Effective Date: June 30, 2023
This Privacy Policy describes how Starr and its subsidiaries and affiliates (“Starr,” “we”, “our”, or “us”) collect, use, disclose and share personal information collected both online (e.g., from this website) and offline (e.g., in person at conferences and events or through our client service channels) (collectively, the “Services”).
Further notices highlighting certain uses we wish to make of your personal information together with the ability to opt-in or opt-out of selected uses may also be provided when we collect personal information from you.
Depending on where you are located, the controller of your personal information under this policy and the applicable law will be different. Please see here for a list of which Starr entities will be controllers in which countries. In addition to the foregoing, Starr Insurance Holdings, Inc. may also act as controller. We can confirm which processing activities are undertaken by which entity should you request this.
We may collect personal information from various sources including:
The third parties we collect personal information from may include third party companies such as credit reporting agencies, law enforcement agencies and other government entities. We may also collect personal information about you from our group companies. From time to time, we may use or augment the personal information we have about you with information obtained from other sources, such as public databases, social media platforms and other third parties. For example, we may use such third -party information to confirm contact information or to better understand your interests by associating demographic information with the information you have provided.
We automatically collect some information and data about your computer and mobile devices when you visit our website. To collect this information, we may use cookies, web beacons, and similar technologies. For more information about how we use cookies, please visit this site.
At this time, we do not respond to Do-Not-Track signals.
We may collect different types of personal information, including:
We may aggregate and/or irreversibly de-identify personal information collected in connection with the Services and use it for any purpose, including product and service development and improvement activities.
With respect to individuals located in Hong Kong and Thailand, please note that in order for us to provide our products and/or Services to you, it is mandatory that we require you to provide certain personal information, which is described to you on or before when we obtain such personal information. In the event that you do not provide such personal information, we may not be able to provide you with our products and/or Services or part thereof.
Some of the categories of personal information that we collect are sensitive personal information (also known as “special categories of personal information”). In particular, we may process data concerning your health in connection with the administration of insurance policies and any claims.
In some circumstances, we (and other insurance market participants) may need to collect and use this sensitive personal information and information relating to criminal convictions and offences. Where this is required, unless other legal grounds apply, your consent to this processing is necessary for us to provide you with the relevant Services and you hereby consent to such processing. Otherwise, we may not be able to provide you with the relevant Services or part thereof. However, you may withdraw your consent at any time (please see the “Your Rights and Choices” section of this Privacy Policy for further information about how to do this).
Starr does not sell sensitive personal information or disclose sensitive personal information to third parties to use for their own benefit.
We collect, use and disclose personal information for the purposes set out below.
With respect to individuals located in the EU/UK, Thailand and the Philippines, use of personal information must be based on one of a number of legal bases and we are required to set out the grounds in respect of each use. In the list below, we have set out the legal bases that apply to the purposes for which we use your personal information. You can find an explanation of each of these legal bases at Appendix 1 of this Privacy Policy.
As mentioned above, we may also use and share de-identified personal information for any other legitimate purposes, including product and service development and improvement activities. We base this de-identification on the ground that it is within our legitimate interests (to enable us to improve our business, products and Services).
We may share your personal information for the purposes (and the legal bases) set out above as follows:
Your personal information may be profiled to assess risk and patterns. We may make automated decisions about you based on such profiles where such decisions are required or authorized by applicable law or where necessary for the performance of a contract with you, for example for sanctions, fraud prevention and money laundering purposes.
We may use criteria such as demographics, employment status and other related factors to determine your eligibility to purchase Starr products and Services on an automated basis or without human/manual intervention by comparing such factors against those used to develop our different risk profiles. The outcome of such decision may include an effect on the rates you are charged, and may limit your ability to obtain our products and Services.
Subject to local legal requirements and limitations, you have a right to object to our use of automated decision-making or request an automated decision to be reviewed by a human being.
We (or our service providers and advertising partners) may send you direct marketing communications and information about our products and services that we consider may be of interest to you and, where required by law, we will ask for your consent at the time we collect your personal information to conduct any of these types of marketing. To the extent permitted by applicable law, we will provide an option to unsubscribe or opt-out of further communication on any electronic marketing communication sent to you or you may opt-out by contacting us as set out in the “Contact Us” section below.
Marketing profiles: Please note that we may use or augment the personal information we have about you with information obtained from other sources, such as public databases, social media platforms and other third parties to provide you with tailored marketing communications.
