Information We Collect
Depending on the nature of the services provided, C.J. Coleman may act as:
an independent controller; a joint controller with insurers, reinsurers, brokers or delegated authorities; or a processor/service provider acting on behalf of insurers, reinsurers, intermediaries or clients.
Depending on your interaction with us, we may collect the following categories of information: -Identifiers: Name, alias, postal address, unique personal identifier, online identifier, Internet Protocol (IP) address, email address, and account name. -Professional or Employment-Related Information: Job title, employer, and work history. -Commercial Information: Records of products or services purchased, obtained, or considered. -Internet or Other Electronic Network Activity Information: Browsing history, search history, and information regarding your interaction with our website or advertisements (via Google Analytics 4). -Special Category Data / Sensitive Personal Information: As a specialised insurance firm, we may collect health information, medical history, or information regarding criminal convictions and offences where necessary for underwriting or processing insurance claims.
How We Use Your Information
We use your information for the following purposes: -Providing Insurance Services: Processing applications, underwriting risks, issuing policies, and managing claims. -Communication: Responding to inquiries via Microsoft 365 platforms and providing customer support. -Analytics and Marketing: Using Google Analytics 4 to understand website traffic and improve our digital presence. -Legal Compliance: Complying with regulatory requirements within the insurance industry.
We may use automated decision-making and profiling to help us provide quotes, assess risk, detect fraud, and administer policies and claims. This may include automated processing of information you provide to us, information we receive from brokers/insurers/reinsurers, and information from third-party sources (where permitted by law). When we use it: For example, at quotation/renewal, underwriting assessment, pricing and terms, triage of claims, and fraud/risk screening. Logic involved (underwriting and pricing): Our tools apply underwriting rules and statistical models to assess and score risk. Depending on the product and service line, the logic may consider factors such as: -the nature of the insured risk (e.g., industry/occupation, activities, property/asset characteristics, location and exposure indicators); -prior claims or loss history and related patterns; -the requested cover, limits, excess/deductible, and policy features; -policyholder or business attributes relevant to the risk (e.g., years of experience, governance and risk controls); -fraud indicators and consistency checks (e.g., validation of information and anomaly detection); -market/portfolio factors used to maintain sustainable pricing and capacity (e.g., aggregation and reinsurance considerations). -outcome and consequences: Automated processing may influence whether we can offer cover, what terms are offered, the level of premium, the need for additional information, or whether a claim is prioritised for further review. -safeguards and your choices: Where UK/EU law applies and a decision is based solely on automated processing and produces legal or similarly significant effects, you have the right to request human intervention, to express your point of view, and to contest the decision. Please contact our Data Protection Officer for such requests.
Under the GDPR, we rely on the following legal bases: -Contractual Necessity: To provide the insurance services you have requested. -Legal Obligation: To comply with financial and insurance regulations. -Legitimate Interests: For our marketing activities and website optimisation. -Consent: Where we process special category data (e.g., health data), we will obtain your explicit consent unless processing is necessary for reasons of substantial public interest on the basis of UK/EU law.
Your data is primarily processed through Microsoft 365 and stored within their secure cloud infrastructure. For Microsoft 365, Exchange (email data), OneDrive, and SharePoint data are held in the UK, and Teams chat and channel data are held in Europe. We also use Cloudflare for DNS (domain name system) resolution for this site. Cloudflare only holds DNS records for this site. DNS records are public records by nature, and Cloudflare acts as a "signpost" directing traffic to the correct server, rather than processing or storing personal data itself. No personal data (such as IP addresses, device/browser data, request headers, WAF/security logs, or caching) is processed or stored by Cloudflare for this site beyond the standard DNS resolution function.
In addition to the digital service providers listed in our Cookie Policy, we may share your personal data with the following categories of recipients where necessary to provide our insurance broking and risk management services: -Insurers and Underwriters — to obtain quotes, arrange cover, process claims, and manage policies -Reinsurers — where required for risk assessment or claims handling -Loss Adjusters and Surveyors — to assess and manage claims -Legal Professionals — including solicitors and barristers instructed in connection with claims or disputes -Medical Professionals — where medical evidence is required in connection with a claim -Regulatory Bodies — including the Financial Conduct Authority (FCA), the Information Commissioner's Office (ICO), and the Financial Ombudsman Service, where we have a legal or regulatory obligation to disclose information -Premium Finance Providers — where you arrange to pay your insurance premium by instalments -Fraud Prevention Agencies — to verify identity and prevent fraud We require all recipients to handle your personal data in accordance with applicable data protection law and only for the specific purposes for which it was shared.
