Privacy & Data Processing
%20(1).png)
Welcome to Beazley Security Services Limited’s Privacy and Data Protection Policy (“Privacy Policy”).
1. Introduction and Scope
Beazley Security LLC (“Beazley Security,” “we,” “us,” or “our”) respects your privacy and is committed to protecting it through our compliance with this policy (this “Policy”).
This Policy applies to two distinct properties, which are addressed separately where their data practices differ:
• The Beazley Security marketing website(s) (the “Marketing Site”), which the public may browse to learn about our products, services, and content; and
• The Beazley Security client portal (the “Portal” or “VERACIS”), a restricted platform available to registered clients and authorized users for accessing services, account information, and security-related data.
The Marketing Site and the Portal are together referred to as the “Sites,” and any associated features, content, applications, or in-person/virtual events or engagements are referred to as the “Services.” Where a practice described in this Policy applies to only one of the Sites, that is stated explicitly (for example, Section 4 and Section 13).
This Policy describes how we collect, use, disclose, and protect personal information (“Personal Information” or “PII”) in connection with the Sites and Services. “User” means any visitor to the Marketing Site and any registered user of the Portal.
For the Marketing Site and associated marketing, account administration, event management, and business operations activities, Beazley Security LLC acts as the controller of Personal Information.
If the Portal is used by clients to process personal data belonging to their own end clients, that relationship is governed by the Data Processing Agreement.
2. Information We Collect
A. Information You Provide Directly
Depending on how you interact with the Sites, we may collect information such as:
• Contact details: name, company, job title, phone number, email address, and mailing address;
• Account and registration information for the Portal, including login credentials, role, and organization details;
• Information submitted through forms, downloads, uploads, event registrations, or support requests; and
• Any other information you choose to provide, which is provided at your discretion. You are responsible for maintaining the confidentiality of any credentials issued to you and for all activity that occurs under your account.
B. Information Collected Automatically
We and our service providers automatically collect certain technical information when you use the Sites, including device and browser type, IP address, operating system, domain, approximate location (such as country or time zone), and navigation activity. On the Marketing Site, this may also include granular interaction data collected through session-recording and heatmap analytics tools, such as mouse movements, clicks, scrolling, and on-page element interactions. See Section 5 for details on cookies and similar technologies.
C. Portal-Specific Information
Because the Portal provides access to security-related services, it may involve additional categories of information beyond what is collected on the Marketing Site, such as:
• Information about your organization's systems, assets, or security posture that you or your organization submits in order to receive Services;
• Communications and support tickets exchanged through the Portal; and
• Usage and audit logs of Portal activity, maintained for security and account-management purposes.
D. Sensitive Personal Information
In limited circumstances, we may process sensitive categories of Personal Information where necessary to provide the Services, maintain the security of our systems and client environments, comply with legal obligations, or as otherwise permitted by applicable law. Depending on the nature of the Services, this may include information relating to account credentials, security incidents, authentication records, system activity, or other information submitted by clients in connection with the Services.
We do not use Sensitive Personal Information to infer characteristics about individuals or for purposes requiring a separate right to limit use or disclosure under applicable law, except as expressly permitted by law.
E. Events and Recordings
If you attend a Beazley Security in-person or virtual event or meeting, we may record all or part of it for operational, training, educational, documentation, business, and marketing purposes. Where required by applicable law, we will provide notice and obtain consent before recording.
F. Aggregated and De-Identified Data
We compile anonymous aggregated statistics from Users for internal purposes such as benchmarking, capacity planning, and reporting on usage trends. Aggregated or de-identified data does not identify any individual User and is not treated as Personal Information.
3. Legal Bases for Processing (EEA, UK, and Similar Jurisdictions)
Where the General Data Protection Regulation (“GDPR”), the UK GDPR, or a similar law applies, we rely on one or more of the following legal bases for each processing purpose described in this Policy:
• Consent — for example, for non-essential cookies or marketing communications, which you may withdraw at any time;
• Performance of a contract — to register you for, and deliver, the Services you request, including Portal access;
• Legitimate interests — for example, to secure our Sites, prevent fraud, and improve our Services, balanced against your rights and interests; and
• Legal obligation — where we must retain or disclose information to comply with applicable law.