You have the right to opt out of such analysis of your personal information that we use to tailor the direct marketing that we send to you, at any time. You can exercise this right by contacting us as set out in the “Contact Us” section below. Please note that we also carry out digital advertising campaigns from time to time that do not rely on your personal information. Subject to any local law requirements, your opt-out will not have effect on such advertising campaign. Additionally, when you request an opt-out, it may take some time to process the request. Therefore, it is possible that you may receive marketing communications scheduled prior to our receipt of your withdrawal of consent.
If you opt -out of or do not provide your consent to receiving marketing or commercial communications, we retain the right to send you non-marketing communications such as correspondence about your relationship with us, information about transactions, or notifying you of updates to our Privacy Policy or Terms of Use.
Depending on where you reside, you may have certain rights and choices regarding our collection, usage, disclosure or processing of your personal information. These rights and choices shall include but not limited to the following:
We will verify your identity in connection with any requests regarding your personal information and take steps designed to ensure that only you ( or your authorized representative(s)) exercise rights with respect such information. If you are an authorized agent making a request, we may require and request additional information to verify you are authorized to make the request.
We endeavor to comply with your request as soon as reasonably practicable and in compliance with all applicable laws. Please note, however, that your exercise of these rights may be subject to certain conditions and exemptions and permitted by applicable law. If we reject your request, we will endeavor to notify you of the reason(s) for the rejection.
Starr does not sell personal information or disclose personal Information to third parties to use for their own benefit; however, we allow certain companies to place tracking technologies like cookies on our websites. Those companies receive information about your interaction with our websites that is associated with your browser or device and may use that data to serve you relevant ads on our websites or others. To opt-out of this practice, click here. For more information please see our Cookie Policy.
We will not restrict or deny you access to our Services because of the choices you make in connection with your personal information, but please note, certain choices may affect our ability to provide you with our Services. For example, we cannot delete all of your information if we are processing a claim on your behalf.
Please contact us using the contact details below in the “Contact Us” section if you would like to exercise any of these rights or request more information. Where required by applicable law, we will notify you if we reject your request and notify you of the reason(s) we are unable to honor your request. With respect to individuals located in the EU/UK, where we are unable to resolve an inquiry or a complaint, you have the right to contact the data protection regulator in the European country in which you are based. A list of the data protection regulators and their contact details can be found here. With respect to individuals located in the Philippines, where we are unable to resolve an inquiry or a complaint, you have the right to contact the National Privacy Commission.
With respect to individuals located in Thailand, where we are unable to resolve an inquiry, a complaint or you believe that we infringed applicable law, you have the right to contact or file a complaint to the Personal Data Protection Committee or other relevant authority.
Any personal information you provide to us may be stored and processed, transferred between and accessed from the United States (including our group companies and our external IT service providers), and other countries. However, we will handle your personal information in accordance with this Privacy Policy regardless of where your personal information is stored/accessed.
We take reasonable steps to ensure that the overseas recipients of your personal information do not breach the privacy obligations relating to your personal information. Where required by certain jurisdictions, we will transfer your personal information subject to jurisdiction-approved safeguards and in accordance with applicable law, such as standard contractual clauses. For example, if you are located in the EU/UK, we will transfer your personal information subject to approved safeguards unless we are permitted under applicable EU/UK data protection law to make such transfers without such formalities.
We maintain reasonable administrative, technical and physical safeguards designed to protect the personal information we maintain against accidental, unlawful or unauthorized destruction, loss, alteration, access, disclosure or use. However, because no security measure is 100% effective, unauthorized entry or use, hardware or software failure, and other factors may compromise the security of information about you at any time, and to the extent permitted by applicable law, we bear no liability for uses or disclosures of personal information or other data arising in connection with theft of the information or other malicious actions.
We retain personal information for the period necessary to fulfil the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by applicable law. Please note that we often need to retain certain data for recordkeeping purposes, for purposes connected with the establishment, exercise, or defense of legal claims and/or to complete any transactions that you began prior to requesting a change or deletion. In addition, there may be certain data (including personal information) that we may not allow you to review for legal, security or other reasons. We periodically delete and/or destroy retained personal data in compliance with applicable obligations to do so.
Our website may contain links to other websites operated by third parties. We make no representations or warranties in relation to the privacy practices of any third-party website and we are not responsible for the privacy policies or the content of any third-party website. Third party websites are responsible for informing you about their own privacy practices. Please check these policies before you submit any personal information to such third-party websites.
