This Privacy Notice explains in detail the type of Personal Data we may collect about you when you interact with us. It also explains how we’ll store and handle that data, and keep it safe.
We know that there is a lot of information here but we want you to be fully informed about your rights, and how Media Insurance Services uses your data. We will also explain in ‘HOW OUR INSURERS USE YOUR PERSONAL DATA’ how Canopius Managing Agents Limited, look after your data.
We hope the following sections will answer any questions you have but if not, please do get in touch with us.
If you want more information about GDPR click here or here (please note we can’t be responsible for the content of external websites). This external website is to educate the public about the main elements of the General Data Protection Regulation (GDPR).
It is likely we will need to update this Privacy Notice from time to time. We will notify you of any significant changes, but you are welcome to come back and check it whenever you wish.
For the purposes of the Data Protection Laws, the Data Controllers in relation to any Personal Data you supply are MIS and the Insurer. MIS shall also process any claim you or your estate may have as Data Processor for the Insurer.
A list of definitions for GDPR are available here (please note we can’t be responsible for the content of external websites)
Data Controller the entity which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.
Data Processor means the person which processes Personal Data on behalf of the Data Controller.
Data Protection Laws means all applicable statutes and regulations in any jurisdiction pertaining to the processing of Personal Data, including but not limited to the privacy and security of Personal Data.
Data Protection Regulator means any governmental or regulatory body or authority with responsibility for monitoring or enforcing a party’s compliance with the Data Protection Laws.
GDPR shall mean General Data Protection Regulation (Regulation 2016/679), effective 25 May 2018.
Data Subject means the identified or identifiable natural living person to whom the Personal Data relates.
Personal Data means any information relating to the data subject.
Processing means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Media Insurance Services Limited market and administer for this Accidental Death Insurance Product.
Canopius Managing Agents Limited, Syndicate 4444 at Lloyd’s are the Insurer (underwriters) for this Accidental Death Insurance Product.
Explaining the Legal Bases We Rely On
The law on data protection sets out a number of different reasons for which a company may collect and process your Personal Data, including:
Consent
In specific situations, we can collect and process your data with your consent.
For example, when you tick a box to receive products, services and promotions.
When collecting your Personal Data, we’ll always make clear to you which data is necessary in connection with a particular service.
Contractual obligations
In certain circumstances, we need your Personal Data to comply with our contractual obligations.
For example, if you take out a policy with us, we will collect your name, address, date of birth and bank account details to process your application.
Legal compliance
If the law requires us to, we may need to collect and process your data.
For example, we can pass on details of people involved in fraud or other criminal activity to law enforcement agencies.
Legitimate interest
In specific situations, we require your data to pursue our legitimate interests in a way which might reasonably be expected as part of running our business and which does not materially impact your rights, freedom or interests.
For example, we will use your address details to send you direct marketing information by post, telling you about products and services that we think might interest you.
When Do We Collect Personal Data?
When you visit our website and complete a form or take out a policy with us.
- When you start a policy with us.
- When you engage with us on social media.
- When you contact us by any means with queries, complaints etc.
- When you enter prize draws or competitions.
- When you have provided us with your information in the process of making a claim on a policy or at other times during the life of a policy.
What Sort of Personal Data do We Collect?
If you have a policy with us: your name, gender, date of birth, home address, bank account details, email and telephone numbers. Also details of your interactions with us through our customer services department may be added to our notes.
For example, we collect notes from our conversations with you, details of any changes you advise us of, complaints or claims made and how and when you contact us. This may include comments about your policy or documents received regarding your policy.
When a claim is made copies of documents you provide to prove your identity when payment is made of a claim (including your passport and/or driver’s licence). This will include details of your full name, address, date of birth and facial image. If you provide a passport, the data will also include your place of birth, gender and nationality.
Personal Data
Categories of Personal Data
- Personal details (such as name, date of birth, sex, contact details and any other personal identifiers supplied to us);
- Details of family (such as details of current and past marriages or civil partnerships, details of dependants, children and nominees);
- Other financial details (such as bank details).
- Details of physical or mental health supplied to us.
