This notice (“Privacy Notice”) is provided by Hiscox Re Insurance Linked Strategies Ltd. (“we” or “us”) and sets out our policies with respect to the collection, sharing and use of personal information.
How we collect information
We may collect personal data about you through:
- information provided directly to us by you, or another person on your behalf, through our website, by email or post, or in person;
- information that we obtain in relation to any transactions between you and us;
- recording and monitoring of telephone conversations and electronic communications with you as described below; or
- the use of Internet “cookies” (an information collecting device from a web server), as described further below.
We may also, in some circumstances, receive personal information about you from third parties, such as service providers or trading counterparties, regulatory or law enforcement agencies and agencies conducting background checks. Personal information may also be obtained from publicly accessible sources of information, such as public databases, industry associations, social media and online professional networks.
Why we collect information
We may collect and use your personal information for the purposes of administering the relationship between us, marketing our products and services to you or the businesses with which you are associated, monitoring and analysing our activities, and complying with applicable legal or regulatory requirements.
We will use one of the permitted grounds under the applicable law to process your information. Such grounds include instances where you have given your consent and cases where your consent is not required under applicable law, such as where we are required to comply with a legal obligation, or performance of a contract, or where we or a third party determine that is necessary for our legitimate business interests to collect and use your personal information.
The legitimate business interests to collect your personal information may include any of the purposes identified above and any other purpose where we or a third party have determined that you have a reasonable expectation for us or a third party to collect or use your personal information for such purpose. You have the right to object to the use of your personal data for direct marketing purposes (see below).
What are the consequences of failing to provide your personal information?
As a regulated investment manager, we are subject to certain legal and regulatory obligations that may require us to collect and store your personal information, such as the requirements to comply with the applicable law on prevention of financial crime (such as money laundering or terrorist financing), tax and regulatory reporting, or the rules on recording and monitoring of communications (as described below).
We may also need to collect and use your personal information for the purposes of entering into or performance of a contractual arrangement between us, such as an investment in one of our managed products.
A refusal to provide us with personal information will, depending on the purpose for which your personal information is required, have various consequences such as us being unable to communicate with you, the termination of any service or other contractual arrangement between us, or, where we have a reasonable suspicion of illegal activity, we may be required to make a report to regulatory or enforcement agencies.
The types of personal data we may collect and use
The types of personal data we may collect will depend on the nature of our relationship with you and the purpose of which information is being collected. Such personal data might include your name and address (including proofs of name and address), contact details, date of birth, gender, nationality, photograph, signature, copies of identity documents, occupational history, job title, income, assets, other financial information, bank details, investment history, tax residency and tax identification information.
How long do we retain your personal information?
We will generally keep personal information about you for as long as necessary in relation to the purpose for which it was collected, or for such longer period if required under applicable law or necessary for the purposes of our other legitimate interests.
The applicable retention period will depend on various factors, such as any legal obligation to which we or our service providers are subject as well as on whether you decide to exercise your right to request the deletion of your information from our systems. As a minimum, information about you will be retained for the entire duration of any business relationship we may have with you, and for a minimum period of seven years after the termination of any such relationship.
We will, from time to time, review the purpose for which we have collected information about you and decide whether to retain it, update it, or securely delete it, if the information is no longer required.
Do we share your personal information with third parties?
To the extent it is relevant to the purpose for which we collect your information, we may share your personal data with third parties, such as:
- our affiliates or other entities that are part of the Hiscox Group of Companies or with our clients;
- any person to whom we have a right or obligation to disclose personal data, or where we determine that disclosure is necessary to protect or defend our rights or property, including with regulators, courts of law, governmental, regulatory or law enforcement agencies;
- our internet, IT, telecommunications and other service providers, including legal advisers, accountants, payroll administrators, insurance providers and administrators;
- service providers and trading counterparties to our clients, including placement agents or distributors, brokers, banks, trading venues, clearing houses, custodians, corporate services providers, administrators of our funds, and providers of customer relationship management tools;
- credit reference agencies and other third parties conducting background checks in the context of employment or client, counterparty, or investment due diligence;
- any person, as directed by you; or
- any person to whom we transfer any of our rights or obligations under any agreement, or in connection with a sale, merger or consolidation of our business or other transfer of our assets, whether voluntarily or by operation of law, or who is otherwise deemed to be our successor or transferee.
Transfers of personal information to countries outside of the European Economic Area (EEA)
As a Bermuda incorporated company and given the international nature of our business, your personal data may be transferred to, or collected from, countries outside of the EEA, such as to jurisdictions where we or our clients conduct business or have a service provider, including countries that may not have the same level of data protection as that afforded by the EU General Data Protection Regulation or other data protection rules applicable to us (collectively, “Data Protection Law”). In these circumstances, we take steps to ensure that the recipient agrees to keep your information confidential and that it is held securely in accordance with the requirements of Data Protection Law, such as by requesting appropriate contractual undertakings in our legal agreements with service providers.
What are your rights?
You have certain rights under Data Protection Law in respect of the personal data we hold about you and which you may exercise. These rights generally include:
- to request access to your information;
- to request rectification of inaccurate or incomplete information;
- to request erasure of your information (a “right to be forgotten”);
- to restrict the processing of your information in certain circumstances;
- to object to our use of your information, such as where we have considered such use to be necessary for our legitimate interests (e.g. in the case of direct marketing activities);
- where relevant, to request the portability of your information;
- where you have given consent to the processing of your data, to withdraw your consent; and
- to lodge a complaint with the competent supervisory authority.
How to contact us
If you have any questions about this Privacy Notice or requests with regards to the personal data we hold about you, you may contact us at firstname.lastname@example.org or by writing to Hiscox Re Insurance Linked Strategies Ltd., 4th Floor, Wessex House, 45 Reid Street, Hamilton HM12, Bermuda.
Recording and monitoring of communications
We may record and monitor telephone conversations and electronic communications with you for the purposes of:
- ascertaining the details of instructions given, the terms on which any transaction was executed or any other relevant circumstances;
- ensuring compliance with our regulatory obligations; or
- detecting and preventing the commission of financial crime.
Copies of any such recordings will be stored for a period of five years, or such other longer period as we may determine from time to time.
25 May 2018