Skip to the content

Menu

Insurance Data Solutions Ltd. Privacy Notice

Document Owner: Data Protection Lead
Approved by: Senior Management
Approval Date: 22.06.2026

Last Updated on Website 23.06.26
Next Review Date: 22.06.2027 (or earlier if required)


1. Privacy Notice Introduction

Insurance Data Solutions Ltd (“we”, “us”, or “our”) is committed to protecting your personal data and respecting your privacy.

This Privacy Policy explains how we collect, use, store and protect personal data when you:
• Visit our website
• Contact us or engage with our business
• Use our consulting services and insurance-focused Software as a Service (SaaS) solutions.

We process personal data in accordance with:
• UK GDPR
• Data Protection Act 2018
• Data (Use and Access) Act 2025

It is important that you read this Privacy Policy together with any other detailed privacy notices we may provide when we are collecting or processing personal data about you (for example, employee privacy notices, client-specific notices, or contractual documentation such as Data Processing Agreements), so that you understand how and why we are using your personal data across different contexts.

2. Who we are

Insurance Data Solutions Ltd is a company registered in England and Wales (Company No. 05909592).

We act as:
• A data controller in relation to website users, enquiries, marketing activities, recruitment and employment-related processing.
• A data processor where we process personal data on behalf of our clients, primarily within the insurance sector, as part of our data services and SaaS solutions, strictly in accordance with their instructions and contractual arrangements.

3. What personal data do we collect

3.1 Personal data we collect directly (where we act as Data Controller)
We collect personal data directly from you when you interact with our website or communicate with us.

Identity Data
• First name, last name
• Job title or role
Contact Data
• Business email address
• Telephone number
• Company name and address
Enquiry and Communications Data
• Information provided through forms, email, telephone, or other channels
• Records of correspondence
Technical Data
• IP address
• Browser type and version
• Device and network information
• Operating system and platform
Usage Data
• Website activity, page views, session data
Marketing and Communications Data
• Preferences in receiving communications
• Engagement with marketing activity

Employee and Workforce Data
We process personal data relating to our employees, contractors and job applicants in connection with recruitment, employment and internal business operations.
This may include:
• Identity and contact details
• Employment, professional and qualification information
• Payroll and financial information
• Performance, training and HR-related records

Special Category Data in relation to Employees and Contractors
This may include:
• Health and medical information
• Information relating to absence or fitness to work
• Diversity and equal opportunities data, where voluntarily provided

Such data is processed only where necessary and in accordance with applicable data protection legislation, including where an appropriate condition under Article 9 of the UK GDPR applies. Access to such data is restricted and subject to appropriate safeguards.

Criminal Convictions Data – Employee and Workforce Data
In the context of recruitment and employment, we may also process personal data relating to criminal convictions and offences, where this is necessary and permitted by law.
This may include:
• Criminal background checks (such as Disclosure and Barring Service (DBS) checks)
• Information provided as part of recruitment screening or vetting processes

Such data is processed only where necessary and in accordance with applicable data protection legislation and relevant legal obligations. Access to this data is strictly limited and subject to appropriate safeguards.

Further details are set out in our Employee Privacy Notice.

3.2 Personal data processed as part of our services (where we act as Data Processor)

While providing our consulting services and SaaS solutions, we may process personal data on behalf of our clients.

Our Services are used by clients, including insurers, brokers, managing agents and other organisations, to store and process personal data relating to their own customers and authorised users. In this context, our clients act as the data controller, and we act as a data processor.

We process such personal data strictly in accordance with our clients’ documented instructions and the terms of our contractual arrangements, including Data Processing Agreements.

Client Stakeholder and Professional Data
We may process personal data relating to employees, representatives and other stakeholders of our clients and partners.
This may include:
• Identity and contact details
• Professional roles, responsibilities and business contact information
• Communications and correspondence
• System access and usage data where access to our platforms is provided

Client Customer and End-User Data (Insurance Data)
As part of delivering our services, we process personal data contained within our clients’ systems, datasets and insurance-related records.
This may include personal data relating to:
• Policyholders
• Claimants
• Insured individuals
• Other individuals associated with insurance policies or claims

The data processed will depend on the nature of the service, but may include:
• Policy, claims and coverage information
• Financial and transaction-related data
• Risk, underwriting or claims-related data
• Information relating to incidents, claims history or losses

Personal Data within Client Datasets
The personal data processed as part of our services may vary depending on the datasets provided by our clients and the services being delivered.
This may include:
• Identity and contact details
• Personal identifiers such as date of birth
• Account or reference numbers
• Other data fields contained within client records

We do not control the specific content of client datasets and process such data strictly in accordance with client instructions.

