{"id":1517,"date":"2021-09-15T20:12:05","date_gmt":"2021-09-15T20:12:05","guid":{"rendered":"https:\/\/penmore.com\/insurance\/?page_id=1517"},"modified":"2021-09-16T10:20:44","modified_gmt":"2021-09-16T10:20:44","slug":"privacy-policy","status":"publish","type":"page","link":"https:\/\/penmore.com\/insurance\/privacy-policy\/","title":{"rendered":"Privacy Policy"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; custom_padding_last_edited=&#8221;on|tablet&#8221; _builder_version=&#8221;4.9.10&#8243; custom_padding=&#8221;200px||0px||false|false&#8221; custom_padding_tablet=&#8221;120px||||false|false&#8221; custom_padding_phone=&#8221;&#8221;][et_pb_row _builder_version=&#8221;3.25&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;3.25&#8243; custom_padding=&#8221;|||&#8221; custom_padding__hover=&#8221;|||&#8221;][et_pb_text admin_label=&#8221;Privacy Policy&#8221; _builder_version=&#8221;4.9.10&#8243; _module_preset=&#8221;default&#8221; header_font_size=&#8221;35px&#8221; hover_enabled=&#8221;0&#8243; custom_margin=&#8221;||20px||false|false&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<h1>Privacy Policy<\/h1>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.9.10&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221;]<\/p>\n<h2>Privacy \u2013 Definition:<\/h2>\n<p><em>Privacy is the right of an individual to control who has access to his or her personal information and under what circumstances.<\/em><\/p>\n<h2>POLICY<\/h2>\n<p>The privacy of your personal information is of the utmost importance to <strong><em>Penmore.<\/em><\/strong>\u00a0 <strong><em>Penmore<\/em><\/strong> believes that protecting the privacy and the confidentiality of its customers\u2019 personal information is an important part of its relationship with them any information gathered by <strong><em>Penmore<\/em><\/strong> will be kept strictly confidential and will only be used or shared in ways for which you have specifically consented.\u00a0 Unless we have your express consent, <strong><em>Penmore<\/em><\/strong> will not sell, rent or trade your personal information to any third party.<\/p>\n<p>The personal information that <strong><em>Penmore<\/em><\/strong> holds or will hold concerning you will be treated confidentially, and will be kept in a file opened for the purpose of allowing you to benefit from various insurance, annuity, credit and other related financial services offered by your insurer.\u00a0 This information will only be consulted by the personnel of your insurer who require access to it in the course of their duties.<\/p>\n<p>You may have access to your file and request that information be corrected if you prove that it is incorrect, incomplete, ambiguous, outdated or unnecessary.\u00a0 You must then send a written request to the person in charge of the protection of personal information at <strong><em>Penmore.<\/em><\/strong><\/p>\n<p><strong>Why Penmore collects Personal Information<\/strong><\/p>\n<p><strong><em>Penmore<\/em><\/strong> collects, uses and discloses personal information about its customers for the purposes of managing their financial-related needs.\u00a0 This includes evaluating and assessing insurance needs, underwriting, coverage assessment, compiling statistics, providing all policy related or administrative services, loss control, compliance with any regulatory requirements, claims investigation, protecting against error and fraud, ensuring information is accurate and up to date, and determining your payment of premiums.<\/p>\n<p><strong><em>\u00a0<\/em><\/strong><strong><em>Penmore<\/em><\/strong> may also collect, use and disclose personal information about third parties for the purpose of handling claims made against our customers.<\/p>\n<p><strong>What type of Personal Information <em>Penmore<\/em> collects<\/strong><\/p>\n<p>The types of personal information that <strong><em>Penmore<\/em><\/strong> may collect are property details, claims histories, employment information, professional history, medical and health information, driving records and financial information.\u00a0 Which of those types we collect in a particular case depends on which of our purposes is applicable and on the particular circumstances.<\/p>\n<h2>How <em>Penmore<\/em> Obtains Personal Information<\/h2>\n<p>The personal information collected by <strong><em>Penmore<\/em><\/strong> is provided to us by you directly or through an insurance company or agent, by ways of your insurance application, and by service providers.