SURANCE PRIVACY STATEMENT – CANADA
Updated: July 2021
Surance Ltd. (collectively, “Surance”, “we”, “our” or “us”) recognize the importance of privacy. The purpose of this privacy statement (“Privacy Statement”) is to inform you about our privacy practices, including how we collect, use and disclose your Personal Information.
This Privacy Statement applies to all of our operations in Canada or operations in connection with Canada, unless we have provided you with a separate privacy statement for a particular product, service or activity. In particular, this Privacy Statement applies to your use of the mobile application powered by Surance, your communications with Surance, your purchase of insurance through use of the application powered by Surance (collectively, the “Cyber Application”).
Privacy Statement Updates
This Privacy Statement is current as of the “updated” date which appears at the top of this page. We may modify this Privacy Statement from time to time. When changes are made to this Privacy Statement they will become immediately effective when published in a revised Privacy Statement posted on our website unless otherwise noted. We may also communicate the changes through our services or by other means.
Please review this Privacy Statement carefully. By submitting your Personal Information to us, by registering for or using any of the services we offer including The Cyber Application, by using our website, or by voluntarily interacting with us, you consent to our collecting, using and disclosing your Personal Information as set out in this Privacy Statement, as revised from time to time.
When you use our services, including The Cyber Application, you will also interact with others, such as such as insurance providers and intermediaries (“Insurance Providers”) and other organizations. Our Services may be branded by your Insurance Provider or another organization and may be provided to you in connection with services provided to you by your Insurance Provider or another organization. Insurer Providers and others with whom you interact may also collect, use and disclose your Personal Information. This Privacy Statement only describes how Surance collects, uses and discloses your Personal Information. To understand how others with whom you interact collect, use and disclose your Personal Information, you must review their privacy statements.
WHAT THIS PRIVACY STATEMENT COVERS
This Privacy Statement covers the following topics:
-
Meaning of Personal Information
-
Your Consent to Collection, Use and Disclosure
-
Personal Information We Collect
-
How We Use Your Personal Information
-
How We Share Your Personal Information
-
Opting Out of Communications
-
Retention of Personal Information
-
Information Security
-
Accessing and Updating Your Personal Information
-
International Transfer and Storage of Information
-
Third Party Websites and Services
-
Children’s Information
-
How to Contact Us
Meaning of Personal Information
"Personal Information" means information about an identifiable individual as described under Canadian privacy laws. This information may include your name, mailing address, e-mail address and telephone number, your account information with us, your account information with other services, information about your cyber insurance coverage, information about the claims you have submitted to Insurance Providers, and certain information about the devices and networks on which you use Surance services and the other devices on such networks.
Personal Information does not include any business contact information that is solely used to communicate with you in relation to your employment, business or profession, such as your name, position name or title, work address, work telephone number, work fax number or work e-mail address.
Personal Information also does not include information that has been anonymized or aggregated in such a way that there is no serious possibility it can be used to identify an individual, whether on its own or in combination with other information, or that otherwise is not considered Personal Information under applicable laws.
Your Consent to Collection, Use and Disclosure
We collect, use and disclose your Personal Information with your consent or as permitted or required by Canadian privacy laws. How we obtain your consent (i.e. the form we use) will depend on the circumstances, as well as the sensitivity of the information collected. Subject to applicable laws, your consent may be express or implied, depending on the circumstances and the sensitivity of the Personal Information in question. In some cases, we will seek your consent immediately prior to collecting your Personal Information, for example where Surance services or software ask you to grant certain permissions with respect to your devices or networks.
If you choose to provide Personal Information to us, we assume that you consent to the collection, use and disclosure of that Personal Information as outlined in this Privacy Statement.
If you wish to withdraw your consent to our collection, use or disclosure of your Personal Information, please contact us using the contact information in the “How to Contact Us” section below. However, before we implement the withdrawal of consent, we may require proof of your identity. In some cases, withdrawal of your consent may mean that we will no longer be able to provide certain products or services.
Surance services including the Cyber Application may collect the Personal Information of others who are on the same network where you use the services. If you provide Personal Information about another individual to us or if you use Surance services on networks used by others, it is your responsibility to obtain the consent of that individual to enable us to collect, use and disclose his or her information as described in this Privacy Statement.
