What's on this page:
Your privacy matters to us. This Privacy Policy, which we are required to give you by law, explains what Personal Information we collect about you and how we use it, how you can contact us if you wish to exercise your rights and the procedures that we have in place to safeguard your privacy. Personal Information means any information relating to you or another living individual who is identifiable by us.
This Privacy Policy explains how we use Personal Information which we collect about individuals in relation to our products and services (including through this website, our online platform, My Account and our mobile applications).
If you have a telematics policy, you can find further details regarding how we use your Personal Information in our Telematics Terms and Conditions.
We take the security of your Personal Information very seriously. We use a combination of technical, organisational and physical security measures to protect your Personal Information in line with our obligations under data protection law. Our employees receive training to help us comply with data protection law and safeguard your privacy.
This Privacy Policy is issued on behalf of General Accident, which is a trading name of Aviva UK Digital Limited (a company within the Aviva group that operates within the United Kingdom).
Each Aviva group company that processes your Personal Information is responsible for looking after it in accordance with this Privacy Policy. Usually, where you are an individual policyholder, the Aviva group company that underwrites your insurance policy, Aviva Insurance Limited, will be the main company responsible for your Personal Information, known as the controller, and Aviva UK Digital Limited, who is responsible for the sale and distribution of the product, will be an additional controller. In other cases, your relationship with us will determine which of our group companies are the controller(s) responsible for your Personal Information.
Please check the documentation that we provide to you for details of the specific Aviva companies acting as controller(s) of your Personal Information. We may also share your Personal Information in accordance with this Privacy Policy with other companies in the Aviva group (including Wealthify Limited). For information concerning Aviva please visit the Aviva website .
When we mention "General Accident", "Aviva", "we", "us" or "our", what we mean is the relevant company in the Aviva group that processes your Personal Information. If you have any questions about this, please contact us.
We have separate privacy notices for our different types of products, so if you have a number of Aviva products you may need to review more than one privacy notice. We may also supplement this Privacy Policy with additional privacy notices tailored to our specific relationships with you where this is useful to provide you with a full picture of how we collect and use your Personal Information. This Privacy Policy supplements – but doesn’t override – them.
Most of the Personal Information we collect relates to the individual who is taking out a policy (or other individuals, where it’s taken out jointly or otherwise for the benefit of others). We may also ask for Personal Information about other individuals if we need it. For example, if you ask us to provide insurance for someone other than you, such as other household or family members.
This Privacy Policy also explains how we use Personal Information which we collect about individuals who are not customers, prospective customers, beneficiaries, or prospective beneficiaries of our products and services, but whose Personal Information we process in connection with those products and services, including third party claimants; witnesses to an incident; individuals who have caused a policyholder a loss and whom Aviva have a right to pursue in order to recover those losses; third parties driving a vehicle with a telematics device; legal representatives; general practitioners and other medical or similar professionals; expert witnesses or other expert service providers; and participants in market research.
If you provide us with Personal Information about someone else, we’ll assume that you have their permission, where required. We’ll process their Personal Information according to this Privacy Policy so please encourage them to read it if they want to find out more.
We obtain Personal Information directly from you, including from applications and claims forms that you complete, communications between us, your participation in promotions and market research, your use of our apps and websites, as well as details from the devices you use to interact with our apps and websites or a telematics device, if relevant. Where you are a joint policyholder, named driver or otherwise a beneficiary under a policy, we will also obtain Personal Information from the policyholder.
We may also receive your information from our policyholders e.g. when:
We may also obtain Personal Information from third parties, including the following:
The Personal Information we hold and process will depend on our relationship with you. If you are a policyholder or claimant claiming against one of our policyholders, we may collect detailed information about you for the purposes of managing your product and/or your claim. However, if you are an individual at a company who is providing services to us, e.g. a medical expert, the Personal Information we hold about you will be a lot more limited. We have set out some examples of the Personal Information we may hold, depending on our relationship with you below.
