Get a Quote

Privacy

We think it is important for all our members to be made aware of what information William Russell holds about them, and to be reassured that we’ll process their personal information fairly and securely. This privacy policy explains how we use any personal information we collect about you when using, or enquiring about, our products and services.

William Russell Data Privacy Policy

William Russell includes William Russell Limited, William Russell Europe SRL and the UK branch of William Russell Europe SRL. William Russell respects your privacy and commits to protecting your personal data. For the purposes of this policy, references to “we” or “us” refer to William Russell, and references to “you” or “your” mean the data subject, including your named dependents. This Policy explains what data we collect, how we use it, and your rights under applicable data protection laws.

This data privacy notice is for the attention of all individuals aged 18 and over who share, or authorise a third party to share, their personal data with us, or consent to us processing their data in the future.

Who are we?

William Russell acts as the data controller of your personal data and complies with the relevant data protection law. When William Russell provides policy administration services such as underwriting, claims and complaints handling under delegated authority with its insurers, we act as a joint controller of your personal data. Both William Russell and your insurer independently comply with the relevant data protection law when processing your personal data.

  • William Russell Limited operates as a general insurance intermediary authorised and regulated by the Financial Conduct Authority in the UK.
  • William Russell Europe SRL operates as a mandated underwriter authorised and regulated by the Financial Services and Markets Authority in Belgium.
  • William Russell Europe SRL established a Third Country Branch in the UK authorised and regulated by the Financial Conduct Authority in the UK.

For existing and prospective customers

William Russell administers your policy, but depending on your policy and your location, one of the following insurers insures your policy. Your Plan Agreement confirms this. Your insurer acts as a data controller for the personal data it processes about you.

You can view your insurer’s full data privacy policy here:

1/ Our data privacy principles

At William Russell, we handle personal data responsibly. We adhere to the following principles:

  • Lawfulness, fairness and transparency: We process your data in accordance with the law, and we aim to be open and transparent about how and why we use it.
  • Purpose limitation: We collect data only for specified, explicit and legitimate purposes and do not use it in ways incompatible with those purposes.
  • Data minimisation: We collect only the personal data necessary to provide our services and fulfil our contractual and legal obligations.
  • Accuracy: We take reasonable steps to ensure your data is accurate, complete, and up to date.
  • Storage limitation: We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law.
  • Integrity and confidentiality: We implement technical and organisational measures to protect personal data against unauthorised access, loss or destruction.
  • Accountability: We are responsible for and demonstrate compliance with these principles. Where we act as joint controllers, we ensure that responsibilities are clearly defined among the entities involved.

2/ How we collect your information

We collect data about you in several ways. The main way we collect your data is directly from you. This may be via enquiry or application forms, claims forms, verbally over the telephone or via email. We may also collect data about you and other members on your policy from other members, your employer (if enrolled on a Group policy), your medical practitioners, your insurance adviser (if appointed), and other third parties involved in arranging and administering your policy.

The following is a non-exhaustive list of ways that we may collect your personal information:

  • Via online enquiry or registration forms.
  • Via surveys, feedback forms or other similar forums.
  • When you obtain a quote for any of our policies or services.
  • When you submit an application for any of our policies or services.
  • When you are nominated as a beneficiary for any of our protection insurance policies.
  • During the administration and performance of your contract of insurance with us, including the pre-authorisation, submission and assessment of claims.
  • Via third parties such as employers, medical providers, third parties assisting us with claims management or authorised family members.
  • Via telephone, email, SMS, WhatsApp or any other form of correspondence.
  • Via cookies (please see section 12 of this policy).

3/ What information do we collect?

The information we collect about you depends on your relationship with us and the product or service that we have provided to you, or you (or someone on your behalf) are enquiring about us providing to you.

Depending on the product or service we may request or receive both personal data and special categories of personal data, such as your health and medical information. We may require this information in order to assess your application for a policy with us and/or for processing claims under an existing policy. The information we collect, and when we collect it, will depend on our relationship with you.

