Custodian Financial Services Limited Privacy Policy

Effective date: 01/06/2023

  1. Introduction

Welcome to Custodian Financial Services Limited’s (trading as Custodian) Privacy Policy. Custodian (“us”, “we”, or “our”) (Firm Reference Number 992062) is an appointed representative of Bluefriars Brokers Limited which is authorised and regulated by the Financial Conduct Authority in the UK under Firm Reference Number 604987.

This Privacy Policy applies where you have obtained a quote, incept, renew or amend a policy or make a claim/complaint or otherwise access or use our Insurance Services via the technical service hosted and maintained by us on our cloud services, including via https://www.custodian.club, the Custodian mobile application (“Custodian Platform”), via telephone, post or email.

This Privacy Policy explains how we collect, use and safeguard  your personal data in connection with your use of the Insurance Services. It will also tell you about your privacy rights and how the law protects you.

Custodian is the Data Controller and is responsible for your Personal Data.

Unless otherwise defined in this Privacy Policy, the terms used in this Privacy Policy have the same meanings as in our Terms and Conditions.

We respect your privacy and are committed to protecting your Personal Data.

If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact us using the details set out below.

  1. Definitions

In addition to the terms defined above, the following terms shall have the following meanings when used in this Privacy Policy.

COOKIES are small files stored on your device (computer or mobile device).

DATA CONTROLLER means a natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any Personal Data is or is to be, processed.

EXTERNAL THIRD PARTIES includes:

  1. Other companies within our group of companies – this includes Collectors Club Ltd and other companies within our group from time to time.
  2. Service providers acting as processors who provide the Insurance Service or any part of it on our behalf, perform Insurance Service-related services or assist us in analysing how our Service is used.

These third parties include Google Analytics, GitHub (a development platform to host and review code, manage projects, and build software), Lexis Nexis, payment processor Stripe, and other third parties from time to time which allow us to directly improve the Insurance Service and the Custodian Platform for our users.

  1. Behavioural remarketing providers.
  2. Professional advisers acting as processors or joint controllers including lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, insurance and accounting services.
  3. HM Revenue & Customs, the Financial Conduct Authority, and other regulators and authorities based in the United Kingdom who require reporting of processing activities in certain circumstances.
  4. Insurance market participants. Insurance involves the use and disclosure of your Personal Data by various insurance market participants.
  5. Our Principal (Bluefriars Brokers Limited, which is authorised and regulated by the Financial Conduct Authority (No.604987)), your insurance broker (where applicable), service providers, sub-contractors and agents; and
  6. Our distribution partners, which includes any company that distributes, advertises or recommends insurance policies on our behalf.  

PERSONAL DATA means data about a living individual who can be identified from that data (or from those and other information either in our possession or likely to come into our possession).

  1. Information Collection and Use

For Custodian to provide insurance quotes, insurance policies and/or deal with any claims or complaints, we may need to collect, retain and process certain Personal Data about you as set out below.

We collect several different types of information for various purposes to provide and improve our Service to you.

  1. Types of Data Collected

We may collect, use, store and transfer different kinds of Personal Data about you while arranging insurance cover for you or managing a claim. We have grouped the Personal Data together as follows:

If you fail to provide Personal Data

Where we need to collect Personal Data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you. In this case, we may have to cancel a product or service you have with us, but we will notify you if this is the case at the time.

  1. How Is Your Personal Data Collected?

We use different methods to collect data from and about you including through:

Our Policy on “Do Not Track” Signals:

We honour Do Not Track signals and do not track, plant cookies, or use advertising when a Do Not Track browser mechanism is in place. Do Not Track is a preference you can set in your web browser to inform websites that you do not want to be tracked.

You can enable or disable Do Not Track by visiting the Preferences or Settings page of your web browser.    