Information provided by you or third parties, including:
Information provided by third parties, including:
If you are a witness, third party claimant, claiming against an Aviva policyholder, or have otherwise caused the policyholder a loss, we may also collect:
Information collected from your devices, including:
Information already held by Aviva, including:
Information inferred from your Personal Information, including:
Children’s data:
Sensitive Personal Information
Sometimes we will request or receive Personal Information that is sensitive and we call this “Sensitive Personal Information”. This is information relating to your health, genetic or biometric data, sex life, sexual orientation, racial or ethnic origin, political opinions, religious or philosophical beliefs and trade union membership. It also covers criminal offence data, including information about criminal activity, allegations (including those unproven), investigations, proceedings and penalties. For example, to investigate a bodily injury claim, we’ll need to ask you to provide details of the injury. We know how sensitive this data is, so protecting it is a top priority. The types of Sensitive Personal Information we hold and process where relevant include:
The main purposes for which we use Personal Information are to:
We are committed to collecting and using Personal Information in accordance with applicable data protection laws. By law, we must have a legal justification, known as a lawful basis, in order to use your Personal Information for the purposes described in this Privacy Policy. Depending upon the purpose, our lawful basis will be one of the following:
Where we rely on legitimate interests as our lawful basis, we are required to carry out a balancing test to ensure that our interests, or those of a third party, do not override the rights and freedoms that you have as an individual. The outcome of this balancing test will determine whether we can use your Personal Information for the purposes described in this Privacy Policy. Where we rely on the lawful basis of legitimate interests, the interests being relied upon will usually be:
Our lawful bases for the use of Personal Information:
Purpose | Lawful Basis for Personal Information Processing |
---|---|
Communicating with you and others including complaints handling |
Performance of a contract Compliance with a legal obligation Legitimate interests |
Identifying individuals requiring additional support |
Compliance with a legal obligation Legitimate interests |
Evaluating your application or renewal or to provide a quote |
Performance of a contract Legitimate interests |
Provision of our products and services and administration of a policy including taking payment |
Performance of a contract Compliance with a legal obligation Legitimate interests |
Managing third party relationships |
Performance of a contract Legitimate interests |
Claims assessment and management of claims |
Performance of a contract Compliance with a legal obligation Legitimate interests |
Financial or other crime, fraud and credit checks |
Performance of a contract Compliance with a legal obligation Legitimate interests |
Compliance with legal or regulatory obligations | Compliance with a legal obligation |
Establish, enforce or defend legal rights |
Compliance with a legal obligation Legitimate interests |
Improving quality, training and security | Legitimate interests |
Managing our business operations e.g. accounts, financial analysis, internal audit |
Compliance with a legal obligation Legitimate interests |
Profiling and data analysis (including modelling) | Legitimate interests |
Applying for or claiming on our insurance | Legitimate interests |
Marketing and customer insight analysis, campaign planning etc. |
Legitimate interests Consent |
Marketing in accordance with your preferences |
Legitimate interests Consent |
Buy, sell, transfer or dispose of our business |
Compliance with a legal obligation Legitimate interests |
Archiving, research or statistical purposes | Legitimate interests |
We can only collect and use Sensitive Personal Information where we have an additional, specific lawful basis to process such information. We usually rely upon one of the following lawful bases where we process Sensitive Personal Information:
Our lawful bases for the use of Sensitive Personal Information:
Purpose | Lawful Basis for Sensitive Personal Information Processing |
---|---|
Communicating with you and others including complaints handling |
Necessary for insurance purposes Legal claims Necessary for safeguarding economic well-being of certain individuals |
Identifying individuals requiring additional support |
Necessary for safeguarding economic well-being of certain individuals Necessary for the equality of opportunity or treatment Explicit consent |
Evaluating your application or renewal or to provide a quote | Necessary for insurance purposes |
Providing and administrating a policy, including taking payment | Necessary for insurance purposes |
Managing third party relationships | Necessary for insurance purposes |
Claims assessment and management of claims |
Necessary for insurance purposes Legal claims Vital interests |
Identifying or investigating financial or other crime and fraud |
Necessary for insurance purposes Legal claims Regulatory requirement relating to unlawful acts or dishonesty Clearly or obviously made public by you Prevent or detect crime Prevent fraud |
Compliance with legal or regulatory obligations |
Necessary for insurance purposes Legal claims Regulatory requirement relating to unlawful acts or dishonesty |
Establishing, enforcing or defending legal rights | Legal claims |
Improving quality, training and security | Legal claims |
Managing our business operations, e.g. accounts, financial analysis, internal audit | Legal claims |
Profiling and data analysis (including modelling) | Necessary for insurance purposes |
Applying for or claiming on our insurance |
Necessary for insurance purposes Legal claims |
Buying, selling, transferring or disposing of our business |
Necessary for insurance purposes Legal claims |
Archiving, research or statistical analysis | Necessary for archiving, research or statistical analysis |
Where we cannot rely on one of the above lawful bases to process your Sensitive Personal Information for a particular purpose, we will seek your explicit consent.
