This Privacy Notice explains how we collect, use, store and protect your personal information when providing mortgage and insurance advice. We are committed to treating your data fairly, lawfully and transparently, in line with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the expectations of the Financial Conduct Authority (FCA).
1. Who we are (Data Controller)
Insure My Health
[8 Dudley Road, Bournemouth, BH10 6BS)
We act as the Data Controller for the personal information you provide to us.
If you have any questions about this notice or how we use your data, you can contact our Data Protection Officer (DPO) at:
dpo@therightmortgage.co.uk
2. The personal information we collect
We may collect and process the following categories of personal data:
Personal identifiers and contact details
- Name
- Address
- Date of birth
- Contact details (email, phone number)
Health and medical information
- Relevant medical history
- Lifestyle information
(Used only for insurance advice and underwriting)
Technical and website information
- IP address
- Browser type
- Cookies and tracking data
(See our Cookies Policy for full details)
We only collect information that is necessary for us to provide regulated health insurance advice.
3. How we collect your personal information
Information you provide directly
Most of the information we process is provided by you when you:
- Request insurance advice
- Complete fact‑finds, forms or assessments
- Communicate with us by phone, email or online
Information we receive from third parties
We may also receive information from:
- Insurers – to support insurance applications, underwriting and servicing
4. Why we use your personal information (Lawful Bases)
We process your personal data under the following lawful bases:
Contractual obligation
To provide you with:
- Insurance advice
- Product recommendations
- Application support and underwriting
Legal obligation
To comply with:
- FCA regulations
- Anti‑Money Laundering (AML) legislation
- Prevention and detection of fraud
- Record‑keeping requirements
Legitimate interests
Our legitimate interests include:
- Ensuring the accuracy of records
- Managing our relationship with you
- Monitoring the quality of advice
- Protecting our business from financial crime
- Improving our services and systems
We do not use your data for unrelated marketing without your explicit consent.
5. Who we share your information with
We may share your information with:
Product providers
- Insurance companies
(Specific providers will be disclosed during the advice process)
Regulators and authorities
- Financial Conduct Authority (FCA)
- Information Commissioner’s Office (ICO)
- National Crime Agency (NCA)
- Other law‑enforcement bodies where legally required
Technology and service providers
- Customer Relationship Management systems (e.g., The Key)
- Product sourcing systems (e.g., Mortgage Brain, Trigold, iPipeline, AIR Sourcing)
- Secure cloud‑based storage providers
We never sell your data to third parties.
6. International transfers
Some of our technology providers may store or process data outside the UK.
Where this occurs, we ensure appropriate safeguards are in place, such as:
- UK adequacy regulations
- Standard Contractual Clauses (SCCs)
- Additional technical and organisational protections
We only work with reputable providers who meet UK GDPR standards.
7. Automated decision‑making and profiling
We do not use automated decision‑making to make final lending or insurance decisions.
We may use profiling tools (e.g., sourcing systems) to identify suitable products, but all recommendations are reviewed and approved by a qualified adviser.
8. How we store and protect your information
Your information is stored securely using:
- Encrypted systems
- Access controls
- Secure CRM platforms
- Industry‑standard cybersecurity measures
We take appropriate steps to protect your data from loss, misuse or unauthorised access.
9. How long we keep your information
We retain your data for as long as necessary to meet our legal and regulatory obligations. This typically means:
- insurance advice records: retained for the period during which you may raise a complaint
- AML and financial crime records: retained in line with statutory requirements
After this period, your information is securely and permanently deleted.
10. Your data protection rights
You have the following rights under UK GDPR:
- Right of access – to request copies of your personal data
- Right to rectification – to correct inaccurate or incomplete data
- Right to erasure – to request deletion in certain circumstances
- Right to restrict processing – to limit how your data is used
- Right to object – to object to certain types of processing
- Right to data portability – to request your data in a transferable format
To exercise any of these rights, contact:
dpo@therightmortgage.co.uk
We will respond within one month.
11. How to complain
If you are unhappy with how we use your personal information, you can contact us at:
dpo@therightmortgage.co.uk
You can also complain to the Information Commissioner’s Office (ICO):
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline: 0303 123 1113
Website: www.ico.org.uk

