Safe Harbor Pollution Insurance is committed to safeguarding your privacy and the confidentiality of your personal information. This Notice explains how we collect, use, protect, and manage the personal information entrusted you provide to us. In particular, this Notice aims to provide you with a better understanding of the types of personal information we collect and the purposes for which that information is used, including circumstances where information may be disclosed to third parties and overseas recipients.

WHY DO WE COLLECT, HOLD, USE AND DISCLOSE PERSONAL INFORMATION?

We collect, hold, use and disclose personal information so that we can provide you with products and services including:

  • Arranging and administering insurance.
  • Risk analysis and underwriting.
  • Management of claims, including investigation and settlement.
  • Accounting and auditing.
  • Complaints and disputes management.
  • Legal, regulatory and compliance purposes.

Without your personal information, we may not be able to issue insurance coverage, administer your insurance, answer your questions or concerns, or process your claim.

WHAT TYPES OF PERSONAL INFORMATION DO WE COLLECT AND HOLD?

We collect and hold a range of personal information from and about individuals who are insured, or have submitted a claim, under our insurance policies. Depending on the products or services we are providing to you, we may collect and hold the following information about you:

  • General identification and contact information, which may include some or all of the following information:
    1. Name
    2. Address
    3. E-mail address
    4. Telephone number(s)
    5. Date of Birth
  • Financial information and account details to enable us to underwrite insurance for you and process payments to or from you or your agent.
  • Medical information regarding injuries and treatment.
  • Recordings of telephone calls to our representatives and to call centers operated on our behalf.
  • In the event verification is needed regarding compliance with the Office of Foreign Asset Control, we may be required to request additional information.

We may also collect personal information from employees, prospective employees, service providers and third party contractors.

HOW DO WE COLLECT AND HOLD PERSONAL INFORMATION?

Where it is reasonable and practicable to do so, we collect personal information directly from you or from your insurance broker. This information may be collected using various means including in writing, in person, by telephone, by email or through other electronic messages.

We may also collect your personal information from:

  • Your agents or brokers.
  • Third parties you have asked to provide your personal info to us.
  • Publically available services.
  • Service providers.
  • Other insurers.
  • Credit check bodies.
  • Law enforcement or dispute resolution bodies.
  • Marketing organizations.

We will only collect and use your personal information in accordance with applicable privacy laws. Some laws require your consent to collect certain personal information from you and we will first obtain your consent where required by law to do so.

We hold your personal information in various internal systems and databases including shared drives, email, document management systems and in hard copy. We maintain physical, electronic, and procedural safeguards to protect the security of personal information from misuse and loss, as well as unauthorized access, modification or disclosure. After it is no longer needed or required for applicable legal or regulatory purposes, we dispose of or de-identify personal information.

TO WHAT OTHER ORGANIZATIONS OR THIRD PARTIES DO WE DISCLOSE PERSONAL INFORMATION?

We may make your personal information available to third parties as permitted by applicable law to administer our insurance policies or when required by law to do so. We may provide your personal information to:

  • Contractors or third parties providing services to us related to the administration of insurance policies such as distributors, agents, claims & loss assessors, claims managers, insurance reference bureaus.
  • Our related bodies and corporate companies in the Berkshire Hathaway insurance group that provide administrative services, including processing insurance policies and completing regulatory reporting.
  • Banks and financial institutions for the purpose of processing your application and payments to/from you or your agent.
  • Third party administrators, emergency providers, repairers and suppliers, and investigators for the purpose of processing and administering your claims.
  • Governmental authorities, law enforcement agencies and dispute resolution bodies and agencies.

We do not sell any personal information to marketing companies.

INTERNATIONAL DISCLOSURE OF PERSONAL INFORMATION

We are an international insurance company, with offices in 6 countries. In some circumstances and for the purposes set out above, we may disclose personal information to parties, including our own offices, located in other countries. The laws governing personal data protection vary and the country where your personal information is transferred may have different laws than those in the country in which you reside. The countries where we may disclose personal information are:

  • United States.
  • United Kingdom.

We make all reasonable efforts to ensure that the arrangements we have in place with overseas parties impose appropriate privacy and confidentiality obligations on those parties to ensure that the personal information shared is kept secure and used only for the purposes noted above.

HOW DO YOU ACCESS AND CORRECT YOUR PERSONAL INFORMATION?

We take reasonable steps to ensure that your personal information is accurate, complete and up-to-date.

If you wish to access the personal information we may hold about you or if you believe that the personal information we hold about you is not accurate, complete or up-to-date, you can request access to or correction of the information by contacting us (contact details below).

In order to process any request for access or correction of personal information, we may need to obtain a minimum level of information, including:

  • Full name.
  • Date of Birth.
  • Details of the request, including supporting information, evidencing the individual’s right to access the data.

If you are seeking access to, or correction of, information on another person’s behalf, we will also require written authorization from that individual.

We reserve the right to refuse access to personal information under grounds permitted by applicable privacy laws. There is no fee to access or correct your information but there may be a cost charged, if permitted by applicable law, for providing access to personal information, which reflects the cost of locating and providing the information to you