If you would like to know more about the lawful bases we rely upon, or how the lawful basis of legitimate interests applies to a particular purpose, you can contact us.
In connection with the purposes set out above, we will sometimes share Personal Information with Aviva group companies and third parties, including:
Some of the organisations we share information with may be located outside of the UK. For further information, please see the section on International Data Transfers.
We use your Personal Information and Personal Information about other individuals associated with your policy, to detect and prevent fraud and other financial crime, including to meet our statutory and regulatory responsibilities in relation to fraud and financial crime.
If you’re making an application or a claim, we may use profiling and other forms of automated processing to assess the probability that your application or claim may be fraudulent. This assessment may involve the use of Sensitive Personal Information. For example, we may use your past motoring convictions for motoring insurance. See Automated Decision Making for further details.
We may also use your Personal Information including details of our interactions with you to help us detect fraud committed by brokers or financial advisers or to identify where you or a third party may be at risk of fraud or other financial crime.
To prevent, detect and investigate fraud and financial crime, we:
This will help us verify your identity, make decisions about providing you with our products and related services such as paying claims and trace debtors or beneficiaries.
If you give us false or inaccurate information and we suspect fraud, we’ll record this to prevent further fraud and money laundering. This may be shared between insurers and with fraud prevention agencies and databases.
We can supply on request further details of the agencies and databases we access or contribute to and how this information may be used. If you require further details, please contact us.
For details relating to information held about you by the DVLA please visit http://dvla.gov.uk/
How your Personal Information is used and shared by insurers and databases in relation to motor insurance
The Personal Information you provide will be used by us and shared with other insurers as well as certain statutory and other authorised bodies for:
Insurance underwriting purposes, i.e. to examine the potential risk in relation to your (and/or a third party’s) prospective policy so that we can:
Management Information purposes, to analyse insurance and other markets for the purposes of:
Anti-fraud purposes, to detect and prevent fraudulent claims and/or activities by:
Compliance with legal obligations and responsibilities, including:
Information about your insurance policy will be added to the Motor Insurance Database (MID) managed by the MIB. MID and the data stored on it may be used by certain statutory and/or authorised bodies including the police, the DVLA, the DVA, the Insurance Fraud Bureau and other bodies permitted by law. This information may be used for purposes permitted by law, which include:
If you are involved in a road traffic accident (either in the UK, the European Economic Area or certain other territories), insurers and/or the MIB may search the MID to obtain relevant information.
Individuals who may be citizens of other countries or their appointed representatives making a claim in respect of a road traffic accident may also obtain relevant information which is held on the MID. It is vital that the MID holds your current registration number. If it is incorrectly shown on the MID you are at risk of having your vehicle seized by the police and/or a fixed penalty notice.
You can check that your current registration number details are shown on the MID at www.askmid.com.
How your Personal Information will be processed
You can ask for more information about this. If you require such information, please contact us.
How we use your Driving Licence Number
We collect your Driving License Number (DNL) for insurance underwriting purposes, i.e. to examine the potential risk in relation to your (and/or a third party’s) prospective policy so that we can:
Please note that if you give us false or inaccurate information it may invalidate your insurance policy/prospective insurance policy or it could affect the amount we pay to settle any claims you make under the policy.
We or our agents may:
We use data from a credit reference agency to verify your identity, prevent fraud and carry out risk profiling which allows us to calculate your premium and payment options. We may need to obtain information relating to you at quotation, renewal and in certain circumstances where policy amendments are requested.
