Privacy

Effective date: This Privacy Policy describes how Shidoa collects, uses, stores, shares, and protects personal information in connection with insurance products, this website, client portals, and related services. By using our services, you acknowledge practices described here, subject to mandatory protections that cannot be waived.

1. Information We Collect

Shidoa collects information necessary to evaluate risk, issue policies, service accounts, process claims, comply with law, and improve client experience. Categories include identity and contact details, demographic information relevant to underwriting, financial information related to premium payment and fraud prevention, property and asset descriptions, health information where medical underwriting applies, employment and business operation details for commercial lines, claims history, correspondence records, portal activity logs, and device or browser metadata generated during site visits.

We collect information directly when you submit applications, forms, claim evidence, or portal updates; automatically through cookies and similar technologies that support security, session management, and aggregated analytics; and indirectly from licensed databases, prior insurers with authorization, assessors, medical professionals, repair vendors, and fraud prevention networks where permitted.

Sensitive categories such as health data receive heightened protection with access restricted to personnel whose roles require review and systems meeting enhanced encryption standards. We collect only information proportionate to stated purposes and retain it according to schedules described below.

2. Purposes of Processing

Personal information supports underwriting decisions, premium calculation, policy administration, billing and collections, claims investigation and settlement, fraud detection, regulatory reporting, internal audits, customer support, product development informed by aggregated trends, marketing where consent or legitimate interest applies, and legal defense of rights. Each purpose aligns with insurance operations clients reasonably expect when purchasing coverage.

We do not use health information for unrelated marketing without explicit consent. Behavioral analytics on public website pages help us improve navigation and content clarity; authenticated portal activity is analyzed primarily for security monitoring and service quality rather than advertising profiling.

Automated decision-making may assist underwriting or fraud scoring, but significant adverse decisions include human review upon request where regulations require. You may ask how automated processes influenced outcomes and provide additional context for reconsideration within stated timeframes.

3. Legal Bases for Processing

Processing rests on multiple legal bases depending on context: contract performance for servicing active policies; legal obligations for recordkeeping, tax documentation, anti-money laundering checks, and regulatory filings; legitimate interests such as fraud prevention, network security, and improving service quality balanced against your rights; and consent for optional marketing subscriptions, certain health disclosures, or sharing beyond operational necessity.

Where consent is required, withdrawal does not affect processing already completed or ongoing servicing of policies that do not depend on withdrawn marketing permissions. Some retention remains mandatory despite deletion requests when law compels maintenance of insurance records.

4. Sharing and Disclosure

Shidoa shares information with service providers under contract—cloud hosting, payment processors, print and mail vendors, IT support, and analytics platforms bound by confidentiality and data processing terms. Reinsurers receive aggregated or individual risk information necessary to spread exposure. Claims may require disclosure to assessors, medical reviewers, legal counsel, repair contractors, and counterparties in subrogation or coordination of benefits scenarios.

Regulators, courts, and law enforcement receive information when legally compelled or necessary to prevent serious harm or fraud. Business transfers in merger or acquisition contexts may include client records with notice and continuity protections where required.

We do not sell personal information to unrelated third parties for their independent marketing. Aggregated, de-identified statistics may appear in transparency reports without identifying individuals or specific households.

5. International Transfers

Data may be processed in facilities or by providers located outside your region. When transfers occur, Shidoa implements safeguards such as standard contractual clauses, encryption in transit and at rest, access controls, and vendor assessments verifying comparable protection levels. Copies of applicable transfer mechanisms may be requested through privacy inquiries subject to confidentiality constraints.

6. Cookies and Similar Technologies

Our website uses essential cookies for session integrity, authentication, and security. Functional cookies remember preferences such as language selection where offered. Analytics cookies collect aggregated visit patterns to improve content organization. Marketing cookies, if deployed on optional landing pages, activate only with consent where required.

Browser settings may block cookies, though essential portal functions may degrade without them. Cookie preference tools, where available, distinguish categories so you can accept necessary operations while declining optional analytics or marketing trackers.

7. Data Retention

Retention periods reflect regulatory requirements, limitation periods for potential claims, and operational needs. Policy and claims records typically persist for years after relationship end as mandated by insurance law. Marketing suppression lists retain minimal identifiers indefinitely to honor unsubscribe requests. Inquiry forms from non-clients may be deleted after defined idle periods unless ongoing quote discussions justify continuation.

When retention expires, Shidoa deletes or anonymizes information using secure destruction methods for electronic records and contracted shredding for physical files where applicable.

8. Security Measures

We employ administrative, technical, and physical safeguards including role-based access, multi-factor authentication for internal systems, encryption for sensitive fields, network monitoring, employee training, vendor security reviews, and incident response plans tested periodically. No system is perfectly secure; report suspected compromise immediately so we can investigate and mitigate.

Clients share responsibility for protecting portal credentials, using secure devices, and verifying communications claiming to originate from Shidoa before sharing additional personal details. We will not request full payment card numbers through unsolicited email links.

9. Your Rights

Depending on applicable law, you may request access to personal information, correction of inaccuracies, deletion subject to legal exceptions, restriction of certain processing, portability of data provided in structured formats, objection to processing based on legitimate interests, and withdrawal of consent for optional activities. Marketing unsubscribe links provide immediate opt-out from promotional email.

Requests may require identity verification to prevent unauthorized disclosure. We respond within timeframes mandated by regulation, possibly extending complex requests with notice. Denials include reasons and appeal paths where available. Authorized agents may submit requests with documented authority.

10. Children and Minors

Shidoa insurance products target adults and business entities. We do not knowingly collect personal information from children through marketing sites. Policies covering minors as insured persons process their information through parent or guardian applicants with appropriate authority and heightened care consistent with dependent coverage purposes.

11. Third-Party Websites

Links to external sites—including social sharing platforms—operate under independent privacy policies. Review those policies before submitting information. Shidoa is not responsible for third-party practices even when links appear on our pages or portals.

12. Changes to This Policy

We update this Privacy Policy when practices, technologies, or legal requirements evolve. Material changes appear on this page with revised effective dates. Continued use after updates constitutes acknowledgment where permitted; otherwise we seek consent for changes affecting previously collected data in ways requiring renewed authorization.

13. Contact and Complaints

Privacy questions, rights requests, or concerns about data handling may be submitted through the contact form on this website, marked for the privacy office. Include sufficient detail for identification without oversharing sensitive health or financial data in unsecured channels. We investigate complaints promptly and cooperate with supervisory authorities when unresolved disputes require escalation.

Shidoa treats privacy as integral to the trust insurance requires. Protecting your information enables fair underwriting, efficient claims, and communication you can rely on throughout the coverage lifecycle.

We review this policy annually and after material system changes to ensure descriptions remain accurate as our services evolve.