Insurance Data Solutions
Registered Address:
Dalton House,
9 Dalton Square,
Lancaster,
LA1 1WD
Contact Information
Document Owner: Data Protection Lead
Approved by: Senior Management
Approval Date: 22.06.2026
Last Updated on Website 23.06.26
Next Review Date: 22.06.2027 (or earlier if required)
Insurance Data Solutions Ltd (“we”, “us”, or “our”) is committed to protecting your personal data and respecting your privacy.
This Privacy Policy explains how we collect, use, store and protect personal data when you:
• Visit our website
• Contact us or engage with our business
• Use our consulting services and insurance-focused Software as a Service (SaaS) solutions.
We process personal data in accordance with:
• UK GDPR
• Data Protection Act 2018
• Data (Use and Access) Act 2025
It is important that you read this Privacy Policy together with any other detailed privacy notices we may provide when we are collecting or processing personal data about you (for example, employee privacy notices, client-specific notices, or contractual documentation such as Data Processing Agreements), so that you understand how and why we are using your personal data across different contexts.
Insurance Data Solutions Ltd is a company registered in England and Wales (Company No. 05909592).
We act as:
• A data controller in relation to website users, enquiries, marketing activities, recruitment and employment-related processing.
• A data processor where we process personal data on behalf of our clients, primarily within the insurance sector, as part of our data services and SaaS solutions, strictly in accordance with their instructions and contractual arrangements.
3.1 Personal data we collect directly (where we act as Data Controller)
We collect personal data directly from you when you interact with our website or communicate with us.
Identity Data
• First name, last name
• Job title or role
Contact Data
• Business email address
• Telephone number
• Company name and address
Enquiry and Communications Data
• Information provided through forms, email, telephone, or other channels
• Records of correspondence
Technical Data
• IP address
• Browser type and version
• Device and network information
• Operating system and platform
Usage Data
• Website activity, page views, session data
Marketing and Communications Data
• Preferences in receiving communications
• Engagement with marketing activity
Employee and Workforce Data
We process personal data relating to our employees, contractors and job applicants in connection with recruitment, employment and internal business operations.
This may include:
• Identity and contact details
• Employment, professional and qualification information
• Payroll and financial information
• Performance, training and HR-related records
Special Category Data in relation to Employees and Contractors
This may include:
• Health and medical information
• Information relating to absence or fitness to work
• Diversity and equal opportunities data, where voluntarily provided
Such data is processed only where necessary and in accordance with applicable data protection legislation, including where an appropriate condition under Article 9 of the UK GDPR applies. Access to such data is restricted and subject to appropriate safeguards.
Criminal Convictions Data – Employee and Workforce Data
In the context of recruitment and employment, we may also process personal data relating to criminal convictions and offences, where this is necessary and permitted by law.
This may include:
• Criminal background checks (such as Disclosure and Barring Service (DBS) checks)
• Information provided as part of recruitment screening or vetting processes
Such data is processed only where necessary and in accordance with applicable data protection legislation and relevant legal obligations. Access to this data is strictly limited and subject to appropriate safeguards.
Further details are set out in our Employee Privacy Notice.
While providing our consulting services and SaaS solutions, we may process personal data on behalf of our clients.
Our Services are used by clients, including insurers, brokers, managing agents and other organisations, to store and process personal data relating to their own customers and authorised users. In this context, our clients act as the data controller, and we act as a data processor.
We process such personal data strictly in accordance with our clients’ documented instructions and the terms of our contractual arrangements, including Data Processing Agreements.
Client Stakeholder and Professional Data
We may process personal data relating to employees, representatives and other stakeholders of our clients and partners.
This may include:
• Identity and contact details
• Professional roles, responsibilities and business contact information
• Communications and correspondence
• System access and usage data where access to our platforms is provided
Client Customer and End-User Data (Insurance Data)
As part of delivering our services, we process personal data contained within our clients’ systems, datasets and insurance-related records.
This may include personal data relating to:
• Policyholders
• Claimants
• Insured individuals
• Other individuals associated with insurance policies or claims
The data processed will depend on the nature of the service, but may include:
• Policy, claims and coverage information
• Financial and transaction-related data
• Risk, underwriting or claims-related data
• Information relating to incidents, claims history or losses
Personal Data within Client Datasets
The personal data processed as part of our services may vary depending on the datasets provided by our clients and the services being delivered.
