Privacy Policy
About this Policy
Coverit is committed to responsible privacy practices and complying with the Privacy Act 1988 (Cth)
(“the Act”), including the Australian Privacy Principles (“APP”) in our dealings with customers and other individuals and entities.
The use of We, Us, Our within this Policy: Refers to Coverit.
This Privacy Policy does not apply to:
-
Our acts or practices that are directly related to employee records of current or former employees between the employer and the individual; and
-
Other matters that are exempted under law.
The Act and the APP are designed to protect individuals’ personal information by regulating the ways in which personal information may be collected, used, disclosed, managed and stored.
This Policy is written in simple language. Our specific legal obligations when handling your personal information are outlined in the Act and the APP. We will update this Privacy Policy when our information handling practices change, including how it is collected, used, and under what circumstances it may be disclosed. Updates will be publicised on our website and available at our offices.
What is personal information?
Personal information is information or an opinion that refers to an identified individual, or an individual who is reasonably identifiable: whether the information or opinion is true or not; and whether the information or opinion is recorded in a material form or not.
Sensitive personal information
Sensitive personal information is information or an opinion about a person’s racial or ethnic origin, political opinions, membership of a political association, membership of a professional or trade association or trade union, religious or philosophical beliefs or affiliations, sexual orientation or practices, criminal record, health information, genetic information in certain circumstances, and biometric information that is used for certain purposes.
Our Privacy Officer is responsible for all matters to do with privacy.
Why do we collect, hold and use your personal information?
We collect, hold, and use your personal information to provide our products and services to you and manage our business. We will only collect personal information that is reasonably necessary for one or more of our functions or activities, including providing and administering our products and services for you.
We will ensure that personal information is collected by lawful and fair means and handled in accordance with the Privacy Act and the Australian Privacy Principles.
Where your consent is required by law, including in certain circumstances involving sensitive information, we will seek consent that is appropriately informed, voluntary, current and specific. We may otherwise collect, use or disclose personal information without consent where permitted or required by the Privacy Act or another applicable law.
What information do we collect?
We collect personal information primarily from our clients, but also from other sources as may be necessary. However, we only collect personal information that we need, and we only use the information that we collect for the primary purpose(s) for which we collect it.
These are:
-
For Applicants: Information on application forms for any of our products, insurance policies, roadside assistance or any other contract for which we are administrator ("Product"). This is so we can decide whether to accept your Product application and if so on what terms or administer your Product, including assessing your eligibility to participate in a product or service and establishing, processing or administering any payment or subscription payment arrangements associated with that product or service.
-
For Claimants: Information from you or other third parties to enable us to process claims under your Product and decide whether any claims you make should be accepted and their value.
-
For Agents and others with whom we do business: Information on any forms or documents or given orally to enable us to effectively perform business with you including, without limitation:
-
To assess any entitlement, you may have under any of our incentive programs (if applicable).
-
To ascertain the number and value of Products sold to customers.
-
You are entitled to know what information we collect and hold about you. For example, if we collect information from another source then we will make sure that you are aware and have consented to the collection and use of the information.
We have an obligation to ensure that the information that we collect and store is up-to-date and correct.
How do we collect personal information?
Coverit may collect your personal information that is inferred or generated through various channels, including in-person interactions, written correspondence, telephone communications, and our official website. For applicants seeking our insurance products, the primary method of collecting personal information is through both online and hard copy application forms, along with any accompanying documentation submitted to us. How we collect information from product holders varies based on the circumstances.
For instance, personal information may be gathered during annual renewal processes, through change of details forms, and direct interactions with our dedicated staff.
Additionally, Coverit may collect personal information indirectly. An example of this occurs when an applicant or product holder furnishes personal information about another individual to be covered under a Product or who is involved in a claim.
Where an applicant, product holder or other person provides us with personal information about another individual, we ask that they have authority to provide that information and, where appropriate, make the individual aware that their information may be provided to Coverit and of the purposes for which it will be handled.
Where we collect personal information about an individual from someone other than the individual, we will take such steps as are reasonable in the circumstances to notify the individual of the matters required by the Australian Privacy Principles, unless an exception applies.
How do we use personal information?
These purposes include the following:
-
Providing you a product or service; including:
-
Providing you with a quote.
-
Considering your application.
-
Arranging, verifying, and administering our insurance products and services for you.
-
Communicating details about our products and services.
-
Assessing your eligibility to participate in, purchase, subscribe to or continue to receive a product or service.
-
-
Pricing a Product, offering excesses, and discounts and deciding whether to insure you and the terms.
-
Issuing, renewing, or amending a Product.
-
Assessing risks and underwriting insurance.
-
Managing, assessing, investigating, processing, and settling any claims made.
-
Administering your account, enquiries, complaints, disputes and processing any authorised payments, including establishing, verifying, processing and administering one-off, recurring and subscription payments and dealing with payment enquiries, failed payments, refunds and reconciliations.