\u00a0 For some of our purposes, we may obtain personal information, such as claims, underwriting, credit history and driving records, from other industry sources.<\/p>\n<p>In some cases, <strong><em>Penmore<\/em><\/strong> will consider the need for certain personal information is so obvious as part of the process that the customer\u2019s consent to its collection and use are implied.<\/p>\n<p>In some circumstances, consent may not be required for the collection and use of personal information for the purpose of investigating a breach of an insurance\/fund policy or other agreement, or a contravention of Canadian law.<\/p>\n<p>Subject to legal or contractual restrictions and upon reasonable notice, you may withdraw your consent at any time.\u00a0 At that time, we will advise you of the consequences of withdrawal of your consent.<\/p>\n<h2>How and When <em>Penmore<\/em> Shares Personal Information<\/h2>\n<p><strong>\u00a0<\/strong><strong><em>Penmore<\/em><\/strong> provides personal information to other organizations (including its affiliated companies) only for the purposes listed above, or if required or permitted to do so by law.<\/p>\n<p>In some circumstances, the customer\u2019s consent is not required for the disclosure of personal information; this would apply, for example, to the disclosure of personal information to an approved investigative body when we believe that the information relates to the breach of an insurance policy or other agreement or a contravention of Canadian law; or when we are required by law to disclose the information; or when we disclose information to a lawyer for claims purposes or to obtain legal advice.<\/p>\n<p>When <strong><em>Penmore<\/em><\/strong> provides data containing personal information to service providers, they are subject to confidentiality requirements.<\/p>\n<h2>Securing and Safeguarding Your Personal Information<\/h2>\n<p><strong><em>Penmore<\/em><\/strong> protects your personal information with security safeguards appropriate to the sensitivity of the information<strong><em>.\u00a0 Penmore<\/em><\/strong> employees, contractors and representatives access personal information only when they have a business need to do so.\u00a0 Our employees are made aware of the proper handling of personal information pertaining to this policy.\u00a0 We keep personal information only as long as it is necessary for our purposes listed above.<\/p>\n<h2>Accuracy of and Access to Your Personal Information<\/h2>\n<p><strong><em>Penmore<\/em><\/strong> protects your personal information as accurate and up to date as is required.\u00a0 We will do our best to base any decisions on accurate information; however, we rely on individuals to disclose all material information and to inform us of any changes.<\/p>\n<p>Upon written request and appropriate identification satisfactory to <strong><em>Penmore<\/em><\/strong>, we will provide reasonable access to personal information exclusively to the individual to whom it refers.\u00a0 In some circumstances, we may refuse access; for example, if:<\/p>\n<ul>\n<li>Doing so would likely reveal personal information about a third party<\/li>\n<li>The information is protected by solicitor-client privilege<\/li>\n<li>Doing so would reveal confidential commercial information<\/li>\n<li>Revealing the information could affect the security of another person<\/li>\n<li>The information was generated in the course of a formal dispute resolution process<\/li>\n<\/ul>\n<h3><em>Personal Health Information Protection Act<\/em> (Ontario)<\/h3>\n<p>The Personal Health Information Protection Act, known by its acronym <strong>PHIPA<\/strong>, outlines privacy regulations for health information custodians in <a href=\"http:\/\/en.wikipedia.org\/wiki\/Ontario\">Ontario<\/a>, Canada.\u00a0 It sets out ten principles as standards for protecting personal information.\u00a0 Those principles are summarized below.<\/p>\n<p><strong>Principle 1 &#8211; Accountability<\/strong><\/p>\n<p>Under Principle 1, an organization must designate a person or persons to be <strong>accountable<\/strong> for privacy systems. The principle also requires organizations to implement policies and practices to give effect to the principles.