Claybrooke Privacy Policy

We take data protection and your privacy very seriously at Claybrooke Life Insurance. Here’s how we handle your information

This privacy notice aims to give you information on how Claybrooke Life Insurance collects and processes your personal data through your use of this website, including any data you may provide when you submit our online contact form.

It is important that you read this privacy notice so that you are fully aware of how and why we are using your data.

  1. Who We Are

Data Controller:

 is the data controller and is responsible for your data (collectively referred to as “Claybrooke Life Insurance”, “https://www.claybrooke.org.uk”, “we”, “us”, or “our” in this privacy notice.

We are a registered data controller with the Information Commissioner’s Office, registration number ZA085780.

As a data controller, Claybrooke Life Insurance is tasked with determining the purposes and means of processing personal data.

Responsibilities encompass ensuring data protection principles are adhered to, demonstrating accountability, and implementing measures such as data minimisation and security assessments.

This role involves regularly evaluating the effectiveness of these measures and documenting processes to ensure the safeguarding of client data.

Contact Details:

Name: Claybrooke Life Insurance

Email address: enquiry@claybrooke.org.uk

Postal address:

Suite 11

65 Penarth Road

Cardiff

CF10 5DL

  1. The Data We Collect About You

Personal data, or personal information, means any information about an individual from which that person can be identified.

It does not include data where the identity has been removed (anonymous data).

  • Identity Data includes first name and last name.
  • Contact Data includes address, email address and telephone number(s).
  • Technical Data includes internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website.
  • Product Data includes form responses (the data entered and selected within our online contact form).
  • Usage Data includes information about how you use our website.
  • Marketing and Communications Data includes your preferences regarding the receipt of marketing from us and our third-party partners.

We also collect, use, and share Aggregated Data, such as statistical or demographic data, for any purpose.

Aggregated Data may be derived from your personal data, but is not considered personal data in law as this data does not directly or indirectly reveal your identity.

For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature.

However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data, which will be used in accordance with this privacy notice.

We do not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data).

Nor do we collect any information about criminal convictions and offences.

  1. How We Collect Your Personal Data
  • Direct interactions. You may give us your Identity, Contact, Marketing and Communications Data by filling in forms or by corresponding with us by post, phone, email or otherwise.
  • Automated technologies or interactions. As you interact with our website, we may automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, pixels, server logs and other similar technologies. Please see our cookie policy for further details.
  • Technical Data from analytics providers such as Google
  1. How We Use Your Personal Data

We will only use your data when permitted by law.

  • Where we need to perform the service you require effectively
  • Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
Data used to provide the introduction to an FCA authorised broker, in order to provide the service requested by the data subjectData used to provide the introduction to an FCA authorised broker, to provide the service requested by the data subject
  1. Sharing of Your Personal Data
  • FCA authorised Financial Technology (FinTech) companies acting as data processors, joint data controllers or independent data controllers who provide the introduction to FCA authorised brokers by means of IT and system services, which may be based on the data you have provided.
  • FCA authorised insurance brokers acting as data processors, joint data controllers or independent data controllers in order to provide the services required.
  1. Your Legal Rights and Your Personal Data
  • Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
  • Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
  • Request erasure of your personal data. This enables you to request that we delete or remove personal data where there is no legitimate reason for us to continue processing it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law.
  • Object to the processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object when we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
  • Request the restriction of processing your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data’s accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
  • Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

The right to be informed entails transparency regarding the collection and use of personal data, which encompasses clarity about who the data controller is and the purposes for which the data is processed.

Additionally, the right to data portability allows individuals to obtain and reuse their personal data across different services.

For access, individuals can obtain confirmation of whether their data is being processed, where, and for what purpose.

Exercising these rights is facilitated through accessible channels, ensuring users can effectively manage their data preferences and inquiries.

The GDPR ensures users have the right to restrict processing.

Situations warranting such requests can include contesting data accuracy or determining the legitimacy behind processing activities.

During a restriction, data may still be stored but not processed, guaranteeing greater control until matters are resolved.

