Omnilife Privacy Notice
We are committed to protecting personal information that we receive when we provide Omnilife products and services to our policyholders. We seek to maintain transparent practices explaining how we collect, process, and share such information. Protecting your privacy is very important to us.
This privacy notice outlines how and why Omnilife Insurance Company Limited (“Omnilife”, “we”, “us”, “our”) collect personal information and how we provide our products as an insurance business.
This Privacy Notice sets out:
This privacy notice is designed to provide compliance with applicable laws in the United Kingdom and European Union, in particular, the United Kingdom’s Data Protection Act of 2018 and the General Data Protection Regulation, and the European Union’s General Data Protection Regulation.
Personal information means information, or a combination of pieces of information, that could reasonably allow an individual to be identified.
As an insurance business, we need to obtain information from and about individuals (“data subject”, “you”) to engage with them and manage their insurance policies, including life insurance, annuities, group risk and investment policies.
Most of the personal information we collect and use relates to individuals who own our policies (“policyholders”). We may also process personal information about other individuals, including the following:
In most cases we obtain personal information directly from you, mainly from the forms that you complete and provide to us and communications that we have with you.
Depending on the type of your insurance policy and circumstances related to your specific situation, we may also obtain your personal information from the following sources:
The type of personal information we collect, and process will depend upon our engagement with you and the type of an insurance policy we offer. It may include any of the below:
Depending on the type of your insurance policy, some of the categories of information we collect are special categories of personal information (sometimes referred to as “sensitive personal information”). These include:
We use your personal information:
We do not make any decisions about you solely by automated means. For the purposes of fraud prevention, detection and risk assessment we analyse personal information using software that is able to evaluate certain personal aspects about you and predict risks, however the outcomes obtained during this process are always reviewed manually.
We are committed to processing your personal information fairly and lawfully and only to the extent necessary to achieve the purposes listed above.
We must have a legal basis to process your personal information. In most cases, our ability to obtain and process your personal information is based on one of the following legal bases:
Please refer to the table at the end of this privacy notice for further details on the categories of information, the purpose of processing and the legal basis of processing.
We may share your personal information with the following parties:
You have certain rights regarding your personal information. These include the right to:
To exercise any of these rights, please complete a Data Subject Rights Request form on our parent company’s (RGA) website https://www.rgare.com/dsr-intake/insured, or using the contact details provided in section ‘Contact Us’ below.
We will respond to your request within one month of receipt. This may be extended by two further months taking into account complexity and number of requests-provided the extension is informed within the initial month. Please note that Omnilife may require additional information from you in order to honour your requests.
We are committed to working with you to obtain a fair resolution of any request, complaint or concern about privacy. If you remain unhappy with our response, you can complain directly to the Information Commissioner’s Office; to raise such complaint, please visit https://ico.org.uk/concerns/. If you reside in any country that is a member of the European Union, you can contact our EU Representative using the details contained in the ‘Contact us’ section below or complain directly to the data protection authority in the country of your residence.
We implement technical and organisational measures to ensure a level of security appropriate to the risk to the personal information we process. These measures are aimed at ensuring the on-going integrity and confidentiality of personal information. We evaluate these measures on a regular basis to ensure the security of the processing.
We will normally keep your personal information for as long as we are required to retain it to manage your insurance policy or claims for the purposes described above. In most cases we will keep your personal information for 10 years after your policy is closed. If you would like to know more about circumstances around the retention of your personal information, please contact us at the details contained in the ‘Contact us‘ section below.
If we need to transfer your personal information to other members of our group, to service providers, or to other parties located outside the United Kingdom and European Union, we will make sure that adequate safeguards are in place with those parties. We typically rely on our Binding Corporate Rules for internal data transfers among the entities of our group. In case of external data transfers to service providers, we put in place contractual commitments with suitable data protection clauses in accordance with applicable local legal requirements to ensure that your personal information is adequately protected. For more information on the appropriate safeguards in place, please contact us at the details contained in the ‘Contact us’ section below.
If you have any queries in relation to this privacy notice or the way in which your personal information has been collected, you may contact us at privacy@rgare.com or call or write to us.
Our postal address is:
Omnilife Insurance Company Limited, Level 45, 22 Bishopsgate, London, EC2N 4BQ, United Kingdom
Our telephone number is:
+44 020 7374 0123
Our EU Representative postal address is:
RGA International Reinsurance Company dac, 3rd Floor, Block C Central Park, Leopardstown, Dublin 18, D18 X5T1.
Our EU Representative telephone number is:
+353 1.290.2900 (Ireland)
If you would like to exercise a data subject right, you may use our online contact form.
Omnilife’s Data Protection Officer is Dean Scotson. Should you have any questions or concerns for our DPO regarding the way in which your personal information has been used, please contact him via email at dpo@rgare.com.
You may request a copy of this privacy notice from us using the contact details set out above. We may modify or update this privacy notice from time to time. If we make a significant change to this privacy notice, we will post a notice about this on our website and inform you directly.
Further details on the categories of information, the purpose of processing and the legal basis of processing:
Personal Data:
Categories of Information | Purpose of Processing | Legal Basis of Processing |
– Personal details – Identification information – Contact information – Financial information – Information relating to your policy and claims – Employment information – Information relating to business dealings |
– To provide our products and fulfil our contractual obligations to policyholders | – Performance of a contract with you |
– Personal details – Identification information – Contact information – Financial information – Information relating to your policy and claims |
– To review, process and manage claims | – Performance of a contract with you |
– Personal details – Financial information – Information relating to your policy and claims |
– To process payments and taxes, and return or recover money in relation to insurance policies | – Performance of a contract with you – Compliance with a legal obligation – Legitimate interests |
– Personal details – Contact information – Information relating to your policy and claims – Financial information – Information relating to your complaints or enquiries |
– To communicate with you and provide response to your complaints or enquiries | – Performance of a contract with you – Legitimate interests |
– Personal details – Contact information |
– To prevent, detect and investigate fraud and other crime | – Compliance with a legal obligation – Legitimate interests |
– Financial information – Information relating to your policy and claims |
– To carry out data analysis | – Legitimate interests |
– Personal details – Financial information – Information relating to your policy and claims |
– To manage our commercial risk | – Legitimate interests |
– Financial information – Information relating to your policy and claims |
– To manage our business operations | – Compliance with a legal obligation – Legitimate interests |
– Personal details – Financial information – Information relating to your policy and claims – Employment information – Information relating to business dealings |
– To establish, enforce and defend our legal rights | – Compliance with a legal obligation – Legitimate interests |
– Personal details – Contact information – Financial information – Information relating to your policy and claims – Employment information – Information relating to business dealings |
– To comply with applicable legal, regulatory and professional obligations | – Compliance with a legal obligation |
Information relating to business dealings | – To manage relationship with third parties | – Compliance with a legal obligation – Legitimate interests |
– Personal details – Identification information – Contact information – Financial information – Information relating to your policy and claims – Employment information Information relating to business dealings – Information relating to your complaints or enquiries |
– To buy, sell, transfer or dispose of any part of our business | – Compliance with a legal obligation – Legitimate interests |