As part of our regulatory obligations, before we offer you your payment options, we will carry out an affordability assessment. We do this using information from a credit reference agency including an over-indebtedness score and some of the underlying data used to calculate this score. The credit reference agency calculates your over-indebtedness score using information it holds about your existing credit commitments and modelled information relating to income and living expenses. We will use your over-indebtedness score to help assess whether additional credit could cause you financial harm. We will do this when you request a quote and at renewal so that we can decide whether to offer you a monthly credit payment option.
The quotation and affordability searches will appear on your credit report and will be visible to other credit providers. It will be clear it is part of a quote and not a credit application by you. Where you agree to pay monthly under an Aviva credit agreement, the status of your quote search will be updated to reflect your credit application and this will be visible to other credit providers.
In order to carry out these searches we will supply your Personal Information to credit reference agencies and they will give us information about you, such as about your financial history. We do this to assess creditworthiness (including affordability) and product suitability, check your identity, manage your account, trace and recover debts and prevent criminal activity. We will also continue to exchange information about you with credit reference agencies on an ongoing basis, including about your settled accounts and any debts not fully repaid on time. Credit reference agencies will share your information with other organisations. Your Personal Information will also be linked to the data of your spouse, any joint applicants or other financial associates.
Where you are a named driver a policy, in order to ensure we have the necessary facts to assess your insurance risk, verify your identity, help prevent fraud and provide our best premium and payment options, we may need to obtain information relating to you at quotation, renewal and in certain circumstances where policy amendments are requested. We or our agents may undertake checks against publicly available information (e.g. electoral roll, county court judgments, bankruptcy orders or repossession(s)).
The credit reference agency we use for this search is TransUnion. More information about the ways in which TransUnion uses and shares Personal Information can be found on the TransUnion website.
We use automated processes to make decisions. These automated processes use data provided by you, other records we hold about you in our systems and data sourced from third parties to make predictions, including the likelihood that a claim will be made and its value, the likelihood a product will be purchased and the likelihood that a claim might be fraudulent. This helps us to determine eligibility for a policy, the terms of the policy, the price, and whether we can provide you with a monthly credit payment option.
In order to provide you with a price for your insurance policy, the following steps are taken:
Your personalised price may be presented to you in suitable marketing communications, including those sent from price comparison websites or third party partners with whom you have a relationship.
We also make automated decisions throughout the life of your policy, e.g. before offering you a renewal or when dealing with a claim.
Where we make an automated decision using Personal Information which has a legal or substantially similar effect, you have certain rights in relation to that decision. In particular, you have the right to receive meaningful information about the logic involved in relation to the decision, the right to human intervention and the right to obtain an explanation of the decision and challenge it. For more information about this right and how to exercise it please see Data Rights.
We process Personal Information to perform profiling and data analysis to build, train and audit insurance and third party models and algorithms (including those used in our Automated Decision Making).
We also use artificial intelligence and machine learning technologies. Artificial intelligence is a machine’s ability to perform tasks we associate with humans. For example, problem solving, learning and decision making. Machine learning is a type of artificial intelligence that teaches machines to learn and interpret from information and then provide a response. One type of artificial intelligence that we use is natural language processing. Natural language processing involves reading, understanding and analysing speech and text. We may use this to help us with the purposes listed below.
The models, algorithms, and tools we use do a number of things including:
To carry out these purposes we may combine your Personal Information with information relating to other customers, potential customers and/or data provided by third parties. We may also use the Personal Information you submitted to obtain a quote from us for this analysis whether or not you decided to purchase the product.
We use a number of data items as described in this Privacy Policy for these purposes. Before we use any such data, we carry out a number of checks including ensuring there are no legal restrictions on using the data under data protection laws, the Equality Act 2010 or under FCA rules and we consider whether use of the data might cause outcomes that are unfairly or unlawfully biased. We then use statistical modelling techniques to assess the data to ensure that the data tells us something meaningful. From time to time, we may share your Personal Information with third parties who provide us with new data which we will test to understand if such new data provides additional understanding.
Where possible, we pseudonymise the Personal Information in order to perform this analysis. This means that we remove information from which you can be directly identified, e.g. your name, and replace it with a pseudonym or unique identifier. We do this to maximise the security of your information.