Furthermore, individuals hold the right to object to data processing when it interferes with personal freedoms, though strong interests or legal claims might override this in rare instances.

If you wish to exercise any of the rights set out above, please contact enquiry@claybrooke.org.uk  for further details.

  1. Data Security

We have implemented appropriate security measures to prevent your personal data from being accidentally lost, used, accessed in an unauthorised way, altered, or disclosed.

Claybrooke Life Insurance employs effective encryption protocols to protect personal data during transmission.

These security measures include the use of Secure Sockets Layer (SSL) technology, which ensures data integrity and confidentiality.

Regular audits and security assessments are conducted to identify and rectify vulnerabilities.

Employees undergo stringent background checks and receive data protection training to reinforce their role in safeguarding information.

In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know.

Claybrooke Life Insurance enforces layered security protocols to prevent unauthorised access.

These protocols include multi-factor authentication (MFA) for accessing sensitive data.

By applying MFA, users must confirm their identity using additional credentials after entering their password, thereby enhancing security.

Additionally, data-at-rest encryption ensures information stored in databases remains secure from unauthorised access, adding another layer of protection to stored data beyond transport encryption.

They will only process your data in accordance with our instructions, and they are subject to a duty of confidentiality.

We have established procedures to address any suspected personal data breaches and will notify you and any applicable regulator of a breach where required by law.

  1. Data Retention

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your data, the purposes for which we process your data and whether we can achieve those purposes through other means, and the applicable legal requirements.

  1. Data Transfers to Third Countries

The data we collect from you may, on occasion, be stored and/or processed at a destination outside the European Economic Area (EEA).

It may also be processed by organisations operating outside the EEA who work for us or for one of our suppliers.

These organisations may be engaged in fulfilling your request, order, or reservation and providing support services.

With data sometimes processed in countries without equivalent privacy legislation, reassurance is offered by Binding Corporate Rules (BCRs).

These legally enforceable internal instructions govern the handling of intracompany data.

When used in conjunction with SCCs, BCRs assure stakeholders that their information is shielded by stringent standards similar to those advocated by the European Commission.

The data’s integrity and privacy are prioritised across jurisdictions, backed by regular scrutiny and compliance checks.

Where we use certain service providers, we may use specific contracts approved by the European Commission, which give personal data the same protection it has in Europe.

Transfers to third countries are carefully managed through adherence to international data transfer agreements like Standard Contractual Clauses (SCCs).

These legally binding contracts offer a framework ensuring data is protected to European standards.

When organisations outside the EEA process data, particular attention is given to maintaining equal protection measures.

This includes working solely with entities that comply with recognised data protection frameworks or regulations similar to those within the EEA.

Where we use providers based in the US, we may transfer data to them if they are part of the Privacy Shield, which requires them to provide similar protection to personal data shared between Europe and the US.

We will take steps reasonably necessary to ensure there is an adequate level of protection of your data and that your data is treated securely and in accordance with our Privacy Policy.

  1. Cookies

We use cookies to distinguish you from other users of our Sites and Services. This helps us provide you with a good experience and allows us to improve them.

Cookies come in different forms, like session and persistent cookies, each serving distinct purposes.

Session cookies, for instance, expire once you close your browser, while persistent cookies remain until deleted or expired.

Users can manage these preferences directly from their browser settings. Options often available include enabling browser notifications when cookies are set or declining all cookies, which may affect website usability.

For comprehensive privacy, users are advised to review and clear their browser cookies periodically.

You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies.

In addition to managing preferences from browser settings, users can enhance their online privacy by periodically clearing their cookies.

This action can prevent sites from tracking browsing habits over time.

Internet Explorer, Chrome, Safari, and Firefox each provide user-friendly guides on how to manage cookies effectively.

By doing this, users protect their information from potential misuse while maintaining optimal control over their personal data.

If you disable or refuse cookies, some parts of this website may become inaccessible or not function properly.

