MS notices

Privacy Notice

This Privacy Notice (“Notice”) explains the personal data collection, use, and sharing practices of Aptia UK Limited and its affiliates (together, “Aptia”, “we,” “us,” and “our”) in connection with your use of our website www.aptia-group.com (“Website”). 

Aptia UK Limited is a “controller” of personal data processed in connection with this Website to which the “European Privacy Laws” apply which, for the purposes of this Notice, means all applicable legislation and regulations relating to the protection of personal data in force from time to time in the UK, EU or EEA, including (without limitation) the General Data Protection Regulation as it forms part of the laws of England and Wales, Scotland, and Northern Ireland and the UK Data Protection Act 2018. Unless stated otherwise, the terms “controller”, “data subject”, “personal data” and “processing” shall be interpreted in accordance with the European Privacy Laws.

Before you use or submit any personal data through or in connection with the Website, please carefully review this Notice. If you do not agree to this Notice, please do not access or use the Website.
If you have any questions about this Notice or Aptia’s privacy practices, you can contact us and our Data Protection Officer at WebEnquiries@aptia-group.com or by using our contact form.

01

Information We Collect

We collect personal data in multiple ways, including when you provide personal data directly to us and when we collect personal data from you through automated technologies (such as cookies) via your browser or device.

We do not intentionally collect special category or sensitive personal data in connection with your use of the Website unless you directly provide us with such personal data.

The Website is intended for users over the age of 18 and is not directed at children under the age of 16. We do not knowingly encourage or solicit visitors to this Website who are under the age of 18 or knowingly collect personal data from anyone under the age of 18. If we become aware that we have collected personal data from children under the age of 18, we will take reasonable steps to delete it as soon as practicable.

We do not use automated decision-making, including profiling, in relation to the personal data that we process in connection with your use of the Website.

If you do not provide us with certain personal data, including by blocking any or all cookies or not providing relevant personal data in any correspondence with us, then you may be able to fully access or use the Website and/or we may not be able to respond to your correspondence in whole or in part.


Information You Provide Directly to Us


We will collect and process any personal data that you provide to us in connection with your access to and use of the Website, including when you contact us via email or the “Contact Us” page available on the Website. For example, this may include your name, email address, phone number and mailing address.


Information that Is Automatically Collected


We will collect data about your use of the Website through the use of internet server logs and online tracking technologies, like cookies. A web server log is a file where website activity is stored. A cookie is a small text file that is placed on your device when you visit a website. 

These tracking technologies will allow us, amongst other things, to manage the security and accessibility of the Website, and the personal data that they collect may include device information such as IP addresses, location information (by country and city), unique device identifiers, IMEI and TCP/IP address, browser types, browser language, operating system, mobile device carrier information, as well as information relating to how you interact with the Website such as referring and exit web pages and URLs, platform type, the number of clicks, domain names, landing pages, pages and content viewed and the order of those pages, statistical information about the use of the Website, the amount of time spent on particular pages, the date and time you used the Website, the frequency of your use of the Website, error logs, and other similar information.

Please see our Cookie Notice for further information relating to the cookies that the Website uses.

02

How We Use Your Information and Our Legal Basis

We may use the personal data that we collect from and about you to for the following purposes and in reliance on the following legal bases:

  • To ensure secure and functional access to the Website. We process personal data for this purpose on the basis of our legitimate interest in providing you with relevant information on our Website and ensuring the security and proper use of our Website.

     

  • To process and respond to your communications. We process personal data for this purpose on the basis of our legitimate interest in considering questions, comments, feedback and other correspondence that you send to us and responding where appropriate.
     

Please note that we may combine certain personal data that you provide or we collect from or about you (including automatically collected information) with other personal data that you provide or we collect from our abut you, and use such combined personal data in accordance with this Notice.

We may aggregate and/or de-identify personal data collected in 
connection with the Website. We may use de-identified and/or aggregated data for any purpose, including without limitation for research and marketing purposes.

03

When We Disclose Your Information

We may disclose and/or share your personal data with third parties under the following circumstances:

  • To our service providers to the extent necessary for them to provide the relevant services to us, which may include website and/or data hosting, security and administration services.
     
  • To other entities within the Aptia group from time to time as part of our internal business processes.
     

To relevant third parties who we reasonably believe that disclosure is necessary or appropriate for any of the following reasons: (a) to comply with legal process, including any judicial proceeding, court order or request from a regulator, or for national security or purposes of public importance; (b) to enforce or apply our Terms of Use; or (c) to protect the rights, property, or personal safety of Aptia, our agents and affiliates, our users, and the public.

We may disclose your personal data to any additional third parties based on your consent to do so.

04

International Transfers
The Website is hosted in the UK. As described above in the “When We Disclose Your Information” section, we may share your personal data with third parties including service providers, affiliates and as required by law or in connection with our legal rights as necessary to fulfil the purposes set out in this Notice. 

This may involve sharing your personal data with such third parties who are based outside of the UK, including jurisdictions that may not offer the same level of protection of such personal data as the UK. If transfer or make available your personal data outside of the UK, such transfers will only be made in accordance with, where applicable, the European Privacy Laws, which may include implementing appropriate safeguards. 

For further information about any such appropriate safeguards used, please contact us and our Data Protection Officer at WebEnquiries@aptia-group.com or by using our contact form.

05

Sub-Processors

Whether any sub-processor is used for any particular client engagement will depend on the country in which services are provided, the line of business, the nature of the services and any specific client terms or processes agreed. 