<\/p>\n<p><strong>Principle 2 &#8211; Purpose<\/strong><\/p>\n<p>The philosophy and <strong>purpose<\/strong> of the policy should reinforce the organization&#8217;s commitment to the privacy and confidentiality of all personal information, both employee and client, and to implementing systems to manage this. It should be stated what information will be collected and for what reasons and that all personal information will be kept confidential and used only for the purpose for which it was collected (or other legitimate business purposes, such as administering benefit plans). It is important to have consistent policies &#8211; management should treat employees&#8217; personal information with the same confidentiality employees are expected to treat client information. Personal information should be broadly defined in the policy to include any identifiable information about a person or client, whether recorded or not.<\/p>\n<p><strong>Principle 3 &#8211; Consent<\/strong><\/p>\n<p>Except for data required to be collected by various laws (e.g. information that must be gathered under the <em>Income Tax Act<\/em> about an individual&#8217;s entitlement to certain tax exemptions), organizations should commit to gaining <strong>consent<\/strong> to collect, use and\/or further disclose personal information in terms that are clear and unambiguous.<\/p>\n<p><strong>Principle 4 &#8211; Limited collection<\/strong><\/p>\n<p>Information <strong>collection<\/strong> must be specific, relevant and necessary and only for the purposes specified. Employers should be aware of the information they are required by law to collect and retain.<\/p>\n<p><strong>Principle 5 &#8211; Limited use, disclosure, retention<\/strong><\/p>\n<p><strong>Use<\/strong> of the information must also be <strong>limited<\/strong> to the purposes specified, limited in its <strong>disclosure<\/strong> and <strong>retained<\/strong> only as long as necessary. Employers may be required to disclose information under court order or subpoena and policies should recognize this.<\/p>\n<p><strong>Principle 6 &#8211; Accuracy<\/strong><\/p>\n<p>Information should be <strong>accurate<\/strong>, complete and up-to-date and processes should allow for this maintenance.<\/p>\n<p><strong>Principle 7 &#8211; Safeguards<\/strong><\/p>\n<p>Information must be <strong>safeguarded<\/strong> during use, storage and disposal. Personal information about clients or customers will often have different storage and access systems than employee information. Employee information is often only accessed by supervisory personnel, Human Resources and\/or Payroll personnel and the employees themselves; it can be stored electronically or manually in the Human Resources or Payroll Department, protected by locks and keys or by passwords. Client information, often required by numerous employees, must be more accessible and therefore, must have strict rules regarding the collection, use and disclosure of such data. Access to the data should be protected by passwords and there should be a prohibition against releasing any client information except as necessary to fulfil one&#8217;s duties. Sensitive materials such as employee or client medical files should be kept separately and safeguarded.<\/p>\n<p>Processes should be set up to document and regulate who has internal access to employee information. Procedures should be in place to ensure employee consent in writing to release information to third parties. Access to client information by employees will, of course, depend on job descriptions. Security measures, such as passwords, and adequate training to ensure employees know how to properly collect, use and disclose client information should be part of the policy.<\/p>\n<p>By law, some employee information must be kept for specific time periods. Processes should be documented to ensure information no longer required is disposed of properly so that it can not fall into the wrong hands. Similarly, outdated client information must be adequately disposed of, either by destruction or archiving.<\/p>\n<p><strong>Principle 8 &#8211; Openness<\/strong><\/p>\n<p>Privacy policies should be <strong>open<\/strong> and clear regarding accountability measures and means and rights of access.<\/p>\n<p><strong>Principle 9 &#8211; Individual access<\/strong><\/p>\n<p><strong>Individuals<\/strong> should be informed of the existence of information and their rights to <strong>access<\/strong> and correct such data, subject to logistic and\/or security limitations.<\/p>\n<p><strong>Principle 10 &#8211; Challenging compliance<\/strong><\/p>\n<p>Privacy policies should include processes to <strong>challenge compliance<\/strong> with these principles to the person designated accountable for privacy and information management.<\/p>\n<p><strong><em>Penmore\u2019s<\/em><\/strong> Privacy Policy may be modified from time to time to comply with the applicable laws or to reflect our updated business practices, without prior notice.