Technical, Profile and Usage Data (Service Delivery and System Operations)
We may also process:
• User account data, usernames and credentials
• System logs, authentication records and audit trails
• Platform usage and interaction data

These activities are carried out solely to deliver, maintain and secure our services and do not alter the roles of the parties as controller and processor.

Special Categories of Personal Data – Client Data
In the course of providing our services, we may process Special Categories of Personal Data contained within client datasets, particularly in insurance and claims-related contexts.
This may include:
• Health or medical information
• Injury or claims-related data

In such cases:
• We act as a data processor
• We process such data strictly in accordance with client instructions and contractual arrangements
• The responsibility for identifying the lawful basis and applicable conditions rests with the client as data controller.

Criminal Convictions Data – Client Data
We may also process personal data relating to criminal convictions and offences where such information is included within client datasets.
In such cases:
• We act as a data processor
• We process such data strictly in accordance with client instructions and contractual arrangements
• The responsibility for identifying the lawful basis for processing rests with the client as data controller.

All such data is handled with appropriate technical and organisational measures to ensure its security and confidentiality.

Processing on behalf of clients
Where we process personal data on behalf of our clients, we do so strictly in accordance with their documented instructions and the terms of applicable contractual arrangements, including Data Processing Agreements.

The specific categories of personal data processed will vary depending on the services provided and client requirements.

4. How we collect personal data

We collect personal data in various ways, depending on how you interact with us and our services.

We collect personal data that you provide directly to us, including when you:
• Complete forms on our website, for example, “contact us” forms
• Communicate with us via email, telephone or other channels
• Engage with us in relation to our services or enquiries
• Register for or access our services, where applicable

Through your use of our website and services
We may collect personal data automatically when you interact with our website or services, including through:
• Cookies and similar tracking technologies
• Website usage data, such as page views and navigation behaviour
• Technical data such as IP address, browser type and device information

Further information is provided in our Cookie Notice.

 

Through the use of our SaaS platforms and services
Where our SaaS platforms or services are used, personal data may be collected and processed through:
• User account creation and access
• Manual data entry by authorised users
• File uploads and data imports
• API integrations and system-to-system data transfers
• System logs, authentication processes and audit trails
In these cases, personal data is typically provided to us by or on behalf of our clients, who act as the data controller.

From third parties

We may receive personal data from third parties, including:

• Our clients, when they provide personal data in connection with the services

• Organisations that use our SaaS platforms and services to process and store personal data relating to their employees, authorised users or customers, including where they provide access to such platforms to authorised users.

• Analytics, marketing and data enrichment providers

• Third-party integrations or connected systems

 

Important information about client-provided data
Where personal data is provided to us by or on behalf of our clients (including through our SaaS platforms, integrations or data transfers), our clients are responsible for:
• Ensuring that the personal data is collected and shared lawfully
• Providing appropriate privacy information to individuals
• Obtaining any required consents.

In these circumstances, we process personal data strictly in accordance with our clients’ instructions and contractual arrangements, including Data Processing Agreements.

5. How we use your personal data (Purpose, Data and Lawful Basis)

We collect and process personal data only where we have a lawful basis to do so under applicable data protection legislation. The purposes for which we process personal data, the types of personal data involved, and the lawful bases we rely on are set out in the table below. Please note that we may rely on more than one lawful basis depending on the specific circumstances. Where we rely on Legitimate Interests, we ensure that such interests are balanced against your rights and freedoms.

