1. About this Notice
This Privacy Notice explains how Everlife Group Ltd collects and uses personal information when you visit our website, contact us, request information or advice about a service, receive our communications, make a complaint or otherwise interact with us as a prospective or existing customer.
Additional privacy information may be supplied during an advice, application, insurer, lender, investment-platform or other service process where the responsible organisation or use of information is different. Staff and job applicants receive separate privacy information.
2. Who is responsible for your information?
An insurer, lender, investment provider, platform or other regulated service provider may be a separate controller for its own purposes. Where another organisation will receive your information, we explain its identity and role at the appropriate point and make its privacy information available where required.
3. How to contact us about privacy
4. Information we may collect
The categories depend on the service and stage of the journey.
Identity and contact information
Name, title, date of birth where required, address, email, telephone number and communication preferences.
Enquiry and appointment information
The product or service you want to discuss, whether the enquiry is personal or business-related, preferred contact method and time, appointment details and the limited message you choose to provide.
Protection-needs information
Family or business circumstances, employment or occupation, income and financial commitments, existing cover, desired protection, affordability and other information needed to understand or administer the requested service.
Application and policy information
Product, provider, cover amount, term, premium, policy identifiers, underwriting status, application communications, trust or beneficiary administration where relevant, policy changes and service records.
Health and other special-category information
Health, medical, lifestyle, disability or vulnerability information only where it is necessary and the lawful basis and special-category condition have been established. Initial website forms are not intended for medical histories.
Business information
Employer, company, ownership, shareholders, employees or eligible groups, accounts or valuation information and business needs where relevant to a commercial protection request.
Communication and service information
Emails, messages, call notes, call recordings where used, live-chat transcripts, support needs, complaints and the outcome of customer-service interactions.
Website and device information
IP address, device and browser information, security logs, pages visited, links used and cookie or similar-technology identifiers, subject to the choices and rules described in our Cookie Policy.
Marketing information
The channels and content you selected, the wording and version of the choice shown, timestamp, source, withdrawals, opt-outs and suppression records.
Source and referral information
Where an enquiry came from, campaign or referring website, the firm or person that referred you and the permission or notice associated with a purchased or third-party lead where applicable.
Identity-verification and fraud-prevention information
Documents, results or metadata used only where proportionate and necessary for identity, legal, insurer, security or fraud-prevention purposes. We seek to avoid keeping copies longer than needed.
Criminal-offence information
5. Where information comes from
We may receive information:
- Directly from you through forms, calls, meetings, applications and correspondence.
- From a family member, business contact, employer, shareholder, trustee or authorised representative who is permitted to provide it.
- From an Everlife adviser, insurer, lender, investment provider, platform, broker or referral partner where relevant to the requested service.
- From lead providers or marketing partners, but only after the collection notice and permission evidence have been assessed.
- From identity, fraud, sanctions, financial or other verification providers where necessary and lawful.
- From public sources such as Companies House or professional and regulatory registers.
- From website, analytics and advertising technologies in line with your choices and applicable rules.
If you provide information about another person, you should be authorised to do so and, where appropriate, tell them that you have shared it and direct them to this Notice.
6. Why we use information and our lawful bases
Replace this table after the Record of Processing Activities and lawful-basis assessment are complete.
Responding to enquiries and requested contact
Purpose: to respond, route and administer the enquiry you asked us to make.
Likely basis: taking steps at your request before a contract and/or legitimate interests in responding and operating our service, depending on the facts.
Arranging appointments and consultations
Purpose: to schedule, prepare for and follow up the conversation requested.
Likely basis: steps at your request before a contract and/or legitimate interests.
Providing insurance information, advice, arranging or introductions
Purpose: to deliver the exact service described to you, assess demands and needs where applicable, make a recommendation where authorised, administer a referral or support an application.
Likely basis: steps before a contract, performance of a contract, legal obligation and/or legitimate interests, allocated purpose by purpose.
Underwriting and policy administration
Purpose: to obtain or support insurer assessment, administer applications, policies, changes, trusts and claims within our approved role.
Likely basis: steps before a contract, contract, legal obligation and legitimate interests. Insurers may act as separate controllers.
Legal and regulatory compliance
Purpose: customer records, disclosures, monitoring, complaints, fraud prevention, regulatory reporting, audit and cooperation with authorities.
Likely basis: legal obligation and legitimate interests in demonstrating compliance and protecting the service.
Service quality, training and call recording
Purpose: quality, training, evidence, complaint handling and security where calls are recorded.
Accessibility and additional support
Purpose: to understand and provide reasonable communication or service adjustments.
Basis: legal obligation and legitimate interests, with an Article 9 condition where the information reveals health or another special category.
Website security and fraud prevention
Purpose: protect systems, investigate suspicious activity and maintain security logs.
Basis: legitimate interests and legal obligations where applicable.
Analytics and website improvement
Purpose: understand aggregated use and improve the website.
Advertising, audience creation and conversion measurement - not used at initial launch
Everlife does not intend to use advertising pixels, audience creation, remarketing or advertising conversion measurement on the initial compliance-first website.
Direct marketing
Purpose: send the Everlife guides, news or offers you selected.
Basis: consent for the applicable electronic channels or the soft opt-in where its conditions are met, plus the documented UK GDPR basis. You can object or opt out at any time.
Business administration and legal claims
Purpose: finance, governance, contracts, risk, insurance, legal advice and establishing or defending claims.
Basis: legal obligation, contract and legitimate interests.