Starr does not knowingly collect personal information from children under 13 (or children under 18 or 20 where the age of majority in the relevant country is 18 or 20 years old, or children who have not reached the age of majority, as the case may be). If a parent or guardian becomes aware that his or her child has provided us with personal information without their consent, he or she should contact us at dataprotection@starrcompanies.com. If we become aware that a child under 13 (or 18 or 20, or children who have not reached the age of majority, as the case may be) has provided us with personal information, we will delete such personal information from our files.
We may change this Privacy Policy from time to time. If we do so, we will post the updated policy on our sites and will indicate when the Privacy Policy was last revised and, if required by applicable law, notify you of the changes. If we make any material changes, we will provide you with additional notice. You should periodically review our current Privacy Policy to stay informed of our personal information practices.
If you provide personal information to us regarding other individuals, you agree: (a) to inform the individual about the content of this Privacy Policy, and any other of our applicable privacy notices provided to you; and (b) to obtain any legally-required consent of personal information about the individual in accordance with this Privacy Policy, other privacy notices, and applicable law and/or regulation.
If you have any questions about this Privacy Policy, any concerns or a complaint regarding the treatment of your personal information or a possible breach of your personal information, please contact us at dataprotection@starrcompanies.com:
Starr Insurance Compliance Director
399 Park Ave
New York, NY 10022
Details of our EU Data Protection Officer are as follows:
Data Protection Officer
4th Floor, 30 Fenchurch Avenue
London, EC3M 5AD
ukgdpr@starrcompanies.com
Lawful bases under EU/UK law, the laws of Thailand and the laws of the Philippines (this only applies to individuals located within the EU/UK, Thailand and the Philippines)
1.1 The main lawful bases for our use of personal information are as follows:
California Residents
Below are the categories of Personal Information about California residents that Starr collected and disclosed for a business purpose in the past twelve (12) months. We collect these categories of personal information from the sources described in the “How We Collect Personal Information” and “Automated Collection” sections above, and for the purposes described in the “How We Use Personal Information” referenced above. Please note that our collection, use, and disclosure of your personal information will vary depending on the circumstances and nature of our interactions or relationship with you.
Disclosures: We may disclose for a business purpose each of the categories of personal information described in the table below to the following categories of other entities: advertising networks, advisors, affiliates, agents, auditors, banks, consultants, counsel, courts, government entities, law enforcement, operating systems/platforms, regulators, reinsurers, representatives, service providers, and tribunals.
Category of Personal Information & Examples | Examples | Collected | Disclosed for Business Purpose(s) |
Name, Contact Information, and Other Identifiers | Real name, alias, residential address, mailing address, phone number, date of birth, social security number, tax identification number, passport number, driver's license or state identification card number, email address, Internet Protocol address, online identifiers (e.g., usernames or handles), insurance policy number, and financial and payment information as described below. | Yes | Yes |
Account Information and Customer Records | Username, email, and password used to access a Starr account. A paper or electronic record containing personal information, as well as information, provided by a reinsurance or insurance broker/agent for underwriting purposes, and information detailed in a list of claims, including the categories of information referenced in this table. | Yes | Yes |
Financial and Payment Information | Financial or payment information used to complete a transaction, such as bank account number, payment card number, and payment history. | Yes | Yes |
Characteristics of Protected Classifications Under California Law | Age (40 years or older), race, national ancestry, national origin, citizenship, religion or creed, marital status, pregnancy, medical condition, physical or mental disability, sex, sexual orientation, and veteran or military status. | Yes | Yes |
Sensitive Personal Information including Health and Biometric Information | Criminal records, medical records and/or history (e.g., including conditions, diagnoses, genetic information, and biometric information that contains identifying information, such as measurements of physical characteristics, blood pressure, sleep, health, or exercise data). | Yes | Yes |
Audio, Video, and Other Electronic Data | Audio recordings, including phone calls, video records, and photographs. | Yes | Yes |
Usage Data / Internet Activity | Internet or other electronic network activity information regarding interactions with portals, Internet websites, applications, or advertisements, including, but not limited to, Internet Protocol address, browsing history, clickstream data, search history, and content of public posts. | Yes | Yes |
Non-Public Educational Information | Education records, that are directly related to a student and maintained by an educational institution or party acting on its behalf (e.g., grades, transcripts, class lists, schedules, student identification codes, and disciplinary records). | Yes | Yes |
Employment Information | Employment history, qualifications, credentials, licenses, disciplinary record, and participation information. | Yes | Yes |
Inferences Drawn from Other Personal Information | Inferences drawn from any of the information identified above to make a profile of a California resident, including preferences, behavior, characteristics, and attitudes | Yes | Yes |