We process personal data as follows:

Purpose

Types of Personal Data

Lawful Basis

Responding to enquiries

Identity, Contact, Enquiry and Communications Data

Legitimate Interests – to respond to enquiries and provide information

Managing business relationships and communications

Identity, Contact, Communications Data

Legitimate Interests – to manage and maintain business relationships

Providing services and SaaS solutions

Identity, Contact, Client and Service Data, Profile and Account Data, Technical and Usage Data

Contract / Legitimate Interests

Managing system access and service delivery

Profile and Account Data, Technical Data, Usage Data

Contract

Processing transactions, invoicing and billing

Identity, Contact, Financial and Transaction Data

Contract / Legal Obligation

Internal administration and record keeping

Identity, Contact, Financial Data, Transaction Data

Contract / Legal Obligation / Legitimate Interests

Improving website functionality and services

Technical Data, Usage Data

Legitimate Interests – to improve performance and user experience

Analytics and service improvement

Profile Data, Technical and Usage Data

Legitimate Interests – to develop and improve services

Marketing communications

Identity, Contact, Marketing Data

Consent (or Legitimate Interests where permitted)

Conducting surveys and collecting feedback

Identity, Contact, Profile Data, Interaction Data

Legitimate Interests – to improve services

Compliance with legal obligations

Identity, Contact, Financial Data, Client Data (where required)

Legal Obligation

Handling complaints and data subject rights requests

Identity, Contact, Communications Data

Legal Obligation

Monitoring, security and fraud prevention

Technical Data, Usage Data, System Logs

Legitimate Interests / Legal Obligation

Recruitment and assessing job applications

Identity, Contact, Professional Data

Legitimate Interests – to assess suitability for roles


Where Special Categories of Personal Data are processed, an additional condition under Article 9 of the UK GDPR applies.

Where personal data relating to criminal convictions is processed, this is carried out only where permitted by applicable law and subject to appropriate safeguards.

Further information about how we process personal data in specific contexts may be provided in additional privacy notices.

We only process personal data that is necessary, relevant and proportionate to the purpose for which it is collected.


6. Data sharing and disclosures

We may share personal data with third parties where necessary for the purposes set out in this Privacy Policy. These may include:
• Our employees, contractors and service providers who require access to personal data to perform their roles
• IT and infrastructure providers, including hosting, cloud storage and system providers, such as Microsoft Azure
• Analytics and marketing providers, including tools such as Google Analytics, HubSpot and Lead Forensics
• Professional advisers, including lawyers, auditors, insurers, brokers and financial advisers
• Business partners, agents and third parties involved in the delivery of our services
• Regulators, courts, tribunals and law enforcement authorities where required or permitted by law
• Third parties involved in business transfers, including where our business or assets may be transferred or acquired

Processing on behalf of clients
Where we process personal data on behalf of our clients:
• We act as a data processor
• We only share personal data in accordance with our clients’ instructions and contractual arrangements
• Recipients of such data are typically engaged as sub-processors or authorised third parties under those arrangements.

Third-party analytics and marketing tools
We use third-party analytics and marketing tools, including Google Analytics, HubSpot and Lead Forensics, to help us:
• Understand how our website and services are used
• Support marketing and business development activities
• Improve performance and user experience

Further information about the use of cookies and tracking technologies is provided in our Cookie Notice.

7. International transfers

We primarily store and process personal data within the United Kingdom, including, where applicable, hosting within UK-based Microsoft Azure data centres.

In limited circumstances, personal data may be accessed from outside the United Kingdom in connection with:
• The use of global service providers and cloud platforms
• Remote access by authorised personnel
• The provision, maintenance and support of our services
Where such access or processing occurs, we ensure that appropriate safeguards are in place to protect personal data, including:
• Standard Contractual Clauses (SCCs) or other approved transfer mechanisms
• Data transfer risk assessments
• Appropriate technical and organisational security measures

Where we process personal data on behalf of clients, any international access or transfer is carried out in accordance with our contractual arrangements and the data controller's instructions.

We ensure that personal data remains protected in accordance with applicable data protection legislation at all times.

8. Automated decision-making

We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects.

9. Data retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements.

In some circumstances, we may retain personal data for a longer period, for example:
• Where required to comply with legal or regulatory obligations
• Where there is an ongoing relationship with you or our clients
• In the event of a complaint or where we reasonably believe there is a prospect of litigation

To determine the appropriate retention period for personal data, we consider:
• The amount, nature and sensitivity of the personal data
• The potential risk of harm from unauthorised use or disclosure
• The purposes for which the data is processed and whether those purposes can be achieved through other means
• Applicable legal, regulatory and contractual requirements

Where we process personal data on behalf of our clients, retention periods are determined by the client as data controller and governed by our contractual arrangements. Where personal data is no longer required, it is securely deleted or anonymised in accordance with our data retention and disposal procedures.