This may include:
• Identity and contact details
• Personal identifiers such as date of birth
• Account or reference numbers
• Other data fields contained within client records
We do not control the specific content of client datasets and process such data strictly in accordance with client instructions.
Technical, Profile and Usage Data (Service Delivery and System Operations)
We may also process:
• User account data, usernames and credentials
• System logs, authentication records and audit trails
• Platform usage and interaction data
These activities are carried out solely to deliver, maintain and secure our services and do not alter the roles of the parties as controller and processor.
Special Categories of Personal Data – Client Data
In the course of providing our services, we may process Special Categories of Personal Data contained within client datasets, particularly in insurance and claims-related contexts.
This may include:
• Health or medical information
• Injury or claims-related data
In such cases:
• We act as a data processor
• We process such data strictly in accordance with client instructions and contractual arrangements
• The responsibility for identifying the lawful basis and applicable conditions rests with the client as data controller.
Criminal Convictions Data – Client Data
We may also process personal data relating to criminal convictions and offences where such information is included within client datasets.
In such cases:
• We act as a data processor
• We process such data strictly in accordance with client instructions and contractual arrangements
• The responsibility for identifying the lawful basis for processing rests with the client as data controller.
All such data is handled with appropriate technical and organisational measures to ensure its security and confidentiality.
Processing on behalf of clients
Where we process personal data on behalf of our clients, we do so strictly in accordance with their documented instructions and the terms of applicable contractual arrangements, including Data Processing Agreements.
The specific categories of personal data processed will vary depending on the services provided and client requirements.
We collect personal data in various ways, depending on how you interact with us and our services.
We collect personal data that you provide directly to us, including when you:
• Complete forms on our website, for example, “contact us” forms
• Communicate with us via email, telephone or other channels
• Engage with us in relation to our services or enquiries
• Register for or access our services, where applicable
Through your use of our website and services
We may collect personal data automatically when you interact with our website or services, including through:
• Cookies and similar tracking technologies
• Website usage data, such as page views and navigation behaviour
• Technical data such as IP address, browser type and device information
Further information is provided in our Cookie Notice.
From third parties
We may receive personal data from third parties, including:
• Our clients, when they provide personal data in connection with the services
• Organisations that use our SaaS platforms and services to process and store personal data relating to their employees, authorised users or customers, including where they provide access to such platforms to authorised users.
• Analytics, marketing and data enrichment providers
• Third-party integrations or connected systems
Important information about client-provided data
Where personal data is provided to us by or on behalf of our clients (including through our SaaS platforms, integrations or data transfers), our clients are responsible for:
• Ensuring that the personal data is collected and shared lawfully
• Providing appropriate privacy information to individuals
• Obtaining any required consents.
In these circumstances, we process personal data strictly in accordance with our clients’ instructions and contractual arrangements, including Data Processing Agreements.
We collect and process personal data only where we have a lawful basis to do so under applicable data protection legislation. The purposes for which we process personal data, the types of personal data involved, and the lawful bases we rely on are set out in the table below. Please note that we may rely on more than one lawful basis depending on the specific circumstances. Where we rely on Legitimate Interests, we ensure that such interests are balanced against your rights and freedoms.
We process personal data as follows:
|
Purpose |
Types of Personal Data |
Lawful Basis |
|
Responding to enquiries |
Identity, Contact, Enquiry and Communications Data |
Legitimate Interests – to respond to enquiries and provide information |
|
Managing business relationships and communications |
Identity, Contact, Communications Data |
Legitimate Interests – to manage and maintain business relationships |
|
Providing services and SaaS solutions |
Identity, Contact, Client and Service Data, Profile and Account Data, Technical and Usage Data |
Contract / Legitimate Interests |
|
Managing system access and service delivery |
Profile and Account Data, Technical Data, Usage Data |
Contract |
|
Processing transactions, invoicing and billing |
Identity, Contact, Financial and Transaction Data |
Contract / Legal Obligation |
|
Internal administration and record keeping |
Identity, Contact, Financial Data, Transaction Data |
Contract / Legal Obligation / Legitimate Interests |
|
Improving website functionality and services |
Technical Data, Usage Data |
Legitimate Interests – to improve performance and user experience |
|
Analytics and service improvement |
Profile Data, Technical and Usage Data |
Legitimate Interests – to develop and improve services |
|
Marketing communications |
Identity, Contact, Marketing Data |
Consent (or Legitimate Interests where permitted) |
|
Conducting surveys and collecting feedback |
Identity, Contact, Profile Data, Interaction Data |
Legitimate Interests – to improve services |
|
Compliance with legal obligations |
Identity, Contact, Financial Data, Client Data (where required) |
Legal Obligation |
|
Handling complaints and data subject rights requests |
Identity, Contact, Communications Data |
Legal Obligation |
|
Monitoring, security and fraud prevention |
Technical Data, Usage Data, System Logs |
Legitimate Interests / Legal Obligation |
|
Recruitment and assessing job applications |
Identity, Contact, Professional Data |
Legitimate Interests – to assess suitability for roles |
Where Special Categories of Personal Data are processed, an additional condition under Article 9 of the UK GDPR applies.