Special Category Data
In order to assess the terms of the insurance contract or administer claims that arise, the Insurer and MIS may need to collect data that the Data Protection Act and GDPR define as special category (such as medical history or criminal convictions etc).
Information gathered by the use of cookies in your web browser.
How and Why Do We Use Personal Data?
We want to give you the best possible customer experience. We therefore may use your data to offer you products, services and promotions, including policy upgrades, that are likely to interest you.
The data privacy law allows this as part of our legitimate interest in understanding our customers and providing the highest levels of service.
Of course, if you wish to change how we use your data, you’ll find details in the ‘What are my rights?’ section below or just contact us over the phone.
Remember, if you choose not to share your Personal Data with us, or refuse certain contact permissions, we might not be able to provide some products you may be interested in.
Click below for some examples of how we use your Personal Data and why.
Some examples of how we use your Personal Data and why
(This includes processing data to administer your Policy, offer you upgrades and pay benefits):
- To supply and administer your policy. If we don’t collect your Personal Data we won’t be able to process your application and comply with our legal obligations;
- To respond to your queries, requests and complaints. Handling the information you provide us enables us to respond. We may also keep a record of these to inform any future communication with us and to demonstrate how we communicated with you throughout. We do this on the basis of our contractual obligations to you, our legal obligations and our legitimate interests in providing you with the best service and understanding how we can improve our service based on your experience;
- Carrying out our obligations to provide information to the Insurer;
- Statistical and financial modelling;
- To protect our business and your policy from fraud and other illegal activities. This includes using your Personal Data to maintain, update and safeguard your account. We will do all of this as part of our legitimate interest;
- To process payments and to prevent fraudulent transactions. We do this on the basis of our legitimate business interests. This also helps to protect our policyholders from fraud;
- If we discover any criminal activity or alleged criminal activity through our fraud monitoring and suspicious transaction monitoring, we will process this data for the purposes of preventing or detecting unlawful acts. We aim to protect the policyholders, staff and suppliers we interact with from criminal activities;
- With your consent, we will use your Personal Data to keep you informed about relevant products and services. Of course, you are free to opt out of hearing from us by any of these channels at any time;
- To send you relevant, personalised communications by post in relation to updates, services and products. We’ll do this on the basis of our legitimate business interest. You are free to opt out of hearing from us by post or email at any time;
- To send you communications required by law, by our Insurers or which are necessary to inform you about our changes to the policy we provide you. For example, updates to this Privacy Notice, Policy Terms and Conditions relating to your Policy. These service messages will not include any promotional content and do not require prior consent when sent by email or text message. If we do not use your Personal Data for these purposes, we would be unable to comply with our legal obligations;
- To administer any of our prize draws or competitions which you enter, based on your consent given at the time of entering;
- To develop, test and improve the systems, services and products we provide to you. We’ll do this on the basis of our legitimate business interests;
- To comply with our contractual or legal obligations to share data with law enforcement. For example, when a court order is submitted to share data with law enforcement agencies or a court of law;
- To comply with any relevant industry or professional rules and regulations or any applicable voluntary codes;
- To send you survey and feedback requests to help improve our services. These messages will not include any promotional content and do not require prior consent when sent by email or text message. We have a legitimate interest to do so as this helps make our products or services more relevant to you. Of course, you are free to opt out of receiving these requests from us at any time by updating your preferences;
- Sometimes, we’ll need to share your details with a third party who is providing a service (such as print companies or internal company audits). Without sharing your Personal Data, we’d be unable to fulfil our legal obligation;
- Transferring or analysing data in connection with any sale, merger, acquisition, disposal, reorganisation or similar change of business or service provider.
How Do We Protect Your Personal Data?
We know how much data security matters to all our policyholders. With this in mind we will treat your data with the utmost care and take all appropriate steps to protect it.
We secure access to all transactional areas of our website using ‘https’ technology.
Access to your Personal Data is password-protected, and any special category data is secured by password-protection and access is limited to binder authorised personnel only.
We regularly monitor our system for possible vulnerabilities and attacks, and we carry out penetration testing to identify ways to further strengthen security.
How Long will We Keep Your Personal Data?