-
Providing information to payment service providers, financial institutions and other service providers where reasonably necessary to establish, assess, authorise, process or administer payments or subscription payments relating to a product or service.
-
Providing you with information about products, services, offers or opportunities from Coverit or our related or associated entities, where permitted by law and subject to your right to opt out of receiving such communications.
-
Training our employees, agents and representatives.
-
Auditing, monitoring, or for quality assurance purposes and security matters.
-
Detecting, investigating and preventing fraud.
-
Complying with laws, statutory authorities, or government departments and agencies.
-
Other purposes communicated to you at the time we collected your personal information or as required or permitted by law.
We do not use or disclose the information for any other purpose without the person’s consent or where the use or disclosure is otherwise permitted or required by law, including where it is reasonably necessary to provide or administer a product or service requested by you.
In particular, we do not:
-
Trade, rent or sell personal information; or
-
Provide personal information to third parties except as described in this Privacy Policy, where you have consented, where the disclosure is reasonably necessary to provide or administer a product or service requested by you, or where the disclosure is otherwise permitted or required by law.
Quality of personal information
To ensure that the personal information we collect is accurate, up-to-date and complete we:
-
Record information in a consistent format
-
Where necessary, confirm the accuracy of information we collect from a public source
-
Promptly add updated or new personal information to existing records
-
Regularly audit our contact lists to check their accuracy.
-
We also review the quality of personal information before we use or disclose it.
What can we disclose?
The Privacy Act does allow us to use or disclose information in some circumstances. For example, we can use your information in other ways if you consent to us doing so or if required to do so by law. We may also use or disclose your personal information where reasonably necessary to provide, administer or support a product or service requested by you, or where otherwise permitted by the Privacy Act and the Australian Privacy Principles.
Parties to whom we may disclose your personal information include
:
-
Third parties who can assist in processing your claims and who can help us decide whether any claim you make should be accepted and the value of your claim e.g. Repairers, Consultants, the Agent through whom you purchased the vehicle and Product.
-
Any Underwriter or other party for whom we are a Product administrator.
-
Any party who enables us to provide you with an incentive program or who enables us to effectively perform business with you.
-
Payment processors, payment gateways, financial institutions, subscription platform providers, merchants and other service providers engaged to assess, establish, authorise, process, administer, reconcile or manage payments, recurring payments or subscription payments relating to a product or service.
-
Service providers that assist us with identity verification, fraud prevention, transaction monitoring, account administration or determining your eligibility to participate in or continue to receive a product or service.
-
Any entity related to or associated with us, and service providers acting on our or their behalf, for the purpose of providing you with information about products, services, offers and opportunities that we or our related or associated entities believe may be relevant to you, including direct marketing and remarketing activities, where permitted by law.
Where we use or disclose your personal information for direct marketing or remarketing, we will provide you with a simple means of opting out of receiving those communications. You may opt out at any time by using the unsubscribe or opt-out facility provided in the relevant communication or by contacting us directly using the contact details set out in this Privacy Policy.
If you opt out, we will take reasonable steps to ensure that your personal information is no longer used for the direct marketing or remarketing communications covered by your request. Opting out of marketing communications will not prevent us from contacting you where necessary to administer your existing product, service, account, payment or subscription arrangement.
Please contact us if you do not wish to receive direct marketing or remarketing communications from us or our related or associated entities, or if you have concerns about our use of your personal information. Simply forward your request to customerservice@coveritsolutions.com.au.
Cross-Border disclosure of personal information
We may disclose your personal information to our related and associated entities, business partners, reinsurers and service providers that may be located in Australia or overseas.
The countries in which overseas recipients may be located will vary from time to time but currently include the United Kingdom and South Africa.
Before disclosing personal information to an overseas recipient, we will take such steps as are reasonable in the circumstances to ensure that the overseas recipient handles that information in accordance with the Australian Privacy Principles, except where an exception under the Privacy Act applies. In some circumstances, Coverit may remain accountable under the Privacy Act for the handling of your personal information by an overseas recipient.
We take reasonable steps to protect personal information disclosed overseas, which may include contractual, technical and organisational safeguards appropriate to the circumstances.
Any information disclosed may only be used for the purposes described in this Privacy Policy or as otherwise permitted or required by law.
Storage and security of personal information
Under the Privacy Act (Australian Privacy Principle 11), we take reasonable steps to protect the personal information we hold from misuse, interference and loss, and from unauthorised access, modification or disclosure.
These measures may include:
-
Regularly assessing the risk of misuse, interference, loss and unauthorised access, modification or disclosure of personal information.
-
Conducting internal or external reviews and audits, where appropriate, of our privacy and information security controls.
-
Implementing appropriate physical, technical and organisational security controls, which may include network authentication, access controls, monitoring, encryption and other security measures.
Where we no longer require personal information for any purpose for which we are permitted to use or disclose it, we will take reasonable steps to destroy the information or ensure that it is de-identified, unless we are required by law or a court or tribunal order to retain it.
How long will Coverit retain your information?