  1. Use of Data

We will only use your Personal Data when the law allows us to. Most commonly, we will use your Personal Data in the following circumstances:

  1. Where we need to perform the contract we are about to enter into or have entered into with you or where you’ve given consent to us using that data for the purposes of (b). This includes:  
  1. Assessing your application for an insurance policy with us including assessing the risk and the price;
  2. Providing you with an insurance policy and to help us assess the risk where you have given us access to the App Data;
  3. Communicating with you in respect of the insurance policy and other Insurance Services that we offer and keeping you up to date with information in respect of your insurance policy;
  4. Sharing information with those who help us provide our Insurance Services;
  5. Managing our relationship with you;
  6. Adjusting insurer net and gross premiums based on agreed rating concessions in our broker system;
  7. Setting broker acceptance and decline criteria based on customer and vehicle attributes;
  8. Setting retail pricing, including brokerage commission and fees based on customer and vehicle attributes; and
  9. Supporting you and insurer(s) with claims reporting.
  1. Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests. This includes:
  1. Monitoring our relationship with you to continually develop and improve our Insurance Services and the Custodian Platform;
  2. Our internal business purposes, such as management of our products and audit purposes;
  3. Working with our group companies to allow you to store and keep information about your insurance with us on the Custodian Platform allowing you to keep all information in one place;
  4. providing personalised content and information to you/marketing to you about other Insurance Services we offer.
  1. Where we need to comply with a legal obligation. This includes:
  1. Complying with our obligations pursuant to the law and to the financial services regulations to which we are subject. It may also include obligations to other regulators and to HMRC.
  1. Necessary for a public interest. This includes where we need to use your Special Category Data for the purpose of putting in place an insurance policy.
  2. For any other purpose where we have obtained your consent.

Promotional offers from us

We may use your Personal Data to contact you with insurance-related newsletters, marketing or promotional materials and other information that may be of interest to you. You may opt out of receiving any, or all, of these communications from us by following the unsubscribe link or by emailing at insurance@custodian.club.

Third-party marketing

Your Personal Data will never be sold on to external parties or organisations for marketing purposes.

We will get your express opt-in consent before we share your Personal Data with any third party for marketing purposes (including other companies within our group). We require all third parties to respect the security of your Personal Data and to treat it in accordance with the law.  

Opting out

You can ask us or third parties to stop sending you marketing messages at any time by logging into the website and checking or unchecking relevant boxes to adjust your marketing preferences OR by following the opt-out links on any marketing message sent to you OR by contacting us at any time.

Change of purpose

We will only use your Personal Data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.

If we need to use your Personal Data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.

Please note that we may process your Personal Data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

  1. Retention of Data

We will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy.

We will only retain your Personal Data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements.  

We will also retain Technical Data for internal analysis purposes. Technical Data is generally retained for a shorter period, except when this data is used to strengthen the security or to improve the functionality of our Service, or we are legally obligated to retain this data for longer time periods.

We may retain your Personal Data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

To determine the appropriate retention period for Personal Data, we consider the amount, nature and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.

  1. Transfer of Data

Many of our External Third Parties are based outside the UK so their processing of your Personal Data will involve a transfer of data outside the UK.

Whenever we transfer your Personal Data out of the UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

  1. We will only transfer your Personal Data to countries that have been deemed to provide an adequate level of protection for Personal Data.
  2. Where we use certain service providers, we may use specific contracts approved for use in the UK which give Personal Data the same protection it has in the UK.

Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

Please contact us if you want further information on the specific mechanism used by us when transferring your Personal Data out of the UK.

  1. Disclosure of Data

We may disclose personal information that we collect, or you provide, to:

  1. External Third Parties (as defined in the Definitions section) for the purposes set out below.

Companies within our group: We share your Personal Data with our group companies  so that we can provide information to you about other services we offer that may be of benefit to you, to allow you to store and view your documents in one place and to provide you with a seamless experience when you use a Custodian product (whether an Insurance Service or a product offered by one of our group companies).