We may collect the following personal data:

  • Identity data: such as your name, date of birth, gender, nationality and country of residence.
  • Contact data: such as your email address, telephone number and postal address.
  • Financial data: such as your bank account details and payment information.
  • Technical data: such as your IP address, browser type and device information.
  • Usage data: such as your interactions with our website, services and communications.

We may also collect the following Health and Insurance related data (Special Category Data):

  • Health data: such as your medical history, lifestyle information (e.g. smoking, alcohol consumption), medications, symptoms and diagnoses.
  • Occupation and Employment data: such as your job title, occupation, industry, duties and income.
  • Insurance history: such as your previous policies, claims history and underwriting information.

4/ How we use your data

We mainly use your personal data to provide and administer our insurance policies. Depending on the products or services you use, we use your personal data for the following purposes:

4.1 Service delivery

We use your personal data to assess eligibility for our products and services and underwrite our insurance policies. We also use your personal data to calculate your premiums and process your claims. When administering your insurance policy or services, we use your personal data to communicate with you about your policy, account or claim.

In the event of a claim, we may provide your personal data, including medical information, to those involved in your treatment or care, or to your representative (if you have chosen one). We do this confidentially. Unless you specifically instruct us otherwise, we address correspondence about all claims (including those made by dependents) to the plan holder. An insured dependent over the age of 16 has the right to confidentiality regarding their claims and medical information. To exercise this right, they should contact member services.

4.2 Marketing and communication

We may use your personal data to send service-related updates, policy information or offers (with your consent where required), or to tailor information and offers to your interests.

4.3 Management information and analytics

We may process your personal data for the purposes of monitoring and improving the performance of our services, analyse trends, customer behaviour and service usage, to support business planning and decision-making, and/or to identify opportunities to improve customer experience and product offerings.

4.4 Fraud prevention and investigation

Where necessary, we may use your personal data to detect and prevent fraudulent activity, financial crime, or misuse of services. We may also use your personal data to investigate and respond to suspected or actual breaches of law, contracts or policy terms.

4.5 Legal and regulatory compliance

We may process your personal data to comply with laws and regulations applicable to insurance and financial services, and/or to provide information to regulators, auditors or law enforcement when required.

Activity/purpose

Data used (not exhaustive)

Legal basis for processing

Notes on Health/Special category data

Policy eligibility assessment
Identity
Contact
Occupation
Health
Lifestyle
Contractual necessity: necessary to provide your insurance policy
Health data relies on your explicit consent
Premium calculation
Identity
Financial
Health
Occupation
Nationality
Country of residence
Contractual necessity: necessary to calculate the correct risk premium
Health data relies on your explicit consent
Claims management
Identity
Contact
Health
Claims history
Contractual necessity: necessary to assess and process your insurance claim
Health data relies on explicit consent unless the processing is necessary for the performance of the contract, for example sharing with your medical providers for the purposes of approving your claim
Administration services & Communications
Identity
Contact
Country of residence
Account details
Financial
Contractual necessity/legitimate interest: necessary to administer your insurance policy and ensure records are kept up to date
Health data only collected if relevant and if so relies on consent
Marketing/product offers
Identity
Contact
Policy preferences
Consent
Explicit consent always required for marketing
Fraud detection & prevention
Identity
Contact
Financial
Health
Claims history
Occupation
Legitimate interest
Health data: explicit consent only if no legal basis under legitimate interest
Management reporting and analytics
Aggregated personal data
Trends
Legitimate interest
Personal health data is minimised or pseudonymised where possible
Research and product development
Aggregated policy and useage data
Consent/legitimate interest
Where health data is used relies on explicit consent or pseudonymisation
Legal & regulatory compliance
Identity
Contact
Nationality
Occupation
Financial
Health
Legal obligation
Shared in compliance with relevant data protection laws

6/ Profiling and automated decision making

We do not make decisions relating to cover available under our insurance policies based solely on automated decision making.

7/ Sharing your data

We may share your personal data only where we have legitimate cause to do so in accordance with section 5 of this Policy. We share your data with our insurers, insurance partners and other third parties as listed below.