Whenever we collect or process your Personal Data, we’ll only keep it for as long as is necessary for the purpose for which it was collected.
At the end of that retention period, your data will be completely anonymised, for example by overwriting all Personal Data so that it can be used in a non-identifiable way for statistical analysis and business planning.
Cancelled policies
We will delete all Personal Data a maximum of seven years from the last premium collected on a Policy, and not make any further use of such Personal Data, provided that MIS and/or the Insurer may retain a copy of such Personal Data:
- where required to do so under regulation or applicable law; or
- for the purposes of establishing, exercising or defending legal claims.
Who Do We Share Your Personal Data With?
Apart from our insurers, we sometimes share your Personal Data with trusted third parties.
For example, print companies, IT consultants for fraud management, our insurers to bind your policy and to handle complaints and so on.
Here is the policy we apply to those organisations to keep your data safe and protect your privacy:
- We provide only the information they need to perform their specific services.
- They may only use your data for the exact purposes we specify in our contract with them.
- We work closely with them to ensure that your privacy is respected and protected at all times.
- If we stop using their services, any of your data held by them will either be deleted or rendered anonymous.
Examples of the kind of third party suppliers we work with are:
- IT companies who support our website and other business systems.
- Operational companies such as printers to send out our annual mailing.
- Google/Facebook to show you products that might interest you while you’re browsing the internet. This is based on either your marketing consent or your acceptance of cookies on our website.
- Data insight companies to ensure your details are up to date and accurate.
For fraud management, we may share information about fraudulent or potentially fraudulent activity in our premises or systems. This may include sharing data about individuals with law enforcement bodies.
We may also be required to disclose your Personal Data to the police or other enforcement, regulatory or Government body, in your country of origin or elsewhere, upon a valid request to do so. These requests are assessed on a case-by-case basis and take the privacy of our policyholders into consideration
For further information please contact our Data Protection Lead.
What Are Your Rights Over Your Personal Data?
An overview of your different rights
You have the right to request:
- Access to the Personal Data we hold about you, free of charge.
- The correction of your Personal Data when incorrect, out of date or incomplete.
- That we stop using your Personal Data for direct marketing.
- That we stop any consent-based processing of your Personal Data after you withdraw that consent.
You can contact us to request to exercise these rights at any time as follows:
Building 2, Ground Floor
Guildford Business Park Road
Guildford
GU2 8XG
t. 01483 542710 or visit www.mediainsuranceservices.co.uk
If further information is required from the Insurer as to how it processes data, or as to the exercise of any rights under any Data Protection Laws, You should read the Data Protection Policy on the Insurer’s website at www.canopius.com/privacy/privacy-notice or contact:
The Data Protection Officer
Building 2, Ground Floor
Guildford Business Park Road
Guildford
GU2 8XG
How to amend your Personal Information
If we choose not to action your request we will explain to you the reasons for our refusal.
Your right to withdraw consent
Whenever you have given us your consent to use your Personal Data, you have the right to change your mind at any time and withdraw that consent.
Where we rely on our legitimate interest
In cases where we are processing your Personal Data on the basis of our legitimate interest, you can ask us to stop for reasons connected to your individual situation. To comply with this we you will have to cancel any active policy held with us.
We must then do so unless we believe we have a legitimate overriding reason to continue processing your Personal Data.
Direct marketing
You have the right to stop the use of your Personal Data for direct marketing activity. We must always comply with your request.
Checking your identity
To protect the confidentiality of your information, we will ask you to verify your identity before proceeding with any request you make under this Privacy Notice.
If you have authorised a third party to submit a request on your behalf, we will ask them to prove they have your permission to act.
How Our Insurers Use Your Personal Data
When you apply for a policy your data will be collected and used by the insurer (Canopius Managing Agents Limited, Syndicate 4444 at Lloyd’s) and their other group companies under the terms and conditions of the Policy.
The security of your data is very important to them and they will handle it with regard to all appropriate security measures. They will collect and process data (including personal information) about any person insured under this Policy for its administration, the handling of claims and the provision of customer services, and may share it with related entities and with trusted service providers and agents such as lawyers, as well as other parties such as anti-fraud databases, subject to proper instruction and control.
