Aon Insurance Managers (Guernsey) Limited (“Aon”) is a subsidiary of Aon plc and forms part of the 30 offices globally of Aon Captive & Insurance Management. Aon provides insurance management services in Guernsey. Aon is committed to protecting your privacy. This commitment reflects the value we place on earning and keeping the trust of our customers, business partners and others who share their personal information with us.
We are required under relevant data protection laws to produce this privacy notice (this “Notice”) to data subjects about whom we hold personal information.
What does this Privacy Notice do?
This Notice explains Aon’s information processing practices. It applies to any personal information you provide to us and any personal information about you that we collect from other sources. This Notice is a statement of your rights regarding your personal information. This is not a contractual document and it does not create any rights or obligations.
This Notice does not apply to your interaction with any third party that might be connected to Aon, either directly or indirectly (for example any website that may be linked to any website that this Notice is published on) and you should refer to their specific privacy notice.
Who is responsible for your information?
Throughout this Notice, ”Aon” refers to Aon Insurance Managers (Guernsey) Limited, including its affiliated companies and subsidiaries (also referred to as ”we”, ”us”, or ”our”). Aon is responsible for your personal information and is a Data Controller for the purposes of data protection laws.
Where we act as a data processor for a third party (namely the data controller) the third party is responsible for how personal information is processed and will have its own privacy notice.
When and how do we collect your information?
We will collect personal information when:
- we perform services for you / our clients;
- you request a service from us;
- you perform a service for us;
- you enquire about our services;
- you register with or use any of our websites or applications;
- you attend an Aon site or event;
- you apply for a position at Aon;
- you are an employee of Aon;
- you contact us with a query;
- you engage with us over social media; and / or
- you engage with us in other ways.
What personal information do we collect?
When we interact with you for one of the activities listed above, we ask that you provide accurate and necessary information that enables us to start the task. When you provide personal information to us, we will use it for the purposes stated at the point of collection or for purposes that are otherwise obvious from the context of collection, for example when:
- providing you with services or information;
- you apply for a position with us; or
- we create a profile for you on our website or on an application.
The information we collect about you may include but is not limited to the following:
- basic personal details, such as your contact details, date of birth, age, gender, marital status, occupation, place of birth and nationality;
- identification / verification information, details of your employment history and proof of address; and
- Financial details such as bank account information, credit history and bankruptcy status.
Sensitive Personal Information
We will not collect any sensitive personal information unless this is required. Sensitive personal information includes information relating to:
- race or ethnic origin;
- political opinions;
- religious or other similar beliefs;
- trade union membership;
- physical or mental health; and
- sexual life.
Where you provide us with sensitive personal information, we will request that you understand and give your explicit consent that we may use and if required disclose this information to third parties for the purposes agreed. If you provide personal information about other individuals such as employees or dependents you must obtain their consent prior to your disclosure to us.
Information we collect over Aon websites, mobile applications and social media
We may ask you for some or all of the following types of information when you register for events, request services, manage accounts, access various content and features or directly visit our websites. This includes, but is not limited to:
- contact information, such as name, e-mail address, postal address, phone number and mobile number;
- user name, password, password reminder questions and password answers;
- communication preferences, such as which newsletters you would like to receive;
- search queries;
- contact information about others when you refer a friend to a particular site or service (this information is used solely to facilitate requested communications); and
- information posted in community discussions and other interactive online features.
You can engage with us through social media websites or through features such as plug-ins or applications on our websites that integrate with social media sites. You may also choose to link your account with us to third party social media sites. When you link to your account or engage with us on or through third party social media sites, plug-ins, or applications, you may allow us to have ongoing access to certain information from your social media account (for example, name, e-mail address, photo, gender, birthday, the posts or the 'likes' you make).
If you access our websites on your mobile telephone or mobile device, we may also collect your unique device identifier and mobile device IP address, as well as information about your device's operating system, mobile carrier and your location information. We may also ask you to consent to providing your mobile phone number (for example, so that we can send you push notifications).
How do we use your personal information?
Performing services for our clients
We process personal information which our clients provide to us in order to perform our professional services. The purposes for which your personal information is processed will be determined by the scope and specification of our client engagement and by applicable laws, regulatory guidance and professional standards.
Administering our client engagements
We process personal information about our clients and the individual representatives of our corporate clients in order to:
- carry out ‘Know Your Client’ checks and screening prior to starting a new engagement;
- carry out client communication, service, billing and administration;
- deal with client complaints; and
- administer claims.
Contacting and marketing our clients and prospective clients
We process personal information about our clients and the individual representatives of our corporate clients in order to:
- contact our clients in relation to current, future and proposed engagements;
- send our clients newsletters, know-how, promotional material and other marketing communications; and
- invite our clients to events (and arrange and administer those events).
Conducting data analytics
We are an innovative business which relies on developing sophisticated products and services by drawing on our experience from prior engagements. We are not concerned with analysis of identifiable individuals and we take steps to ensure that your rights and the legitimacy of our activities are ensured through the use of aggregated or otherwise anonymised information.
Fulfil legal and regulatory obligations and monitor compliance with the same
Aon processes personal information on employees to comply with tax and other legal obligations.
