Privacy Policy

We are committed to protecting your privacy. We will use any data we may collect about you lawfully and in accordance with current data protection laws.

If you'd like a copy of our privacy notice for your records, you can here.

1. Who we are

We're Hastings Group Holdings Plc (also referred to as 'Hastings', 'we', 'us' or 'our') and our registered office is at Conquest House, Collington Avenue, Bexhill-on-Sea, East Sussex TN39 3LW.

Under data protection laws we are a ‘Data Controller.’

For customers: Hastings Insurance Services Limited has a separate privacy notice which can be found here.

2. Information we collect from or about you

We'll collect and process information about you from a number of sources, including details:

You give us:

  • By registering to use our site.
  • By completing forms to subscribe to our services or receive our materials.
  • By email or phone for queries. 

We get from your use of our website:

Information collected may include:

  • Personal details such as your name (including former names), contact details (e.g. your address and former addresses, telephone numbers and email address).
  • Location details.
  • Information about how you access our website, including the website you visited before landing on our websites. We automatically receive the IP address of your computer, or the proxy server that you use to access the Internet and this may include information to identify your browser or device to analyse web traffic. 
  • Your marketing preferences.

3. How we use your information

We must have a legal reason to use your personal data, we obtain your personal data for the purposes set out below:

  • Where you have given consent we might send you communications that contain result financial updates and news updates about the company or offers that we think might be of interest to you or that you have requested.
  • To ensure the content from our site is presented in the most effective manner for you and for your computer, and to improve your digital journey (legitimate interest).

Your personal data includes our legitimate business purposes and commercial interest in keeping our records updated, being efficient about how we fulfil our legal and contractual duties. You have a right to object to this processing, as detailed in (Section 6). Where we have relied on your consent to process your data, you can withdraw at any time to stop the processing as detailed in (Section 6). You can opt out of any marketing communications at any time by clicking the unsubscribe link in the email.

4. Who we share your information

In order to provide you with our services we will have to share your information with the following: 

  • Third party service providers who support the operation of our systems and website.
  • Third party service providers who help us deliver the services we provide to you.
  • For regulatory or legal purposes or to protect our rights, or other parties.
  • To respond to requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities.

We use Campaign Monitor, to send out alerts to your email address. Information about their security and privacy notice can be found here: https://www.campaignmonitor.com/trust/

Sending data outside the EEA

We may transfer personal data to countries which have reached Adequacy Decisions with the European Commission, or are part of the Privacy Shield in the US.

5. How long will we store your information?

We will retain an your personal data for so long as the purpose you have provided it for still exists, except where a longer retention period is required or permitted by law or industry standards.

6. Your rights an how to contact us

You have the right to:

  • a copy of the personal data we hold for you (please see Section 7).
  • have your data corrected if it’s wrong or incomplete. 
  • have your data deleted or removed if it’s no longer needed. 
  • restrict the processing of your personal data.
  • withdraw any permission you’ve given in respect of your personal data (including marketing). You can unsubscribe email links or by contacting us (contact details below). 
  • data portability - to keep and re-use your data in an electronic form for your own purposes or to ask we pass the information to another organisation.
  • get human intervention on the part of the controller, where you are subject to a decision based solely on automated processing, including profiling, which has a significant effect on you, to express your point of view and/or to contest the decision – We do not use automated decision making.
  • object where we’re processing your information on the grounds of it being in our legitimate interests to do so.

We will uphold your rights to the best of our abilities; however, data protection laws allow us to continue to process your personal data if we have a legitimate reason to do so. For example, if data is needed for legal requirement.

Our data protection team is responsible for overseeing questions in relation to this privacy notice. You can contact them at:

Data Protection Team

Email address: dataprotection@hastingsdirect.com 
Postal address: Hastings Group Holdings Plc, Conquest House, Collington Avenue, Bexhill-on-Sea TN39 3LW

7. Subject Access Request

You have the right to obtain:

  • have confirmation your data is being processed.
  • access to your personal data.
  • other supplementary information, which is referred in this privacy notice.

You can access your personal data we hold by filling in this form or by writing to us at this address:

Data Protection Team

Email address: dataprotection@hastingsdirect.com 
Postal address: Hastings Insurance Services Limited, Conquest House, Collington Avenue, Bexhill-on-Sea TN39 3LW

8. Complaints

If you’re not happy with the way your personal data is held or processed, please tell us using the contact details above.

You can complain to the Information Commissioners Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). The ICO will usually require you to have approached us first to try to resolve the matter.

9. Notice Updates

We may update or amend this privacy notice from time to time to comply with the law or meet changing business requirements. Any changes to this policy will be posted on this page.

This version was last updated on 7 June 2018. Historic versions are archived and you can get these by contacting us.

10. Glossary

‘Data Protection Laws’" means the General Data Protection Regulation ((EU) 2016/679), the Data Protection Act 2018 and any national implementing laws, regulations and secondary legislation, as amended or updated from time to time, in the UK.