[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Privacy PolicyPrivacy \u2013 Definition: Privacy is the right of an individual to control who has access to his or her personal information and under what circumstances. POLICY The privacy of your personal information is of the utmost importance to Penmore.\u00a0 Penmore believes that protecting the privacy and the confidentiality of its customers\u2019 personal information is [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"_et_pb_use_builder":"on","_et_pb_old_content":"<h1>Privacy \u2013 Definition:<\/h1>\r\n<em>Privacy is the right of an individual to control who has access to his or her personal information and under what circumstances.<\/em>\r\n<h1>POLICY<\/h1>\r\nThe privacy of your personal information is of the utmost importance to <strong><em>Penmore.<\/em><\/strong>\u00a0 <strong><em>Penmore<\/em><\/strong> believes that protecting the privacy and the confidentiality of its customers\u2019 personal information is an important part of its relationship with them any information gathered by <strong><em>Penmore<\/em><\/strong> will be kept strictly confidential and will only be used or shared in ways for which you have specifically consented.\u00a0 Unless we have your express consent, <strong><em>Penmore<\/em><\/strong> will not sell, rent or trade your personal information to any third party.\r\n\r\nThe personal information that <strong><em>Penmore<\/em><\/strong> holds or will hold concerning you will be treated confidentially, and will be kept in a file opened for the purpose of allowing you to benefit from various insurance, annuity, credit and other related financial services offered by your insurer.\u00a0 This information will only be consulted by the personnel of your insurer who require access to it in the course of their duties.\r\n\r\nYou may have access to your file and request that information be corrected if you prove that it is incorrect, incomplete, ambiguous, outdated or unnecessary.\u00a0 You must then send a written request to the person in charge of the protection of personal information at <strong><em>Penmore.<\/em><\/strong>\r\n\r\n<strong>Why Penmore collects Personal Information<\/strong>\r\n\r\n<strong><em>Penmore<\/em><\/strong> collects, uses and discloses personal information about its customers for the purposes of managing their financial-related needs.\u00a0 This includes evaluating and assessing insurance needs, underwriting, coverage assessment, compiling statistics, providing all policy related or administrative services, loss control, compliance with any regulatory requirements, claims investigation, protecting against error and fraud, ensuring information is accurate and up to date, and determining your payment of premiums.\r\n\r\n<strong><em>\u00a0<\/em><\/strong><strong><em>Penmore<\/em><\/strong> may also collect, use and disclose personal information about third parties for the purpose of handling claims made against our customers.\r\n\r\n<strong>What type of Personal Information <em>Penmore<\/em> collects<\/strong>\r\n\r\nThe types of personal information that <strong><em>Penmore<\/em><\/strong> may collect are property details, claims histories, employment information, professional history, medical and health information, driving records and financial information.\u00a0 Which of those types we collect in a particular case depends on which of our purposes is applicable and on the particular circumstances.\r\n<h2>How <em>Penmore<\/em> Obtains Personal Information<\/h2>\r\nThe personal information collected by <strong><em>Penmore<\/em><\/strong> is provided to us by you directly or through an insurance company or agent, by ways of your insurance application, and by service providers.\u00a0 For some of our purposes, we may obtain personal information, such as claims, underwriting, credit history and driving records, from other industry sources.\r\n\r\nIn some cases, <strong><em>Penmore<\/em><\/strong> will consider the need for certain personal information is so obvious as part of the process that the customer\u2019s consent to its collection and use are implied.\r\n\r\nIn some circumstances, consent may not be required for the collection and use of personal information for the purpose of investigating a breach of an insurance\/fund policy or other agreement, or a contravention of Canadian law.\r\n\r\nSubject to legal or contractual restrictions and upon reasonable notice, you may withdraw your consent at any time.