Privacy Policy

Ensign Insurance Brokers Limited

https://ensigninsuranceltd.com/

This Privacy Policy explains how Ensign Insurance Brokers Limited ("Ensign Insurance", "we", "us" or "our") collects, uses, shares, stores and protects personal data when you visit our website, request an insurance quotation, enquire about our insurance and risk-management services, submit information for placement or administration of insurance, or otherwise interact with us through our digital channels.

This policy is intended to be read together with any service-specific terms, consent notices, cookie notice or other privacy information presented at the point where personal data is collected.

1. Who we are and scope of this policy

This policy applies to personal data processed through https://ensigninsuranceltd.com/ and related online interactions controlled by Ensign Insurance Brokers Limited. It also applies where information submitted through the website is subsequently used to provide or administer the relevant services.

For purposes of applicable privacy and data-protection laws, the entity determining the purposes and means of processing personal data will ordinarily act as the data controller (or equivalent role under applicable law). Service providers may act as processors or service providers on our instructions, while certain regulated or independent recipients may act as separate controllers.

2. Personal data we may collect

  • Identification and contact information, including names, telephone numbers, email addresses, postal addresses and other contact details.
  • Quotation and policy information, including the type of cover requested, sums insured, insured assets, dependants, beneficiaries and information needed to obtain, place, renew or administer insurance.
  • Financial and transaction information, including premium and payment information where relevant.
  • Claims-related information, including accident, loss, incident, witness, third-party and supporting-document information.
  • Health and other sensitive personal data where relevant to medical, life, personal accident, travel, WIBA or other insurance products. We process such data only where permitted by law and where it is necessary for the insurance service requested.
  • Identity, due-diligence and compliance information required by insurers, regulators or applicable anti-fraud, anti-money laundering or sanctions controls.
  • Website and device information, including IP address, browser/device type, pages visited, referral information, cookies and similar technologies.
  • Communications and preferences, including quotation requests, enquiries, complaints, marketing preferences and records of correspondence.

We may also collect information from publicly available sources, regulators, service providers, business partners or other persons where this is lawful and relevant to the service or interaction.

3. How we collect personal data

  • Directly from you when you complete a form, create an account, request a quotation or service, send us a message, submit documents or otherwise communicate with us.
  • From another person acting for or connected with you, such as an employer, family member, authorised representative, customer, supplier, counterparty or adviser.
  • Automatically when you use our website or digital services, through server logs, cookies and similar technologies.
  • From third parties and public sources where necessary for verification, service delivery, compliance, security or legitimate business purposes.

4. Why we process personal data

Depending on your interaction with us, we process personal data to:

  • respond to enquiries and provide quotations, insurance placement, policy administration, renewals, endorsements and claims support;
  • assess insurance needs and communicate with insurers, underwriters, reinsurers, medical providers, loss assessors, investigators and other insurance-market participants as necessary;
  • verify identity, prevent fraud, comply with regulatory, legal, audit and record-keeping requirements, and manage complaints and disputes;
  • process payments and reconcile premiums or other amounts where applicable;
  • improve our website, services, customer experience, security and business operations; and
  • send product updates or marketing communications where permitted by law, with a clear means to opt out.

5. Lawful bases for processing

We process personal data in accordance with the privacy and data-protection laws that apply to the relevant individual, processing activity and jurisdiction. Where a law requires a specific lawful basis, we rely on the basis appropriate to the circumstances. Depending on the jurisdiction, this may include:

  • performance of a contract with you or taking steps at your request before entering into a contract;
  • compliance with a legal or regulatory obligation;
  • our legitimate interests or those of a third party, where those interests are not overridden by your rights and freedoms;
  • your consent, where consent is appropriate or legally required;
  • protection of vital interests in limited circumstances; and
  • another lawful basis expressly recognised by applicable law.

Where we process sensitive personal data, we will also rely on an additional condition permitted by law, such as explicit consent, legal/regulatory necessity, establishment or defence of legal claims, or another applicable statutory basis.

6. Sensitive personal data and sector-specific processing

Insurance can require the processing of sensitive personal data, particularly health and medical information. We limit such processing to what is relevant to the requested cover, underwriting, policy administration or claims handling, apply enhanced access controls, and disclose it only to parties that require it for those purposes or as required by law.

7. Sharing personal data

We do not sell personal data. We may disclose personal data, on a need-to-know basis and subject to appropriate legal and contractual safeguards, to:

  • insurers, underwriters, reinsurers and insurance-market service providers;
  • medical providers, claims administrators, loss assessors, investigators, repairers, surveyors and professional advisers where relevant to a policy or claim;
  • payment, communications, hosting, IT, cybersecurity, analytics and document-management service providers acting under appropriate safeguards;
  • regulators, courts, law-enforcement agencies and public authorities where disclosure is required or permitted by law; and
  • other parties where you instruct us, consent to the disclosure, or where disclosure is necessary to protect lawful rights.

