PRIVACY NOTICE
This Privacy Notice provides information on your use of this Website and governs how Bridgehaven Europe Specialty DAC (BHVN) collects, uses, and protects your personal data. This privacy notice does not extend to any third-party websites, applications or portals that can be accessed from this website including, but not limited to, any links we may provide to social media websites.
Please read this Privacy Notice carefully.
DEFINITION AND INTERPRETATIONS
In this Privacy Notice, the following terms have the meanings set out below:
Data | all information submitted to Bridgehaven Europe Specialty DAC, including via the Website, email, telephone etc.
|
Cookies | small text files placed on your device when you visit certain parts of the Website and/or use certain Website features.
|
Data Protection Laws | all applicable laws relating to the processing of personal data, including EU GDPR and all national implementing and supplementary laws, regulations, and secondary legislation.
|
GDPR | the EU General Data Protection Regulation.
|
Bridgehaven Europe Specialty, “BHVN”, “we”, or “us” | Bridgehaven Europe Specialty DAC is a company incorporated in Ireland, registered number 340407. BHVN’s registered office is at Merrion Hall, Strand Road, Sandymount, Dublin 4, Ireland.
|
UK and EU Cookie Law | The Privacy and Electronic Communications (EC Directive) Regulations 2003, as amended by subsequent regulations in 2011 and 2018, as applicable and implemented in both the United Kingdom and the European Union and its member states.
|
User or “you” | Business contacts, Customers, Individuals who request or receive out marketing communications, Individuals who make general enquiries, Participants in competitions, promotions, or similar activities, and any third party accessing the Website who is not (i) employed by Bridgehaven Europe Specialty DAC and acting in the course of employment, or (ii) engaged as a consultant or otherwise providing services to Bridgehaven Europe Specialty DAC and accessing the Website in that capacity.
|
Website | www.bhvn-ins.com and any sub-domains, unless expressly excluded by separate terms and conditions.
|
The following sections will guide you through our practices for collections, usage, disclosure, and retention of your (personal) data.
Controller
Bridgehaven Europe Specialty DAC determines the purpose for which and the way in which your data is processed.
Personal data we collect
“Personal data” means any information that can be used to identify a natural person, directly or indirectly.
Individuals in scope of this Privacy Notice
This Privacy Notice applies to all individuals whose data we process, including (but not limited to)
- Business contacts
- Customers
- Users of our websites and online services
- Individuals who request or receive out marketing communications
- Individuals who make general enquiries
- Participants in competitions, promotions, or similar activities
We collect the following data depending on the purpose of your interaction with us and as allowed by applicable law:
- General information such as, name, telephone number, email address.
- Any other information you provide us with on your application form.
- In the event you attend events with us, we may collect relevant details e.g. your event preferences, dietary requirements etc.
How we collect your data
We collect Data in the following ways:
- Data provided by you – such as when you provide your personal data to us, including from any of our Sites, surveys, live events, market research, and other direct communications (telephone, email etc.) and/or solicitations.
- Data collected automatically – when you access the Website, certain Data is collected automatically, for example: information about your visit, including IP address, access dates and times, frequency of visits, and interactions with Website content.
- Data collected via cookies, in line with your browser settings.
For more information about the cookies we use and how to change your cookie preferences, please see our cookies policy: https://www.bhvn-ins.com/cookies/.
How we use/process your data
We are legally required to have a valid basis for collecting and processing your personal data. The table below sets out the different ways in which we use your data, along with the legal grounds on which we rely for each activity.
The legal bases are:
- Legitimate interest
- Legal obligation
- Consent
- Contract
- Public task
- Vital interests
In certain scenarios (e.g., AML obligations), such processing is necessary for us to provide our services to you (e.g., underwriting) or is otherwise a statutory or contractual requirement. Where such data is not provided, we may not be able to provide you with our services or continue our relationship with you.
Personal Data | Purpose/use | Legal Basis |
General information including name, telephone number, email address | Business development: source new opportunities and prospective MGAs to support under delegated authority. | Legitimate interest (developing our business and identifying new opportunities) Consent
|
General information such as, name, telephone number, email address. Payment information such as bank account details, payment card details, assets and liabilities. | Commercial Review: assessment of the commercial viability of the potential partnerships. It includes high level financial forecasting to confirm that all parties (MGA, BHVN and Reinsurers) can achieve sustainable and satisfactory ROI | Legitimate interest (perform service to you our client and to other parties (including reinsurers and MGA) and to ensure the most appropriate service is being provided) Consent |
Bank account details, financial information, name | Technical Review: compliance review, financial stability, and actuarial review | Legitimate interest to ensure that the business remain financially stable and no actions are required to ensure compliance. Legal obligation including under Solvency II and Central Bank Regulations Consent Contract
|
General information such as, name, telephone number, email address. Payment information such as bank account details, payment card details, assets and liabilities. | Fraud and crime prevention, sharing data with third party anti-fraud agencies such as the Motor Insurance Bureau, The Claims and Underwriting Exchange and law enforcement agencies | Legal obligations in respect of fraud, money laundering, including the Criminal Justice (Theft and Fraud Offences) Act, 2001 and Criminal Justice Act 2010. Legitimate interest in fraud and crime prevention and protecting our business.