\u00a0 At that time, we will advise you of the consequences of withdrawal of your consent.\r\n<h2>How and When <em>Penmore<\/em> Shares Personal Information<\/h2>\r\n<strong>\u00a0<\/strong><strong><em>Penmore<\/em><\/strong> provides personal information to other organizations (including its affiliated companies) only for the purposes listed above, or if required or permitted to do so by law.\r\n\r\nIn some circumstances, the customer\u2019s consent is not required for the disclosure of personal information; this would apply, for example, to the disclosure of personal information to an approved investigative body when we believe that the information relates to the breach of an insurance policy or other agreement or a contravention of Canadian law; or when we are required by law to disclose the information; or when we disclose information to a lawyer for claims purposes or to obtain legal advice.\r\n\r\nWhen <strong><em>Penmore<\/em><\/strong> provides data containing personal information to service providers, they are subject to confidentiality requirements.\r\n<h2>Securing and Safeguarding Your Personal Information<\/h2>\r\n<strong><em>Penmore<\/em><\/strong> protects your personal information with security safeguards appropriate to the sensitivity of the information<strong><em>.\u00a0 Penmore<\/em><\/strong> employees, contractors and representatives access personal information only when they have a business need to do so.\u00a0 Our employees are made aware of the proper handling of personal information pertaining to this policy.\u00a0 We keep personal information only as long as it is necessary for our purposes listed above.\r\n<h2>Accuracy of and Access to Your Personal Information<\/h2>\r\n<strong><em>Penmore<\/em><\/strong> protects your personal information as accurate and up to date as is required.\u00a0 We will do our best to base any decisions on accurate information; however, we rely on individuals to disclose all material information and to inform us of any changes.\r\n\r\nUpon written request and appropriate identification satisfactory to <strong><em>Penmore<\/em><\/strong>, we will provide reasonable access to personal information exclusively to the individual to whom it refers.\u00a0 In some circumstances, we may refuse access; for example, if:\r\n<ul>\r\n \t<li>Doing so would likely reveal personal information about a third party<\/li>\r\n \t<li>The information is protected by solicitor-client privilege<\/li>\r\n \t<li>Doing so would reveal confidential commercial information<\/li>\r\n \t<li>Revealing the information could affect the security of another person<\/li>\r\n \t<li>The information was generated in the course of a formal dispute resolution process<\/li>\r\n<\/ul>\r\n<h3><em>Personal Health Information Protection Act<\/em> (Ontario)<\/h3>\r\nThe Personal Health Information Protection Act, known by its acronym <strong>PHIPA<\/strong>, outlines privacy regulations for health information custodians in <a href=\"http:\/\/en.wikipedia.org\/wiki\/Ontario\">Ontario<\/a>, Canada.\u00a0 It sets out ten principles as standards for protecting personal information.\u00a0 Those principles are summarized below.\r\n\r\n<strong>Principle 1 - Accountability<\/strong>\r\n\r\nUnder Principle 1, an organization must designate a person or persons to be <strong>accountable<\/strong> for privacy systems. The principle also requires organizations to implement policies and practices to give effect to the principles.\r\n\r\n<strong>Principle 2 - Purpose<\/strong>\r\n\r\nThe philosophy and <strong>purpose<\/strong> of the policy should reinforce the organization's commitment to the privacy and confidentiality of all personal information, both employee and client, and to implementing systems to manage this. It should be stated what information will be collected and for what reasons and that all personal information will be kept confidential and used only for the purpose for which it was collected (or other legitimate business purposes, such as administering benefit plans). It is important to have consistent policies - management should treat employees' personal information with the same confidentiality employees are expected to treat client information. Personal information should be broadly defined in the policy to include any identifiable information about a person or client, whether recorded or not.\r\n\r\n<strong>Principle 3 - Consent<\/strong>\r\n\r\nExcept for data required to be collected by various laws (e.g. information that must be gathered under the <em>Income Tax Act<\/em> about an individual's entitlement to certain tax exemptions), organizations should commit to gaining <strong>consent<\/strong> to collect, use and\/or further disclose personal information in terms that are clear and unambiguous.