City Brokers Ltd - Privacy Notice
City Brokers Ltd (“CBL”, “we”, “us”, “our”, “the Company”) is a private company incorporated in Mauritius. We are one of the leading insurance broking companies in Mauritius which provides consultancy and insurance brokerage services to corporate and individual clients. Our registered office is located at IBL House Caudan Waterfront, Port Louis, Mauritius and principal place of business is situated at 2nd Floor, Harbour Front Building, John Kennedy Street, Port Louis, Mauritius.
City Brokers respects your privacy, and is committed to protecting the privacy, confidentiality and security of the personal data you provide us when you use our website, when you contact our office, or when you otherwise interact with us.
2. Which personal data we collect?
Personal data is defined in the Data Protection Act 2017 (DPA) and it refers to data about an individual who can be identified from either that particular data, or from that data and other information which we have or are likely have access to.
Personal health information means identifying information about an individual relating to their physical or mental health.
Personal data is collected where reasonably necessary for our functions and activities. Personal data that we may hold include the following:
- Your name, address, signature and contact details;
- Your age and date of birth;
- your national identity card number, your passport details;
- your marital status
- Personal Health Information:
- information related to your health conditions,
- current medication or treatments used by the patient;
- previous/current medical history, including, where relevant, a family medical history;
- the name of any health service provider or medical specialist to whom the patient is referred
- your contact details (phone and fax numbers, email addresses);
- your residential address;
- your claim history,
- your banking details,
- information and registration number of your vehicle or boat,
- your driving licence number;
- your employment details;
- payment-related information;
- information related to your financial situation or your personal assets;
- photos and video recordings;
- CV, pictures and qualifications details when you either spontaneously apply for a job at CBL or respond to a vacancy notice;
- other personal data as may be provided by an individual from time to time;
- your photos and videos when you participate to corporate events, cocktails, sports events organised by CBL;
- your name, surname, signature and national identity card details in our visitors’ log book when you visit us;
- any other personal data necessary to fulfil your special requests; and
- any other personal data that you choose to provide to us.
- CBL records may include relevant information that you have told us, or information provided on your behalf by your guardians or parents if you are a minor, or from your other third party detailed in section 3.Most of the time we will collect your personal data directly from you, but we may sometimes receive it directly from your employer when it pays or contributes to your insurance cover, from your fleet management company, or from your leasing company.Your records may be held by CBL either in paper-form or electronically in a computer system.
Wherever possible, we will collect personal data directly from you. However, in some cases we collect information from third parties being our trusted partners such as our corporate clients being your employer, leasing companies, fleet management companies, insurance companies, surveyors, or other service providers engaged in your insurance process/ service.
We will only collect, use and disclose personal data because we are satisfied that we have an appropriate legal basis to do so, or with your consent, your deemed consent or as may be otherwise permitted under the DPA or other applicable laws.
In addition to the personal data, you provide to us, certain information related to you that is not considered personal data under the DPA may also be collected. We collect this information to improve our website. Such non-personal data may include information such as your IP address, the internet browser you use, details of your interaction with our website and other types of non-personal data.
3.1 General purposes
In using our services and providing us with your personal data, you hereby agree that CBL may collect, store, process, disclose, access, review and/or use your personal data (including special categories of personal data) about you, whether obtained from you or from other sources, for the purposes set out below and/or any other administrative or operational purposes and/or the purpose of managing your relationship as a client with CBL:
We use your personal data in the course of our business activities and interaction with you for the following purposes:
- Providing comprehensive insurance solutions to you;
- To carry out and administer our services and products to you. These may include claims management, risk management consulting and other forms of insurance related services, employee benefits program administration, life and pension related services;
- Request, review, analyse insurance quotations for you and your insured(s).
- Provide advice on insurance products best suited to your profile and that of your insured(s).
- Process any claims under your insurance policy, including settlement of claims and any related investigations to be carried out.
- Communicate your claims experience and loss rations in relation to your insurance policy.
- Communication on any matters relating to the services and/or products which you are entitled under your insurance policy.
- Complying with all applicable laws including reporting to industry regulators and other legal authorities.
- Treating your application including your dependents;
- Administering your claims and following up the payments of your claims or repair process of your assets ;
- Improving our claims management services;
- Making or obtaining payment, and/or recovery of any debts owed to CBL / Insurers.
- Work effectively with others providing you your insurance cover and services following a claim;
- Resolving complaints and dealing with enquiries made by you;
- Provide information and services as requested by you;
- Understand and assess your ongoing needs and offer products and services to meet those needs;
- Assess the quality of services provided to you;
- Maintenance and updating of the data;
- Administrative or operational purposes;
- Collection of fees, charges and expenses for services provided;
- Verification and identification purposes;
- Carrying out billing, accounting, auditing and the maintenance of proper book-keeping for CBL operations and business;
- The disclosure of the relevant books, documents, records and information (in hard or soft copy) to the auditors for the preparation of financial reports;
- compliance with the applicable laws and regulations;
- performing our agreement with you;
- promoting eventual business relationships;
- treating your applications for specific job vacancies or on a spontaneous basis;
- performing recruitment analytics with CVs received;
- ensuring security of our offices and people;
- keeping an accurate evacuation list in case of emergency;
- promoting our corporate and marketing initiatives (events, cocktails etc) on CBL social medias;
- fulfilling our legitimate commercial interests; and
- sending you communications if you have consented to receiving same, and for any other purposes for which we obtained your consent.