  • enabling a service to recognise your device so you don’t have to give the same information several times during one task
  • recognising that you may already have given a username and password so you don’t need to do it for every web page requested
  • measuring how many people are using services, so they can be made easier to use and there’s enough capacity to ensure they are fast
  • analysing anonymised data to help us understand how people interact with govt services so we can make them better

How to control and delete cookies:

We will not use cookies to collect personally identifiable information about you.

However, if you wish to restrict or block the cookies which are set by our websites, or indeed any other website, you can do this through your browser settings. The ‘Help’ function within your browser should tell you how.

Alternatively, you may wish to visit the AboutCookies.org website, which contains comprehensive information on how to do this on a wide variety of browsers.

You will also find details on how to delete cookies from your machine, as well as more general information about cookies.

Please be aware that restricting cookies may impact the functionality of our website.

If you wish to view your cookie code, just click on a cookie to open it. You’ll see a short string of text and numbers.

The numbers are your identification card, which can only be seen by the server that gave you the cookie.

For information on how to do this on the browser of your mobile phone, please refer to your handset’s user manual.

Cookies We Use and Why:

Strictly Necessary Cookies

These cookies let you move around the website and use essential features like secure areas.

These cookies don’t gather any information about you that could be used for marketing or to remember where you’ve been on the Internet.

  • Remember things like information you’ve entered on forms
  • Make sure you connect to the right service on our website when we make any changes to the way the website works.
  • Gather information that could be used to advertise products or services to you.
  • Remember your preferences or username beyond your current visit.

Accepting these cookies is a condition of using the website, so if you prevent these cookies we can’t guarantee our website will perform as expected during your visit.

Performance Cookies

These cookies help identify information about how you use our website e.g. which pages you visit, and if you experience any errors.

These cookies don’t collect any information that could identify you—all the information collected is anonymous and is only used to help us improve how our website works, understand what interests our users, and measure the effectiveness of our advertising.

  • Provide statistics on how our website is used.
  • See how effective our adverts are (we don’t use these cookies to target adverts to you when you visit other websites).
  • Help us improve the website by measuring any errors that occur.
  • Test different designs of our website.

Using our site indicates that you accept the use of ‘Performance’ cookies.

Accepting these cookies is a condition of using the website, so if you prevent them, we cannot guarantee how our site will perform for you.

Functionality cookies

Functionality cookies are used to provide services or to remember settings to improve your visit.

Functional cookies are instrumental in personalising a user’s experience by remembering preferences and previous interactions.

By storing basic information, such cookies help create smoother user journeys through the site, which is particularly beneficial for frequent visitors.

Meanwhile, analytical cookies contribute by collecting anonymous data on user behaviour, helping to refine and adapt website functions.

These elements combined ensure operational efficiency while prioritising user experience and privacy.

  • Remember settings you’ve applied, such as layout, text size, preferences and colours.
  • Remember, if we’ve already asked you if you want to fill in a survey or review.
  • Show you when you’re logged in to the website.

Cookies defined as ‘Functionality’ will not be used to target you with adverts on other websites.

Preventing these cookies may mean we can’t offer you some services, and will reduce the support we can offer you.

It’s also possible that preventing these cookies will stop us from remembering that you didn’t want a specific service.

For example, social media sharing cookies apply when you share our content on a social network such as Facebook or Twitter.

Targeting/marketing cookies

We have relationships with carefully selected and trusted marketing suppliers. Sometimes you might see our adverts on other websites.

This is because a cookie has been used to deliver the ad to you.

It is important to understand that these cookies are completely anonymous – they are only stored on your computer.

No information is ever shared with other websites, and you can opt out of targeted marketing directly from these trusted suppliers.

Preventing these cookies may stop us from offering you some services. All of these cookies are managed by third parties.

  1. How to Make A Complaint

To exercise all relevant rights, queries or complaints, please contact us at enquiry@claybrooke.org.uk to discuss your concerns.

Following this, if you are still dissatisfied, you can contact the Information Commissioner’s Office directly at https://ico.org.uk/