Insurance

We know insurance can be confusing - let us help you find the right plan that best suits your needs. It's quick and easy, and you'll be on your way in minutes!

Find Your Plan

Student

Insurance

Your privacy is important to us and we (IMG®) are committed to maintaining the privacy of personal data obtained in the course of our business activities and complying with applicable laws and regulations (including the EU and UK General Data Protection Regulation - GDPR) regarding the processing of data. Our privacy policies tell you what personal data we collect, why we collect it, what we do with it, as well as what rights you have over your data. You can view our full privacy policies by selecting the appropriate policy below. Please contact us at dpo@imglobal.com if you have any questions.

IMG, Inc – Privacy Policy

Effective: July 2025

This statement (the “Privacy Policy”) applies to IMG websites, services, products and applications that collect data and display these terms, owned and operated by International Medical Group®, Inc. and its subsidiaries (collectively “IMG”, “IMG®”, “we”, “us”, or “our”). Please note that International Medical Group Limited and IMG Europe AB operate in accordance with the IMG Limited and IMG Europe AB privacy policies which you can find on our privacy policy landing page.

At IMG, we are committed to earning your trust by respecting and protecting the privacy of the personal information you provide to us online. The following describes how IMG collects, uses, shares and secures the personal information you provide, as well as the human resources data of our employees. It also describes your choices regarding use, access, and correction of your personal information.

If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at:
https://feedback-form.truste.com/watchdog/request .

Under certain conditions, you may be entitled to invoke binding arbitration regarding your privacy concerns when other dispute resolution procedures have been exhausted.

Collecting Your Information

IMG collects many kinds of information in order to operate effectively and provide you the best products, services and experiences we can. Regardless of the source, we believe it’s important to treat the personal information with care and to help you maintain your privacy.

In correlation with your relationship with us (e.g. consumer insured or policyholder; producer or appointed representative; or other person relating to our business), we may collect the following personal information from you and your dependents:

  • Name; gender; marital status; citizenship; date of birth; physical attributes; activity records such as exercise routines; current or former medical condition and health status including other factors affecting insurability; relationship to the policy holder, insured, or claimant; contact information such as email, mailing, or alternate address, telephone, mobile, fax number; affiliated company or sponsoring organization; financial information such as payment card number and billing address; government issued ID’s such as social security number; telephone recordings of calls to our representatives and call centers; unique identifiers such as certificate, group, insured or member ID, producer, and ITIN number; education, qualifications, and previous experience for job applicants.

We may also collect from you, information about your contacts such as your beneficiaries; your medical practitioner’s name, address, and contact information; to fulfill and/or process a claim. When you provide us with personal information about your contacts we will only use this information for the specific reason for which it is provided. If you believe that one of your contacts has provided us with your personal information and you would like to request that it be removed from our database, please contact DPO@imglobal.com .

We may receive information about you from third parties from whom we have obtained data, and combine this data with information we already have about you. This information helps us to update, expand and analyze our records and provide products and services that may be of interest to you. If you provide us personal information about others, or if others give us your information, we will only use that information for the specific reason for which it was provided to us. Example of the type of personal information that may be obtained from third parties may include, purchased marketing data about our customers from third parties that is combined with information we already have about you, to create more tailored advertising and products.

As is true of most websites, we gather certain information automatically. This information may include Internet protocol (IP) addresses, browser type, Internet service provider (ISP), referring/exit pages, the files viewed on our site (e.g., HTML pages, graphics, etc.), operating system, date/time stamp, and/or clickstream data to analyze trends and to administer the site.

Contact information for IMG’s Data Protection Officer:

9200 Keystone Crossing
Suite 800
Indianapolis, IN USA 46240
1-800-628-4664
DPO@imglobal.com

Browser Controls for “Do Not Track” and Tracking Protection

Some IMG browsers have incorporated “Do Not Track” features. Most of these features, when turned on, send a signal or preference to the web sites you visit indicating that you do not wish to be tracked. Those IMG sites may continue to engage in activities you might view as tracking even though you have expressed this preference, depending on the sites’ privacy practices.