We may also disclose your relevant personal data to other insurers where you have another insurance policy that covers the same costs you are claiming from us. We do this to ensure we only pay our fair proportion of the costs.

7.1 Disclosures to our insurers

To administer your policy, including underwriting, claims and complaints, we may share your personal data and your special category personal data with our insurance partners. When we share data with our insurers under their instruction or authority, they process that data in accordance with their data privacy policy (detailed at the top of this Policy).

The insurers we may share your personal data with are:

  • AWP P&C Limited, an insurer in the UK authorised by the Prudential Regulation Authority and regulated by the Financial Conduct Authority and the Prudential Regulation Authority.
  • AWP H&L SA, an insurer in France regulated by the French Prudential Supervisory Authority (“Autorité de Contrôle Prudentiel et de Résolution”).

7.2 Disclosures to third parties

We may also disclose your information to the third parties listed below for the purposes described in this data privacy policy. These may include:

  • Your relatives, family or other legal representatives
  • Your insurance advisor or broker (if you have one)
  • Current, past or prospective employers
  • Your healthcare providers
  • Our insurance partners, brokers, reinsurers, or other companies who act as introducers or distributors of our products
  • Our third-party service providers such as IT suppliers, marketing agencies, auditors, tax and legal advisors
  • Our third-party providers of ancillary products and services, such as telehealth providers, health and well-being and other support services detailed in your policy documents
  • Central and local government, for example for investigating fraud
  • Regulatory authorities such as the Financial Conduct Authority in the UK, relevant Data Protection authorities or fraud/crime agencies

8/ How we keep, store and dispose of your personal data

We hold your personal data in various forms, including electronic databases, computerised files, and paper files.

Personal data may be held for a period after your policy ends with a view to preventing or detecting fraud, or as we are required to under Belgian, French or UK law. This will generally be for a period of six (6) years from when your policy ends and any outstanding claims have been settled. This is in order to comply with legal obligations and to defend a claim that can be brought against us during this time.

If you receive a quote from us, we usually delete your information after the 30-day validity period if you do not take up the quote, as the quote is no longer valid. However, we reserve the right to retain your information where we have a legitimate reason, for example, to defend a claim or complaint against us or to fulfil our regulatory obligations.

When we dispose of your personal data, we do so securely. We may keep non-personally identifiable data for the purpose of research and statistical analysis to improve the services we offer.

9/ Where we store your personal data

At William Russell, we take the protection of your personal data very seriously. We store all personal and sensitive personal data within the UK or the EEA and we apply the safeguards set out in the UK/EU GDPR. We transfer data to our insurance partners in the UK and France as part of our policy management, underwriting, claims and complaint processing.

10/ Other cross-border transfers

We transfer your personal data, and where relevant your health information, outside the UK/EEA, only if:

  • You, your employer or your insurance representative/broker are located in a different jurisdiction; and/or
  • We need to provide medical information to a medical provider in another jurisdiction for underwriting or claims purposes.

Some of our service providers use US‑based sub‑processors, so your personal data may be transferred to the United States. We ensure any such transfer is protected using a lawful transfer mechanism recognised under UK and EU data protection law.

10.1 Safeguards

We carry out any cross-border transfer under appropriate safeguards to protect your data. These safeguards include:

  • Standard contractual clauses approved by the European Commission
  • Binding agreements with medical providers or insurers to enforce data protection obligations
  • Encryption of personal and sensitive data when sending electronically

We transfer special category data, such as your health information, internationally only with your consent where required.

11/ Your rights

You have the following rights regarding how we process your personal information. Please note that some of these rights do not apply in all circumstances, and some are not absolute rights.