Personal Information We Collect
The Personal Information we collect is generally in one or more of the following categories.
-
Products and Services. For individuals located in Canada who use our products and services, including the Cyber Application, we may collect information from you or from your use of our products or services.
-
We collect Personal Information that you submit through your use of our products or services, such as your name, e-mail address, home address, telephone number, other contact information, online accounts, cyber incidents to which you have been subject, and cyber insurance coverage and claims.
-
Surance products and services will automatically collect usage data that is identifiable with you, your devices, and your network when you use our products and services. Surance products and services may automatically collect the following information:
-
Location information
-
Device Information, including device identifiers, device type, and device configuration.
-
Network information, including IP address, network name, and network configuration.
-
Where you use our data restoration services, information that was subject to a cyber incident or ransomware attack.
-
Information regarding the configuration of your mobile phone, the network router and other devices that are connected to the local network of the user.
-
-
-
Website. For individuals located in Canada who visit our website located at https://surance.io or any of our related websites (collectively, “our website”), we may collect information from you or from your activities on our website.
-
Like most websites and other Internet services, we may collect certain technical and device information about your use of our website. Such information may include your Internet protocol address, information about your device, browser and operating system, and the date and time of your visit.
-
Additionally, our website may include certain social media features (for example, the Facebook like button) and other widgets (for example, the ShareThis share button). These features and widgets may collect your Internet protocol address, which page you are visiting on our website, and set cookies to enable the feature and/or widget to function properly. Such features and widgets are hosted by third parties or directly on our website. Your interactions with these features and widgets are governed by the privacy statement of the applicable third party service provider.
-
You have a variety of tools to control the data collected by cookies, web beacons, and similar technologies. For example, you can use controls in your internet browser to limit how the websites you visit are able to use cookies and to withdraw your consent by clearing or blocking cookies.
-
Other Interactions. For individuals located in Canada who otherwise interact with us, whether in person, by phone or email, through social media or otherwise, including individuals who might be interested in acquiring our products or services, who sign-up to receive newsletters or other communications, who respond to surveys and questionnaires, or who submit testimonials or other feedback, we may collect information that you provide to us during these interactions. This information may include your name, e-mail address and other contact information.
How We Use Your Personal Information
We may use your Personal Information for purposes such as:
-
providing you with our products and services and supporting your use of our products and services;
-
evaluating the security of your network, devices, and the general cyber security posture and risks of your network and devices in connection with your use of the Surance products or services or insurance services provided by third parties;
-
to suggest improvements to the configuration of your network and devices to improve your cyber security posture and to reduce risk;
-
to suggest cyber insurance and other insurance products to you;
-
to evaluate whether your devices, networks, or online accounts have been the subject of a cyber incident;
-
to assist you in responding to cyber incidents, including restoring your data;
-
to assist you and your Insurance Provider in processing insurance claims;
-
contacting you relating to our products and services;
-
monitoring the usage of our products and services to support their proper functioning and further improvement;
-
analyzing the needs and activities of our customers to help us better serve them;
-
generating de-identified data to conduct research and analysis related to our business, products and services;
-
responding to inquiries and other requests;
-
collecting opinions and comments about our products and services;
-
providing you with information that we think may interest you, including information about our products and services; and
-
investigating legal claims.
We may use your Personal Information for purposes for which we have obtained your consent, and for such other purposes as may be permitted or required by applicable privacy laws.
-
We do not use the information we collect to advertise third party products and services or targeted advertising of Company products and services across third party websites or service offerings. How We Share Your Personal Information
Insurance Providers
With your consent we will disclose Personal Information regarding your cyber security posture and risk position to third party insurers for the purposes of such insurers providing you with quotes and other information regarding cyber security insurance products. We may also disclose your Personal Information to insurers to facilitate your transactions with such insurers.
Service Providers
We rely on third party services providers (including affiliates)to perform a variety of services on our behalf, such as e-commerce providers, carriers, email, payment card processers, telephone and technical support providers, hosting, data storage and processing service providers, and research and analytics providers.