Coverit will retain personal information for as long as it is reasonably required for the purposes for which it may lawfully be used or disclosed.
The period for which we retain information will depend on the nature of the information and the purposes for which it is held, including the administration of products and services, claims, payments and subscriptions, dispute resolution, fraud prevention, business and record-keeping requirements, and applicable legal and regulatory obligations.
When personal information is no longer required for a permitted purpose, and we are not required by law or a court or tribunal order to retain it, we will take reasonable steps to securely destroy it or ensure that it is de-identified.
Accessing and correcting your personal information
Under the Privacy Act (Australian Privacy Principles 12 and 13), you may ask for access to personal information that we hold about you and ask us to correct that personal information.
You can ask for access or correction by contacting us. We will respond to your request within the period required by the Privacy Act. As an organisation, we are generally required to respond within a reasonable period and we aim to respond within 30 days.
We will ask you to verify your identity before we give you access to your information or correct it, and we will try to make the process as simple as possible. If we refuse to give you access to, or correct, your personal information, we must notify you in writing setting out the reasons.
If we make a correction and we have disclosed the incorrect information to others, you can ask us to tell them about the correction. We must do so unless there is a valid reason not to.
If we refuse to correct your personal information, you can ask us to associate with it (for example, attach or link) a statement that you believe the information is incorrect and why.
We will not charge you for making an access or correction request. We will not charge you for correcting your personal information. Where permitted by the Privacy Act, we may charge a reasonable amount for giving you access to your personal information, provided that the charge is not excessive. We will advise you of any proposed charge before providing access.
Destruction and de-identification of personal information
The Privacy Act does not generally provide an individual with an absolute right to require an organisation to erase their personal information on request.
However, you may contact us to request deletion or de-identification of personal information that we hold about you. We will consider your request having regard to our obligations under the Privacy Act and any applicable legal or regulatory retention requirements.
Where we no longer need personal information for any purpose for which we are permitted to use or disclose it, and we are not legally required to retain it, we will take reasonable steps to destroy the information or ensure that it is de-identified.
Dealing with Coverit Online
This Policy also applies to any personal information that you provide to us, including personal information that you email to Coverit or provide when using our website.
There are inherent risks in transmitting information across the Internet. Coverit cannot ensure the security of personal information transmitted to us via online channels. However, once we receive personal information online, we will take reasonable steps to protect that information from misuse, loss, unauthorised access, modification or disclosure, other than in accordance with this Policy. If you are concerned about conveying personal information to Coverit over the Internet, you may prefer to contact us by telephone or mail.
Our website uses cookies and web beacons. A cookie is a small piece of code that is placed on your computer. A web beacon is a piece of code that is placed on each page that communicates the cookie’s content once the page is visited. Cookies and web beacons may collect information about each page of the website that you visit, your server address, the type of browser you are using, your operating system, your top-level domain name and the date and time that each page is accessed. Use of cookies and web beacons does not involve the retrieval or recording of any personal information (such as a name or email address) by Coverit. In all cases in which cookies are used, the cookie will not collect personal information except with your consent. You can disable cookies by turning them off in your browser; however, our website may not function properly if you do so.
This Policy does not apply to, and Coverit is not responsible for, the use of, or the protection of information provided to, other websites linked to our website.
Notifiable Data Breach (NDB) Scheme
Coverit operates in accordance with the Notifiable Data Breaches (NDB) Scheme under the Privacy Act. Where Coverit has reasonable grounds to believe that an eligible data breach has occurred, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by law.
An eligible data breach generally arises where personal information is lost or is subject to unauthorised access or disclosure, the circumstances are likely to result in serious harm to one or more individuals, and remedial action has not prevented the likely risk of serious harm.
Coverit will take appropriate steps in response to a suspected or actual data breach, including, where applicable:
-
Taking prompt steps to contain the breach and reduce the risk of harm;
-
Assessing whether the breach is likely to constitute an eligible data breach in accordance with the Privacy Act;
-
Where required, preparing and providing a statement to the OAIC about the eligible data breach; and
-
Where required, notifying affected individuals, or otherwise publicising the notification, in accordance with the Privacy Act.
Where we suspect that an eligible data breach may have occurred, we will undertake the assessment required under the Privacy Act expeditiously and within the applicable statutory assessment period.
How can I make a privacy complaint?
If you believe that we have not handled your personal information in accordance with the Privacy Act, the Australian Privacy Principles or this Privacy Policy, you may make a complaint to our Privacy Officer using the contact details set out in this Privacy Policy.
Please provide sufficient information for us to understand and investigate your complaint. We will acknowledge and investigate your complaint and aim to provide you with a response within 30 days. If we require additional time, we will let you know.
Generally, you should first give us an opportunity to investigate and respond to your complaint.
If you are not satisfied with our response, you may be entitled to take your complaint to an applicable external dispute resolution scheme or to the Office of the Australian Information Commissioner (OAIC).
You can contact the Office via their website or by writing to Office of the Australian Information Commissioner, GPO Box 5218, Sydney NSW 2001.