Most web browsers have a feature related to tracking protection that helps prevent the websites you go to from automatically sending details about your visit to third-party content providers. When you add a tracking protection list, the browser may block third-party content, including cookies, from any site that is listed as a site to be blocked. By limiting calls to these sites, the browser will limit the information these third-party sites can collect about you. And when you have a tracking protection list enabled, certain browsers may send a do not track signal or preference to the web sites you visit. For more information about Tracking Protection Lists and how to find them, please see your browser’s privacy statement or help documentation.

Our Use of Cookies and Similar Technologies

IMG uses cookies and similar technologies for several purposes. Please see our Cookie Policy located here

How We Use Your Personal Information

IMG uses the personal information we collect to operate, improve and personalize the products and services we offer. Personal information collected through one IMG service may be combined with information collected through other IMG services to give you a more consistent and personalized experience in your interactions with us. We may also supplement this with information from other companies. For example, we may use services from other companies to help us derive a general geographic area based on your IP address in order to customize certain services to your geographic area.

For IMG services, we use this information to provide you with relevant search results. We also use the information we collect to maintain and improve the quality, security and integrity of our products and services. For example, we may use this information for research purposes and to improve the relevancy of search results. This information is also necessary in order to detect and protect against security threats such as botnet attacks, click fraud, worms, and other threats. We also may use the information to communicate with you, for example, informing you when an insurance contract is ending, letting you know when updates are available or letting you know when you need to take action to keep your account active.

We also may use this information to assist in the fulfillment of the insurance product you purchased or the processing and administration of any insurance claims that you may submit, including, but not limited to working with providers, handling appeals, and resolving complaints. This information may be securely transmitted to third party business partners we have engaged to adjudicate, reprice, fulfill and pay claims. For a complete list of the third parties with whom we have or may in the future safely and securely share your personal information, please contact the Data Protection Officer (DPO).

IMG provides many of our sites and services free of charge because they may be supported by advertising. In order to make these services widely available, the information we collect may be used to help improve the advertisements you see by making them more relevant to you. For example, we may use search query data for the purpose of personalizing the ads we display to you as you use our services or those of our advertising partners. The search terms you enter are categorized and certain user segments are inferred based on those terms. For example, if you search on terms associated with sports, we may associate a “sports segment” with the unique identifier contained in your cookie, and you will then be more likely to see ads related to sports.

IMG acknowledges that you have the right to access your personal information. IMG has no direct relationship with the individuals whose personal data it processes. An individual who seeks access, or who seeks to correct, amend, or delete inaccurate data should direct their query to IMG’s Data Protection Officer. If requested to remove data we will respond within a reasonable timeframe. In certain circumstances we may be required by law to retain your personal information or may need to retain your personal information in order to continue providing a service.

When you sign into a site or service using your IMG account, we collect certain information in order to verify your identity on behalf of the site or service, to protect you from malicious account usage, and to protect the efficiency and security of the IMG account service. If you received your account from a third party, like an employer, a producer, spouse, or the legal representative, that third party may have rights over your account, including the ability to reset your password, view your account usage or profile data, read or store content in your account, and suspend or cancel your account. In these cases, you are subject to the IMG terms of use and to any additional terms of use from that third party. If you are the administrator on behalf of an employer or producer and have provided your users with IMG accounts, you are responsible for all activity that takes place within such accounts.

All sites or services that offer or market IMG’s products are required to have a posted privacy statement, but we do not control or monitor the privacy practices of external sites, and their privacy practices will vary. You should carefully review the privacy statement for each site you sign into in order to determine how each site or service will use the information it collects.

Creating an IMG Account - Some of our websites allow you to create an IMG account by providing an email address, a password and other “account proofs,” such as an alternate email address, a phone number, and a question and secret answer. We will use your “account proofs” for security purposes only - for instance, to verify your identity in the event that you cannot access your IMG account and need assistance, or to reset your password if you cannot access the email address associated with your IMG account. Some services may require added security, and in those cases, you may be asked to create an additional security key. The email address and password that you use to sign up for your IMG account are your “credentials” that you will use to authenticate with our network.