Where a third party processes personal data on our instructions, we require it to process the data only for authorised purposes, keep it secure and comply with applicable data-protection obligations. Independent recipients remain responsible for their own lawful processing.

8. International transfers

Because our websites and services may be accessed internationally, personal data may be transferred to, stored in or accessed from countries other than the country in which you are located. Where applicable law regulates such transfers, we use a legally recognised transfer mechanism or safeguard, which may include adequacy decisions, standard contractual clauses, binding corporate rules, contractual safeguards, consent where valid, or another permitted mechanism. We apply additional safeguards to sensitive or special-category data where required.

9. Cookies and similar technologies

Our website may use cookies, pixels, local storage and similar technologies to operate essential functions, remember preferences, maintain security, understand website performance and, where permitted, support analytics or marketing. Non-essential cookies should be used in accordance with applicable consent requirements. You can also manage cookies through your browser settings, although disabling essential cookies may affect website functionality.

10. Direct marketing

Where permitted by law, we may use your contact details to send information about relevant products, services, offers or updates. We will provide an appropriate opportunity to opt out of direct marketing. You may withdraw your marketing consent or object to direct marketing at any time using the unsubscribe mechanism provided or by contacting us through the website. Service, security, regulatory and transactional communications are not marketing and may still be sent where necessary.

11. Security

We use reasonable administrative, organisational, physical and technical measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include access controls, authentication, encryption where appropriate, secure configurations, backups, monitoring, staff confidentiality obligations, vendor controls and incident-response procedures. No internet transmission or storage system can be guaranteed to be completely secure.

12. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including service delivery, legal and regulatory compliance, tax and accounting, fraud prevention, audit, dispute resolution and the establishment, exercise or defence of legal claims. Retention periods vary depending on the type of information, the relationship and applicable sector requirements. When information is no longer required, we will delete, anonymise or securely dispose of it, subject to lawful exceptions.

13. Your data-protection rights

Depending on where you are located and the law applicable to our processing, you may have some or all of the following rights, subject to lawful limitations and exemptions:

Right What it means
Be informed receive clear information about how and why your personal data is processed.
Access request confirmation whether we process your personal data and obtain a copy, subject to lawful limitations.
Rectification ask us to correct inaccurate or incomplete personal data.
Erasure request deletion of personal data where there is no lawful reason for continued processing, subject to legal and regulatory retention duties.
Restriction request restriction of processing in circumstances permitted by law.
Object object to processing based on legitimate interests and to direct marketing.
Data portability receive certain personal data in a structured, commonly used and machine-readable format where applicable.
Withdraw consent withdraw consent at any time where consent is the lawful basis, without affecting processing already carried out lawfully.
Automated decisions seek human review where a decision based solely on automated processing produces legal or similarly significant effects, where applicable.
Complain raise a concern with us and, where applicable, lodge a complaint with the competent privacy or data-protection authority in your jurisdiction.

We may need to verify your identity before acting on a rights request. Rights are not absolute; where we lawfully decline or limit a request, we will explain the basis where required.

14. Children and age restrictions

Our website is not intended to collect personal data from children unless this is necessary for a specific service and is handled in accordance with applicable law. Where information about a child is required, we will seek appropriate authority or consent from a parent, guardian or other authorised person where required.

15. Third-party links

Our website may contain links to third-party websites, platforms or services. We are not responsible for the privacy practices of independent third parties. We encourage you to review their privacy notices before providing personal data.

16. Personal data breaches

We maintain procedures for identifying, assessing and responding to personal-data breaches. Where a breach is legally reportable, we will notify the competent data-protection or privacy authority and affected individuals within the time and manner required by the applicable law.

17. Jurisdiction-specific privacy rights

This is a global privacy notice. Privacy rights and our obligations may vary by jurisdiction. Where applicable, we will comply with mandatory local requirements, including the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the Kenya Data Protection Act 2019, South Africa’s Protection of Personal Information Act (POPIA), and other applicable national or state privacy laws. If a mandatory local rule provides greater protection than this policy, that rule will apply to the relevant processing.

Residents of jurisdictions that provide additional rights may, where applicable, request information about categories or specific pieces of personal data collected, correction or deletion, restriction or objection, portability, withdrawal of consent, information about disclosures, and review of certain automated decisions. Where applicable law provides rights to opt out of the sale, sharing or use of personal data for targeted or cross-context behavioural advertising, we will honour valid requests. We do not discriminate against individuals for exercising applicable privacy rights.

18. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal obligations or data-processing practices. The version published on the website is the current version and applies from the time it is uploaded. Material changes may also be communicated through an appropriate website or service notice.

19. Contact us

For privacy questions, requests or complaints, please contact us through the contact details or Contact Us facility published on our website:

https://ensigninsuranceltd.com/

Website contact details currently published: info@ensigngroup.world | +254 703 660 066.

You may also have the right to lodge a complaint with the competent data-protection or privacy regulator in the country or region where you live, work, or where you believe an infringement occurred. Where Kenya law applies, this includes the Office of the Data Protection Commissioner of Kenya.