Where personal data relating to criminal convictions is processed, this is carried out only where permitted by applicable law and subject to appropriate safeguards.
Further information about how we process personal data in specific contexts may be provided in additional privacy notices.
We only process personal data that is necessary, relevant and proportionate to the purpose for which it is collected.
We may share personal data with third parties where necessary for the purposes set out in this Privacy Policy. These may include:
• Our employees, contractors and service providers who require access to personal data to perform their roles
• IT and infrastructure providers, including hosting, cloud storage and system providers, such as Microsoft Azure
• Analytics and marketing providers, including tools such as Google Analytics, HubSpot and Lead Forensics
• Professional advisers, including lawyers, auditors, insurers, brokers and financial advisers
• Business partners, agents and third parties involved in the delivery of our services
• Regulators, courts, tribunals and law enforcement authorities where required or permitted by law
• Third parties involved in business transfers, including where our business or assets may be transferred or acquired
Processing on behalf of clients
Where we process personal data on behalf of our clients:
• We act as a data processor
• We only share personal data in accordance with our clients’ instructions and contractual arrangements
• Recipients of such data are typically engaged as sub-processors or authorised third parties under those arrangements.
Third-party analytics and marketing tools
We use third-party analytics and marketing tools, including Google Analytics, HubSpot and Lead Forensics, to help us:
• Understand how our website and services are used
• Support marketing and business development activities
• Improve performance and user experience
Further information about the use of cookies and tracking technologies is provided in our Cookie Notice.
We primarily store and process personal data within the United Kingdom, including, where applicable, hosting within UK-based Microsoft Azure data centres.
In limited circumstances, personal data may be accessed from outside the United Kingdom in connection with:
• The use of global service providers and cloud platforms
• Remote access by authorised personnel
• The provision, maintenance and support of our services
Where such access or processing occurs, we ensure that appropriate safeguards are in place to protect personal data, including:
• Standard Contractual Clauses (SCCs) or other approved transfer mechanisms
• Data transfer risk assessments
• Appropriate technical and organisational security measures
Where we process personal data on behalf of clients, any international access or transfer is carried out in accordance with our contractual arrangements and the data controller's instructions.
We ensure that personal data remains protected in accordance with applicable data protection legislation at all times.
We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements.
In some circumstances, we may retain personal data for a longer period, for example:
• Where required to comply with legal or regulatory obligations
• Where there is an ongoing relationship with you or our clients
• In the event of a complaint or where we reasonably believe there is a prospect of litigation
To determine the appropriate retention period for personal data, we consider:
• The amount, nature and sensitivity of the personal data
• The potential risk of harm from unauthorised use or disclosure
• The purposes for which the data is processed and whether those purposes can be achieved through other means
• Applicable legal, regulatory and contractual requirements
Where we process personal data on behalf of our clients, retention periods are determined by the client as data controller and governed by our contractual arrangements. Where personal data is no longer required, it is securely deleted or anonymised in accordance with our data retention and disposal procedures.
Under applicable data protection legislation, you have the following rights in relation to your personal data:
• The right to access your personal data
• The right to request correction of inaccurate or incomplete data
• The right to request erasure of your personal data
• The right to object to or restrict processing
• The right to request portability of your personal data
• The right to withdraw consent where processing is based on consent
We maintain procedures to ensure that data subject requests are handled appropriately and in accordance with applicable legislation.