  • Right to access: You can ask us to confirm whether we hold your personal data and request a copy of it. There will not usually be a charge for this request and we will usually provide the information to you electronically unless you request otherwise.
  • Right to rectification: You can ask us to correct any inaccurate or incomplete personal data we hold about you.
  • Right to erasure (“right to be forgotten”): You can request deletion of your personal data when we no longer need it or you withdraw your consent. We may retain your data if we need it for legal obligations, contract performance or legitimate interests.
  • Right to restrict processing: You can ask us to limit how we use your personal data in certain situations, such as when you contest its accuracy.
  • Right to data portability: You can request your personal data in a structured, machine-readable format and, where feasible, have it transferred to another provider. This right applies only to data you provided, on an automated basis and where processing is based on your consent or contractual necessity.
  • Right to object: You can object to processing for direct marketing or, in some cases, where the basis is legitimate interests. This is an absolute right for direct marketing but not for legitimate interests or legal obligations.
  • Right to withdraw consent: You can withdraw consent for processing at any time. This is an absolute right, but if you withdraw your consent, this may affect our ability to provide services.
  • Right to complain: You have the right to lodge a complaint with a supervisory authority if you believe we are not processing your data lawfully.

12/ Cookies and tracking

We use cookies and similar technologies on this website. Cookies are text files containing small amounts of information, which your computer or mobile device downloads when you visit a website. When you return to websites, or visit websites that use the same cookies, they recognise these cookies and therefore your browsing device.

Like most financial services providers, we use cookies to do lots of different jobs, such as letting you navigate between pages efficiently, remembering your preferences and improving your browsing experience. They also help ensure that ads you see online are more relevant to you and your interests. We also use similar technologies such as pixel tags and JavaScript to perform these tasks.

If you visit our website, we deploy these technologies to provide an online service suited to your device and to prevent and detect fraud, keeping you secure. When you visit our website from any device (mobile, tablet or computer), we collect information about your use of this site, such as your device or browser details (including device type, operating system, screen resolution), how you interact with the site, and the IP address your device connects from.

12.1 We use cookies to:

  • Ensure your security and privacy when in our secure sites
  • Temporarily store input information in our quote tools
  • Provide you with ads that are more relevant to you and your interests, and improve our targeting and enhance your journey through our sites and partner sites
  • Improve our understanding of how you navigate through our sites so we can identify improvements
  • Evaluate our sites’ advertising and promotional effectiveness (we own the anonymous data collected and we don’t share it with anyone)

We use both our own (first-party) and partner companies’ (third-party) cookies to support these activities:

  • Cookies generated on our website pass through to third-party services that support our website functionality
  • Our use of cookies can lead to personally identifiable information being collected and stored within the UK, e.g. if you use our quote tool, we create a record in our third-party tools and Dynamics (our member records management system)

12.2 Types of cookie we use

Necessary: Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

Cookie

Duration

Description

__cf_bm
1 hour
This cookie, set by Cloudflare, is used to support Cloudflare Bot Management
_GRECAPTCHA
6 months
Google Recaptcha service sets this cookie to identify bots to protect the website against malicious spam attacks
ARRAffinity
session
ARRAffinity cookie is set by Azure app service, and allows the service to choose the right instance established by a user to deliver subsequent requests made by that user
ARRAffinitySameSite
session
This cookie is set by Windows Azure cloud, and is used for load balancing to make sure the visitor page requests are routed to the same server in any browsing session
__cfruid
session
Cloudflare sets this cookie to identify trusted web traffic
OptanonConsent
1 year
OneTrust sets this cookie to store details about the site’s cookie category and check whether visitors have given or withdrawn consent from the use of each category
_calendly_session
21 days
Calendly, a Meeting Schedulers, sets this cookie to allow the meeting scheduler to function within the website and to add events into the visitor’s calendar
cookieyes-consent
1 year 1 month 4 days
CookieYes sets this cookie to remember users’ consent preferences so that their preferences are respected on subsequent visits to this site. It does not collect or store any personal information about the site visitors
PHPSESSID
session
This cookie is native to PHP applications. The cookie stores and identifies a user’s unique session ID to manage user sessions on the website. The cookie is a session cookie and will be deleted when all the browser windows are closed
rc::a
Never expires
This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks
rc::c
session
This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks
rc::f
Never expires
This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks
rc::b
session
This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks
.AspNetCore.Antiforgery.*
session
This cookie is set by Microsoft ASP.NET Core to prevent cross-site request forgery (CSRF) attacks. This cookie is essential for the security of our website
m
1 year 1 month 4 days
Stripe sets this cookie for fraud prevention purposes. It identifies the device used to access the website, allowing the website to be formatted accordingly
flaretrk
1 year
Used by Attributor