4. How We Use Information
We use information we collect to:
• provide, maintain, and improve the Sites and Services, including Portal functionality;
• respond to inquiries, support requests, and registrations;
• customize and personalize your experience;
• communicate with you about your account, the Services, or updates (including security notices);
• manage internal business operations, including security, fraud prevention, and analytics;
• send marketing communications where permitted, always with the ability to opt out; and
• comply with legal, regulatory, and contractual obligations.
We do not use Portal information for advertising purposes. We retain Personal Information only for as long as necessary to fulfill the purposes described in this Policy, consistent with the retention periods in Section 8. We do not sell Personal Information for money.
5. Cookies and Similar Technologies
We and our service providers use cookies and similar technologies (collectively “Tracking Technologies”) on the Sites to:
• remember your preferences and login state;
• understand how the Sites are used and improve them;
• support security and fraud prevention; and
• where you consent, support advertising and marketing analytics.
Strictly necessary cookies (for example, those required for login and security) are used without separate consent, as permitted by law.
Non-essential cookies (such as analytics and advertising cookies) are used only where you have provided prior consent, for Users in the EEA, UK, and other jurisdictions where opt-in consent is legally required. Users may accept, reject, or customize non-essential cookies through our cookie consent mechanism. Consent may be withdrawn at any time through the cookie preference controls made available on the Sites.
Session recording and heatmap analytics are tracked on the Marketing site, where Microsoft Clarity is used. This is to understand how visitors navigate and interact with our pages. Clarity may capture mouse movements, clicks, scrolling, and similar on-page interactions, and this data is processed by Microsoft. Clarity is a non-essential tracking technology that is configured not to run until a visitor has provided consent through our cookie banner, and it is not used on the Portal. You may decline or withdraw consent to Clarity at any time using the cookie preference controls referenced in this Section, and certain sensitive on-page fields are configured to be masked from capture. Certain sensitive fields are masked from capture and recording.
Most browsers also allow you to block or delete cookies directly; doing so may limit certain features of the Sites.
6. How We Share Information
A. Service Providers and Sub-processors
We share Personal Information with vendors and service providers who perform functions on our behalf, such as hosting, analytics, customer support, and email delivery. These providers are contractually bound to use the information only as instructed by us and to apply appropriate security measures. A current list of our sub-processors is available at https://trust.beazley.security.
B. Aggregated and Non-Identifying Information
We may share aggregated, de-identified, or non-PII data with trusted third parties to support advertising, analytics, or marketing efforts. Such parties are prohibited from using this information beyond our instructions, and it is not combined with PII in a way that re-identifies you.
C. Legal Requirements and Safety
We may disclose Personal Information where required by law or legal process, or where necessary to protect the rights, safety, or property of Beazley Security, our Users, or the public. We resist legally deficient disclosure requests where permissible and, where legally allowed, will notify affected Users of government requests for their information.
D. Business Transfers
If we are involved in a merger, acquisition, financing, or sale of all or part of our business or assets, Personal Information may be transferred to the parties involved, subject to standard confidentiality protections.
E. No Sale of Personal Information; Targeted Advertising
We do not sell Personal Information in exchange for money. To the extent our use of analytics or advertising cookies constitutes a “sale” or “sharing” of Personal Information under applicable U.S. state law (such as the CCPA/CPRA), you may opt out as described in Section 9.
7. International Data Transfers
The Sites are operated in the United States. If you access the Sites from the EEA, the UK, Canada, or elsewhere outside the United States, your information will be transferred to, and processed in, the United States, where data protection laws may differ from those of your home jurisdiction.
Where such transfers are subject to the GDPR or UK GDPR, we rely on appropriate safeguards recognized under those laws, such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, rather than on consent alone. Copies of these safeguards are available on request from [email protected].
8. Data Retention
Data Retention periods vary based on the nature of the information, the Services provided, legal obligations, contractual requirements, and operational needs. We retain Personal Information only for as long as reasonably necessary to fulfill the purposes described in this Policy, including:
• for as long as your Portal account remains active, plus a limited period thereafter to allow for reactivation, dispute resolution, or legal compliance;
• for Marketing Site inquiries and marketing communications, until you opt out or a period of inactivity elapses; and
• as required to comply with legal, tax, audit, or regulatory obligations, or to establish, exercise, or defend legal claims.
When Personal Information is no longer needed, we securely delete it.
Separately, data that is ingested into the Portal in connection with the delivery of contracted services (for example, security data submitted or generated as part of an engagement) is retained in accordance with the retention terms set out in the applicable client Statement of Work (“SOW”) or services agreement, rather than under the general retention practices described above.