You can use an email address provided by a third party (such as those ending in gmail.com or yahoo.com) when signing up for your IMG account. Upon creating an IMG account, we may send you an email asking you to verify that you are the owner of the email address associated with your IMG account. This is designed to verify the validity of the email address and help prevent email addresses from being used without the permission of their owners. Thereafter, we may use that email address to send you communications relating to your use of IMG products and services; we may also send you promotional emails about IMG products and services as permitted by local law.

Accessing Your Personal Information and Search History

When using a web browser, you can access and manage your information, including Search History, through the preferences page. You may clear your search history from appearing on the site by following the steps provided in see your search history. Clearing your history removes it from the Search History and prevents that history from being displayed on the web browser, but does not delete information from our standard search logs, which are retained and are replaced with artificial identifiers.

Upon request IMG will provide you with information about whether we hold any of your personal information. You may access, correct, or request deletion of your personal information by logging into your account or by contacting  DPO@imglobal.com . We will respond to your request within a reasonable timeframe. In certain circumstances we may be required by law to retain your personal information, or may need to retain your personal information in order to continue providing a service.

Children

Our websites are not structured to attract children. Accordingly, we do not solicit or knowingly collect any personal information from anyone who visits our websites that we know to be under 13 years of age. If we are made aware that information is or has been submitted by or collected from a child below 13, we will immediately delete their personal information. This provision does not apply to insureds, customers or other individuals on behalf of whom we provide services as a result of a customer or an insured relationship.

Other Important Privacy Information

Below you will find additional privacy information you may find important. Much of this describes common practices that we want you to know about and some of this is just stating the obvious (for example, we will disclose information when the law requires it). Please keep in mind that this information is not a complete description of our practices – this is all in addition to the other, more specific information contained in the privacy statements, agreements and releases relating to each IMG product and service you use.

Sharing or Disclosing Personal Information

Except as described in this privacy statement, we will not disclose your personal information to a third party without your prior consent and as permitted under applicable laws.

We may share your information with third parties who provide services on our behalf to help with our business activities. These companies are authorized to use your personal information only as necessary to provide these services to us. When we share information with these other companies to provide services for us, they are not allowed to use it for any other purpose and must keep it confidential. These services may include:

  • Adjudicating and managing the claims process
  • Payment processing to healthcare providers
  • Providing customer service
  • Sending marketing communications (subject only to your express consent)

In certain situations, IMG may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. We may also disclose your personal information as required by law, such as to comply with a subpoena or other legal process, when we believe in good faith that disclosure is necessary to protect the rights or property of IMG, our insureds, clients or our customers, including enforcing the terms governing your use of the services, protect your safety or the safety of others, investigate fraud, or respond to a government request. If IMG is involved in a merger, acquisition, or sale of all or a portion of its assets, you will be notified via email and/or a prominent notice on our website, of any change in ownership, uses of your personal information, and choices you may have regarding your personal information.

In addition to any sharing described in the privacy statement for the product or service you are using, IMG may share or disclose personal information with other IMG controlled subsidiaries and affiliates. For your (opt-out) choices on this type of sharing, please contact DPO@imglobal.com .

We may also share some search query data with selected third parties for research purposes. Before we do so, we remove all unique identifiers such as IP addresses and cookie IDs from the data. We also run the data through a process designed to remove identifiable information that users may have included in the search terms themselves (such as social security numbers or credit card numbers). Additionally, we require these third parties to keep the data secure and not to use the data for any other purposes.

Protecting the Security of Personal Information

IMG is committed to protecting the security of your personal information. We use a variety of generally accepted standards of security technologies and procedures to help protect the personal information submitted to us, from unauthorized access, use or disclosure both during transmission and once it is received. For example, we store the personal information you provide on computer systems that have limited-role based access and are in controlled facilities. When we transmit highly confidential information (such as a credit card number or password) over the Internet, we protect it through the use of encryption, such as the Secure Socket Layer (SSL) protocol.

If a password is used to help protect your accounts and personal information, it is your responsibility to keep your password confidential. Do not share it. If you are sharing a computer, you should always log out before leaving a site or service to protect access to your information from subsequent users. If you have questions about the security of your personal information, you can contact  DPO@imglobal.com .