If we provide your information to service providers, then we require that the service providers keep your Personal Information secure, and only handle it for limited purposes for which it is provided. We do not authorize the service providers to disclose your Personal Information to unauthorized parties or to use your Personal Information for their direct marketing purposes. If you would like more information about our service providers, please contact us using the contact information in the “How to Contact Us” section below.
Permitted or Required Disclosure
Additionally, we may use and disclose your information when we believe such use or disclosure is permitted, necessary or appropriate: (a) under applicable law, including laws outside your country of residence; (b) to comply with legal process; (c) to respond to requests from public and government authorities, including public and government authorities outside your country of residence; (d) to enforce the terms of the agreements for our products and services; (e) to protect our rights, operations or property; (f) to allow us to pursue available remedies or limit the damages that we may sustain. In addition, we may transfer your Personal Information and other information to a third party in the event of any reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, brands, affiliates, subsidiaries or other assets, or other business transaction.
If we otherwise intend to disclose your Personal Information to a third party, we will identify that third party and the purpose for the disclosure, and obtain your consent.
Opting Out of Communications
If you no longer want to receive marketing-related emails from us, you may opt-out of receiving marketing-related emails by clicking the “unsubscribe” link at the bottom of any email you receive from us. You may also opt-out by contacting us directly using the contact information in the “How to Contact Us” section below.
-
We will endeavour to respond to your opt-out request promptly, but we ask that you please allow us a reasonable time to process your request. Please note that if you opt-out from receiving marketing-related emails, we may still need to send you communications about your use of our products or services, or other matters.
-
Retention of Personal Information
We will use, disclose or retain your Personal Information only for as long as necessary to fulfill the purposes for which that Personal Information was collected and as permitted or required by applicable privacy laws.
Information Security
We have implemented physical, organizational, contractual and technological security measures with a view to protecting your Personal Information from loss or theft, and unauthorized access, disclosure, copying, use or modification. We have taken steps to ensure that the only personnel who are granted access to your Personal Information are those with a business ‘need-to-know’ or whose duties reasonably require such information.
Despite the measures outlined above, no method of information transmission or information storage is 100% secure or error-free, so we unfortunately cannot guarantee absolute security. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of any information that you provided to us has been compromised), please contact us immediately using the contact information in the “How to Contact Us” section below.
Accessing and Updating Your Personal Information
We expect you, from time to time, to supply us with updates to your Personal Information, when required. We will not routinely update your Personal Information, unless such a process is necessary.
You may make a written request to review any Personal Information about you that we have collected, used or disclosed, and we will provide you with any such Personal Information to the extent required by applicable laws. You may also challenge the accuracy or completeness of your Personal Information in our records. If you successfully demonstrate that your Personal Information in our records is inaccurate or incomplete, we will amend the Personal Information as required.
We may require that you provide sufficient identification to fulfill your request to access or correct your Personal Information. Any such identifying information will be used only for this purpose. In certain cases, you may exercise your rights through the interface of Surance products or services. You may also submit your request by filling the form we make available on our website or by contacting us as set out in the “How to Contact Us” section below.
International Transfer and Storage of Information
Your Personal Information may be stored and processed at data centers managed by us or third party service providers in [Canada, the United States of America, the European Union, and in other jurisdictions]. Other jurisdictions may have different data protection rules than Canada. While your Personal Information is outside of Canada, it is subject to the laws of the country in which it is located. Those laws may require disclosure of your Personal Information to authorities in that country. For written information about our policies and practices regarding service providers outside of Canada, contact our Privacy Officer using at the contact information in the “How to Contact Us” section below.
Third Party Websites and Services
We may provide links to third party websites for your convenience and information. We may also make available to you opportunities to purchase, subscribe to, or use other products and online services from third parties with different privacy practices, including insurance products, and those other products and online services are governed by their respective privacy statements and policies. This Privacy Statement does not address, and we are not responsible for, the privacy, information, or other practices of any third parties, including those of Insurance Providers and of others you interact when using our services, including the Cyber Application. We do not assume responsibility for the privacy practices of such third parties, and we encourage you to review all third party privacy policies prior to using third party websites, products or services.
How to Contact Us
All comments, questions, concerns or complaints regarding your Personal Information or our privacy practices should be sent to our Privacy Officer as follows:
Address:
Attention: Privacy Officer
Saar Bar
+972 52 3355307
By e-mail: