dotted line
Acromas Insurance Limited logo

Data protection privacy policy

Last updated: June 2025

Introduction

This privacy policy gives you information about how Acromas Insurance Company Limited (AICL) collects and processes your personal data. It is important you read this document together with any other privacy or fair processing policies we give you on specific occasions where we collect or process your personal data. This privacy policy supplements other notices and privacy policies and is not intended to override them.

Who are you dealing with?

Acromas Insurance Company Limited (AICL) are the underwriter for home and motor insurance products which are sold and administered by Saga Services Limited. For further information on insurance policy sales and administration, or for detail of how Saga market their products and services, please refer to the Saga Privacy Policy (link below):

Saga Group Privacy Policy
Please go https://www.saga.co.uk/privacy-policy or contact the Saga Data Protection Officer at: Saga Group Plc, Pancras Square, London, N1C 4AG or email data.protection@saga.co.uk.

Should you need to contact AICL regarding data related concerns about your motor and/or home insurance policy or your rights (see below for more information about your rights), please contact the Data Protection Officer at: Ageas House, Hampshire Corporate Park, Templars Way, Eastleigh, Hampshire, SO53 3YA or email thedpo@ageas.co.uk.

Back to top

The data we collect about you

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:

  • Identity Data includes first name, maiden name, last name, username or similar identifier, title, marital status, next of kin, family members, dependents, date of birth, nationality, gender and proof of your identity.
  • Contact Data includes billing address, email address, telephone numbers.
  • Financial Data includes bank account, payment card details, income, credit rating and payment details.
  • Transaction Data includes details about payments to and from you and other details of products and services you have purchased from us, quotes, contact history, claims history and communications history.
  • Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.
  • Profile Data includes your username and password, account number, unique ID’s, vehicle registration, policy number, quote number, claim number.
  • Usage Data includes information about how you use our website.
  • Marketing and Communications Data includes your preferences in receiving marketing. This may include information we have obtained from credit reference agencies.
  • Image Data includes photographs, webcam footage.

We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy policy.

With regards to special categories of data, we may collect for example health data but only where relevant to the products or services you are purchasing or enquiring about. We may also collect information about criminal convictions and offences. For example, we may require details of motoring convictions to ensure the insurance price we provide is accurate.

If you fail to provide personal data

Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with goods or services). In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case at the time.

Back to top

How your personal data is collected

We use different methods to collect data from and about you including through:

  • Direct interactions. You may give us your Identity, Contact, Technical and Profile Data by filling in forms or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:
    • apply for our products or services;
    • create an account on our website;
    • request marketing to be sent to you.
  • Automated technologies or interactions. As you interact with our website, we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies. We may also receive Technical Data about you if you visit other websites employing our cookies. Useful information about cookies, including how to remove them, can be found on the Saga Group website under the ‘Cooking Settings’ section.
  • Third parties or publicly available sources. We will receive personal data about you from various third parties and public sources as set out below:
    • Technical Data from the following parties:
      1. analytics providers such as Decibel Insight, Google based outside the UK;
      2. advertising networks based inside OR outside the UK; and
      3. search information providers based inside OR outside the UK.
    • Contact, Financial and Transaction Data from providers of technical, payment and delivery services such as price comparison websites for insurance products.
    • Identity and Contact Data from data brokers or aggregators for marketing purposes.
    • Identity and Contact Data from publicly available sources [such as Companies House and the Electoral Register based inside the UK] Including data from credit reference agencies.
    • Databases including, but not limited to, the Motor Insurer’s Bureau (MIB), the Claims Underwriting Exchange (CUE), Motor Insurance Anti-Fraud Theft Register (MIAFTR) and the Insurance Fraud Bureau (IFB) for detection of financial crime and fraud.
    • Government agencies and regulatory bodies including the police and the Driver and Vehicle Licencing Agency (DVLA).

Back to top

How we use your personal data

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

  • Where we need to perform the contract we are about to enter into or have entered into with you.
  • Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
  • Where we need to comply with a legal obligation.
  • Where it is necessary in order to protect your vital interests or those of another individual.

We do not sell, trade, or rent your personal information to others.

Back to top

Purposes for which we will use your personal data

We have set out below, in a table format, a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.

Note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground we are relying on to process your personal data where more than one ground has been set out in the table below.

Purpose/Activity Type of data Lawful basis for processing including basis of legitimate interest
To provide you with a quote (for insurance or travel) and to register you as a new customer
  • Identity
  • Contact
  • Performance of a contract with you
  • Necessary for our legitimate interests

To provide goods and/or services that you request. This may be through:

  • the administration of your policy and managing any claims you make, e.g. insurance
  • Identity
  • Contact
  • Technical
  • Profile
  • Performance of a contract with you
To communicate with you about an enquiry you have made, to notify you if there is a problem with your product or service, to let you know about important functionality changes to the website or if there is another genuine reason for doing so
  • Identity
  • Contact
  • Performance of a contract with you
  • Necessary for our legitimate interests (to enable us to communicate effectively with you)
To ensure quality assurance and for audit purposes and compliance with regulations
  • Identity
  • Contact
  • Financial
  • Transaction
  • Performance of a contract with you
  • Necessary for compliance with a legal obligation
  • Necessary for our legitimate interests

To carry out fraud prevention and credit checks.

To help us prevent fraud and money laundering, assess your premium at quote and renewal, for credit applications and to assist with identity checks in order to prevent money laundering.

A copy of this search will be left on your credit file but will not affect your credit score.

To assess financial and insurance risk we make full and open checks on electoral roll registers and public data provided to us by credit reference bureaus and other third parties.

For identity checking for money laundering purposes.

  • Identity
  • Contact
  • Financial
  • Transaction
  • Performance of a contract with you
  • Necessary for compliance with a legal obligation
  • Necessary for our legitimate interests (to protect our business from fraud and other financial risks)

To prevent and detect crime.

To manage risks to our business includes pricing insurance risk.

To prevent fraudulent behaviour on our websites

  • Identity
  • Contact
  • Financial
  • Transaction
  • Performance of a contract with you
  • Necessary for our legitimate interests (to protect our business from fraud and other crimes)

Necessary for our legitimate interests (to protect our business from fraud and other crimes)

  1. Manage payments, fees and charges
  2. Collect and recover money owed to us
  • Identity
  • Contact
  • Financial
  • Transaction
  • Performance of a contract with you
  • Necessary for our legitimate interests (to recover debts due to us)
To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, statistical reporting and hosting of data)
  • Identity
  • Contact
  • Technical
  • Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)
  • Necessary to comply with a legal obligation
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences, including customer value and retention.
  • Technical
  • Usage
  • Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)

Back to top

Sharing your information

As previously mentioned, we do not sell, trade or rent your information, and will never disclose information about you (including information obtained from our dealings with you) to third parties, except:

  • Where we have a legal interest in a company;
  • To fulfil your specific orders for a product, service or information if it is delivered by a third party. In these instances, while the information you provide will be disclosed to them, it will only be used for the administration of the product, service or information provided. This could include (but is not limited to), verification of any quote given to you, claims processing, underwriting, pricing purposes as appropriate, testing, and to maintain management information for business analysis;
  • For underwriting, pricing, insurance rating analysis and testing purposes, and to maintain management information for business analysis;
  • Where we have your consent to do so.

We must have your consent to discuss your account with a third party, for example a family member. You may give this consent either orally or in writing and you may give it at any time by contacting us.

We may be obliged by law to pass on your information to the police or any other statutory or regulatory authority. In some cases, exemptions may apply under relevant data protection legislation, whereby we can legitimately release personal data e.g. to prevent or detect crime or in connection with legal proceedings.

After you purchase a product or service from us, we may enter into an arrangement for that service to be provided by a new third party. If this happens, the terms and conditions of your contract with us will provide that you consent to the transfer and processing of personal and/or special category personal data to the new provider, subject to the requirements of the GDPR and associated legislation.

If we provide information to a third party (either a provider of a product or service, or an external data processing agency such as a mailing house) or a company in which AICL has a legal interest, we will exercise the strictest contractual controls, requiring them and any of their agents and/or suppliers to:

  • Maintain the security and confidentiality of the information and restrict access to those of its own employees
  • Use the data for the agreed purpose only and prevent it being used for any other purpose by any other party
  • Refrain from communicating with you other than concerning the product in question
  • Return the data to us at the conclusion of any contract term and destroy or delete any copies made of all or any part of the information unless copies are needed to be kept to comply with regulations.

We will restrict the information disclosed to the absolute minimum necessary.