We may retain your information for as long as your account is active or as needed to provide you services, comply with our legal obligations, resolve disputes, and enforce our agreements.

Storage and Retention - We store search terms (and the cookie IDs associated with search terms) separately from any account information that directly identifies the user, such as name, e-mail address, or phone numbers. Further, we have built-in technological and procedural safeguards designed to prevent the unauthorized connections of this data.

You may sign-up to receive email or newsletter or other communications from us. If you would like to discontinue receiving this information, you may update your email preferences by using the “Unsubscribe” link found in emails we send to you or at your member profile on our website or by contacting DPO@imglobal.com .

We display personal testimonials of satisfied customers on our website in addition to other endorsements. With your consent, we may post your testimonial along with your name. If you wish to update or delete your testimonial, you can contact DPO@imglobal.com .

Our website(s) offers publicly accessible blogs or community forums. You should be aware that any information you provide in these areas may be read, collected, and used by others who access them. To request removal of your personal information from our blog or community forum, contact DPO@imglobal.com . In some cases, we may not be able to remove your personal information, in which case we will let you know if we are unable to do so and why.

Our website(s) includes links to other websites whose privacy practices may differ from those of IMG. If you submit personal information to any of those websites, your information is governed by their privacy policies. We encourage you to carefully read the privacy policy of any website you visit.

You may access IMG services when using other non-IMG sites or services. These sites may use the IMG API. You should refer to the privacy policy of the site for any questions about their information collection and usage practices.

California Consumer Privacy Act

IMG does not sell your personal data to third parties and will not do so. Any data that IMG processes on your behalf is subject to your express consent or relates to services that you have asked us to perform on your behalf.

You may access, correct, or request deletion of your personal information by logging into your account or by contacting DPO@imglobal.com . We will respond to your request within a reasonable timeframe. In certain circumstances we may be required by law to retain your personal information or may need to retain your personal information in order to continue providing a service. If you believe you have other rights under the California Consumer Privacy Act or have other questions regarding your data, please contact IMG’s Data Protection Officer (DPO).

Changes to Our Privacy Statements

We will occasionally update our privacy statements to reflect customer feedback and changes in our services. When we post changes to a statement, we will revise the "last updated" date at the top of the statement. If there are material changes to the statement or in how IMG will use your personal information, we will notify you either by prominently posting a notice of such changes before they take effect or by directly sending you a notification (sent to the e-mail address specified in your account). We encourage you to periodically review the privacy statements for the products and services you use to learn the latest information on our privacy practices.

How to Contact Us

Questions about this Statement or about IMG’s handling of your information, please contact DPO@imglobal.com , or
International Medical Group, Inc.
9200 Keystone Crossing
Suite 800
Indianapolis, IN USA 46240

IMG Limited & IMG Europe AB - Privacy Policy

Effective: July 2025

This Privacy Notice (Notice) applies to websites, services, products and applications that collect data and display these terms, owned and operated by International Medical Group Limited and IMG Europe AB (collectively “IMG”, “IMG®”, “we”, “us”, or “our”).

Personal Data is any information about an individual who is identified or identifiable. We value your privacy and respect your rights in relation to your Personal Data. This Notice lets you know how we use your Personal Data and provides details of your rights under data protection laws.

It is important that you read this Notice together with any other privacy notices we may provide so that you are fully aware of how and why we are using your Personal Data. This Notice supplements all other privacy notices provided by us and is not intended to override them.

Who does this Notice relate to?

This Notice provides information about how we collect and use Personal Data and is for anyone:

  • who purchases (or contact us about purchasing) our products and services;
  • who uses third party assistance services under an insurance policy where we are the service provider for those services e.g., services such as arranging clinical care, claims handling, evacuation services, repatriation
  • who works with us, such as intermediaries or suppliers; and
  • who uses our website

Our website is not intended for children and we do not solicit or knowingly collect any personal information from children without the consent of the child’s parent/ guardian. We may also process your Personal Data where we are appointed to handle medical insurance claims on behalf of your insurer. Where we handle claims on behalf of an insurer, we are not the controller of your Personal Data and this Notice does not apply. The relevant insurer and/or their managing general underwriter will be the controller of your Personal Data and you should check their privacy notices to find out about how your Personal Data is handled.

