Privacy Policy
Introduction & Context
This Privacy Notice specifies how we use and collect information in our role as a third-party service provider.
In accordance with the General Data Protection Regulation and related UK data protection legislation, we are committed to protecting the confidentiality and security of the information that is provided to us in order for us to be compliant with the appropriate laws.
In order to provide your customers with the services and functionality that you have contracted us for, we need to process, collect and keep information about them. Our role in relation to our business activities is as a data processor.
If you have any questions or queries about this policy, please contact us on the details listed below.
​
Who are we?
"Claimsure" is a service provided by Paysure Solutions Ltd. “Paysure" (also referred to in this Notice as “we", "us", or "our") means Paysure Solutions Ltd and it’s subsidiaries.
​​
What role does Paysure play with regards to data privacy?
Paysure is a service provider (third party) to the insurance industry to enable digital capabilities that enrich the customer experience through automating claims and improving processes, this approach also improves the information provided to our clients to make decisions on claims and underwriting. Furthermore, Paysure facilitates payments, via its third parties, on behalf of the insurer to allow the insurers customers to receive the service under their insurance policy as decided by the insurer.
As such Paysure is a data processor acting on behalf of the data controller who is the insurer or intermediary (including Managing General Agents). In our role as a data processor we take data security and data privacy seriously, being a core original design consideration at the birth of our platform and technology.
If the insurer/intermediary or client choses not to share certain data with us, then some of our service could be restricted, including our ability to help reduce fraud (such as checking location of customer and card payment).
Data controllers and the relationship with data processors
Because we use third-party, cloud-based software, some data will be processed by these external organisations. Paysure also processes some of these data on our own systems. In all cases, the controller of the data is the insurance provider/intermediary where Paysure is the data processor including the third-party processors.
As a data processor, we will follow the policies of the data controller as provided to us – we will also review the data controller policy against that of our third-parties to ensure that they are aligned and compliant.
It is the responsibility of the data controller to ensure that any on-going changes in the data controllers’ policy is provided to us, and with appropriate warning to implement any changes required. The data controller is also responsible to ensure that they have:
-
informed their customers who we are and how we use their personal information, as set out in the data controllers’ and our Privacy Policies; and
-
permission from the individual for us to use and store their personal information, as set out in this Privacy Policy
​
​
What information will Paysure collect?
When a customer of the insurer or intermediary signs up to receive a service that is provided by Paysure, that customer’s personal information might be passed on to us to help deliver that service and to control any aspect of any the related claim to that customer (or that customer’s dependents) and also manage any financial aspects such as fraud. Personal data is any information that may identify a living individual.
An insurance provider or intermediary may also collect, use and store sensitive personal information such as criminal convictions and medical conditions as necessary in relation to insurances such as home, travel and health insurance. This information may be shared with us in our role as a third party to the insurance provider. Where necessary, the insurance provider should have obtained the customer’s consent to the processing of such information.
​​
​
IP Addresses
Paysure may also collect IP addresses (an IP address is a number that can uniquely identify a specific computer or other network device on the internet). We may use analysis software (e.g. Google Analytics) to look at IP addresses and cookies for the purpose of enhancing your user experience. This information is not used to develop a personal profile of you and the log files are regularly purged.
​​
​
Cookies
When we provide services, we want to make them easy, useful and reliable. Where services are delivered on the Internet or via applications on mobile devices, this sometimes involves placing small amounts of information on your device, for example, computer or mobile phone. These include small files known as cookies. They cannot be used to identify the customer personally. Any cookies that may be used are used either solely on a per session basis or to maintain user preferences. Cookies are not shared with any third parties.
These pieces of information are used to improve services for you through, for example:
-
Enabling fraud detection activities that utilise information, such as your location.
-
Enabling a service to recognise your device so you don't have to give the same information several times during one task.
-
Measuring how many people are using services, so they can be made easier to use and there's enough capacity to ensure they are fast.
The customer can manage these small files themselves and learn more about them through Internet browser cookies - what they are and how to manage them.
​
​
How will Paysure use the information collected about the insurer’s or intermediary’s customers?
Examples of data that could be used would be identifying information such as name, membership number and address for creating and distributing membership & payment cards.
Additionally, the location of the card and customer or financial transaction related to a claim or specific claim information (including medical information about the customer or the customers’ dependents) that will be used to assess a claim by the insurer or intermediary. Any data captured, or submitted by the insurer’s or intermediary’s customer, for a claim will be used to help the insurer assess the claim and decide on the outcome of the claim. This data may be capture via Paysure’s mobile application or website and passed onto the insurer or intermediary for the purpose as described above. Furthermore, these data could also be used to assess and monitor fraud (financial crime and/or insurance fraud).
