Privacy Policy

Polaris Reinsurance Solutions FlexCo, Kärntner Ring 5-7, 1010 Vienna, Austria, company register number: fn 655745g, Handelsgericht Wien, (hereinafter also »Polaris Re« »us« or »we«) regards the lawful and correct treatment of personal information as important to our successful operations and to the protection of confidence of those with whom we deal. As such this statement will apply equally to all our website users, business partners and clients, irrespective of where they are based. This Privacy Policy describes how we as controller process and use the personal data that we receive from any such individuals and how to contact us if you have any additional questions regarding our processing of personal data. 

1. Our Commitment

We will ensure that all our employees obtain, use and disclose personal information lawfully and correctly. To this end we fully endorse and adhere to the principles and rules of data protection, as set out in particular in the EU General Data Protection Regulation and the Austrian Data Protection Act (hereinafter the »Acts«). We shall apply the Acts globally, except where part or all of any local law will prevail. 

We will:

  • observe the conditions in the Acts regarding the lawful, fair and transparent collection and use of personal data;
  • meet our legal obligations to specify the purposes for which we process personal data and the legal grounds for such processing;
  • collect and process adequate and relevant personal data, only to the extent that it is necessary to fulfil our operational needs or to comply with any legal requirement; 
  • ensure the accuracy of any personal data kept by us; 
  • ensure that personal data shall only be stored in a form which permits identification of data subjects if this in necessary for the purposes for which the personal data are processed; 
  • ensure that the rights of data subjects about whom personal data are held, can be exercised fully under the Acts;
  • take appropriate technical and organisational security measures to safeguard personal data and to ensure integrity and confidentiality of such data; 
  • ascertain that personal data is not transferred outside the European Union (hereinafter the "eu") and/or the European Economic Area (hereinafter the "eea") without suitable safeguards or agreement from the data subject. 

By disclosing your personal data to us using this website or in any other manner, you constitute acceptance to the collection, storage and processing of such information by Polaris Corporate Solutions GmbH in the manner set out in this Privacy Policy. 

2. Handling with Your Personal Data

In the following we provide you with information on which personal data we collect and how we use and handle your personal data when you use either our website or enter in a business relationship with us. We endeavour to ensure that you are informed as to: (i) the purpose for collecting the information, (ii) what the information will be used for, and (iii) the legal basis for any such processing of your personal information. 

Polaris does not use automated decision-making including profiling when handling with your personal data. 

2.1. Using our Website

When you call up our website, your browser will transfer certain data to our web server. The below mentioned personal data will be collected as is technical necessary to make our website available to you and to guarantee stability and security. The following data may be collected, briefly stored and used: IP address, data on time and duration of access, content of request (specific site), transferred volume of data, website requesting access, browser, language settings, version of browser software operating system and surface. 

This website does not use cookies. 

The legal basis for the handling of above personal data results from the fact that such handling is required to guarantee stability and security and to detect, prevent and investigate attacks on our website. 

Please note that where our website contains links to other websites, we are not responsible for the privacy practices and/or contents of those websites. This Privacy Policy applies solely to personal data collected through our own website.

2.2. Use of "Contact us" Option 

You can contact us directly via the contact form available on our website. Personal data gathered through this function include your name and e-mail address (both required) as well as telephone number, subject and any other personal data that you voluntarily provide in the message content.

We collect and process this data solely for the purpose of responding to your request. 

The legal basis for such processing is Article 6(1)(b) gdpr, as your request relates to pre-contractual measures.