Who is the controller of your Personal Data?

IMG is the controller for your Personal Data (referred to as “IMG”, "we", "us" or "our" in this Notice).

What happens if this Notice is updated or your Personal Data changes?

This Notice was last updated on the date stated at the beginning of the Notice. We will publish any changes to this Notice on our website and where necessary we will also send you a copy via post or email. It is important that the Personal Data we hold about you is accurate and up to date. Please keep us informed if your Personal Data changes during your relationship with us.

What Personal Data do we collect about you?

We collect, use, store and transfer different kinds of Personal Data about you which we have outlined below. The terms below are mainly used to explain why we use the Personal Data in the way we do:

  • Claim Data - Information relating to claims made by you under your insurance policy.
  • Communication Data - The channel and method by which we communicate with you and the contents of communications with you.
  • Contact Data - Correspondence addresses, personal and professional email addresses, details of the company you work for, contact information in social media profiles, personal and professional telephone numbers and business cards.
  • Credit Check Data - Information needed for the carrying out of credit checks, including name, date of birth, address history, bank account details, income, outstanding debts, employment details, income and credit history.
  • Criminal Data - Information relating to criminal offences and convictions are collected when carrying out anti-fraud or anti-money laundering checks, or other background screening checks to prevent crime.
  • Financial Data - Bank account details.
  • Identity Data - Name, marital status, title, date of birth, gender, national insurance number, passport or identity card details and driving licence details.
  • Marketing Data - Your preferences in receiving marketing from us.
  • Medical Data - Information about your health, medical conditions and medical treatment received or planned.
  • Policy Data - Information relating to your medical insurance policy.
  • Professional Data - Information about your professional life, including your role, expertise and experience, any regulatory licences you hold and solvency status
  • Special Category Data - Any information about you which relates to your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, your health as well as genetic data and biometric data for the purpose of uniquely identifying you
  • Transaction Data - Details about payments to and from you and other details of services we have provided to you and details of services you provide to us where you are a supplier or provider of services.
  • Technical Data - Internet protocol (IP) address, browser type and version, time zone setting, location, browser plug-in types and versions and operating system and platform.
  • Usage Data - Information about how you use our website and services.

What happens if you don’t provide us with your Personal Data?

Where we need to collect Personal Data because: (a) we are complying with a legal or regulatory obligation; or (b) we need it under the terms of a contract we have with you; or (c) the information is necessary to enter into a contract with you, and you fail to provide that Personal Data when requested, we may not be able to perform the contract we have or are trying to enter into with you. In this case, we may have to decline to provide services to you or enter into a contract with you, but we will notify you if this is the case at the time.

How do we collect Personal Data about you?

We collect Personal Data from and about you using the following methods:

  1. Direct interactions - We collect your Personal Data from you when through our direct interactions with you in person either online or offline. For example:
    • by telephone (where we may record calls for quality assurance purposes);
    • via our website (including webchats and virtual assistants);
    • by using our portals and apps;
    • by using our products and services;
    • by completing application or other forms; and
    • by post or email.
  2. Automated technologies or interactions - As you interact with our website, we automatically collect Technical Data. We collect this Personal Data by using cookies, server logs and other similar technologies. You can see a copy of our cookie notice by clicking here .
  3. Third parties - We receive Personal Data about you from third parties such as
    • insurance brokers or aggregators who introduce you to us as a prospective customer;
    • suppliers who are providing services to you, for example medical practitioners and hospitals;
    • your employer if they are responsible for your insurance policy or if you are a supplier or broker who interacts with us;
    • individuals who have a policy under which you are insured, for example you are a named dependant on your spouse’s policy; and
    • social media and other public sources where fraud is suspected.

What do we use your Personal Data for and why?