If we wish to use your personal information for a purpose which is not compatible with the purpose for which it was collected we will request your consent. In all cases, we balance our legal use of your personal information with your interests, rights, and freedoms in accordance with applicable laws and regulations to make sure that your personal information is not subject to unnecessary risk. There might be instances where we are required by law or regulation to share your information without your prior consent and without notifying you.
Legal Basis for Processing
Aon relies on the following legal grounds to collect and use your personal information:
Processing of your personal information may be justified by a ‘lawful basis’ for processing. In the majority of cases, processing will be justified on the basis that:
- the processing is necessary for the performance of a contract to which you are a party, or to take steps (at your request) to enter into a contract;
- the processing is necessary for us to comply with a relevant legal obligation (for example, where we are required to collect certain information about our clients or employees for tax or accounting purposes, or where we are required to make disclosures to courts or regulators); and / or
- the processing is in our legitimate commercial interests, subject to your interests and fundamental rights (for example, where we use personal information provided to us by our clients to deliver our services and that processing is not necessary in relation to a contract to which you are a party).
In limited circumstances, we will use your consent as the basis for processing your personal information (for example, where we are required to obtain your prior consent in order to send you marketing communications).
Before collecting and / or using any personal information, or criminal record information, we will establish a lawful basis which will allow us to use that information. This basis will typically be:
- your explicit consent;
- the establishment, exercise or defence by us or third parties of legal claims; or
- a context specific exemption provided for under applicable local laws.
Do we collect information from children?
Aon participates in youth training schemes and occasionally organises social gatherings at which children attend and in these cases limited personal information may be collected.
In all cases Aon will only collect the following information from children with the prior written consent of their Parents or Guardian:
- name, age and address; and
How long do we retain your personal information?
How long we retain your personal information depends on the purpose for which it was obtained and the nature of the personal information. We will keep your personal information for no more than the time required to fulfil the purposes described in this Notice unless a longer retention period is required or permitted by law. We have implemented appropriate measures to ensure that your personal information is securely destroyed in a timely and consistent manner when no longer required.
In specific circumstances we may store your personal information for longer periods of time so that we have an accurate record of your dealings with us in the event of any complaints or challenges, or if we reasonably believe there is a prospect of litigation relating to your personal information or dealings.
Do we disclose your personal information?
We may share your personal information with other Aon entities, brands, divisions and subsidiaries to serve you, including for the activities listed above.
We do not rent, sell or otherwise disclose personal information to unaffiliated third parties for their own marketing use. We do not share your personal information with third parties except in the circumstances described below.
We disclose personal information to business partners who provide certain specialised services to us, or who co-operate with us on projects. These business partners operate as separate data controllers and are responsible for their own compliance with data protection laws. You should refer to their privacy notices for more information about their practices. Examples of business partners to which we way may disclose personal information include:
- banking and finance products – for example, credit and fraud reporting agencies, debt collection agencies, insurers, reinsurers, and managed fund organisations for financial planning, investment products and trustee or custodial service providers in which you or our client invests; and
- insurance broking and insurance products – for example, insurers, reinsurers, other insurance intermediaries, insurance reference bureaus, medical service providers, fraud detection agencies, our advisers such as loss adjusters, lawyers and accountants and others involved in the claims handling process.
Authorised Service Providers
We may disclose your personal information to service providers we have retained (as data processors) to perform services on our behalf. These service providers are contractually restricted from using or disclosing the information except as necessary to perform services on our behalf or to comply with legal requirements. These activities could include any of the processing activities that we carry out as described in the above section, ‘How do we use your personal information?’. Examples of authorised service providers to which way may disclose personal information include:
- IT service providers who manage our IT and back office systems and telecommunications networks;
- marketing automation providers; and
- contact centre providers.
These third parties appropriately safeguard your personal information and their activities are limited to the purposes for which your personal information was provided.
Legal Requirements and Business Transfers
We may disclose personal information:
- if we are required to do so by law, legal process, statute, rule, regulation or professional standard, or to respond to a subpoena, search warrant, or other legal request;
- in response to law enforcement authority or other government official requests;
- when we believe disclosure is necessary or appropriate to prevent physical harm or financial loss;
- in connection with an investigation of suspected or actual illegal activity;
- in the event that we are subject to a merger or acquisition to the new owner of the business; and / or
- for audits or to investigate a complaint or security threat.
We might be restricted by law from notifying you that we have disclosed your information.
Do we transfer your personal information across geographies?
We are a global organisation and may transfer certain personal information across geographical borders to our other offices, authorised service providers or to business partners in other countries working on our behalf in accordance with applicable law. Our affiliates and third parties may be based locally or they may be based overseas in jurisdictions which may not have been determined by the European Commission to have an adequate level of data protection.
When we transfer to such jurisdictions we use a variety of legal mechanisms to help ensure that your rights and protections travel with your personal information:
- we ensure transfers are covered by agreements based on the European Union (“E.U.”) Commission's standard contractual clauses, which contractually oblige each member to ensure that personal information receives an adequate and consistent level of protection wherever it resides;
- where we transfer your personal information to third parties we obtain contractual commitments from them to protect your personal information. Some of these assurances are well recognised certification schemes like the E.U. / United States of America Privacy Shield for the protection of personal information transferred from within the E.U. to the United States, or the standard contractual clauses; or
- where we receive requests for information from law enforcement or regulators, we carefully validate these requests before any personal information is disclosed.
