. |
| Object | object to processing based on legitimate interests and to direct marketing. |
| Data portability | receive certain personal data in a structured, commonly used and machine-readable format where applicable. |
| Withdraw consent | withdraw consent at any time where consent is the lawful basis, without affecting processing already carried out lawfully. |
| Automated decisions | seek human review where a decision based solely on automated processing produces legal or similarly significant effects, where applicable. |
| Complain | raise a concern with us and, where applicable, lodge a complaint with the competent privacy or data-protection authority in your jurisdiction. |
We may need to verify your identity before acting on a rights request. Rights are not absolute; where we lawfully decline or limit a request, we will explain the basis where required.
Our website is not intended to collect personal data from children unless this is necessary for a specific service and is handled in accordance with applicable law. Where information about a child is required, we will seek appropriate authority or consent from a parent, guardian or other authorised person where required.
Our website may contain links to third-party websites, platforms or services. We are not responsible for the privacy practices of independent third parties. We encourage you to review their privacy notices before providing personal data.
We maintain procedures for identifying, assessing and responding to personal-data breaches. Where a breach is legally reportable, we will notify the competent data-protection or privacy authority and affected individuals within the time and manner required by the applicable law.
This is a global privacy notice. Privacy rights and our obligations may vary by jurisdiction. Where applicable, we will comply with mandatory local requirements, including the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the Kenya Data Protection Act 2019, South Africa’s Protection of Personal Information Act (POPIA), and other applicable national or state privacy laws. If a mandatory local rule provides greater protection than this policy, that rule will apply to the relevant processing.
Residents of jurisdictions that provide additional rights may, where applicable, request information about categories or specific pieces of personal data collected, correction or deletion, restriction or objection, portability, withdrawal of consent, information about disclosures, and review of certain automated decisions. Where applicable law provides rights to opt out of the sale, sharing or use of personal data for targeted or cross-context behavioural advertising, we will honour valid requests. We do not discriminate against individuals for exercising applicable privacy rights.
We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal obligations or data-processing practices. The version published on the website is the current version and applies from the time it is uploaded. Material changes may also be communicated through an appropriate website or service notice.
For privacy questions, requests or complaints, please contact us through the contact details or Contact Us facility published on our website:
https://ensigninsuranceltd.com/
Website contact details currently published: info@ensigngroup.world | +254 703 660 066.
You may also have the right to lodge a complaint with the competent data-protection or privacy regulator in the country or region where you live, work, or where you believe an infringement occurred. Where Kenya law applies, this includes the Office of the Data Protection Commissioner of Kenya.