We will only use your Personal Data where the law allows us to. Most commonly, we will use your Personal Data in the following circumstances:

  • to comply with a legal or regulatory obligation for example our obligations to carry out anti-money laundering checks under the Proceeds of Crime Act 2002 and the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017;
  • where it is in our legitimate interest or that of a third party such as an insurer. We will always make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your Personal Data for our/ a third party’s legitimate interest;
  • where we have a contract with you and use of your Personal Data is necessary for performance of the contract or to take steps at your request before entering into such a contract;
  • where it is in your vital interests for us to use your Personal Data, for example to ensure you receive the correct medical treatment; and
  • generally, we do not rely on consent as a legal basis for processing your Personal Data. If we do, you can withdraw your consent at any time by following the opt-out links on any marketing communications sent to you or by contacting us at DPO@imglobal.com .

The table set out in Appendix A explains the ways in which we use your Personal Data and the legal basis which is used.

Some information that we process is Special Category Data, such as Medical Data. When we process Special Category Data additional obligations apply and we are only allowed to process this data in limited circumstances. We are permitted to process Special Category Data to administer your insurance policy and to provide you with medical support, to enable the performance of your insurance policy and/or to provide you with medical or other services.

How do we use your Personal Data for marketing and how can you opt out?

We may use your Identity, Contact, Communications Data, Technical and Usage Data to form a view on what we think you may want or need, or what may be of interest. This is how we decide which products, services and offers may be relevant for you. You will receive marketing communications from us if we have appropriate consent to send you marketing communications.

You can ask us to stop sending you marketing communications at any time by following the opt-out links on any marketing communications sent to you or by contacting us at DPO@imglobal.com .

What are your rights under data protection law?

You have a number of rights in relation to how we use your Personal Data; these are set out below in more detail:

  • Access - This enables you to receive a copy of the Personal Data we hold about you.
  • Rectification - This enables you to have any incomplete or inaccurate Personal Data corrected.
  • Erasure - This enables you to ask us to delete Personal Data where there is no good reason for us continuing to process it. Note, however, that we may not always be able to comply with your request for erasure because of specific legal reasons which will be notified to you, if applicable, at the time of your request.
  • Objection - This enables you to object to the processing of your Personal Data where we are relying on our legitimate interests (or those of a third party) and you object to processing on this ground as you feel the processing impacts your fundamental rights and freedoms. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms. You also have the absolute right to object where we are processing your Personal Data for direct marketing purposes.
  • Restriction - This enables you to ask us to suspend the processing of your Personal Data in the following scenarios: (a) where you want us to establish the accuracy of the Personal Data; (b) where our use of the Personal Data is unlawful but you do not want us to erase it; (c) where you need us to hold the Personal Data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) where you have objected to our use of your Personal Data but we need to verify whether we have overriding legitimate grounds to use it.
  • Portability - This enables you, in certain situations, to request transfer of your Personal Data to you or to a third party. We will provide your Personal Data (to you, or a third party you have chosen) in a structured, commonly used, machine-readable format.
  • Your right to withdraw consent - If we are relying on consent to process your Personal Data, you can withdraw your consent at any time, however, this will not affect the lawfulness of any processing carried out before you withdraw your consent

If you wish to exercise any of the rights set out above, please contact us at DPO@imglobal.com .

Before we can process your request, we may need information from you to help us confirm your identity. This is a security measure to ensure that rights are being exercised by the correct person and to ensure that Personal Data is not disclosed to, erased by or altered by any person who has no right to do so.

Who do we share your Personal Data with and where do we transfer your Personal Data?

We may share your Personal Data with third parties for the purposes set out in Appendix A found below

Some of the third parties are based outside the UK and/or the European Economic Area (EEA) so their processing of your Personal Data will involve a transfer of Personal Data outside the UK and/or the EEA. Whenever we transfer your Personal Data out of the UK and/or the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is in place:

  • We may transfer your Personal Data to countries that have been granted an adequacy decision by the European Commission and/or an adequacy regulation by the UK Secretary of State (as applicable) confirming that the country in question provides an adequate level of protection for Personal Data; or
  • We may use specific contracts approved by the European Commission and/or the UK (as applicable) which ensure that Personal Data is adequately protected. When we rely on this measure, we will conduct risk assessments and take appropriate measures to ensure that the third-party can comply with the provisions of such contracts and we have confirmed that the country to which the Personal Data is transferred provides enforceable data subject rights and effective legal remedies for data subjects are available there; or
  • We may transfer your Personal Data to a country where you are located to enable the provision of services to you under your insurance policy. For example, if you require medical support or evacuation services in a country outside the UK or EEA. Where we transfer your Personal Data outside the UK or EEA for these purposes, we are allowed to do so because it is necessary for the performance of your insurance contract.

