Privacy Notice for Maiden Life & General

•••

For Maiden Life & General (“we”, “us”, “our”) it is extremely important that personal information should be protected. We respect your right to privacy and take our responsibilities seriously in relation to the processing of personal data. We do not collect or process personal data unnecessarily. We do not knowingly attempt to solicit or receive information from children.

In this privacy notice you can read about how we gather and use your personal data. You will also be given information about the rights you have in your dealings with us and how you can use them. 

We would advise you to read through this privacy notice carefully so you understand how and why we process your personal data before you begin using any of our services.

If we are to offer you our insurance policies or any of our other services, we will use your personal data in the way which is set out below. When we process your personal data we do so in accordance with current laws and regulations. 

Under this Privacy Notice, and unless we have entered into a different agreement with you, we will be what’s known under the General Data Protection Regulation (EU) 2016/679 (the “GDPR”) as the “controller” of the personal data you provide to us. 

We are each controllers of personal data – which means that we decide the means and purposes for which personal data is processed.  In this policy the companies are jointly referred to as Maiden Life & General (or we, us etc.). We are each independently responsible for processing your personal data as described in this notice.    
 

What personal information will we collect from you?

In your communication with us, you may submit information about yourself to us in a variety of different ways, by corresponding with us by phone, e-mail, or otherwise. It includes information you provide to us. For example, when you take out a policy with us, contact us, or register a claim, or if you use another of our services where you provide personal information.

The following are examples of information about you which you may submit to us: 

Personal and contact information— name, address, date of birth, Personal Public Service Number, passport number, e-mail address, mobile telephone number, age, title, etc.
Information about your health and employment, including special categories of data — whether you are in full-time employment and how long you have been employed, etc.
Information relating to claims for indemnification, including special categories of data — for example, information about illness and other events which may create an entitlement under the policy.
Financial data — bank account numbers, etc.   
 

All of this information is necessary so that we can conclude and implement our agreement with you. If you do not submit this information to us, we may be prevented from offering you a policy or meeting your claim.

We may also gather personal information about you from other sources. The following are examples of information about you that we may gather from another party: 

Financial data — information about the loans which you insure with us. Such information is gathered from the lenders and/or the insurance intermediary who arranged the policy.
Information about customer/member relations — that you are a customer or member of a specific company, credit union, or organisation which has a group policy with Maiden Life & General, to establish that you are entitled to take out a specific policy. Such information is gathered from the insurance intermediary or from the party which has a group policy with us. 
 
Cookies

We make use of cookies and similar technology to provide a good on-line experience which suits you. For more information about how this works, please refer to our cookie policy.

 
Why do we use your personal information and what do we use them for?

We will only use your personal information when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

Where we need to perform the contract that we are about to enter into or have entered into with you.

Where it is necessary for our legitimate interest (or those of a third party) and your interests and fundamental rights do not override those interests.

Where we need to comply with a legal or regulatory obligation. 

 

The information which you submit to us and which we otherwise gather about you is necessary so that we can assess if you can have a policy with us or not, identify the premiums and conditions we can offer you, and conclude and manage the insurance policy. Your personal details are primarily used for those purposes, but we may also process your personal details for other purposes as set out below.   

 

Purpose for which your details will be processed
(i.e. why we process your details)
Type of Data Legal basis for processing your details
(i.e. the basis on which process your details)
To manage your relationship with us (including confirmation of your identity and checking that your personal and contact details are correct) and your payment details, e.g., so we can fulfil our obligations to you as an insured and can provide the services which you require of us and provide information about them. Identity Data; 
Financial Data; and
Health Data. 
Necessary for our legitimate interests to respond to new and existing customers and to grow our business.

Performance of a contract with you.
To manage our services and internal activities, including customer analysis, marketing, trouble shooting, data analysis, testing, research, and statistical purposes. Technical Data; and
Usage Data.
Necessary for our legitimate interests to respond to new and existing customers and to grow our business and to develop services.
To prevent any abuse of our services, including fraud, to manage risk and carry out our risk analysis. Usage Data;
Financial Data;
Health Data; and Identity Data.
To comply with the relevant legislation.

Necessary for our legitimate interest in identifying, asserting, and pursuing legitimate claims. 
To ensure that content is presented clearly for you online (with the help, among other things, of cookies). Usage Data;
Technical Data; and Consent.
Consent and/or an interest in the smooth and effective operation of the service (see also our cookie policy).

Necessary for our legitimate interests to respond to new and existing customers and to grow our business and to develop services.
To develop and improve our services with a view, for example, to generating new products and create new business opportunities. Usage Data; and 
Technical Data. 
Consent and/or an interest in the smooth and effective operation of the service (see also our cookie policy).

Necessary for our legitimate interests to respond to new and existing customers and to grow our business and to develop services.* 
To comply with the relevant legislation including legislation on measures to counter money laundering, accountancy law, tax law, and rules on the capital adequacy ratio requirements. Identity Data; and
Financial Data.
To comply with the relevant legal requirements.
Where you have given us your consent to do so, to provide you with information about other services we feel may interest you. Identity Data;
Technical Data; and
Usage Data.
Consent.
To provide you with information about services we offer that are similar to those that you have enquired about. Identity Data;
Technical Data; and
Usage Data.
Necessary for our legitimate interests (to develop our products or Services and grow our business).
To manage payments, fees and charges and to collect and recover money owed to us. Identity Data; and
Financial Data.
Performance of a contract with you.

