Commitment to Personal Data Privacy
Martello Re Limited and its affiliated entities (collectively “Martello Re”, “us” “our” and “we”) are committed to maintaining the security, confidentiality, and privacy of Personal Data. “Personal Data” means information associated with a specific identifiable individual (“Data Subject”) but does not include information about corporate or commercial entities. This Personal Data Privacy Notice documents our commitment to protecting Personal Data. All Martello Re employees must conduct their business in compliance with the Martello Re Personal Data Privacy Principles, as set out in this Personal Data Privacy Notice, and with all applicable Personal Data protection, privacy, secrecy, electronic communications, and confidentiality laws and regulations, and any other applicable laws or regulations to the extent that they relate to Personal Data privacy (“Data Privacy Laws and Regulations” or
“personal data privacy”).
Personal Data Privacy Principles
To ensure a consistent, accountable, global approach to data privacy compliance, Martello Re has implemented the following set of Personal Data Privacy Principles which establish good data privacy practices, demonstrate compliance with Data Privacy Laws and Regulations and outline Martello Re’s high-level commitments to handling and using the Personal Data it collects generates, holds and processes.
- Transparency: We will be clear and transparent about how we collect and use Personal Data, including providing a Data Subject with a statement of how we use their data where required.
- Fair and lawful usage: We will only collect, process and store Personal Data lawfully and where we have a legitimate reason to do so.
- Limited purposes: We will collect and process Personal Data for specified and lawful purposes and will not use it for further, incompatible purposes without first taking all steps necessary under applicable Data Privacy Laws and Regulations.
- Data minimization and adequacy: We will ensure collection, retention and processing of Personal Data is proportionate. We will strike an appropriate balance to ensure that we process sufficient data to carry on our business and achieve any specified lawful purpose, while making sure that we do not collect, retain or process excessive amounts of Personal Data.
- Data quality and accuracy: We will maintain appropriate standards of Personal Data quality and integrity and implement policies in respect of Personal Data accuracy, including taking steps to avoid becoming out of date where appropriate.
- Data security and retention: We will retain Personal Data securely, implement appropriate Personal Data retention policies, and we will dispose of Personal Data securely when it is no longer required. We will ensure that appropriate processes are put in place so only Martello Re employees with a business requirement to access such Personal Data are authorized and able to do so.
- Training and awareness: We will ensure that Martello Re employees with access to Personal Data are trained appropriately on their obligations regarding that Personal Data.
- Data Subject’s rights: We will ensure that the Data Subject’s rights are observed following applicable Data Privacy Laws and Regulations, including any timelines established.
- Third parties: Where we appoint a vendor or agent, we will require them to apply standards equivalent to the Martello Re Personal Data Privacy Principles. We will only disclose Personal Data to governmental or judicial bodies, law enforcement, agencies, or our regulators where this is allowed by applicable Data Privacy Laws and
Regulations or otherwise required by applicable laws and regulations. - Data transfers: Where we voluntarily transfer Personal Data to another Martello Re entity, third party or to another jurisdiction, we will ensure that the personal data transfer is lawful and that the recipient is required to apply the same, or equivalent, standards as the Martello Re Personal Data Privacy Principles.
Responsibility
Martello Re is responsible for Personal Data in its possession or control. We have designated an individual to be responsible for compliance with this Personal Data Privacy Notice and have adopted procedures to protect Personal Data, receive and respond to complaints, access requests and inquiries, train employees regarding policies and procedures and communicate our policies to a Data Subject as required. We will monitor ongoing developments in privacy legislation and make changes to this Personal Data Privacy Notice as required.
What We Collect
In addition to Personal Data provided to us through our employees or website, we may also collect publicly available information. The Personal Data we may hold includes:
- Contact information, including name, telephone number, address and email address.
- Occupation and employer details.
- Identification documents (which may include gender, nationality, photograph,
signature, date
Purposes
Martello Re comes into the possession of Personal Data as part of our operations.
We only collect and process Personal Data if it is lawful to do so, specifically where:
- it is required to fulfill a contract with a Data Subject;
- it is needed for us to comply with the law;
- we must perform a task in the public interest;
- it is necessary for our legitimate interests or the legitimate interests of a third party; or
- a Data Subject has provided us with their consent.
Martello Re may use Personal Data for the following purposes:
- to meet our regulatory, legal, and professional obligations;
- to establish and manage our relationship with a Data Subject;
- to monitor and manage the performance of our business operations;
- to manage conflicts of interest;
- to analyze performance and generate internal reports;
- to invoice and process payments;
- to process applications for employment;
- to monitor visitor traffic to and usage of the Martello Re website;
- to engage in business transactions;
- to prevent fraud;
- to undertake network and information security activities; and
- for any other purposes for which we have a Data Subject’s consent or for which
Martello Re or its third parties have a legitimate interest.
Martello Re collects and processes Personal Data to fulfill its contractual obligations with a Data Subject and meet our applicable statutory obligations.
