Client Privacy Notice
In order to properly administer Your policy or claim Starstone Underwriting Limited (hereafter “Starstone”, “We” “Us” or “Our”) provide this notice on data processing to customers, clients, claimants and beneficiaries (hereafter “You” or “Your”) in order to give You an overview of Our practices with respect to the collection, storage, use, disclosure or erasure (hereafter jointly “Processing“) of information of any kind (e.g., Your name, address, policy or claim information, etc.) related to You (hereafter jointly “Personal Data”) in connection with Your relationship with Us.
Scope of applicability
This notice applies to You if you are a customer, client, claimant or beneficiary.
Processing of Your Personal Data (categories of Personal Data)
We process the following of Your Personal Data collected during the lifecycle of Our relationship with You from You, or authorized third parties: Your name and other identification data, bank account details, information related to Your policy or claim, health-related information, Your communications with Us and their content.
We process Your Personal Data for the following purposes: providing a quotation, policy administration, claim processing, providing payments, compliance with applicable laws and regulations as well as security and fraud prevention, compliance with corporate financial responsibilities.
Legal justifications for the Processing of Your Personal Data
In accordance with Article 6 of the General Data Protection Regulation (GDPR) the Processing is necessary for:
- the administration of an insurance policy ( 6(1)(b) GDPR and the corresponding provisions in local data protection law, “Contract Justification”);
- the administration of claims (Art. 6(1)(f) GDPR, “Legitimate Interest Justification”).
Data transfers and recipients and legal justification for such transfers
Starstone is a member of Enstar Group. We transfer Your Personal Data to other Enstar Group companies and third parties (e.g., business partners, reinsurers, third party administrators), and, in accordance with applicable law, governmental authorities, courts, external advisors, and similar third parties, some of the aforementioned recipients are located in jurisdictions outside the EEA.
We are establishing that all recipients located outside the EEA will provide an adequate level of data protection for Your Personal Data and that appropriate technical and organizational security measures are in place to protect Your Personal Data. Any onward transfer (including Our affiliates outside the EEA) is subject to appropriate onward transfer requirements as required by applicable law.
Retention periods for and deletion of Your Personal Data
Your Personal Data will be deleted once it is no longer needed for the purposes for which it was originally collected or as required by applicable law.
Your statutory rights
You have a number of rights with regard to the Processing of Your Personal Data, each as per the conditions defined in applicable law, such as the right to get access to Your data, to get it corrected, erased or handed over. Please refer any of Your questions to the Data Protection Officer at Starstone (email@example.com).
Right to object:
You have the right to object, on grounds relating to Your particular situation, at any time to the processing of Your Personal Data by Us and We can be required to stop processing Your Personal Data. If You exercise this right, Your Personal Data will no longer be processed for such purposes by us. Exercising this right will not incur any costs.
Such a right to object may not exist, in particular, if the processing of Your Personal Data is necessary to take steps prior to entering into a contract or to perform a contract already entered into.
Changes of this notice
This notice is subject to change. Please revisit this website regularly to view the latest version.
How to contact us
If You wish to exercise Your rights or if You have any questions concerning this notice, please address Your request to the Data Protection Officer (firstname.lastname@example.org).
Please note that the aforementioned rights might be limited under the applicable national data protection law.
Right to lodge a complaint
In case of complaints You have the right to lodge a complaint with a supervisory authority, in particular in the Member State where You live or where the alleged infringement of the GDPR occurred.