Where we transfer your Personal Data to the United States under paragraph 12.2.1, we do so in accordance with the UK Extension to the EU-US Data Privacy Framework which ensures that the transfer is protected by safeguards including adherence to principles governing security, data integrity, and transparency in processing. IMG holds a certification under this framework which demonstrates our commitment to maintaining the privacy and security of Personal Data when conducting cross-border transfers.

Please see below for details of the third parties we share your Personal Data with and where we send your Personal Data:

  • other companies in our group who support us with providing our services;
  • medical practitioners and support staff who provide medical assistance to you and other service providers who provide support to you under your insurance policy, such as commercial ambulance providers, air ambulance providers;
  • our external clinical advisers who provide advice to us on medical issues in specialist cases;
  • insurance brokers;
  • the insurer with whom you hold your insurance policy;
  • service providers who provide IT and systems administration services and access to platforms we use for operational purposes to run our business, including payment processors
  • professional advisers including lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, insurance and accounting services to us;
  • HM Revenue & Customs, regulators and other authorities based in the UK who require reporting of processing activities in certain circumstances, for example to ensure we are complying with legal and regulatory obligations;
  • third parties who require access to the Personal Data we process for the purposes of the prevention or detection of crime or for the purposes of legal proceedings;
  • external auditors who provide auditing and similar compliance services to us to ensure we are complying with our legal and regulatory obligations when we provide services to you, process your Personal Data or where we are certified under any relevant schemes or certifications;
  • financial providers who provide us with financial services and facilities; and
  • if there is a change of ownership or control of our business, such as a merger, restructure, sale of the business or its assets or we acquire a new business, your information may be shared with the parties involved in this change. We will anonymise the information where possible and any recipients will be bound by contractual terms to keep such information confidential.
  • We require all third parties to respect the security of your Personal Data and to treat it in accordance with the law and the terms of the contract we have in place with them where they are our third-party service providers.

    Please contact us at DPO@imglobal.com if you want further information on the specific mechanism used by us when transferring your Personal Data out of the UK and/or EEA or you would like more information about the third parties we share your Personal Data with.

How do we keep your Personal Data safe?

We have appropriate security measures in place to prevent your Personal Data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your Personal Data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your Personal Data on our instructions, and they are subject to a duty of confidentiality.

We also have in place procedures to deal with any suspected Personal Data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

How long will we keep your Personal Data for?

We will only keep your Personal Data for as long as necessary for the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for Personal Data, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the applicable legal requirements.

As a general rule we will keep your Personal Data for seven (7) years after you stop being our customer or business partner.

In some circumstances we may anonymise your Personal Data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

US residents

California Consumer Privacy Act

  • IMG does not sell your Personal Data to third parties and will not do so. Any data that IMG processes on your behalf is subject to your express consent or relates to services that you have asked us to perform on your behalf.
  • You may access, correct, or request deletion of your personal information by logging into your account or by contacting DPO@imglobal.com . We will respond to your request within a reasonable timeframe.
  • In certain circumstances we may be required by law to retain your personal information or may need to retain your personal information in order to continue providing a service. If you believe you have other rights under the California Consumer Privacy Act or have other questions regarding your data, please contact us on DPO@imglobal.com .

Third-party links on our website

Our website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share Personal Data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.

Contact us and complaints

You have the right to make a complaint about the processing of your Personal Data or in relation to the exercise of any of your rights at any time to the ICO, ( www.ico.org.uk ) or to your local data protection regulator. We would, however, appreciate the chance to deal with your concerns before you approach a regulator.

