Your personal information will be held and used by us in accordance with UK Data Protection legislation. For the purposes of the Data Protection Act 1998 (the “Act”), the data controller is Surely Services Limited, and our details can be found on register of the Information Commissioner’s Office Website http://ico.org.uk (Registration Number ZA053431).
About your data
Information we collect from you
Sensitive personal data
We may on occasion ask you to provide sensitive personal data as defined in the Act (for example, questions relating to your health or criminal convictions for the purpose of providing insurance quotations). By proceeding with obtaining a quote, we will take that as your explicit consent to such information being processed by ourselves and the relevant third party product providers. This sensitive information will not be used by us or the relevant third party product providers except for the specific purposes for which you provide it and in connection with the product or service requested.
How we use your data
We (or third parties acting on our behalf) may use your personal information in the following ways:
We will also disclose your personal information to third parties who provide the products and services you apply for via our website. In some instances we may need to share your personal information with our subsidiaries, affiliates or other members of our group.
We also may need to disclose your personal information where it is necessary to comply with any applicable laws or regulation or to protect ourselves or our users (including exchanging information with other companies for the purposes of fraud protection or the investigation of other unlawful conduct). Regulatory bodies may require disclosure for the purposes of monitoring or enforcing our (or third party product providers) compliance with laws, regulations or applicable codes of conduct.
In the event that we sell our business, we may disclose your personal data to the prospective buyer of our business.
How and where we store your personal information
As required by the Act, we follow strict security procedures in the storage and disclosure of personal information, to minimise the risk of unauthorised access. We take all reasonable steps to ensure your personal details remain secure. The personal information that we collect from you may also be transferred to and stored outside of the European Economic Area.
Our website is hosted on a cloud service provided by Amazon Web Services located in the Republic of Ireland. We use encryption software to prevent access to your personal information. Unfortunately, the internet is never a completely secure environment and we cannot guarantee that hackers or unauthorised personnel will not gain access to your personal information despite our best efforts.
When you enter personal details on our website, you’ll be entering these details within a secure environment. We use SSL (Secure Socket Layers) encryption to protect the details you send us, and the padlock symbol will appear in most browsers confirming that we have appropriate certificates in place (from Comodo).
Accuracy of your information
We endeavour to ensure that the information we hold about you is accurate and kept up to date, and we shall assume that the information you provide to us is accurate. Should you inform us of inaccuracies in the information which we hold in relation to you or, if we discover that such information is inaccurate, it shall be promptly rectified by us.
You may request a copy of the information we hold about you. We will be happy to provide you with such information upon request and the payment of £10 in order to cover our administrative expenses in relation to your request.
This policy was last updated in August 2014.