Further information regarding the sub-processors used by Aptia Group can be obtained from your local Aptia contact. 

You can find information about the internal and external sub-processors used by Aptia below:

  • Aptia UK Limited (based in the UK). Line of business: Pensions & Benefits Admin. Category: Aptia Group entity.
     
  • Aptia Group India Private Limited (based in India). Line of business: Pensions & Benefits Admin. Category: Aptia Group entity.
     
  • Aptia Group Portugal S.A. (based in Portugal). Line of business: Pensions & Benefits Admin. Category: Aptia Group entity.
     
  • Aptia Insurance Services Group LLC (based in the US). Line of business: Pensions & Benefits Admin. Category: Aptia Group entity.
     

06

Security Measures
We limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality and required to keep your personal data secure.
We have implemented appropriate technical, physical, and organisational security measures to protect to the extent possible against the loss, misuse, and/or alteration of your personal data. 

These safeguards vary based on the nature and sensitivity of the personal data that we collect and store, and the purpose for which it is collected and stored by us. However, the transmission of information and data via the internet is not completely secure, and we cannot and do not guarantee that these measures will prevent every unauthorised attempt to access, use, or disclose your personal data; any transmission of data by you to or through this Website is at your sole risk.

We have put in place procedures to deal with any suspected data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

07

Data Retention
We retain the personal data we collect in connection with the Website for as long as necessary to fulfil the purposes set forth in this Notice, unless a longer retention period is legally required or permitted, or where requested by you. We will not retain more personal data than we need for those purposes.

08

Third-Party Links and Services

The Website may contain links to third-party websites (e.g., social media sites like LinkedIn) and other services. If you choose to use these websites or services, you may disclose your personal data not just to those third parties, but also to their users and the public more generally depending on how their services function. 

Aptia is not responsible for the content or privacy practices of such third party websites or services. The collection, use and disclosure of your personal data by those third parties will be subject to any applicable privacy notices of the third party websites or services, and not this Notice. We encourage you to read the privacy notices of each website you visit.

09

Your Data Subject Rights

European Privacy Laws


To the extent that European Privacy Laws apply to our processing of your personal data in connection with the Website, you have the following rights in respect of your personal data that we process in connection with this Website:
The right to obtain confirmation of whether we are processing your personal data and, if we are, to obtain a copy as well as certain information regarding our processing.

 

  • The right to require us to rectify any inaccuracies in your personal data without undue delay.
     
  • The right to require us to erase your personal data without undue delay in certain circumstances.
     
  • The right to require us to restrict our processing of your personal data in certain circumstances.
     
  • The right to require us to transmit your personal data to another controller in certain 
    circumstances.
     
  • The right to object to certain types of processing of your personal data in certain circumstances.
     

Where we are relying on your consent in order to lawfully process your personal data, the right to 
withdraw that consent in certain circumstances.
 


When exercising any of these rights we may need to request specific information from you to help us confirm your identity and ensure that we respond appropriately. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it or inappropriately processed. We may also contact you to ask you for further information in relation to your request to speed up our response.
 

To exercise these rights, please email us and our Data Protection Officer at WebEnquiries@aptia-group.com or using our contact form setting out the nature of your request.

You also have the right to lodge a complaint regarding our processing of your personal data with the relevant supervisory authority, which in the UK is the UK Information Commissioner’s Office (https://ico.org.uk/global/contact-us). However, we encourage you to contact us in the first instance so that we may resolve your concerns directly as best and as promptly as we can.
 

United States residents

U.S. state consumer privacy laws may provide their residents with additional rights regarding our use of their personal information. Colorado, Connecticut, Virginia, and Utah each provide their state residents with rights to: (i) confirm whether we process their personal information; (ii) access and delete certain personal information; (iii) data portability; and (iv) opt-out of personal data processing for targeted advertising and sales. Colorado, Connecticut, and Virginia also provide their state residents with rights to: (a) correct inaccuracies in their personal information, taking into account the information’s nature processing purpose; and (b) opt-out of profiling in furtherance of decisions that produce legal or similarly significant effects. 

Nevada provides its residents with a limited right to opt-out of certain personal information sales. To exercise any of these rights set forth in this section, please email us at at WebEnquiries@aptia-group.com or using our contact form setting out the nature of your request.

 

10

Changes to a Privacy Policy

We're constantly trying to improve our Websites and Services, so we may need to change this Privacy Notice from time to time as well. We will alert you to material changes by, for example, placing a notice on our Websites and/or by sending you an email (if you have registered your e-mail details with us) when we are required to do so by applicable law. You can see when this Privacy Notice was last updated by checking the date at the top of this page. You are responsible for periodically reviewing this Privacy Notice.

11

Do Not Track

Individual users can enable their browsers to send DNT requests in addition to:

  • The Network Advertising Initiative offers a central site where you can opt-out of certain kinds of tracking or ad targeting by its members.

  • The Digital Advertising Alliance (DAA) provides a consumer opt-out page for the companies participating in their Self-Regulatory Program for Online Behavioural Advertising.

  • Some leading companies provide their own opt-out mechanisms for their registered users.  For example, at these links you can control your opt-outs for Google, for Microsoft, and for Yahoo!.

12

Contacting Us
If you have any questions about this Notice, or Aptia’s privacy practices, you can contact us and our Data Protection Officer at WebEnquiries@aptia-group.com or using our contact form.