Necessary for our legitimate interests (to recover debts due to us). 
To manage our relationship with you, including notifying you about changes to the services, or our Privacy Notice. Identity Data;
Technical Data and
Usage Data.
Performance of a contract.

Necessary to comply with a legal obligation.

Necessary for our legitimate interests (to keep our records updated and to study how customers use our products and services). 
To administer and protect our business, our website, and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes. Identity Data;
Technical Data; and
Usage Data.
Necessary for our legitimate interests (for running our business and as part of our efforts to keep our website and the services safe and secure).
To measure or understand the effectiveness of advertising we serve to you and others, and, where applicable, to deliver relevant advertising to you. Identify Data;
Technical Data; and
Usage Data.
Necessary for our legitimate interests (to study how customers use our products or services, to develop them, to grow our business and to inform our marketing strategy).


*For more information about the way in which we balance our interest in processing your personal details and any interest you may have in your personal data not being processed for the stated purpose please contact us. You can find the contact details under ’Contacting us’ below.

We shall also use your details in our communications with you. Sometimes we may carry out customer satisfaction surveys of services. That communication may take place via electronic communication channels or by telephone. If you do not want us to communicate with you in that way, you can contact us by sending an e-mail to dataprotection@maideniis.com or unsubscribing from the e-mails we send to you.  

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us at dataprotection@maideniis.com. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. Please note that we may process your personal data without your knowledge or consent, in compliance with this Privacy Notice, where this is required or permitted by law.  

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered, or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your personal data upon our instructions and they are subject to a duty of confidentiality.  

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so. 

Your rights

 

Your rights What does this mean?
Right of access You may request access at any time to a copy of the personal data we hold about you. Any such request should be submitted to us in writing and sent to dataprotection@maideniis.com. We will need to verify your identity in such circumstances and may request more information or clarifications from you if needed to help us locate and provide you with the personal data requested.

There is usually no charge applied to access your personal data (or to exercise any of the other rights). However, if your request is clearly unfounded, repetitive, or excessive, we may charge a reasonable fee. Alternatively, we may refuse to comply with your request in these circumstances. 
Right to correction It is important that we should have correct information about you and we advise you to let us know if any of your personal details are incorrect, for example, if you have changed your name or moved. You can correct information about yourself which is incorrect or incomplete at any time. To do so at any time, please contact us by email at dataprotection@maideniis.com.
Right to deletion If your personal details are no longer needed for the purpose for which they were gathered, you are entitled to require that they be deleted. That right to have details deleted is known, amongst other things, as the ‘right to be forgotten’. In some cases, we may be under a legal obligation which prevents us from deleting your information immediately. That may involve, for example, obligations under legislation on accountancy, tax, or money laundering, or the legislation and regulations which apply to insurance companies. In such cases, we ensure that access to your information is restricted in such a way that it is only used to allow us to fulfil our legal obligations and our contractual obligations to you. To request deletion at any time, please contact us by email at dataprotection@maideniis.com.
Right to restrict You may restrict us from processing your personal data in any of the following circumstances:

you have contested the accuracy of the personal data we hold on record in relation to you or for a period of time to enable us to verify the accuracy of the personal data; • the processing of your personal data is unlawful and you request the restriction of use of the personal data instead of its erasure;

we no longer require your personal data for the purpose of processing but you require this data for the establishment, exercise, or defence of legal claims; or

where you have contested the processing (under Article 21(1) of the GDPR) pending the verification of our legitimate grounds. 
Right to object You are entitled to object to direct marketing at any time. If you should otherwise consider that we have no right to process your personal details or if you want an automatic decision to be reviewed, you are also entitled to object to our processing your data. In that event, we only have the right to continue processing if we can show compelling reasons which outweigh your own interests, rights, and freedoms. However, we are at all times entitled to process your personal details if it is necessary to establish, exert, or defend legitimate claims. To object to the processing of data at any time, please contact us by email at dataprotection@maideniis.com.
Right of data portability You are entitled to have the information which you have submitted to us, and which we process on the basis of your consent or in order to conclude and/or implement our contract with you, moved to another party in a structured and machine-readable format.
Right to withdraw consent If we process your personal details based on your consent, you have the right to withdraw your consent at any time. The withdrawal will not have any retrospective effect and will not therefore have any impact on processing which has already taken place.
Right to complain If you are not satisfied with the way in which we handle your personal details you can contact our data protection officer and we shall look into your complaint: dataprotection@maideniis.com

If you are not satisfied with our answer or consider that we are processing your personal details in an illegitimate or unlawful way you may lodge a complaint with the Irish Data Protection Commission https://forms.dataprotection.ie/contact


 
The rights described in this section are personal rights and are exercisable only by the individual person (or data subject) concerned.

Whom do we share your details with?
Where do we process your details?
How long shall we keep your information?
Politically exposed persons
Contacting us


 Privacy Notice for Maiden Life & General last revised 12 January 2024.