We keep Personal Information for as long as is reasonably required for the purposes explained in this Privacy Policy. We also keep records - which may include Personal Information - to meet legal, regulatory, tax or accounting needs. For example, we are required to retain an accurate record of your dealings with us, so we can respond to any complaints or challenges you or others might raise later. We’ll also retain files if we reasonably believe there is a prospect of litigation. The specific retention period for your Personal Information will depend on your relationship with us and the reasons we hold your Personal Information.
To support us in managing how long we hold your data and our record management, we maintain a data retention policy which includes clear guidelines on data retention and deletion.
If you would like more information about our data retention policy, please contact us.
Sometimes we, or third parties acting on our behalf, may need to transfer Personal Information outside of the UK. We’ll always take steps to ensure that any transfer of Personal Information outside the UK is carefully managed to protect your privacy rights and ensure that adequate safeguards are in place. This might include transfers to countries that the UK considers will provide adequate levels of data protection for your Personal Information (such as countries in the European Economic Area) or putting contractual obligations in place with the party we are sending information to. Transfers within the Aviva group will be covered by an agreement entered into by members of the Aviva group (an intra-group agreement) which contractually obliges each group company to ensure that your Personal Information receives an adequate and consistent level of protection wherever it is transferred within the group.
For more information about data transfers and the safeguards we have put in place, please contact us.
We may use Personal Information to send you direct marketing communications about our products and services that we feel you’ll be interested in. This may include marketing relating to products offered by other brands or companies within the Aviva group (such as Wealthify and Succession Wealth) as well as communications about promotions and prize draws.
Marketing communications may be sent by email, post, SMS, telephone and push notification. You may also see display advertising on websites, mobile applications, social media, television or in online search results.
You have control over our use of your Personal Information in relation to marketing communications. You can:
Please note that opting out of one type of marketing, e.g. by email or telephone, doesn’t mean you will be opted out of all marketing. Bear this in mind when you manage your preferences. You can always contact us directly if you would like us to stop all forms of direct marketing.
We try to limit marketing and only send you offers and promotions that you might be interested in, based on Personal Information we have about you and profiling that we have carried out (further details can be found under the sub-heading ‘Marketing profiles’ below). We may use information provided by third parties to send you direct marketing and we may use your Personal Information to send other people direct marketing, e.g. people you live with.
Please remember that if you opt out of receiving marketing, we will still send you communications relating to your products. If you choose to opt out of tailored offers and advertising, you may still see generic advertising displayed online and in My Account, it just might not be as relevant to you.
Cookies and similar technologies
We rely on third-party advertising technology (such as the deployment of cookies or small text files on our website or pixels within emails) to collect information about you. This technology is used to optimise what you may see on our websites and deliver content when you are browsing elsewhere. We may also collect information about your use of other websites. We do this to provide you with advertising that we believe may be relevant for you, as well as to improve our own products and services.
For further information about cookies and other technologies we use on our website and how to manage cookies, please see our Cookie Policy.
Social media and online platforms
We share Personal Information with media agencies and social media and other online platforms to help us target our online marketing. Social media and other online platforms may also use Personal Information they hold and combine it with Personal Information received from us to create target audiences. These are audiences that we think would be interested in our online advertising. This may involve social media and other online platforms building a ‘lookalike’ profile of the type of person we are trying to target and providing specific adverts to those people when they browse the internet or use social media.
If we use or share Personal Information with third parties in order to send you direct marketing, we will respect the marketing preferences you have set. We recommend you routinely review the privacy notices and preference settings that are available to you in My Account and any online platforms and smart devices you use as they will dictate how adverts and other messages are displayed and shared across those platforms.
Marketing profiles
We use automated processes to help us provide more personalised marketing of our products. To do this, our automated process creates a marketing profile for you using information such as:
Our process analyses this data to determine the most relevant products, services, offers or benefits to offer you and to decide the appropriate time and channel for offering them to you.
Information obtained in relation to one product may be used in relation to marketing other products from the Aviva group.
We may also create profiles using your Personal Information together with information relating to other individuals, we use these profiles to decide what marketing may be of interest to individuals with similar characteristics to you.