10. Your rights

Under applicable data protection legislation, you have the following rights in relation to your personal data:

• The right to access your personal data
• The right to request correction of inaccurate or incomplete data
• The right to request erasure of your personal data
• The right to object to or restrict processing
• The right to request portability of your personal data
• The right to withdraw consent where processing is based on consent

We maintain procedures to ensure that data subject requests are handled appropriately and in accordance with applicable legislation.

11. Requests relating to personal data processed on behalf of clients

 

Where we process personal data on behalf of our clients, for example, in connection with our SaaS solutions and services, we act as a data processor and do not determine the purposes or means of processing that data.
If you submit a request to us in relation to personal data processed on behalf of one of our clients, we will:
• Inform you that we act as a data processor
• Request further information where necessary to identify the relevant data controller and verify your identity • Where appropriate, direct you to the relevant data controller
• Assist the data controller in responding to your request in accordance with our contractual obligations
In such cases, the data controller, for example, your insurer, broker, employer, or the organisation managing your policy and using our SaaS platforms and services to process its data, is responsible for responding to your request and providing you with the relevant information.
Where we are unable to identify the relevant data controller based on the information provided, we may not be able to progress your request and will advise you accordingly.

 

 

12. Data security

We are committed to ensuring that personal data is securely processed and protected.
We implement appropriate technical and organisational measures aligned with our Information Security Management System (ISMS), which is certified to ISO 27001 (Information Security Management) and ISO 9001 (Quality Management), to protect personal data from misuse, interference, loss, unauthorised access, modification or disclosure.
These measures include:
• Access controls and role-based permissions
• Monitoring, logging and audit controls
• Encryption where appropriate
• Secure system design and configuration
• Staff training and awareness

13. Data breach management

In the event of a personal data breach, we will respond in accordance with applicable legal and regulatory obligations.
This includes:
• Identifying and assessing the nature and impact of the breach
• Taking appropriate steps to contain and mitigate the breach
• Implementing remedial actions to prevent recurrence

Where we process personal data on behalf of clients, we will notify the relevant client without undue delay upon becoming aware of a personal data breach affecting their data, in accordance with our contractual obligations.

Where required, we will support our clients in fulfilling their obligations as data controllers, including notifying supervisory authorities and affected individuals.

Where we act as a data controller, we will notify the relevant supervisory authority (the Information Commissioner's Office, ICO) and affected individuals in accordance with applicable legal requirements.

14. Security of information

While we take appropriate steps to protect personal data, no method of transmission over the internet or method of electronic storage is completely secure.

Accordingly, we cannot guarantee the absolute security of any information transmitted to or from our systems, and any such transmission is at your own risk.

15. Cookies and tracking technologies

Cookies are small text files placed on your device to help us recognise your preferences and improve how our website and services function. We use cookies and similar technologies in different ways depending on how our website and services are accessed.

(i) Website cookies and technologies
We use cookies on our public-facing website to:
• Enable core website functionality
• Analyse usage and performance
• Improve user experience
• Support marketing and business development activities

Where required by law, non-essential cookies, including analytics and marketing cookies, are not deployed until user consent has been obtained through our cookie consent mechanism.

(ii) SaaS platform cookies and technologies
Within our SaaS platforms and services, cookies and similar technologies may be used to:
• Enable system functionality and operation
• Support authentication and secure access
• Maintain session information
• Manage system performance and security

These technologies are generally limited to what is strictly necessary for the platform's operation. Where personal data is processed within our SaaS platforms, the client acts as the data controller and is responsible for determining the appropriate legal basis and, where applicable, for obtaining consent.

Further information about the cookies we use, including how to manage your preferences, is provided in our Cookie Notice.

16. Complaints, data protection concerns and information requests

If you have any concerns about how your personal data is being used, you are encouraged to raise this with us in the first instance. We operate an internal process for handling data protection complaints, which includes:
• Providing clear methods for submitting complaints
• Recording and assessing complaints appropriately
• Investigating concerns in a timely and proportionate manner
• Providing a response and outcome

We will acknowledge receipt of complaints within 30 days and, without undue delay, take appropriate steps to investigate and respond, including keeping you informed of progress where appropriate.