We are committed to ensuring that personal data is securely processed and protected.
We implement appropriate technical and organisational measures aligned with our Information Security Management System (ISMS), which is certified to ISO 27001 (Information Security Management) and ISO 9001 (Quality Management), to protect personal data from misuse, interference, loss, unauthorised access, modification or disclosure.
These measures include:
• Access controls and role-based permissions
• Monitoring, logging and audit controls
• Encryption where appropriate
• Secure system design and configuration
• Staff training and awareness
In the event of a personal data breach, we will respond in accordance with applicable legal and regulatory obligations.
This includes:
• Identifying and assessing the nature and impact of the breach
• Taking appropriate steps to contain and mitigate the breach
• Implementing remedial actions to prevent recurrence
Where we process personal data on behalf of clients, we will notify the relevant client without undue delay upon becoming aware of a personal data breach affecting their data, in accordance with our contractual obligations.
Where required, we will support our clients in fulfilling their obligations as data controllers, including notifying supervisory authorities and affected individuals.
Where we act as a data controller, we will notify the relevant supervisory authority (the Information Commissioner's Office, ICO) and affected individuals in accordance with applicable legal requirements.
While we take appropriate steps to protect personal data, no method of transmission over the internet or method of electronic storage is completely secure.
Accordingly, we cannot guarantee the absolute security of any information transmitted to or from our systems, and any such transmission is at your own risk.
Cookies are small text files placed on your device to help us recognise your preferences and improve how our website and services function. We use cookies and similar technologies in different ways depending on how our website and services are accessed.
(i) Website cookies and technologies
We use cookies on our public-facing website to:
• Enable core website functionality
• Analyse usage and performance
• Improve user experience
• Support marketing and business development activities
Where required by law, non-essential cookies, including analytics and marketing cookies, are not deployed until user consent has been obtained through our cookie consent mechanism.
(ii) SaaS platform cookies and technologies
Within our SaaS platforms and services, cookies and similar technologies may be used to:
• Enable system functionality and operation
• Support authentication and secure access
• Maintain session information
• Manage system performance and security
These technologies are generally limited to what is strictly necessary for the platform's operation. Where personal data is processed within our SaaS platforms, the client acts as the data controller and is responsible for determining the appropriate legal basis and, where applicable, for obtaining consent.
Further information about the cookies we use, including how to manage your preferences, is provided in our Cookie Notice.
If you have any concerns about how your personal data is being used, you are encouraged to raise this with us in the first instance. We operate an internal process for handling data protection complaints, which includes:
• Providing clear methods for submitting complaints
• Recording and assessing complaints appropriately
• Investigating concerns in a timely and proportionate manner
• Providing a response and outcome
We will acknowledge receipt of complaints within 30 days and, without undue delay, take appropriate steps to investigate and respond, including keeping you informed of progress where appropriate.
We aim to resolve complaints promptly and transparently in accordance with applicable data protection legislation.
If you are not satisfied with the outcome, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO).
If you have any questions about this Privacy Policy, wish to exercise your data protection rights (including submitting a data subject access request), or raise a complaint, please contact:
IDS Data Protection Lead
Email: enquiries@insurancedatasolutions.co.uk
When making a request, you may be asked to provide sufficient information to enable us to:
• Verify your identity
• Understand the nature of your request
• Identify the relevant data or, where applicable, the relevant client or service
This information is required to ensure that we can respond to your request accurately and in accordance with applicable data protection legislation. Where necessary, we may request additional information before processing your request.
We may update this Privacy Policy from time to time. Updates will be published on our website.
Our website may contain links to third-party websites, such as client, partner or other external websites.
We do not have any control over those websites and are not responsible for the protection and privacy of any personal data which you provide whilst visiting those websites.
Those websites are not governed by this Privacy Policy, and we recommend that you review the privacy notice applicable to each website you visit.