Promotions and prize draws
We occasionally run promotions and prize draws for our customers and third parties. Our communications to you about these promotions before you enter them are marketing. If you opt out of receiving direct marketing, you will not receive communications about promotions and prize draws.
We may use your Personal Information to select you as a winner, inform you of promotion outcomes and send prizes to your nominated address. We may use third party fulfilment partners to assist us in administering promotions, including contacting you on our behalf. In accordance with the rules of the Advertising Standards Authority, we may publish or make publicly available information that indicates that a valid award has taken place. If we do this, only your surname, country and, if applicable, your winning entry, will be published. You have the right to object to this use of your Personal Information.
You have legal rights under data protection laws in relation to your Personal Information. Read below to learn more about each right you may have.
We may ask you for proof of identity when you make a request to exercise any of these rights. We do this to ensure we only disclose information to the right individual.
We aim to respond to all valid requests within one month. It may take us longer if the request is particularly complicated or you have made several requests. We’ll always let you know if we think a response will take longer than one month. We may also ask you to provide more detail about what you want to receive or are concerned about.
We may not always be able to do what you have asked. This is because your rights will not always apply, e.g. if it would impact the duty of confidentiality we owe to others, or if the law allows us to deal with the request in a different way. We will always explain to you how we are dealing with your request. In some circumstances (such as the right to erasure or withdrawal of consent), exercising a right might mean that we can no longer provide our product to you.
For further information about or to exercise any of your rights, please contact us.
Your rights are as follows:
Access to your Personal Information
You may ask us for a copy of your Personal Information together with specified details about how we use your information. This is commonly known as a 'subject access request'.
If you wish to make a subject access request, please fill out this form or write to us using the details in the Contacting Us section.
If your request is made electronically, we will, where possible, respond to you electronically. Otherwise, we will normally respond in writing unless you request otherwise.
Rectification of your Personal Information
We do our best to ensure that your Personal Information is accurate and kept up to date. If you believe your information is inaccurate or incomplete, then please contact us to request that we amend or update it.
Erasing your Personal Information
You may ask us to erase your Personal Information, but this right only applies in certain circumstances, e.g. where:
This isn’t an absolute right and we have to balance your request against other factors such as legal or regulatory requirements, which may mean we cannot erase your Personal Information.
Restricting processing of your Personal Information
You may ask us to stop using your Personal Information in certain circumstances such as:
This isn’t an absolute right and we may not be able to comply with your request.
Data portability
In some cases, you can ask us to transfer Personal Information that you have provided to us to another third party of your choice. This right only applies where:
Right to object
You can object if you no longer wish to receive direct marketing from us. Please see Marketing for further information.
You may also object where you have grounds relating to your particular situation and the lawful basis we rely on for using your Personal Information is our (or a third party's) legitimate interests. However, we may continue to use your Personal Information where there are compelling legitimate grounds to do so.
Automated decision making and profiling
You have the right not to be subject to a decision using your Personal Information which is based solely on automated processing (without human involvement) where that decision produces a legal effect or otherwise significantly affects you. This right does not apply if the decision is:
You do however have a right to request human intervention, express your view and challenge the decision.
Withdrawing consent
In some circumstances we ask for your consent to use your Personal Information. You are free to withdraw your consent at any time.
If it is the case that we need your consent to provide you with a particular product and you wish to withdraw your consent, we may no longer be able to provide our product to you. Where that is the case, we will inform you before taking any action.
If you have any questions about this Privacy Policy or how to exercise your rights, please contact our Data Protection Officer:
Write to: The Data Protection Team, Aviva, PO Box 7684, Pitheavlis, Perth PH2 1JR
Email us: DATAPRT@aviva.com
If you'd like to submit a subject access request, please fill out this form or write to us at the above address.
If you’re not happy with the way we’re handling your Personal Information, you have a right to make a complaint with your local data protection supervisory authority at any time. In the UK this is the Information Commissioner's Office (ICO). We ask that you please attempt to resolve any issues with us before contacting the ICO.
This Privacy Policy is updated from time to time to take account of changes in our business activities, legal requirements and to make sure it’s as transparent as possible, so please check back here for the current version. You can see when this Privacy Policy was last updated by checking at the bottom of this page.
Updated: 27/09/2023