Much of the personal data we process is provided directly by you or your authorised representatives (e.g. employees, brokers, or family members). However, we may also obtain personal data from the following sources: -Insurance industry databases — including the Claims and Underwriting Exchange (CUE), the Motor Insurance Database (MID), and other industry registers used for risk assessment, claims history verification, and fraud prevention -Credit reference and fraud prevention agencies — to verify identity, assess financial standing, and prevent fraud -Public registers — including the Electoral Register, Companies House, and the Land Registry -Previous insurers or brokers — where you have authorised the transfer of your policy or claims history -Loss adjusters, solicitors, and medical professionals — in connection with the administration of a claim -Introducers and referrers — where you have been introduced to us by a third party (e.g. an affinity partner or another broker) We will only use data from these sources where we have a lawful basis to do so and where it is necessary for the provision of our services or compliance with legal obligations.
Where we transfer personal data from the UK and/or EEA to countries that do not provide an "adequate" level of data protection under applicable law, we use appropriate safeguards. Depending on the circumstances, these may include: -Standard Contractual Clauses (SCCs): EU SCCs approved by the European Commission, together with any required supplementary measures. -UK International Data Transfer Addendum / UK IDTA: The UK GDPR transfer mechanisms used for restricted transfers from the UK. -Binding Corporate Rules (BCRs): Where a group company or supplier relies on approved BCRs, we may use these as a transfer safeguard. We also take steps to ensure that recipients are bound by appropriate confidentiality and security obligations and that transfers are limited to what is necessary for the purposes described in this policy.
This section applies to California residents (and, where relevant, to residents of other US states with similar privacy laws) when we collect personal information as a "business" for purposes of the CCPA/CPRA. 8.1 Notice at Collection Categories collected: We collect the categories of personal information described in Section 2 (including, where relevant, Sensitive Personal Information). Purposes: We collect and use personal information for the purposes described in Section 3 (including providing insurance services such as broking, underwriting support, and claims management; operating our business; security; fraud prevention; and legal/compliance). Retention: We retain personal information for as long as reasonably necessary and proportionate to achieve the purposes described in this policy, as further described in Section 10. 8.2 Sales/Sharing; targeted advertising We do not "sell" personal information for money. Our use of third-party analytics and advertising technologies (e.g., Google) may constitute "sharing" for cross-context behavioural advertising under certain US state laws. Where required, you may opt out of such sharing. 8.3 Sensitive Personal Information (SPI) and insurance Where we collect or use Sensitive Personal Information (for example, health or medical information needed to assess risk, administer a policy, or manage a claim), we do so for permitted insurance-related purposes such as underwriting, claims handling, fraud prevention, legal compliance, and service administration. We do not use Sensitive Personal Information to infer characteristics about you for unrelated purposes. Where applicable, you may have the right to limit the use and disclosure of Sensitive Personal Information to certain permitted purposes. 8.4 Your CCPA/CPRA rights Subject to verification and any applicable exemptions, you may have the right to: -request access to the personal information we hold about you; -request deletion of certain personal information; -request correction of inaccurate personal information; and -opt out of the "sale" or "sharing" of personal information (as described above). You also have the right not to receive discriminatory treatment for exercising your privacy rights.
Contact Us
We have appointed a Data Protection Officer to oversee our privacy compliance. For any questions regarding this policy or to exercise your rights, please contact:
Attention: Jim Foster (DPO) Email: jim.foster@cjcoleman.com Address: 2-4 Idol Lane, London EC3R 5DD, United Kingdom.
Changes to This Policy
We may update this Global Privacy Policy from time to time to reflect changes in law or our data practices. The "Last Updated" date at the top of this policy will indicate when changes were last made. We may update this Global Privacy Policy from time to time to reflect changes in law or our data practices. The "Last Updated" date at the top of this policy will indicate when changes were last made.