We aim to resolve complaints promptly and transparently in accordance with applicable data protection legislation.

If you are not satisfied with the outcome, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO).

17. Data protection contact details

If you have any questions about this Privacy Policy, wish to exercise your data protection rights (including submitting a data subject access request), or raise a complaint, please contact:

IDS Data Protection Lead
Email: enquiries@insurancedatasolutions.co.uk

When making a request, you may be asked to provide sufficient information to enable us to:
• Verify your identity
• Understand the nature of your request
• Identify the relevant data or, where applicable, the relevant client or service

This information is required to ensure that we can respond to your request accurately and in accordance with applicable data protection legislation. Where necessary, we may request additional information before processing your request.


18. Changes to this policy

We may update this Privacy Policy from time to time. Updates will be published on our website.


19. Links to other websites

Our website may contain links to third-party websites, such as client, partner or other external websites.

We do not have any control over those websites and are not responsible for the protection and privacy of any personal data which you provide whilst visiting those websites.

Those websites are not governed by this Privacy Policy, and we recommend that you review the privacy notice applicable to each website you visit.

COOKIES POLICY

Cookies we use –

Cookie Name and Category

Description

Expires After

Analytics (non-essential)

_gat_gtag_UA                Google Analytics

_gid                  Google Analytics

_ga                   Google Analytics

 

Google Analytics (non-essential performance cookies). These cookies are used to collect information about how visitors use our website. We use the information to help us improve the website.

The cookies collect information in an anonymous form (no personal data), including the number of visitors to the website, where visitors have come to the website from, and the pages they visited on this site.

1 minute 

24 hours

1 year, 1 month, 4 days

Essential

ARRAfinity

Used by our website load balancer

Session

Essential

ARRAffinitySameSite

Used by our website load balancer

Session

Essential

__RequestVerificationToken

For Security Checks

Session

Analytics (non-essential)

ai_user                                  

Used by our website for error tracking

1 year

Analytics (non-essential)

ai_session 

Used by our website for error tracking

 

30 minutes

Chat (non-essential)

Hubspotutk

__cf_bm   

messagesUtk         

__hstc 

__hssrc 

__hssc

Hubspot – Live Chat

With the Consent to collect chat cookies setting enabled, HubSpot will prompt visitors for consent to drop a cookie in their browser before they start a chat or when they attempt to the leave the page during a chat conversation. This cookie is used to interact with website visitors and provide a visitor's chat history.

 

6 months

30 minutes

6 months

6 months

Session

30 minutes

WHAT ARE COOKIES?

IDS uses cookies to collect information. Cookies are small data files which are placed on your computer or other devices when you browse this website. They are used to ‘remember’ and record when your computer or device accesses our website. It can present tailored options based on the information stored about your last visit. Some Cookies are essential for the effective operation of our website. They are also used to analyse traffic to tailor the products and services offered and marketed to you, both on our websites and elsewhere. In most cases, cookies are not intrusive but are there to make the page work better either directly (such as essential cookies), or indirectly (such as performance (analytics) cookies to assist web designers in making the site easier to use).

Some cookies could be considered intrusive if they collect personal data or otherwise identify you as an individual and further use this data. IDS do not use such cookies on this website.

INFORMATION COLLECTED

Our cookies collect information about browsing behaviour when you access this website via the same computer or device. This includes information about pages viewed and your journey in our website. We do not use cookies to collect or record information on your name, address or other contact details if you are not a business. 

WHAT ARE COOKIES USED FOR?

The main purposes for which cookies are used are to enable IDS to collect information about your browsing patterns, including to monitor the success of marketing campaigns plus performance and proper functioning of our website.

What types of cookies are there?

At the highest level, cookies can be considered to be either:

Essential or Strictly Necessary: These cookies are essential for the proper operation of a web site. Without these cookies, the website will not perform correctly. Consent is not required for essential cookies, although they should still be listed in a cookie notice. Please see the ‘Cookies we use‘ section for any cookies we consider to be essential.