3.2 Marketing Purposes
Where you have subscribed for our marketing communications (by providing CBL with your telephone number or email address and have indicated to us that you consent to receiving marketing communications via these channels) CBL may contact you from time to time, whether by SMS, email or otherwise, to inform you about our new developments, services and events that we think may be of interest to you.
You will also be able to opt-out from receiving marketing communications at any time, free of charge, by following the unsubscribe instructions contained in each of our marketing communications or by contacting us in accordance with the section “Contact Us” below.
Your personal data may be shared as follows:
- City Brokers may share your personal information with those involved in your health treatment for health insurance and claim management purposes.
- with external companies such as health insurance administrators, insurance companies, medical professionals or institutions, surveyors, private investigators, loss assessors / loss adjusters for the management of your claims, your insurance covers or to investigate a claim, pension administrators, financial institutions where your insurance cover is related to a loan, repairers, rental companies when you need a replacement vehicle; third party suppliers (Disaster recovery or emergency assistance services);
- With your employer or the corporate client, if it participates to the payment of your insurance cover;
- between and among other departments of City Brokers as may be relevant for the purposes set out in section 3 above and to facilitate our activities or relationship, but we shall only do so on a strictly need to know basis;
- with our employees for purposes of fulfilling our business activities, treating job applications or conducting internal analysis with a view to improving our company and services;
- with law enforcement bodies/agencies, regulatory authorities and other statutory authorities upon request; and
- with our agents, advisers, accountants, auditors, lawyers, other professional advisors, contractors, or third-party service providers for the purpose of assisting us to better manage, support or develop our business and comply with our legal and regulatory obligations.
We will ensure that your personal data is kept safely. Only designated persons will have access to your personal data on a strictly “need-to-know” basis for the purposes of fulfilling our agreement, treating job applications or promoting our business relationship with you. In addition, third parties with whom we share your personal data will be contractually obliged to safeguard all personal data to which they have access.
Some disclosures do not require your consent. This happens when we share your personal data with (i) law enforcement bodies/agencies and other statutory authorities, if required by law and (ii) if required or authorised by law or if we suspect any unlawful activities on your part.
Where we have collected your personal data on behalf of another party, the use of your personal data by that party is governed by their privacy policy for which we are not responsible. We may also disclose aggregate or de-identified/anonymised/encrypted data that is not personally identifiable with third parties, including our commercial and strategic partners.
In some cases, we may need to transfer your personal data with organisations located in countries outside our territorial limits in order to provide our services to you. We will take appropriate safeguards in order to secure the personal data being transferred.
Please note that:
- The anti-spam and anti-virus filtering are done by a service provider located in South Africa.
- E-mails servers and e-filling system servers are transferred on Microsoft data cloud based in Europe.
- Personal data collected through our website is transferred to servers based in United States of America.
We will only process your personal data where we are satisfied that we have an appropriate legal basis to do so, such as (i) for the performance of a contract between us; (ii) where you have provided us with your express consent to process your personal data for a specific purpose; (iii) our use of your personal data is necessary to fulfil our statutory obligations with relevant authorities (regulators, tax officials, law enforcement bodies) or otherwise meet our legal responsibilities; (iv) our use of your personal data is in our legitimate interest as an organisation; or (v) for the purpose of management of health services or pursuant to a contract with a health professional.
Where we process special categories of personal data, we will do so in compliance with the requirements of section 29 of the DPA.
CBL has in place reasonable technical and organisational measures to prevent unauthorised or accidental access, processing, erasure, loss, or use of your personal data and to keep your personal data confidential. These measures are subject to ongoing review and monitoring.
We cannot guarantee that our website will function without disruptions. We shall not be liable for damages that may result from the use of electronic means of communication, including, but not limited to, damages resulting from the failure or delay in delivery of electronic communications, interception, or manipulation of electronic communications by third parties or by computer programs used for electronic communications and transmission of viruses.
We may collect and process personal data from minors during the course of our activity and the purpose detailed in section 3, but we will only do so with the permission of your parent or guardian.
In addition, if you are a minor and you are using this website, you may only use do so with the permission of your parent or guardian.
Our website may contain links to other websites, apps, content, services or resources on the internet which are operated by subsidiaries and affiliates of CBL or third parties. If you access other websites, apps, content, services or resources using the links provided, please be aware they may have their own privacy policy, and we do not accept any responsibility or liability for these policies or for any personal data which may be collected through these sites. Please check these policies before you submit any personal information to these other websites.
