This policy statement sets out how Allied World Insurance Company, Allied World National Assurance Company, Allied World Assurance Company (U.S.) Inc., Allied World Specialty Insurance Company, Allied World Surplus Lines Insurance Company, Vantapro Specialty Insurance Company and AW Underwriters Inc. (collectively, “Allied World”, “we”, “us” or “our”) collect, use, store, disclose or otherwise process personal data of natural persons who reside in the State of California (“consumers”, “you” or “your”) so that we can provide you with and manage insurance products and services. This policy also provides information about your rights. At Allied World, we are committed to protecting the privacy of your personal data and complying with our obligations under the California Consumer Privacy Act of 2018 (“CCPA”) and other California privacy laws and regulations.
This policy applies only to consumers whose personal data Allied World has processed other than in the role of job applicant, employee, officer, director or contractor of Allied World.
What Personal Data of Yours We Collect
We collect data that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household (“personal data”). In particular, we have collected the following categories of personal data from consumers within the last 12 months:
|A. Identifiers||A real name, alias, postal address, unique personal identifier, online identifier internet protocol address, email address, account name, social security number, driver’s license number, passport number, or other similar identifiers.|
|B. Categories of personal data in Cal. Civ. Code §1798.80(e)||A name, signature, social security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal data included in this category may overlap with other categories.|
|C. Characteristics of protected classifications under California or federal law||Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status.|
|D. Commercial information||Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.|
|I. Professional or employment-related information||Current or past job history or performance evaluations.|
Personal data does not include publicly available information from federal, state or local government records; de-identified or aggregated consumer information; or information excluded from the CCPA’s scope, such as personal data covered by the Fair Credit Reporting Act, or processed pursuant to the Gramm-Leach-Bliley Act, California Financial Information Privacy Act or the Driver’s Privacy Protection Act of 1994 if in conflict with such acts and their implementing regulations.
Why We Collect Your Personal Data
Allied World (or a third party on our behalf) collects and processes consumer personal data for the purposes of:
- conducting our (re)insurance business, including:
- processing your application, insurance underwriting, policy and claims administration, policy cancelation or renewal;
- administration of broker appointments;
- actuarial research and analysis and risk modelling;
- marketing services;
- general management, including:
- providing or receiving products or services;
- responding to your queries or other correspondence;
- completing due diligence and background checks;
- access to and monitoring of IT applications and systems;
- building access or security;
- transferring books of business, company reorganisations or other potential corporate transactions;
- audits, investigations, claims or litigations, including investigating fraud, misconduct or any unlawful acts;
- complying with regulatory or legal requirements; and/or
- any purposes directly related or comparable to the above, as otherwise set forth in the CCPA, or as otherwise notified to you.
In the preceding 12 months, we have disclosed the following CCPA categories of personal data for a business purpose:
Category A: Identifiers
Category B: Categories of personal data in Cal. Civ. Code §1798.80(e)
Category C: Characteristics of protected classifications under California or federal law
Category D: Commercial information
Category I: Professional or employment-related information
From Where We Collect Your Personal Data
So that we can provide products and services to you, we may collect your personal data from:
- you, your or our agents and representatives, including your family members, current and former employers, service providers, (re)insurance brokers or other intermediaries, employment agencies or other recruiters;
- people who are involved in a claim or who assist us in investigating or handling claims, including the claimant, third parties or beneficiaries claiming under your policy, witnesses, experts, or healthcare practitioners; or
- marketing lists, industry or other databases, social media or other publicly available sources.
To Whom We Disclose or Transfer Your Personal Data
We may disclose or transfer your personal data to other parties where necessary for the business purposes listed above. Since Allied World operates globally, the parties that we disclose or transfer your personal data to may be located inside or outside of California. Outside of California, such locations will vary from time to time, but may include where other members of the Allied World Assurance Company Holdings, Ltd group of companies operate or where other third parties to whom we may transfer data, or their affiliates or sub-contractors, operate.
Third parties to whom we may disclose or transfer your personal data include other insurers; reinsurers; intermediaries; claimants; beneficiaries; market places; professional advisers, third-party service providers or agents; law enforcement and regulatory bodies; healthcare providers; data storage and data handling providers; employment benefit providers; any affiliates or allowed sub-contractors of any of the above; and/or as otherwise required or allowed by applicable law or regulation. In the preceding 12 months, we have not sold any personal data.
How You Can Exercise Your Rights Over Your Personal Data
Your Rights under the CCPA
You have the right to request that we disclose to you the categories of personal data we collected about you, the categories of sources of such personal data, our business purpose for collecting such personal data, the categories of third parties with whom we share personal data and the specific pieces of personal data we collected about you each over the past 12 months.
You have the right to request that we (and we will also direct our service providers to) delete any of your personal data, subject to certain exceptions under the CCPA, including, but not limited to, providing a good or service that you requested, performing our contract with you, complying with a legal obligation or making other lawful uses compatible with the context that you provided it.
How to Exercise Your Rights
To exercise your rights described above, please submit a verifiable consumer request to us using any of the contact information listed below. We will not discriminate against you for exercising any of your CCPA rights.
Only you, or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a request related to your personal data. You may also make a request on behalf of your minor child.
You may only make a request for personal data twice within a 12-month period. Such request must provide sufficient information that allows us to reasonably verify that you are the person about whom we collected personal data or that you are their authorized representative, as well as have sufficient detail that allows us to properly understand, evaluate and respond to it. We cannot respond to a request or provide personal data if we cannot verify your identity or authority.
We aim to respond to requests, or provide a reason for delay or decline where legally permitted, within 45 days of receipt of a verifiable consumer request. Unless unreasonable or unduly burdensome, requests will be handled free of charge. We will deliver any disclosures by mail or electronically, at your option, in a readily useable format. Any disclosures we provide will only cover the 12-month period preceding the receipt of the verifiable consumer request.
If you wish to exercise any of your rights or have any other inquiries or complaints about this policy or in relation to your personal data, please contact us through any of the options listed below. Consumers with disabilities may also contact us to request this policy in an alternative format.
New York, NY 10038
Attn: Chief Information Officer
Changes to this Policy
Please note that we may update this policy from time to time and amend it to reflect changes in legislation or other business changes. You can review the latest version of this policy on our website at https://alliedworldinsurance/usa/