2.3. Business Data 

Polaris Corporate Solutions GmbH provides specialty casualty insurance solutions to other business entities. by offering direct access to Lloyd’s capacities. Since we operate through a B2B business model, we only collect limited amount of personal data namely: (i) personal data of contact persons of our business partners such as name and surname, position, company, e-mail, telephone number and other data which are necessary to enter into a business relationship with such companies or to handle and managed claims/losses, may it be brokers, policyholders or other (re-)insurers; and (ii) personal data of insured parties that are natural persons. With respect to the former, we need to keep and process certain personal data of our business partners for normal contractual purposes. With respect to the latter, we only gather and process data that are necessary for a specific product and its coverage. As a key rule, Polaris collects your data only if we received it directly or indirectly from you (e.g. by a third party acting on your behalf) either pre-, during or after our contractual relationship with you. 

The legal basis for the handling of all such personal data results from the fact that handling is required to facilitate our business relationship with you and to provide you with a specific product, pursuant to Article 6(1)(b) gdpr. Such personal data will be used for our management and administrative use only. We will keep and use it to enable us to run the business and manage our relationship with you effectively, lawfully and appropriately. Failure to provide such data may prevent us from entering into or performing a contract with your company or from providing the requested services through your broker or representative.. 

Furthermore, we may gather some of your data, including further personal data, that is transferred to us voluntarily based on a claim and/or complaint procedure under an existing insurance policy. In such a case we endeavour to process such data only for the purpose of handling the claims procedure. The legal basis for such processing is either Article 6(1)(b) gdpr, where the processing is necessary for the performance of an insurance contract to which you are a party or beneficiary, or Article 6(1)(f) gdpr, where we pursue our legitimate interest in managing and resolving claims.

2.4. Direct Marketing

We may use personal information of our existing business partners such as brokers and clients to contact them from time to time by e-mail with details about other related insurance products or services offered by Polaris Corporate Solutions GmbH which we think will be of interest to them in order to provide them with a personalised service and to give them details of our related services / offers. 

Insofar your data is processed on the legal basis of legitimate interest as stated above, you shall have the right to object, on grounds relating to your particular situation, at any time to processing of your personal data. You have the right to object to the processing of your personal data for marketing purposes without giving reasons. Insofar other purposes apply we shall no longer process the personal data on this legal basis unless we demonstrate compelling legitimate grounds for the processing which overrides your interests, rights and freedoms or for the establishment, exercise or defence of legal claims. The storage or processing on other legal bases also remains unaffected by your objection. 

You may at any time with future effect object to processing of your data for direct marketing by informing us about your wish on any given contact details as follows: info@polaris-underwriting.com, +43 (0) 664 882 99 128 or any other given contacts on our website. 

3. Transfer of Personal Data

We may disclose your information to third parties outside the Polaris Corporate Solutions GmbH only to the extent necessary to provide our services, obtaining professional advice, or administer our business relationship with you.

Your personal data may, in accordance with legal requirements or for the purpose of fulfilling our contractual obligations, be disclosed to the following categories of recipients:

  • our capacity providers and any of the reinsurers;
  • insurance and reinsurance brokers;
  • competent authorities and regulators, where required by applicable laws or regulations;
  • external legal and professional advisors, where necessary for the establishment, exercise or defence of legal claims;
  • accountants, auditors and any other relevant third party performing outsourced functions on our behalf
  • it and cloud service providers, who process data on our behalf as data processors, solely for the purposes of hosting, technical support, or information security.

We do not sell, rent or trade your personal data for marketing purposes.

4. Retention Periods 

We store your personal data as long as it is necessary to fulfil the purpose for which the data have been collected. This means that we permanently delete or efficiently anonymise your personal data when such data are no longer necessary to process your request or an order, or to administrate our client relationship. We will, in any case, retain your personal data for as long as there are statutory retention obligations or potential legal claims are not yet timebarred.

All business data such as data provided to us based on your inquiry or due to our business relationship with you are stored as long as it is necessary to facilitate our services and to foster our business relationship with you. However, some data may be stored for longer periods of time due to our legal obligation based on Austrian legal order (e.g. business data, accounting and financial data pursuant to § 212 Austrian Commercial Code (ugb) and §132 Austrian Federal Fiscal Code (bao) for seven years). Data gathered from insurers and insured persons for the purpose of concluding insurance policies may be stored for the duration of statutory limitation periods to file claims under such policies or in case of any potential claim, throughout the claims procedure (e.g. pursuant to Austrian Civil Code (ABGB) and Austrian Insurance Act (VersVG)). 