Service providers acting as processors who provide the Insurance Service or any part of it on our behalf, perform Insurance Service-related services or assist us in analysing how our Service is used: These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

Behavioural remarketing providers. Collectors Club Ltd (trading as 'Custodian') uses remarketing services to advertise on third party websites to you after you visited the Custodian Platform. We and our third-party vendors use cookies to inform, optimise and serve ads based on your past visits to our Service. Vendors include Google Ads (AdWords), YouTube and Meta.

Professional advisers: who provide consultancy, banking, legal, insurance and accounting services.

HM Revenue & Customs, the Financial Conduct Authority, and other regulators and authorities based in the United Kingdom: for the purpose of complying with reporting obligations.

Insurance market participants: Insurance involves the use and disclosure of your Personal Data by various insurance market participants. We will only share your Personal Data with other insurance market participants if it’s required for a specific purpose and we have a lawful basis to do so.

Our Principal (Bluefriars Brokers Limited, which is authorised and regulated by the Financial Conduct Authority (No.604987)), your insurance broker (where applicable), service providers, sub-contractors and agents: we share you Personal Data with them  in order to administer your account and the products and services provided to you by us now or in the future, including but not limited to our payment processors and electronic documentation providers; and

Our distribution partners, which includes any company that distributes, advertises or recommends insurance policies on our behalf: we share your Personal Data with them so that they can distribute insurance policies on our behalf.  

  1. Disclosure for Law Enforcement.

Under certain circumstances, we may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities. We are legally required to have certain processes in place with regards to anti-bribery and corruption, money laundering and fraud. If any criminal offence is detected or suspected, we may share data with financial and regulatory organisations (e.g. the Financial Conduct Authority, the Information Commissioner’s Office) or law enforcement agencies (e.g. fraud prevention agencies, anti-money laundering agencies and courts) to assist them

  1. Business Transaction.

If we or our subsidiaries are involved in a merger, acquisition or asset sale, your Personal Data may be transferred.

  1. Security of Data

We are committed to ensuring that your information is secure. All Personal Data provided to us is stored on secure servers and only accessed and used in line with our data protection policies and procedures. Your Personal Data will be accessed by our employees or authorised third parties who require the information for their business purposes.

No method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

  1. Your Data Protection Rights Under General Data Protection Regulation (GDPR)

Under certain circumstances, you have rights under data protection laws in relation to your Personal Data. If you'd like to learn more about your rights, please see the website of the Information Commissioner's Office.

You generally have the following rights, which you can usually exercise free of charge:

If you have provided us with a consent to use your Personal Data, you have a right to withdraw that consent easily at any time. Withdrawing a consent will not affect the lawfulness of our use of your Personal Data in reliance on that consent before it was withdrawn.

If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

If you wish to exercise any of the rights set out above or have any other queries or concerns, please don't hesitate to contact us at dpo@custodian.club.

No fee usually required

You will not have to pay a fee to access your Personal Data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.

What we may need from you

We may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Data (or to exercise any of your other rights). This is a security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

Time limit to respond

We try to respond to all legitimate requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

  1. Links to Other Sites

Our Service may contain links to other sites that are not operated by us. If you click a third party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.

This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the Privacy Policy of every website you visit.

  1. Children's Privacy

Our Services are not intended for use by children under the age of 17 (“Children”).

We do not knowingly collect personally identifiable information from Children under 17. If you become aware that a Child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from Children without verification of parental consent, we take steps to remove that information from our servers.

  1. Changes to This Privacy Policy

We keep our Privacy Policy under regular review. This version was last updated on 01/06/2023.

We will notify you of any changes by posting the new Privacy Policy on this page. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

It is important that the Personal Data we hold about you is accurate and current. Please keep us informed if your Personal Data changes during your relationship with us.

  1. Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us in the following ways:

Full name of legal entity: Custodian Financial Services Limited

Email address: dpo@custodian.club

Postal address: FAO: DPO, Custodian Financial Services Limited,  Palliser House, Palliser Road, London, England, W14 9EQ  

You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK regulator for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.

Version 0.1 - June 2023