7. Special-category information, including health
Health information is given additional protection by law. Where it is necessary for an insurance purpose or support request, Everlife must identify both an Article 6 lawful basis and an Article 9 condition before processing it.
Please do not send medical information through a general enquiry form. We will explain the controlled route, purpose and recipients when that information is genuinely needed.
8. Criminal-offence information
9. Who we share information with
Depending on the service, recipients may include:
- Insurers and underwriting, medical-evidence or claims service providers.
- Lenders, investment providers, platforms, custodians or other service providers only where relevant to the service requested and after their role has been explained.
- Advisers, paraplanners, administrators and authorised support staff.
- CRM, calendar, communications, telephony, call-recording, document, security and IT providers.
- Identity, fraud-prevention, sanctions or verification providers.
- Professional advisers, auditors, insurers and regulators.
- The Financial Conduct Authority, Financial Ombudsman Service, Information Commissioner's Office, courts, law enforcement or other authorities where required or appropriate.
- A limited analytics provider, if Everlife activates one, only in line with the choices and lawful arrangements described in this Notice and Cookie Policy.
- A buyer, seller or adviser involved in a genuine corporate transaction, subject to appropriate safeguards.
We name a receiving broker or authorised firm at the point of referral where its identity materially matters. We do not rely only on the phrase "trusted partners" when we know who will receive your information.
10. Insurers, lenders, investment providers and other regulated firms
11. Technology and service providers
Service providers may process information on our instructions under contracts requiring confidentiality, security, assistance with rights, control of sub-processors and deletion or return of information. Some technology companies determine their own purposes for parts of the processing; their role and terms are assessed rather than assumed.
12. International transfers
Some recipients or their service providers may process information outside the United Kingdom. Before making a restricted transfer, we identify the destination and recipient, use an applicable UK adequacy regulation or approved safeguard such as the UK International Data Transfer Agreement or UK Addendum, and complete the current assessment required by law where appropriate.
13. How long we keep information
We use a documented retention schedule based on the purpose, regulatory requirements, provider contracts, complaint and legal-limitation needs, customer expectations, sensitivity and the ability to delete or anonymise the record.
Insert actual periods or criteria for:
We do not keep all financial-services information for a generic seven-year period. Different records have different purposes and retention requirements.
14. Automated decision-making and profiling
15. Marketing and your choices
Service messages about an enquiry, appointment, application or policy are not treated as permission to send unrelated marketing.
We send electronic marketing to individual subscribers where we have the required consent or where the statutory soft opt-in applies to Everlife's own similar products and services. Sole traders and some partnerships can be treated like individuals for electronic-marketing rules. Business-contact personal data remains protected by UK data-protection law.
16. Advertising and conversion measurement
The initial compliance-first website does not use Google Ads tracking, Meta Pixel, Conversions API, remarketing audiences or equivalent advertising technology.
If Everlife later introduces paid-media measurement, it will update this Notice and the Cookie Policy and implement the required consent and data-protection controls before the technology is activated. Medical details, free-text enquiry content and other sensitive information must never be sent to advertising platforms.
17. Cookies and similar technologies
Read our Cookie Policy for the technologies, providers, purposes, lifetimes and controls that apply. You can change optional choices at any time using "Cookie settings" in the website footer.
18. Your rights
Depending on the circumstances, you may have the right to:
- Be informed about use of your personal information.
- Ask for access to your personal information.
- Ask us to correct inaccurate or incomplete information.
- Ask for deletion where the right applies.
- Ask us to restrict processing.
- Object to processing based on legitimate interests.
- Object at any time to direct marketing.
- Receive certain information in a portable format.
- Withdraw consent without affecting earlier lawful processing.
- Ask for safeguards relating to solely automated significant decisions.
- Make a complaint about data protection.
These rights are not absolute in every case. We will explain if a lawful restriction or exemption affects the request.
19. How to make a privacy request
We may ask for proportionate information to confirm identity or authority. We will not routinely demand extensive identity documents where a lower-risk method is sufficient.
20. Data-protection complaints
You can also complain to the Information Commissioner's Office. Visit ico.org.uk/make-a-complaint or contact the ICO using its current published details. We would welcome the opportunity to consider your concern first, but you are not required to do so.
21. Whether information is required
General contact fields are voluntary, but without a way to contact you we may be unable to respond. Some identity, financial, health or business information may later be necessary for an insurer, regulated assessment, contract or legal obligation. We explain what is required and what may happen if it is not provided at the relevant stage.
22. Children's information
23. Security
We use technical and organisational measures intended to protect personal information, including access controls, secure transfer, system monitoring, supplier assessment, staff training and incident processes proportionate to the risk. No online system can be guaranteed completely secure.
24. Changes to this Notice
We review this Notice and update it when our purposes, systems, recipients, regulatory model or legal requirements materially change. We show the effective date and version above. Where a new use would not reasonably be expected, we take appropriate steps to bring it to your attention before it begins.
Privacy Notice publication gates
- Complete controller and joint-controller map.
- Complete Record of Processing Activities.
- Approve Article 6 basis for every purpose.
- Approve Article 9 and Schedule 1 conditions and Appropriate Policy Document where required.
- Name relevant insurers, lenders, investment providers, platforms and other receiving firms meaningfully.
- Complete vendor and international-transfer inventory.
- Complete retention schedule by record type.
- Confirm automated decision-making position.
- Confirm call recording, chat, CRM, calendar and analytics configuration. At initial launch, confirm that no advertising platform is active.
- Confirm rights and data-complaint process under current law.