5. Processing of Data Outside the eu / the eea  

Your data will in part also be processed in countries outside the eu and/or the eea, which may have a lower data protection level than the European countries (for example in cases where our clients' brokers are situated in countries outside the  eu / the  eea or in cases of our cloud-based providers). 

In such cases, we will ensure that a sufficient level of protection is provided for your data, e.g. by concluding specific agreements with our contractual partners that use standard contractual clauses approved by the European Commission to ensure a sufficient level of protection for your personal data (copy available on request), or we will ask for your explicit consent to such processing. 

Your personal data will be transferred to the United Kingdom (uk) based on the European Commission’s adequacy decision (eu) 2021/1772. Under this decision, the UK is considered to provide an adequate level of data protection equivalent to that in the eu, which allows the transfer of personal data without the need for additional safeguards under Article 45 GDPR. Should this adequacy decision be revoked, we will implement appropriate safeguards in accordance with Article 46 GDPR.

We commit to take appropriate measures to protect all personal data transferred to any such third countries, in accordance with applicable data protection Acts and as stated above. 

6. Information Regarding Data Subjects’ Rights

The following rights are in general available to data subjects according to applicable Acts: 

  • right of information about personal data stored by us (for example the right to request information on how personal data are processed and what personal data are processed about you); 
  • right to data access and to data portability (you are entitled to request the personal data that are processed based on your consent or on a contract in a machine readable format which you are entitled to transfer directly to another data controller); 
  • right to request rectification of inaccurate or incomplete personal data, 
  • right to erasure / right to be forgotten (however, please note that deletion could mean that we cannot process requests or orders placed by you), 
  • right to restriction of processing in particular where (i) you contest the accuracy of your personal data; (ii) the processing is unlawful and you oppose the erasure of your personal data; (iii) we no longer need personal information for the purposes of the processing, but you require the information for the establishment, exercise or defence of legal claims; or (iv) you have objected to the processing and pending the verification whether our legitimate grounds override yours;
  • right to object to a processing for reasons of our own legitimate interest, public interest, or profiling, unless we are able to proof that compelling, warranted reasons superseding your interests, rights and freedom exist, or that such processing is done for purposes of the assertion, exercise or defence of legal claims; 
  • right to file a complaint with a relevant data protection authority. For Austria: Österreichische Datenschutzbehörde, Wickenburggasse 8, 1080 Wien, telephone: +43 1 52 152-0, e-mail: dsb@dsb.gv.at.

If processing of personal data is based on your consent, you have the right to revoke your consent to the collection, processing and use of your personal data at any time. The withdrawal will not affect the lawfulness of the processing carried out before you withdraw your consent. 

There may be conditions or limitations to your rights. It is therefore not certain for example you have the right of data portability in the specific case - this depends on the specific circumstances of the processing activity. 

Please note that we may ask you to verify your identity before taking further action on your request. 

7. Contact 

If you still have any concerns about data privacy or security, the handling of your personal data or you wish to exercise any of your above described rights, please contact us at your earliest convenience on info@polaris-underwriting.com, +43 (0) 664 882 99 128 or to any other given contacts on our website. 

8. Amendment of Privacy Policy 

We reserve the right to modify this Privacy Policy from time to time. Changes to our Privacy Policy will be published on our website and will become effective upon publication on our website until revoked or modified. We therefore recommend that you regularly visit the site to keep yourself informed on possible updates. Additionally, we will provide our business partners and clients with a notice of the modification by e-mail. If you do not stop sharing with us your personal data before the date of the modified Privacy Policy becomes affective, your continued access to use our services will constitute acceptance of the modified Privacy Policy.