Transactional information relating to a claim, deductible/excess and any shortfalling of a claim that is processed by Paysure will be retained for accounting and financial record keeping requirements.
​
Data processing procedure
Personal Data shall be processed electronically and/or manually, pursuant to organisational and processing procedures strictly related to the aforementioned purposes. These will be subject to our internal procedures for security, integrity, and confidentiality of the data in compliance with our organisational, physical, and procedural measures.
The data processing shall be carried out pursuant to the correctness, lawfulness, and transparency, in order to protect the confidential nature of the data and the rights of the insurer’s/intermediary’s customer at any time, in compliance with the existing regulations.
The Data Controller, the insurer or intermediary, represents and guarantees that the Personal Data provided by the insurer’s/intermediary’s customer shall be processed pursuant to the highest standards of confidentiality and protection, guaranteeing that the suitable security measures (including both technical and management measures) aimed at preventing the unauthorized access, disclosure, improper or unintentional modification, loss, or destruction of Personal Data are implemented.
​
​
Will Paysure share personal information with anyone else?
We will only supply personal information to other parties where such a transfer is a necessary part of the activities that we undertake, where the insurer/intermediary and their customer give us consent or where we are required to do so by law or regulation (e.g. where the disclosure is necessary for the purposes of the prevention and/or detection of crime).
As a third party and data processor we must disclose personal information back to the relevant data controller(s) i.e. insurance provider or intermediary with whom we are contracted. Some other parties also require disclosure, examples of which could include regulatory bodies, loss adjusters, legal and accountancy firms involved in the claims handling process and Claims and Underwriting Exchange Register, their agents and suppliers as required by the insurance provider or intermediary.
We may be required to disclose personal information to any new owners of the data controller or of ourselves in the event that we are subject to a merger or acquisition. Disclosure may also be made to enable company audits, regulatory inspections or to investigate a complaint, suspicion of fraud or a security threat.
We will never share the customer information of our clients (insurance provider or intermediary) outside our organisation for marketing purposes.
We never sell or otherwise transfer any personal data to commercial companies or other organisations, with the exception of web statistics (see IP addresses and Cookies above) which is hosted and managed by a third-party company (Amazon Web Services or Google Cloud Platform). We collect this information to help us understand how our application is used in order to maintain and improve it and to deal with your requests such as managing your account(s), improving our services and providing you with information about products and services.
​
​
International data transfers
Certain personal information held on our Information Technology systems may be transferred across geographical borders in accordance with applicable law in order to provide the services that the insurer or intermediary have signed-up to – we will be transparent with our clients in this event about this as the data controller will also likely be required to do the same. These transfers are governed by European Union (EU) standard contractual clauses or equivalent data transfer agreements to protect the security and confidentiality of personal information. It is the responsibility of the data controller to ensure that customers have provided this consent.
​
​
How is your data stored?
All data is on secured password protected computer systems with all archived data placed on encrypted drives. Our IT infrastructure is hosted by Amazon Web Services and Google Cloud Platform and their Privacy Policy can be found online.
We use Microsoft Office 365 services such as Outlook, Word, Excel and PowerPoint, which store information on Microsoft’s cloud servers. You can find Microsoft’s privacy policy for Office 365 here: https://privacy.microsoft.com/en-GB/privacystatement
We may from time to time transfer large files of data via third party providers such as; ‘WeTransfer’ their privacy statement can be found here:https://wetransfer.com/legal/privacy.
These third parties are not permitted to share your data or to use it for marketing purposes.
​
​
How long will Paysure keep my personal information?
We will generally only keep your information on our systems for as long as is reasonably required for the purpose(s) for which it was submitted or otherwise as determined by law or regulation and in any case until the reception of the insurer’s or intermediary’s customer request to deactivate and/or cancel the services provided. Once we decide that we no longer need your information it will either be securely and confidentially destroyed or permanently anonymised so that it is unrecognisable and unassignable to any individual.
​​
To request deletion of your data please email us at the contact details below or use this link.
​
Changes to the Paysure Privacy Policy
This privacy policy may be updated from time to time to reflect changes in the law, clarifications, improvements or data controller requirements.
​
​
Our contact details
If you have any specific questions for us please contact us at:
Data Protection and Privacy Officer
Paysure Solutions Ltd
Unit 14036,
PO Box 6945,
LONDON
W1A 6US
Email: DPO@paysure.solutions