01 — Introduction
X Underwriting Managers (Pty) Ltd ("we", "us", "our", or "X Underwriting") is an Authorised Financial Services Provider, FSP 55527. X Gap Cover is underwritten by Compass Insurance Company Limited ("Compass Insure"), a licensed non-life insurer and authorised financial services provider, FSP 12148.
This Privacy Policy explains how we collect, use, store, share and protect personal information in compliance with the Protection of Personal Information Act 4 of 2013 ("POPIA"), the Promotion of Access to Information Act 2 of 2000 ("PAIA"), and all applicable South African data protection legislation.
This policy applies to all personal information collected through our website, applications, communications, and in the course of providing insurance-related services. By engaging with us, you acknowledge that you have read and understood this policy.
We may update this policy from time to time. We will notify you of material changes via a prominent notice prior to those changes taking effect.
02 — Definitions
Personal Information
Any information relating to an identifiable, living, natural person or existing juristic person, including but not limited to: name, identity number, contact details, financial information, health information, biometric information, and correspondence.
De-identified Information
Information from which all personal identifiers have been irreversibly removed such that the individual cannot reasonably be re-identified. De-identified information is no longer considered personal information under POPIA and may be used for analytical, statistical, actuarial and research purposes.
Processing
Any operation or activity concerning personal information, including collection, receipt, recording, organisation, storage, updating, retrieval, use, dissemination, merging, linking, restriction, degradation, erasure or destruction.
Responsible Party
X Underwriting Managers (Pty) Ltd, as the entity that determines the purpose of and means for processing your personal information.
Operator
A person or organisation that processes personal information for us in terms of a contract or mandate, without coming under our direct authority. An operator may only process your information on our instructions, must treat it as confidential, and may not use it for its own purposes.
Data Subject
The natural or juristic person to whom personal information relates — in most cases, this is you as our policyholder, beneficiary, or website visitor.
03 — Information We Collect
We collect personal information that is necessary, relevant and adequate for the purposes set out in this policy. The categories of information we may collect include:
Identity Information
Full name, identity or passport number, date of birth, gender, nationality.
Contact Details
Email address, phone number, residential and postal address.
Financial Information
Banking details for premium collection and claim payments, payment history.
Health Information
Medical aid membership details, medical records and clinical information relevant to claims assessment.
Policy Information
Policy number, cover type, beneficiary details, claims history.
Usage & Technical Data
IP address, browser type, device identifiers, pages visited, time and date of visits, and other diagnostic data collected when you use our website or applications.
Where you contact us by phone, email, post or any other method, we may retain those contact details and any additional information you provide for future reference and service delivery.
Incomplete submissions
We may retain information you provide on our website or application even if you do not complete a registration or transaction. This data may be used to follow up with you and to improve our online processes.
04 — Use of Information
We process your personal information for the following purposes, each of which has a lawful basis under POPIA:
Our own analytics
We use de-identified, aggregated data, from which all personal identifiers have been irreversibly removed, for analytical, statistical, actuarial and research purposes, and to develop and improve our own models for underwriting, claims assessment, fraud detection and service design.
Artificial intelligence used to administer your policy
We also use artificial intelligence tools supplied by third party operators to assist us with the day to day administration of your policy and claims. Where these tools process information that identifies you, they do so only on our instructions and under a written agreement that prohibits the operator from using your information for its own purposes, including training its models, and that requires the operator to impose the same obligations on anyone it appoints to assist it. Where such an operator is located outside South Africa, we transfer your information in accordance with section 72 of POPIA. We rely primarily on that binding agreement, which provides a level of protection substantially similar to that required by POPIA, and additionally on your consent where you have given it. Decisions affecting your cover, your premium or your claim are made by a suitably qualified person and never by automated means alone.
05 — Cookies
Our website uses cookies — small text files stored on your device — to personalise your experience and improve site functionality. Each cookie is unique to your web browser and contains anonymous information such as a unique identifier and the website's domain name.
Types of cookies we useNecessary Cookies
Essential for the website to function correctly. They allow you to navigate and use core features such as account access.
Functionality Cookies
Remember your preferences and choices to provide a more personalised experience on return visits.
Analytical Cookies
Collect aggregated, non-personal statistical data about how visitors use our website, helping us improve the user experience.
You have the right to accept or decline cookies through your browser settings. Declining certain cookies may limit your ability to use some features of our website. We may use Google Analytics to monitor and analyse website usage — you can opt out by installing the Google Analytics opt-out browser add-on.
06 — Sharing Your Information
We do not sell, rent or lease your personal information to third parties. We may share your information only in the following circumstances and only to the extent necessary:
07 — Storage & Retention
Your personal information is stored on secure servers in controlled environments, protected through appropriate physical, electronic and administrative safeguards.