9. Your Privacy Rights and Choices
A. EEA, UK, and Similar Jurisdictions (GDPR)
If the GDPR or UK GDPR applies to you, you have the right to:
• access the Personal Information we hold about you;
• rectify inaccurate or incomplete information;
• erase your information in certain circumstances (“right to be forgotten”);
• restrict or object to certain processing, including direct marketing;
• receive a copy of your information in a portable format; and
• withdraw consent at any time, without affecting prior lawful processing.
You also have the right to lodge a complaint with the data protection supervisory authority in your place of habitual residence, place of work, or the location of an alleged infringement of applicable data protection law.
B. California and Other U.S. States (CCPA/CPRA and similar laws)
If you are a California resident, or a resident of another state with a comprehensive privacy law, you may have the right to:
• know what Personal Information we have collected, used, and disclosed about you;
• delete your Personal Information, subject to certain exceptions;
• correct inaccurate Personal Information;
• opt out of the “sale” or “sharing” of your Personal Information and of targeted advertising; and
• not be discriminated against for exercising these rights.
C. Automated Decision-Making and Profiling
We do not make decisions about individuals based solely on automated processing including profiling, that produce legal effects concerning an individual or similarly significantly affects an individual. If we introduce such processing in the future, we will provide any disclosures and rights required under applicable law.
To opt out of the sale/sharing of Personal Information, or to submit any other rights request, email us at [email protected]. If we decline to act on your request, you may appeal our decision by contacting [email protected].
D. All Users
Regardless of jurisdiction, you may update your Portal profile directly, unsubscribe from marketing emails using the link in each communication, or email us at [email protected] to request changes to your information. We will make good-faith efforts to honor requests within the timeframes required by applicable law.
E. Where Beazley Security Acts as a Processor or Service Provider
Where Beazley Security acts solely as a processor, service provider, or contractor on behalf of a client. That client remains responsible for responding to requests to exercise privacy rights under applicable law. Beazley Security will assist its clients in responding to verified requests as required by applicable law and contractual commitments. If you contact us regarding Personal Information that we process on behalf of a client, we may direct you to that client or forward your request where appropriate.
10. Security
We maintain administrative, technical, and organizational measures designed to protect Personal Information against unauthorized access, use, alteration, or disclosure, including encryption of sensitive data in transit (e.g., TLS/SSL), access controls, and monitoring of the Portal environment. Our security program is maintained in alignment with ISO/IEC 27001 (information security management) and ISO/IEC 27701 (privacy information management).
In the event of a data breach affecting Personal Information, we will notify affected individuals and/or regulators as required by applicable law.
11. Children's Privacy
The Sites and Services are not directed to, and are not intended for use by, individuals under the age of 18. We do not knowingly collect Personal Information from children under 18. If you believe a child has provided us with Personal Information, please contact us at [email protected] so we can investigate and, where appropriate, delete the information.
12. Third-Party Links
The Sites may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites, which are not under our control. We encourage you to review the privacy policy of any third-party site you visit.
13. Additional Terms for the Client Portal
The Portal is made available to our clients and their authorized users under the terms of a separate services agreement. Beazley Security acts as a processor (or “service provider”/“contractor” under U.S. state law) where a client submits, uploads, or otherwise makes available Personal Information through the Portal for us to process on its behalf and on its instructions. For example, data about the client's employees, systems, security telemetry, or end customers. In that capacity, the client is the controller, and our processing is governed by the Data Processing Agreement (“DPA”) between Beazley Security and that client, which takes precedence over this Policy for that data.
14. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will notify you by posting a notice on the Sites, updating the “Last Updated” date, and by updating the Beazley Security Trust Center, to which you can subscribe for notifications and updates. Your continued use of the Sites after a revised Policy takes effect constitutes acceptance of the changes. Where required by applicable law, we will obtain consent to material changes before such changes become effective.
15. Contact Us
If you have questions about this Policy, wish to exercise a privacy right, or want to withdraw consent, please contact us:
Beazley Security LLC
65 Memorial Road, Suite 320
West Hartford, CT 06107
Email: [email protected]
Last Updated: September 2026
To see Beazley Security’s Record of Processing Activities, click here.
To see Beazley Security’s Data Processing Agreement, click here.