We work in partnership with the Motor Insurers’ Bureau (MIB) and associated not-for-profit companies who provide several services on behalf of the insurance industry. At every stage of your insurance journey, the MIB will be processing your personal information and more details about this can be found via their website: mib.org.uk. Set out below are brief details of the sorts of activity the MIB undertake:

  • Checking your driving licence number against the DVLA driver database to obtain driving licence data (including driving conviction data) to help calculate your insurance quote and prevent fraud
  • Checking your ‘No Claims Bonus’ entitlement and claims history
  • Prevent, detect and investigate fraud and other crime, including, by carrying out fraud checks
  • Maintaining databases of:
    • Insured vehicles (Motor Insurance Policy Database or Motor Insurance Database/MID)
    • Vehicles which are stolen or not legally permitted on the road (Vehicle Salvage & Theft Data or MIAFTR)
    • Motor, personal injury and home claims (CUE)
    • Employers’ Liability Insurance Policies (Employers’ Liability Database)
  • Managing insurance claims relating to untraced and uninsured drivers in the UK and abroad
  • Working with law enforcement to prevent uninsured vehicles being used on the roads
  • Supporting insurance claims processes.

Back to top

Fraud prevention and credit checks

We may submit your details to fraud prevention agencies and other organisations to help us prevent fraud and money laundering. We will also conduct a search with a credit reference agency to help us in providing a quote, and to check which payment options we can make available to you. This is referred to as a "soft search", which means a copy of this search will be left on your credit file but will not affect your credit score.

Any searches we make to provide a motor or home insurance quote whereby you wish to pay in instalments may involve additional credit checks via a credit reference agency, which are sometimes referred to as a "hard search". If you go on to pay by instalments, this check will be noted on your credit file and may be reflected in your credit score. You will be informed prior to this search taking place.

To assess financial and insurance risk, we obtain information held on electoral roll registers and publicly available data sources, which is provided to us by credit reference agencies and other third parties. This helps us to assess your premium at quote and renewal, for credit applications and to assist with identity checks in order to prevent money laundering.

If you apply for other financial services and/or products, a check of your details with fraud prevention agencies may be necessary. The precise nature of these processes will be explained when you apply.

Our own security procedures mean that we may occasionally have to request proof of identity or check your presence on the electoral roll.

Back to top

Use and storage of your information overseas

Your information may be transferred to, stored and processed outside of the United Kingdom (UK). AICL or our service providers may use cloud based computer systems i.e. networks, systems and remote servers to process and store your information, to which foreign law enforcement agencies may have the power to access. AICL will not transfer your information outside the UK unless it is to a country which is considered to have equivalent data protection laws or we have taken all reasonable steps to ensure the firm has suitable standards in place to protect your information.

Back to top

Keeping your information

We will keep your information only for as long as is reasonably necessary to provide our products and services to you and to fulfil our legal, regulatory, tax and accounting obligations.

We also keep your information for several years after the expiry of your policy in order to respond to any queries or concerns that may be raised at a later date with respect to the policy or handling of a claim. Please see our full Privacy notice on our website for more details.

Back to top

Amendment and retention of information

Please advise us in writing of any changes in your circumstances, or if you feel we hold inaccurate information about you so that we can update our records accordingly.

We will hold your personal information in accordance with the principles of the GDPR (and associated legislation) and for as long as reasonably necessary to fulfil the purposes for which it was collected. We may obtain your data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect of our relationship with you. We are obliged and permitted by law and regulation to retain certain types of data for a minimum period. The minimum period tends to be for seven years but can be longer (or shorter) if the statute or regulation requires.

Back to top

Data security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

Back to top

Your rights

You have a number of rights in relation to the information that AICL hold about you, including:

  • asking for access to and a copy of your personal information;
  • asking us to correct, delete or restrict the use of your personal information;
  • asking us to move, copy or transfer your personal information to a third party (known as ‘data portability’);
  • objecting to the use of your personal information or to an automated decision including profiling;
  • withdrawing any previously provided permission for us to use your personal information;
  • complaining to the Information Commissioner’s Office at any time if you object to the way AICL use your personal information.

Please note that there are times when AICL will not be able to delete your personal information, such as where we have to fulfil our legal and regulatory obligations or where there is a minimum statutory period of time for which we have to keep your information. If this is the case, then we will let you know our reasons.

To make a request for any of the rights detailed above, please contact the Data Protection Officer at: Ageas House, Hampshire Corporate Park, Templars Way, Eastleigh, Hampshire, SO53 3YA or email thedpo@ageas.co.uk.

Back to top

Updates to our privacy policy and your comments

We keep our privacy policy under regular review, and we publish the date this privacy policy was last updated. If we decide to change our privacy policy, we will update all relevant documentation and post any changes on our websites so that you are always aware of what information we collect, how we use it, and under what circumstances we disclose it. We may also notify you by email sent to the email address specified on your account.

You have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you feel your personal information has not been handled correctly. You can do this via ico.org.uk/concerns or by writing to: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

Back to top

Third-party links

This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.

Back to top