We retain your personal information only for as long as is necessary to fulfil the purposes for which it was collected, and to meet the record-keeping obligations placed on us by law. The periods below are indicative of how long we ordinarily hold each category of information:
Policy & Client Records
5 years after your policy ends, as required by the FAIS General Code of Conduct.
Records of Advice
5 years after the service was rendered, including transaction records and any advice given to you.
Claims & Health Information
5 years after the claim is finalised, including medical records and clinical information used to assess it.
Verification Records
5 years after our relationship with you ends, as required by the Financial Intelligence Centre Act.
Accounting Records
7 years, as required by the Companies Act 71 of 2008.
Telephone Recordings
5 years, where we have recorded instructions or advice given over the telephone.
Incomplete Applications
12 months from your last interaction, where you began a quote or application but did not complete it.
Website & Cookie Data
Up to 26 months for analytics data collected through our website and applications.
Marketing Preferences
For as long as necessary to honour your choice, so that we do not contact you after you have opted out.
These periods are indicative minimums. We may hold information for longer where a claim, dispute, investigation or legal proceeding is active, or where a longer period is required by law. When your information is no longer required, we will securely delete or de-identify it in accordance with our data retention schedule.
Cross-border transfers
Where personal information is transferred outside South Africa, we do so in accordance with section 72 of POPIA. We rely primarily on a binding written agreement with the recipient, which provides a level of protection substantially similar to that required by POPIA and which requires the recipient to impose the same obligations on anyone it appoints to assist it, and additionally on your consent where you have given it.
08 — Security
We implement appropriate technical and organisational measures to prevent unauthorised access, disclosure, alteration or destruction of your data, including encryption of data in transit (SSL/TLS), access controls, secure server environments and regular security reviews.
Please be aware that no method of electronic transmission or storage is completely secure. Where we have issued you a password to access parts of our website or systems, you are responsible for keeping that password confidential.
Security incidents
If there are reasonable grounds to believe that your personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and you as soon as reasonably possible after discovering the compromise, as required by section 22 of POPIA. We may delay notifying you only where a public body responsible for the detection or investigation of offences determines that earlier notice would impede a criminal investigation. We will notify you in writing, and our notice will give you enough information to allow you to take protective measures — a description of the possible consequences of the compromise, the measures we have taken or intend to take in response, what we recommend you do to reduce any harm, and the identity of the unauthorised person if we know it. We will also investigate the cause and take steps to prevent a recurrence.
09 — Your Rights
As a data subject, you have the following rights in relation to your personal information. You may exercise these rights by contacting our Information Officer.
Right to Access
Request confirmation of whether we hold personal information about you and access that information.
Right to Correction
Request that we correct or update inaccurate, incomplete or outdated personal information we hold about you.
Right to Deletion
Request deletion or destruction of your personal information where we are no longer lawfully entitled to retain it.
Right to Object
Object to the processing of your personal information on reasonable grounds, including for direct marketing purposes.
Right to Withdraw Consent
Where processing is based on your consent, withdraw that consent at any time without affecting prior processing.
Right to Complain
Lodge a complaint with the Information Regulator of South Africa if you believe your rights under POPIA have been infringed.
Rights Regarding Automated Decisions
Not be subject to a decision that has legal consequences for you, or affects you substantially, where that decision is based solely on automated processing. You may make representations about any such decision.
Information Regulator contact details
The Information Regulator (South Africa) · JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 · Email: inforeg@justice.gov.za · Website: www.inforegulator.org.za
10 — Children's Privacy
Our services and website are not directed at persons under the age of 18. We do not knowingly collect personal information from children without verifiable parental or guardian consent.
If you are a parent or guardian and believe a child has provided us with personal information without your consent, please contact our Information Officer immediately. We will take prompt steps to remove that information from our records.
Where a minor is a beneficiary under a policy held by an adult, we will process only the minimum personal information of that minor necessary for the administration of the policy.
11 — Third-Party Links
Our website and applications may contain links to external websites. Once you navigate away from our platforms, we have no control over those external sites and are not responsible for the protection of any information you provide to them.
We encourage you to review the privacy policy of any external website you visit. Those sites are governed by their own privacy practices, not by this policy.
12 — Marketing Communications
We may use your personal information to send you marketing communications about our products and services where you have subscribed or where we have a legitimate interest to do so under POPIA.
You may opt out at any time by following the unsubscribe link in any marketing email, or by contacting our Information Officer. Opting out of marketing will not affect service-related communications necessary for the administration of your policy.
13 — Contact & Complaints
If you have any questions, concerns or requests relating to this policy or our handling of your personal information, please contact our Information Officer. We will acknowledge your request within a reasonable time and respond substantively within 30 days.
If you are not satisfied with our response, you have the right to escalate your complaint to the Information Regulator of South Africa at inforeg@justice.gov.za.