\r\n\r\n<strong>Principle 4 - Limited collection<\/strong>\r\n\r\nInformation <strong>collection<\/strong> must be specific, relevant and necessary and only for the purposes specified. Employers should be aware of the information they are required by law to collect and retain.\r\n\r\n<strong>Principle 5 - Limited use, disclosure, retention<\/strong>\r\n\r\n<strong>Use<\/strong> of the information must also be <strong>limited<\/strong> to the purposes specified, limited in its <strong>disclosure<\/strong> and <strong>retained<\/strong> only as long as necessary. Employers may be required to disclose information under court order or subpoena and policies should recognize this.\r\n\r\n<strong>Principle 6 - Accuracy<\/strong>\r\n\r\nInformation should be <strong>accurate<\/strong>, complete and up-to-date and processes should allow for this maintenance.\r\n\r\n<strong>Principle 7 - Safeguards<\/strong>\r\n\r\nInformation must be <strong>safeguarded<\/strong> during use, storage and disposal. Personal information about clients or customers will often have different storage and access systems than employee information. Employee information is often only accessed by supervisory personnel, Human Resources and\/or Payroll personnel and the employees themselves; it can be stored electronically or manually in the Human Resources or Payroll Department, protected by locks and keys or by passwords. Client information, often required by numerous employees, must be more accessible and therefore, must have strict rules regarding the collection, use and disclosure of such data. Access to the data should be protected by passwords and there should be a prohibition against releasing any client information except as necessary to fulfil one's duties. Sensitive materials such as employee or client medical files should be kept separately and safeguarded.\r\n\r\nProcesses should be set up to document and regulate who has internal access to employee information. Procedures should be in place to ensure employee consent in writing to release information to third parties. Access to client information by employees will, of course, depend on job descriptions. Security measures, such as passwords, and adequate training to ensure employees know how to properly collect, use and disclose client information should be part of the policy.\r\n\r\nBy law, some employee information must be kept for specific time periods. Processes should be documented to ensure information no longer required is disposed of properly so that it can not fall into the wrong hands. Similarly, outdated client information must be adequately disposed of, either by destruction or archiving.\r\n\r\n<strong>Principle 8 - Openness<\/strong>\r\n\r\nPrivacy policies should be <strong>open<\/strong> and clear regarding accountability measures and means and rights of access.\r\n\r\n<strong>Principle 9 - Individual access<\/strong>\r\n\r\n<strong>Individuals<\/strong> should be informed of the existence of information and their rights to <strong>access<\/strong> and correct such data, subject to logistic and\/or security limitations.\r\n\r\n<strong>Principle 10 - Challenging compliance<\/strong>\r\n\r\nPrivacy policies should include processes to <strong>challenge compliance<\/strong> with these principles to the person designated accountable for privacy and information management.\r\n\r\n<strong><em>Penmore\u2019s<\/em><\/strong> Privacy Policy may be modified from time to time to comply with the applicable laws or to reflect our updated business practices, without prior notice.","_et_gb_content_width":"","footnotes":""},"class_list":["post-1517","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/penmore.com\/insurance\/wp-json\/wp\/v2\/pages\/1517","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/penmore.com\/insurance\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/penmore.com\/insurance\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/penmore.com\/insurance\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/penmore.com\/insurance\/wp-json\/wp\/v2\/comments?post=1517"}],"version-history":[{"count":0,"href":"https:\/\/penmore.com\/insurance\/wp-json\/wp\/v2\/pages\/1517\/revisions"}],"wp:attachment":[{"href":"https:\/\/penmore.com\/insurance\/wp-json\/wp\/v2\/media?parent=1517"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}