Examples of countries outside the E.U. that we may transfer personal information to include (but are not limited to) the United States of America, the United Kingdom and India.
If you would like further information about whether your information will be disclosed to overseas recipients, please contact us as noted below. You also have a right to contact us for more information about the safeguards we have put in place (including a copy of relevant contractual commitments, which may be redacted for reasons of commercial confidentiality) to ensure the adequate protection of your personal information when this is transferred.
What security measures protect your information?
The security of your personal information is important to us and we have implemented reasonable physical, technical and administrative security standards to protect personal information from loss, misuse, alteration or destruction. We protect your personal information against unauthorised access, use or disclosure, using security technologies and procedures, such as encryption and limited access. Only authorised individuals may access your personal information and they receive training about the importance of protecting personal information.
Our service providers and agents are contractually bound to maintain the confidentiality of personal information and may not use the information for any unauthorised purpose.
What choices do you have about your personal information?
We offer certain choices about how we communicate with our data subjects and what personal information we obtain about them and share with others. When you provide us with personal details, if we intend to use those details for marketing purposes, we will provide you with the option of whether you wish to receive promotional e-mail, SMS messages, telephone calls and postal mail from us. At any time, you may opt out from receiving interest-based advertising from us by contacting us as noted below.
How can you update your communication preferences?
We take reasonable steps to provide you with communications about your personal information. You can update your communication preferences in the following ways:
If you have created a profile or account on one of our websites, you can update your contact information after you log into your account.
If you request electronic communications, such as an e-newsletter, you will be able to unsubscribe at any time by following the instructions included in the communication or contacting us as noted below.
If you previously chose to receive push notifications on your mobile device from us but no longer wish to receive them, you can manage your preferences either through your device or the application settings. If you no longer wish to have any information collected by the mobile application, you may uninstall the application by using the uninstall process available on your mobile device.
Contact us by e-mail or postal address as noted below. Please include your current contact information, the information you are interested in accessing and your requested changes.
If we do not provide you with access, we will provide you with the reason for refusal and inform you of any exceptions relied upon.
Other rights regarding your personal information
Subject to certain exemptions (and in some cases dependent upon the processing activity we are undertaking), you have certain rights in relation to your personal information.
We may ask you for additional information to confirm your identity and for security purposes before disclosing any personal information requested by you. We reserve the right to charge a fee where permitted by law, for instance if your request is manifestly unfounded or excessive.
You can exercise your rights by contacting us. Subject to legal and other permissible considerations, we will make every reasonable effort to honour your request promptly or to inform you if we require further information in order to fulfil your request.
We may not always be able to fully address your request, for example if it would impact the duty of confidentiality we owe to others, or if we are legally entitled to deal with the request in a different way.
Right to Access
You have a right to access personal information we hold about you. If you have created a profile, you can access that information by visiting your account.
Right to Rectification
You have a right to request us to correct your personal information where it is inaccurate or out of date.
Right to be Forgotten / Right to Erasure
You have the right, in certain circumstances, to have your personal information erased. Your information can only be erased if:
- your information is no longer necessary for the purpose(s) for which it was collected; and
- we have no other legal grounds for processing the information.
Right to Restrict Processing
You have the right to restrict the processing of your personal information, but only where:
- its accuracy is contested, to allow us to verify its accuracy;
- the processing is unlawful, but you do not want it erased;
- it is no longer needed for the purposes for which it was collected, but we still need it to establish, exercise or defend legal claims; or
- you have exercised the right to object, and verification of overriding grounds is pending.
Right to Portability
You have the right to information portability, which requires us to provide personal information to you or another controller in a commonly used, machine readable format, but only where the processing of that information is based on:
- consent; or
- the performance of a contract to which you are a party.
Right to Object to Processing
You have the right to object to the processing of your personal information at any time but only where that processing has our legitimate interests as its legal basis. If you raise an objection, we have an opportunity to demonstrate that we have compelling legitimate interests which override your rights and freedoms.
As noted above, you can ask to obtain a copy of, or reference to, the safeguards under which your personal information is transferred outside the European Union.
If you have any questions, would like further information about our privacy and information handling practices, would like to discuss opt-outs or withdrawing consent, or would like to make a complaint about a breach of the law or of this Notice, please contact the Privacy Officer at: [email protected]. Alternatively, you have the right to contact the Office of the Data Protection Commissioner at:
Office of the Data Protection Authority St Martin’s House Le Bordage St Peter Port Guernsey GY1 1BR
E-mail: [email protected]
If you have any questions relating to this Notice, please contact us at the Aon Global Privacy Office, Aon plc, 200 E. Randolph, Chicago, Illinois 60601 or [email protected].
Changes to this Notice
We may update this Notice from time to time. When we do, we will post the current version on our website and we will revise the version date located at the bottom of this page.
This Notice was last updated on 24 May, 2018.