|
General information including name, telephone number, email address. | Communicate and market to you | Consent Legitimate interest (perform service to you our client in providing updates about new service offerings) Contract |
Strictly necessary cookies
| These are cookies that are required for the operation of the Website. They include, for example, cookies that enable you to log into secure areas of the Website, use a shopping cart or make use of e-billing services. | Legitimate interest (perform service to you our client and ensure that our website operates as intended) |
Our cookies collect: your unique user ID; your IP address; Network location. | Analytical/performance cookies: These cookies allow us to recognise and count the number of visitors and to see how visitors move around our Website when they are using it. This helps us to improve the way our Website works, for example, by ensuring that users are finding what they are looking for easily. Functionality cookies: These are used to recognise you when you return to our Website. This enables us to personalise our content for you, greet you by name and remember your preferences (for example, your choice of language or region). By using the Website, you agree to our placement of functionality cookies |
Consent |
Note: You have the right to object to the processing of your personal data on the basis of our legitimate interests. If you do object, we will no longer process your personal data for that particular purpose, unless we have compelling legitimate grounds for the processing which overrides your rights and freedoms, or where the processing is necessary for the establishment, exercise, or defence of legal claims.
Who do we share your personal data with?
We will only share your personal data within Bridgehaven’s Group of companies and service providers and where necessary with certain third parties for the purposes set out in the table above. Third parties may include Business partners: such as MGAs, reinsurers, and brokers. Third party providers: actuary, IT software. Industry bodies such as the Motor Insurance Bureau. We may share the following categories of personal data with third parties:
- Data provided by you – such as when you provide your personal data to us, including from any of our Sites, surveys, live events, market research, and other direct communications (telephone, email etc.) and/or solicitations.
- Data collected automatically – when you access the Website, certain Data is collected automatically, for example: information about your visit, including IP address, access dates and times, frequency of visits, and interactions with Website content.
- Data collected via cookies, in line with your browser settings.
International Transfers
The personal data that we collect from you may be transferred to, and stored at, a destination outside the European Economic Community (“EEA”). Due to the global nature of our business, your personal data may be disclosed to group companies outside of the EEA, including the UK. We have ensured that appropriate safeguards are in place to protect the privacy and integrity of any personal data transferred outside the EEA, including an adequacy decision under Article 45 GDPR, or the Standard Contractual Clauses under Article 46.2 GDPR. Please contact us if you wish to obtain information concerning the safeguards we have in place (see ‘Contact Information’ below).
Keeping data secure/Data security
We implement appropriate technical, organisational, and physical safeguards to protect the personal data we process, in line with client instructions and our legal and regulatory obligations.
Our website and computer systems are equipped with security measures to prevent the loss, misuse, or alteration of the information you provide. In addition, we have established procedures to respond to any suspected personal data breach and will notify you, as well as any relevant regulator, where legally required.
If you become aware of any actual or potential misuse of your information, please contact us immediately at [email protected].
For guidance on protecting your information, devices, and computers against fraud, identity theft, viruses, and other online risks, please visit www.getsafeonline.org. Get Safe Online is supported by HM Government and leading businesses.
Direct marketing
You will receive marketing communication from us if you subscribe to our newsletter. You can opt out of receiving marketing communication from us at any time by contacting us using the details provided under contact information section.
Data retention
We keep your personal data only for as long as reasonably necessary for the purpose for which it was collected or to comply with any applicable legal or ethical reporting or document retention requirements. In particular, the following retention periods apply:
Category of Personal Data | Retention Period |
Customer Records | 7 years |
claims records | 7 years |
AML/KYC records | 5 years |
Cookies data | 1 year |
Your legal rights
You have the following rights in relation to your data…
- Right to access (Subject Access Request) – to a copy of your personal data and information about its processing. You will not have to pay a fee to access your data unless your request is “manifestly unfounded or excessive.” Where we are legally permitted to do so, we may refuse your request.
- Right to correct – the right to have your Data rectified if it is inaccurate or incomplete.
- Right to erase – the right to request that we delete or remove your Data from our systems.
- Right to restrict our use of your Data – the right to “block” us from using your Data or limit the way in which we can use it.
- Right to data portability – the right to request that we move, copy or transfer your Data.
- Right to object – the right to object to our use of your Data including where we use it for our legitimate interests or in respect of direct marketing.
- Right to withdraw consent – You also have the right to withdraw your consent to our processing of your personal data at any time (without affecting the lawfulness of processing based on consent before its withdrawal), in circumstances where we rely on this legal basis to process your data.
To make enquiries, exercise any of your rights set out above, or withdraw your consent to the processing of your Data (where consent is our legal basis for processing your Data), please contact us via e-mail. address:
If you are not satisfied with the way a complaint you make in relation to your Data is managed by us, you may be able to refer your complaint to the relevant data protection authority. For Ireland, this is the Data Protection Commission (DPC). The DPC’s contact details can be found on their website at https://www.dataprotection.ie
It is important that the Data we hold about you is accurate and current. Please keep us informed if your Data changes during the period for which we hold it.
CONTACT INFORMATION
If you have any questions about this Privacy Notice or about the use of your personal data. You may contact us in the following ways:
Email: [email protected]
Updates to this privacy notice
We may update this Privacy Notice from time to time, for example, because of changes to law, technologies, or other developments. We encourage you to review this Privacy Notice periodically so that you will be aware of our current privacy practices.