Functional: Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

Cookie

Duration

Description

wpEmojiSettingsSupports
session
WordPress sets this cookie when a user interacts with emojis on a WordPress site. It helps determine if the user’s browser can display emojis properly
lidc
1 day
LinkedIn sets the lidc cookie to facilitate data center selection
li_gc
6 months
Linkedin set this cookie for storing visitor’s consent regarding using cookies for non-essential purposes
_cfuvid
session
This cookie is set by Windows Azure cloud, and is used for load balancing to make sure the visitor page requests are routed to the same server in any browsing session
VISITOR_INFO1_LIVE
6 months
YouTube sets this cookie to measure bandwidth, determining whether the user gets the new or old player interface
VISITOR_PRIVACY_METADATA
6 months
YouTube sets this cookie to store the user’s cookie consent state for the current domain
yt-remote-device-id
Never expires
YouTube sets this cookie to store the user’s video preferences using embedded YouTube videos
yt-remote-connected-devices
Never expires
YouTube sets this cookie to store the user’s video preferences using embedded YouTube videos
visitorId
Never expires
ZoomInfo sets this cookie to identify a user
ytidb::LAST_RESULT_ENTRY_KEY
Never expires
The cookie ytidb::LAST_RESULT_ENTRY_KEY is used by YouTube to store the last search result entry that was clicked by the user. This information is used to improve the user experience by providing more relevant search results in the future
yt-remote-session-app
session
The yt-remote-session-app cookie is used by YouTube to store user preferences and information about the interface of the embedded YouTube video player
yt-remote-cast-installed
session
The yt-remote-cast-installed cookie is used to store the user’s video player preferences using embedded YouTube video
yt-remote-session-name
session
The yt-remote-session-name cookie is used by YouTube to store the user’s video player preferences using embedded YouTube video
yt-remote-cast-available
session
The yt-remote-cast-available cookie is used to store the user’s preferences regarding whether casting is available on their YouTube video player
yt-remote-fast-check-period
session
The yt-remote-fast-check-period cookie is used by YouTube to store the user’s video player preferences for embedded YouTube videos
__Secure-ROLLOUT_TOKEN
6 months
Description is currently not available
newsletter-focus
1 day
Description is currently not available
csrf_token
session
No description available
loid
1 year 1 month 4 days
This cookie is set by the Reddit. The cookie enables the sharing of content from the website onto the social media platform

Analytics: Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

Cookie

Duration

Description

bcookie
1 year
LinkedIn sets this cookie from LinkedIn share buttons and ad tags to recognize browser IDs
Dynamics365PortalAnalytics
1 day
No description available
ubpv
6 months
Unbounce analytics
ubvt
session
Unbounce cookie
YSC
session
Youtube sets this cookie to track the views of embedded videos on Youtube pages
_ga
1 year 1 month 4 days
Google Analytics sets this cookie to calculate visitor, session and campaign data and track site usage for the site’s analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognise unique visitors
_ga_*
1 year 1 month 4 days
Google Analytics sets this cookie to store and count page views
ubvs
6 months
No description available
ai_user
1 year
Microsoft Azure sets this cookie as a unique user identifier cookie, enabling counting of the number of users accessing the application over time
ai_session
1 hour
This is a unique anonymous session identifier cookie set by Microsoft Application Insights software to gather statistical usage and telemetry data for apps built on the Azure cloud platform
MR
7 days
This cookie, set by Bing, is used to collect user information for analytics purposes
yt.innertube::nextId
Never expires
YouTube sets this cookie to register a unique ID to store data on what videos from YouTube the user has seen
yt.innertube::requests
Never expires
YouTube sets this cookie to register a unique ID to store data on what videos from YouTube the user has seen
CLID
1 year
Microsoft Clarity set this cookie to store information about how visitors interact with the website. The cookie helps to provide an analysis report. The data collection includes the number of visitors, where they visit the website, and the pages visited
_clck
1 year
Microsoft Clarity sets this cookie to retain the browser’s Clarity User ID and settings exclusive to that website. This guarantees that actions taken during subsequent visits to the same website will be linked to the same user ID
SM
session
Microsoft Clarity cookie set this cookie for synchronizing the MUID across Microsoft domains
_clsk
1 day
Microsoft Clarity sets this cookie to store and consolidate a user’s pageviews into a single session recording