COOKIES POLICY
Cookies we use –
Cookie Name and Category |
Description |
Expires After |
Analytics (non-essential)_gat_gtag_UA Google Analytics _gid Google Analytics _ga Google Analytics
|
Google Analytics (non-essential performance cookies). These cookies are used to collect information about how visitors use our website. We use the information to help us improve the website. The cookies collect information in an anonymous form (no personal data), including the number of visitors to the website, where visitors have come to the website from, and the pages they visited on this site. |
1 minute 24 hours 1 year, 1 month, 4 days |
EssentialARRAfinity |
Used by our website load balancer |
Session |
EssentialARRAffinitySameSite |
Used by our website load balancer |
Session |
Essential__RequestVerificationToken |
For Security Checks |
Session |
Analytics (non-essential)ai_user |
Used by our website for error tracking |
1 year |
Analytics (non-essential)ai_session |
Used by our website for error tracking |
30 minutes |
Chat (non-essential)Hubspotutk __cf_bm messagesUtk __hstc __hssrc __hssc |
Hubspot – Live Chat With the Consent to collect chat cookies setting enabled, HubSpot will prompt visitors for consent to drop a cookie in their browser before they start a chat or when they attempt to the leave the page during a chat conversation. This cookie is used to interact with website visitors and provide a visitor's chat history. |
6 months 30 minutes 6 months 6 months Session 30 minutes |
WHAT ARE COOKIES?
IDS uses cookies to collect information. Cookies are small data files which are placed on your computer or other devices when you browse this website. They are used to ‘remember’ and record when your computer or device accesses our website. It can present tailored options based on the information stored about your last visit. Some Cookies are essential for the effective operation of our website. They are also used to analyse traffic to tailor the products and services offered and marketed to you, both on our websites and elsewhere. In most cases, cookies are not intrusive but are there to make the page work better either directly (such as essential cookies), or indirectly (such as performance (analytics) cookies to assist web designers in making the site easier to use).
Some cookies could be considered intrusive if they collect personal data or otherwise identify you as an individual and further use this data. IDS do not use such cookies on this website.
INFORMATION COLLECTED
Our cookies collect information about browsing behaviour when you access this website via the same computer or device. This includes information about pages viewed and your journey in our website. We do not use cookies to collect or record information on your name, address or other contact details if you are not a business.
WHAT ARE COOKIES USED FOR?
The main purposes for which cookies are used are to enable IDS to collect information about your browsing patterns, including to monitor the success of marketing campaigns plus performance and proper functioning of our website.
What types of cookies are there?
At the highest level, cookies can be considered to be either:
Essential or Strictly Necessary: These cookies are essential for the proper operation of a web site. Without these cookies, the website will not perform correctly. Consent is not required for essential cookies, although they should still be listed in a cookie notice. Please see the ‘Cookies we use‘ section for any cookies we consider to be essential.
Non-essential: Anything else that does not fall within the definition of essential cookies. Typically, these are used to analyse behaviour on a website, advertising, etc. These cookies require that the visitor actively consents to them being used and must not be ‘dropped’ onto your device without such consent (UPDATE COMING).
WHAT HAPPENS IF I DISABLE COOKIES?
We are required to obtain your consent for all non-essential cookies used on our website (UPDATE COMING). You can block all cookies (including essential cookies) at any time by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block essential cookies you may not be able to access parts of our site because essential cookies are required to allow it to function correctly. The method of blocking cookies differs from browser to browser, so you are advised to determine the method appropriate to your device and/or browser.
Cookie persistence can be either:
Cookies can also be categorised as follows:
We use cookies on our website www.insurancedatasolutions.co.uk.
As a visitor to our website, you can use the cookie consent manager pop-up to select which categories of cookies you wish to accept or reject.
Insurance Data Solutions utilise third-party tools called Hubspot and Lead Forensics to track businesses that visit our site through IP Address tracking technology. This helps us to identify those businesses visiting our website and the products they are interested in.
https://www.leadforensics.com/privacy-policy/
For more information about cookies and how we use them please read our IDS Cookies Policy Section below.
We use Google Analytics, to collect standard internet log information and details of visitor behavior patterns. We do this to track the total number of visitors to different parts of our website. This information is only processed in a way that does not identify anyone. We do not make and do not allow Google to make, any attempt to find out the identities of those visiting our website.
https://policies.google.com/privacy
You can opt out of being tracked by Google Analytics across all websites, by going to http://tools.google.com/dlpage/gaoptout. Alternatively, some web browsers may have plug-ins that enable analytical cookies to be blocked.
If you have any questions about the cookies that we use or this cookie policy, feel free to email us at: enquiries@insuracendatasolutions.co.uk
Updated 28/01/2025