All data may be used by them for generic risk assessment and modelling purposes but will not be used or passed to any other party for marketing products or services without your express consent. All data provided by you about other people to be insured, such as family, recommending friends or other associates, must be with their permission. It is your responsibility to inform them about the Insurer’s use of their data.
Data will not be retained for longer than necessary and will be deleted within seven years after expiry of this Policy, unless it is further required for legal or regulatory reasons. You have a number of rights in relation to the data, including the right to request a copy of the information, to correct any inaccuracies and in certain circumstances to have it deleted. Data transferred outside the European Economic Area will have equivalent protection.
If further information is required from the Insurer as to how it processes data, or as to the exercise of any rights under any Data Protection Laws, You should read the Data Protection Policy on the Insurer’s website at www.canopius.com/privacy/privacy-notice or contact:
The Data Protection Officer, Canopius Managing Agents Limited (Syndicate 4444 at Lloyd’s)
22 Bishopsgate, London EC2N 4BQ
If you feel that your data has not been handled correctly, or you are unhappy with our response to any requests you have made to us regarding the use of your Personal Data, you have the right to lodge a complaint with the Information Commissioner’s Office.
You can contact them by:
Telephone: 0303 123 1113 (local rate) or 01625 545 745 (national rate).
In writing: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
By Email: casework@ico.org.uk
Online: www.ico.org.uk/concerns (please note we can’t be responsible for the content of external websites)
We hope this Privacy Notice has been helpful in setting out the way we handle your Personal Data and your rights to control it. If you have any questions that haven’t been covered, please contact our Data Protection Lead who will be pleased to help you:
You can contact us by:
Telephone: 01483 542710
In writing: Building 2, Ground Floor, Guildford Business Park Road, Guildford, GU2 8XG
By Email: info@media-ins.co.uk
Online: www.mediainsuranceservices.co.uk
Visitors to our websites
When someone visits www.mediainsuranceservices.co.uk we collect standard internet log information and details of visitor behaviour patterns. We do this to find out things such as the number of visitors to the various parts of the site. We collect this information in a way which does not identify anyone. We do not make any attempt to find out the identities of those visiting our websites (http://mediainsuranceservices.co.uk). We will not associate any data gathered from this site with any personally identifying information from any source. If we do want to collect personally identifiable information through our website, we will be up front about this. We will make it clear when we collect personal information and will explain what we intend to do with it.
Use of cookies by MIS
Cookies are small text files that are placed on your computer by websites that you visit. They are widely used in order to make websites work, or work more efficiently, as well as to provide information to the owners of the site.
The table below explains the cookies we use and why.
| Cookie | Name | Purpose | More Information |
| Google Analytics | _utma _utmb _utmc _utmz |
These cookies are used to collect information about how visitors use our site. We use the information to compile reports and to help us improve the site. The cookies collect information in an anonymous form, including the number of visitors to the site, where visitors have come to the site from and the pages they visited. | Click here for an overview of privacy at Google |
| MIS site cookie acceptance | cookieChk | This cookie is used to record if a user has accepted the use of cookies on the MIS website. | None |
| Google Plusone | PREF NID |
These cookies are used to collect information about how visitors use our site. We use the information to compile reports and to help us improve the site. The cookies collect information in an anonymous form, including the number of visitors to the site, where visitors have come to the site from and the pages they visited. | Click here for an overview of privacy at Google |
Most web browsers allow some control of most cookies through the browser settings. To find out more about cookies, including how to see what cookies have been set and how to manage and delete them, visit www.allaboutcookies.org.
To opt out of being tracked by Google Analytics across all websites visit http://tools.google.com/dlpage/gaoptout.
Media Insurance Services Limited. Registered Office: Warren House, 92 High Street, Cranleigh, Surrey GU6 8AJ.
Registered in England and Wales No. 3886401. Media Insurance Services Limited is authorised and regulated by the Financial Conduct Authority, reference number 1018079. You can find us on the Financial Services Register at https://www.fca.org.uk/firms/financial-services-register or by calling 0800 111 6768.