Advertisement: Advertisement cookies are used to provide visitors with customised advertisements based on the pages you visited previously and to analyse the effectiveness of the ad campaigns.

Cookie

Duration

Description

_fbp
3 months
Facebook sets this cookie to display advertisements when either on Facebook or on a digital platform powered by Facebook advertising after visiting the website
test_cookie
15 minutes
doubleclick.net sets this cookie to determine if the user’s browser supports cookies
NID
6 months
Google sets the cookie for advertising purposes; to limit the number of times the user sees an ad, to unwanted mute ads, and to measure the effectiveness of ads
MUID
1 year 24 days
Bing sets this cookie to recognise unique web browsers visiting Microsoft sites. This cookie is used for advertising, site analytics, and other operations
_uetsid
1 day
Bing Ads sets this cookie to engage with a user that has previously visited the website
_uetvid
1 year 24 days
Bing Ads sets this cookie to engage with a user that has previously visited the website
GCL_AW_P
3 months
Description is currently not available
_gcl_aw
3 months
DoubleClick sets this cookie to understand user interaction with the site and advertising
_gcl_au
3 months
Google Tag Manager sets the cookie to experiment advertisement efficiency of websites using their services
ANONCHK
10 minutes
The ANONCHK cookie, set by Bing, is used to store a user’s session ID and verify ads’ clicks on the Bing search engine. The cookie helps in reporting and personalization as well
SRM_B
1 year 24 days
Used by Microsoft Advertising as a unique ID for visitors
__Secure-YEC
past
Description is currently not available
token_v2
1 day
Description is currently not available
session_tracker
session
This cookie is set by the Reddit. This cookie is used to identify trusted web traffic. It also helps in adverstising on the website

Uncategorised: Other uncategorised cookies are those that are being analysed and have not been classified into a category as yet.

Cookie

Duration

Description

cal_anonymous_id
session
Description is currently not available
__Secure-YNID
6 months
Description is currently not available
reevoo_test.a2t
session
Description is currently not available

12.3 Setting your cookie preferences

You can control how cookies are placed on your device within your own browser.

12.4 What happens to cookies downloaded in the past

You can delete existing cookies from your browser. We anonymise historical information collected from any cookies and we use it to review or compare our websites and advertising performance.

12.5 More information about cookies

13/ Security

We implement appropriate measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. These measures include risk-based access to structured and unstructured filing systems for personal data, limiting access to key systems, and enforcing information security policies and procedures to mitigate unauthorised access to systems.

14/ Policy updates

We update our privacy information from time to time, such as when the law changes or when we change how we intend to use personal information. We recommend checking this policy for changes; however, we will contact you to inform you of any changes to this policy and explain what the changes are and why we made them.

15/ Contact us

You can contact our Data Protection Officer at:

William Russell House, The Square, Lightwater, Surrey, GU18 5SS, UK

Email: [email protected]

If you believe we are not processing your personal data in accordance with the law, please contact our Data Protection Officer first. We will investigate and attempt to resolve your complaint. Alternatively, you can complain to:

  • The UK Information Commissioner’s Office (ICO) via this link: https://ico.org.uk/concerns/
  • The Data Protection Authority, Rue de la Presse-Drukpersstraat, 35, 1000 Brussels, Belgium
Back to top