Non-essential: Anything else that does not fall within the definition of essential cookies. Typically, these are used to analyse behaviour on a website, advertising, etc. These cookies require that the visitor actively consents to them being used and must not be ‘dropped’ onto your device without such consent (UPDATE COMING).

WHAT HAPPENS IF I DISABLE COOKIES?

We are required to obtain your consent for all non-essential cookies used on our website (UPDATE COMING). You can block all cookies (including essential cookies) at any time by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block essential cookies you may not be able to access parts of our site because essential cookies are required to allow it to function correctly. The method of blocking cookies differs from browser to browser, so you are advised to determine the method appropriate to your device and/or browser.

Cookie persistence can be either: 

  • Session or non-persistent cookies: these are only stored on your device during your web session and are automatically deleted when you close your browser – they usually store an anonymous session ID allowing you to browse a website without having to log in to each page.
  • Persistent cookies: a persistent cookie is stored as a file on your computer and it remains there when you close your web browser until it expires (see table below). The cookie can be read by the website that created it when you visit that website again. 

Cookies can also be categorised as follows: 

  • Performance cookies: These cookies enable us to monitor and improve the performance of our website. For example, they allow us to count visits, identify traffic sources and see which parts of the site are most popular (or the least popular). These are non-essential cookies.
  • Essential cookies: These are cookies that ensure the proper functioning of the website (e.g., cookies for login or registration, language preferences, contact forms). Essential cookies would be considered as essential for the website to function correctly and as such would not require consent.
  • Targeting/advertising cookies: These cookies can target audiences based on their browsing behaviour to deliver marketing material more relevant to you. These are non-essential cookies. IDS do not use these cookies at present.
  • Social media advertising and remarketing cookies: The LinkedIn Insight Tag and Facebook Pixel allows us to perform campaign reporting and view insights about website visitors that may come via the campaigns we run on LinkedIn or Facebook. It allows user behaviour to be tracked after they have been redirected to our website via a post or advert. With remarketing, you may see our adverts on LinkedIn or Facebook after you have visited our site. For this to happen, the Facebook Pixel and LinkedIn Insight Tag are activated when a visitor lands on a webpage, and a unique cookie is placed in their browser. Lookalike audience targeting allows us to show adverts on Facebook and LinkedIn to people who are similar to those who have already visited our website. IDS do not use these cookies at present.
  • Facebook opt out: https://www.facebook.com/settings?tab=ads
  • Facebook privacy policy: https://www.facebook.com/privacy/explanation
  • LinkedIn opt out: https://www.linkedin.com/psettings/member-cookies
  • LinkedIn privacy policy: https://www.linkedin.com/legal/privacy-policy

 

HOW WE USE COOKIES AND IP TRACKING SOFTWARE

We use cookies on our website www.insurancedatasolutions.co.uk. 

As a visitor to our website, you can use the cookie consent manager pop-up to select which categories of cookies you wish to accept or reject. 

Insurance Data Solutions utilise third-party tools called Hubspot and Lead Forensics to track businesses that visit our site through IP Address tracking technology. This helps us to identify those businesses visiting our website and the products they are interested in.

https://www.leadforensics.com/privacy-policy/

HubSpot Privacy Policy

For more information about cookies and how we use them please read our IDS Cookies Policy Section below. 

GOOGLE ANALYTICS

We use Google Analytics, to collect standard internet log information and details of visitor behavior patterns.  We do this to track the total number of visitors to different parts of our website.  This information is only processed in a way that does not identify anyone.  We do not make and do not allow Google to make, any attempt to find out the identities of those visiting our website.

https://policies.google.com/privacy

You can opt out of being tracked by Google Analytics across all websites, by going to http://tools.google.com/dlpage/gaoptout. Alternatively, some web browsers may have plug-ins that enable analytical cookies to be blocked. 

If you have any questions about the cookies that we use or this cookie policy, feel free to email us at: enquiries@insuracendatasolutions.co.uk

Updated 28/01/2025

Insurance Data Solutions

Insurance Data Solutions

Registered Address: 

Dalton House,

9 Dalton Square,

Lancaster,

LA1 1WD

 

Contact Information

Telephone:
44 (0)1376 437777
Email:
enquiries@
insurancedatasolutions.co.uk