You have the right to request a copy of the personal data we hold about you. To do this, simply contact our Data Protection Officer and specify what data you would like. We will take all reasonable steps to confirm your identity before providing details of your personal data.
You will not have to pay a fee to access your personal data (or to exercise any of your other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
You have the right to ask us to update, correct or delete your personal data. We will take all reasonable steps to confirm your identity before making changes to personal data we may hold about you. We would appreciate it if you would take the necessary steps to keep your personal data accurate and up-to-date by notifying us of any changes we need to be aware of.
13. Withdrawal of consent and request for deletion of personal data
You may also withdraw your consent to receiving direct marketing communications, or more generally to our processing of your personal data, at any time, and you may in certain circumstances ask us to delete your personal data. However, we may not be able to fulfil our contractual obligations to you if you entirely withdraw your consent or ask us to delete your personal data entirely. To protect your personal data, we shall require that you first prove your identity to us at the time the request is made, for instance by providing a copy of your national identification card, contact details or answering some other security questions to satisfy ourselves of your identity before we may proceed with your request(s).
Whenever reasonably possible and required, we will strive to grant these rights within 30 days, but our response time will depend on the complexity of your requests. We will generally respond to your requests free of charge unless if your request involves processing or retrieving a significant volume of
data, or if we consider that your request is unfounded, excessive or repetitive in which case we reserve the right to charge a fee (as mentioned above regarding access).
There may be circumstances where we are not able to comply with your requests, typically in relation to a request to erase your personal data or where you object to the processing of your personal data for a specific purpose or where you request that we restrict the use of your personal data where we need to keep your personal data to comply with a legal obligation or where we need to use such information to establish, exercise or defend a legal claim. To make these requests, or if you have any questions or complaints about how we handle your personal data or would like us to update the data we maintain about you and your preferences, please contact our Data Protection Officer at the address set out under section 17 below.
Our website uses cookies.
- What is a cookie?
Cookies are small data files that your browser places on your computer or device. Cookies help your browser navigate a website and the cookies themselves cannot collect any data stored on your computer or your files. When a server uses a web browser to read cookies, they can help a website deliver a more user-friendly service. To protect your privacy, your browser only gives a website access to the cookies it has already sent to you.
- Why do we use cookies?
We use cookies to learn more about the way you interact with our content and help us to improve your experience when visiting our website. Cookies remember the type of browser you use and which additional browser software you have installed. They also remember your preferences, such as language and region, which remain as your default settings when you revisit the website. Cookies also allow you to rate pages and fill in comment forms. The cookies we use are:
- Session cookies which allow you to proceed through many pages of a site quickly and easily without having to authenticate or reprocess each new page you visit. The Session Cookies only last until you close your browser.
- Statistics cookies which help website owners to understand how visitors interact with their website by collecting and reporting
information anonymously.
- How are third party cookies used?
For some of the functions within our websites we use third party suppliers, for example, when you visit a page with videos embedded from or links to YouTube. These videos or links (and any other content from third party suppliers) may contain third party cookies and you may wish to consult the policies of these third-party websites for data regarding their use of cookies.
- How do I reject and delete cookies?
We will not use cookies to collect personally identifiable data about you. However, should you wish to do so, you can choose to reject or block the cookies set by the websites of any third-party suppliers by changing your browser settings – see the Help function within your browser for further details. Please note that most browsers automatically accept cookies so if you do not wish cookies to be used you may need to actively delete or block the cookies.
You can also visit www.allaboutcookies.org for details on how to delete or reject cookies and for further data on cookies generally. For data on the use of cookies in mobile phone browsers and for details on how to reject or delete such cookies, please refer to your handset manual. Note, however, that if you reject the use of cookies, you will still be able to visit our websites but some of the functions may not work correctly.
We may amend this privacy notice from time to time. Any amendment will be posted on our website so that you are always informed of the way we collect and use your personal data. Any changes to this privacy notice will become effective upon posting of the revised privacy notice on the website. Use of our website following such changes constitutes your acceptance of the revised privacy notice then in effect but, to the extent such changes have a material effect on your rights or obligations as regards our handling of your personal data, such changes will only apply to personal data after the changes are applied.
This privacy notice is governed by and shall be construed in accordance with the laws of the Republic of Mauritius. This privacy notice is written in the English language and may be translated into other languages. In the event of any inconsistency between the English version and the translated version of this privacy notice, the English version shall prevail.
We have appointed a Data Protection Officer to oversee compliance with and questions in relation to this notice. If you have any questions about this notice, including any requests to exercise your legal rights, please contact our Data Protection Officer using the details set out below:
The Data Protection Officer
City Brokers Ltd
2nd Floor Harbour Front Building,
John Kennedy Street
Port Louis, Mauritius
dpo@citybrokers.mu
(230) 208 25 22
If you believe we have not handled your request in an appropriate manner, you may lodge a complaint with the Data Protection Commissioner (DPC) (The Data Protection Office, 5th floor, SICOM Tower, Wall Street Ebène, Mauritius).
However, we ask that you please try to resolve any issues with us first before referring your complaint to the DPC.