Limits on Collection, Use, Retention and Disclosure of Personal Data
Martello Re does not retain any more Personal Data than we believe is necessary for any of the purposes set out in this Personal Data Privacy Notice or which is dictated by legal or professional requirements. We will destroy, erase or make anonymous documents or other records containing Personal Data as soon as it is reasonable to assume that the original purpose of obtaining and storing it is no longer being served by retention of the Personal Data or retention is no longer necessary for legal, business or professional purposes. We will take reasonable care when
destroying Personal Data to prevent unauthorized access
Transfer of Information
Transfers to Third Parties: Martello Re may, from time to time, use third parties in the course of conducting its business. Martello Re will use reasonable efforts to ensure that the terms of this Personal Data Privacy Notice or a similar policy bind third parties.
International Transfers: Data Subject Personal Data may be transferred to or accessed from countries that may not have data protection laws equivalent to those of a Data Subject country. Unless we have Data Subject’s consent to transfer Data Subject Personal Data, the transfer is necessary for the performance of a contract or is otherwise permitted by applicable data protection and privacy laws, we will only transfer Data Subject Personal Data
to a country considered to have an adequate level of protection. If such a country does not have equivalent privacy laws, Martello Re will ensure it has the appropriate safeguards. Safeguards may include binding corporate policies and procedures, standard contractual data protection clauses approved by applicable supervisory authorities, an approved employee code of conduct, or an approved certification mechanism.
Data Subject’s Rights
Right to Access: A Data Subject has the right to request and obtain from us the details of Data Subject Personal Data and how it is processed, including the purposes of processing, whether it has been disclosed to third parties, and how long we intend to hold on to the data. Data Subject information will be provided upon written request and we reserve the right to request authentication of identity in the event of such a request.
Right to Withdraw Consent: Where a Data Subject has consented to us processing Data Subject Personal Data, the Data Subject has the right to withdraw that consent at any time. If we consider that the withdrawal of such consent will impede our ability to provide any service to the Data Subject we reserve the right to terminate our service in the event of such a withdrawal.
Right to Accuracy/Rectification: A Data Subject has the right to request that we rectify inaccurate Personal Data concerning the Data Subject.
Right to Object To or Restrict Processing: A Data Subject has the right to object to or request
that we restrict processing their Personal Data if:
- they believe the Personal Data we hold about them is inaccurate;
- they believe the processing is unlawful but they oppose us erasing their Personal
Data; - we no longer need to process the Personal Data but they require it for the
establishment, exercise or defense of legal claims; or - they object to the grounds upon which we have determined that processing their
data is legitimate.
We are required to comply with their request unless the processing is to meet the conditions of a contract, under a legal obligation, to protect an individual’s vital interests, or otherwise permitted under applicable law.
Right to Object to Processing for Direct Marketing: A Data Subject has the right to object to processing their data for direct marketing purposes.
Right to Avoid Automated Decision Making: A Data Subject has the right not to be subject to a decision based solely on automated processing (i.e. a decision made without human involvement), including profiling, which produces legal or similarly significant effects concerning them, unless it is necessary for entering into, or the performance of, a contract between the Data Subject and Martello Re.
Right to Data Portability: A Data Subject has the right to receive their Personal Data in a machine-readable format and have that information transferred to another data controller, where technically feasible.
Right to Erasure (”Right to Be Forgotten”): A Data Subject has the right to request for us to erase their Personal Data. We will fulfill this request provided that there are no legal requirements for us to continue processing their Personal Data.
A Data Subject’s Right to Raise Concerns: Martello Re has procedures in place to receive and respond to complaints or inquiries about our policies and practices relating to the handling of Personal Data. If a Data Subject has any questions or concerns about their Personal Data or how Martello Re uses it, they can contact our Data Protection Officer at the address below.
If we are unable to address their concerns satisfactorily, they have the right to communicate with the relevant supervisory authority.
Accuracy
Martello Re may require a Data Subject to advise when their Personal Data changes, verify or update their Personal Data.
Safeguarding Personal Data
Martello Re protects the Personal Data in its custody or control by making reasonable security arrangements to prevent unauthorized access, collection, use, disclosure, copying, modification or disposal, per our information security policy. Confidentiality and security are not assured when information is transmitted through email or other wireless communication. Martello Re will not be responsible for any loss or damage suffered due to a breach of security or confidentiality when information is transmitted by email or wireless communication. We will take a Data Subject’s use of a particular mode of communication as permission for us to communicate with them using the same method of communication unless otherwise instructed by the Data Subject.
Contact Us
If a Data Subject has any questions about this Personal Data Privacy Notice or their Personal Data, they may direct their inquiries in writing to the Data Protection Officer at:
Martello Re
12 Church Street
Hamilton HM 11
Bermuda
Martello Re reserves the right to amend this Personal Data Privacy Notice.
Last updated June 2023.