If you have any questions about this Notice, including any requests to exercise your legal rights, or if you would like to raise a complaint, you can contact our data protection officer at DPO@imglobal.com .

Cookies

Please see our cookie notice for details of the cookies we use on our website

Appendix A

IndividualPurpose for processing Data usedLegal basis relied on
Prospective policyholders To contact you to provide you with information about us and the services that we offer where you have requested a quote or other information.
  • Identity Data
  • Contact Data
  • Communication Data
  • Medical Data
  • Professional Data
  • Legitimate interests, to respond to requests for information from you and to grow our business.
Prospective policyholders and current policyholders Marketing our services and relevant insurance products to you.
  • Marketing Data
  • Identity Data
  • Contact Data
  • Communication Data
  • Technical Data
  • Usage Data
  • Legitimate interests, to grow our business through marketing.
  • Consent
Policyholders, prospective policyholders and suppliers To conduct checks to ensure we are not prevented from engaging/working with you by any relevant sanctions regime.
  • Identity Data
  • Contact Data
  • Professional Data
  • To comply with our legal and regulatory obligations.
PolicyholdersArranging your insurance policy, administering your insurance policy and providing related services to you, including arranging for the provision of medical services.
  • Communication Data
  • Contact Data
  • Financial Data
  • Identity Data
  • Transaction Data
  • Policy Data
  • Medical Data
  • Special Category Data
  • Legitimate interests, to enable us to fulfil our contracts with insurers, under which we provide services to you.
PolicyholdersHandling claims that you raise under your insurance policy.
  • Communication Data
  • Contact Data
  • Identity Data
  • Financial Data
  • Claim Data
  • Policy Data
  • Medical Data
  • Special Category Data
  • Legitimate interests, to enable us to fulfil our contracts with insurers, under which we provide services to you.
Policyholders, prospective policyholders and suppliers To prevent and detect fraud against you or us by investigating any suspicious claims, transactions or behaviours
  • Identity Data
  • Contact Data
  • Communication Data
  • Financial Data
  • Policy Data
  • Medical Data
  • Technical Data
  • Usage Data
  • Legitimate interests, to minimise fraud which could be damaging for you and/or us and insurers with whom we work.
Policyholders and prospective policyholders Training our staff in handling calls and correspondence from customers.
  • Communication Data
  • Policy Data
  • Medical Data
  • Claim Data
  • Legitimate interests, to train our staff so that they can provide a better service
PolicyholdersDealing with policyholder queries and complaints.
  • Contact Data
  • Transaction Data
  • Financial Data
  • Communication Data
  • Policy Data
  • Medical Data
  • Claim Data
  • Special Category Data
  • Legitimate interests, to respond to queries raised by policyholders in order to provide a good service and to resolve complaints raised by policyholders.
Individual suppliers To administer our contract with you including managing service levels, payments, fees and charges.
  • Identity Data
  • Contact Dat
  • Financial Data
  • Transaction Data
  • Communication Data
Performance of a contract.
Corporate supplier contacts To manage our contract with the supplier, including managing service levels and payments.
  • Identity Data
  • Contact Data
  • Communication Data
  • Professional Data
  • Legitimate interests, to manage our relationships with corporate suppliers.
All individuals covered by this Notice To enforce legal rights or defend or undertake legal proceedings.
  • Identity Data
  • Contact Data
  • Communication Data
  • Financial Data
  • Transaction Data
  • Technical Data
  • Usage Data
  • Medical Data
  • Claim Data
  • Legitimate interests, to protect our business, interests and rights (for example where we make a claim to recover monies owed to us)
All individuals covered by this Notic Performing quality control checks, preparing for and taking part in internal and external audits and preparing for and taking part in audits/investigations by relevant regulatory bodies.
  • Identity Data
  • Contact Data
  • Communication Data
  • Financial Data
  • Transaction Data
  • Technical Data
  • Usage Data
  • Medical Data
  • Claim Data
  • To comply with our legal and regulatory obligations
  • Legitimate interests, to ensure we provide a good quality service and run and manage IMG effectively where audits/quality control checks are not required by law or regulation.