Privacy Policy
Effective Date: July 01, 2026
Last Updated: July 01, 2026
Unique Risks Ltd. (“Unique Risks,” “we,” “us,” or “our”) is an Ontario-based Managing General Agent (“MGA”) providing insurance-related products and services through brokers, insurers, reinsurers, claims professionals, service providers, and other insurance-market participants.
In the course of our business, we collect, use, disclose, retain, and protect personal information in order to provide insurance products and services, assess and underwrite risk, administer policies, support claims handling, meet legal and regulatory obligations, and operate our business.
Unique Risks is committed to protecting the privacy and confidentiality of personal information in accordance with the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and other applicable Canadian privacy laws.
This Privacy Policy explains how we handle personal information and how individuals may contact us with questions, access requests, correction requests, or privacy complaints.
1. Scope of this Policy
This Privacy Policy applies to personal information that Unique Risks collects, uses, discloses, or otherwise handles in connection with our insurance-related business activities.
This may include personal information relating to:
-
applicants, insureds, policyholders, claimants, beneficiaries, directors, officers, employees, contractors, and other individuals associated with commercial insurance risks;
-
broker, insurer, reinsurer, adjuster, vendor, and business partner contacts;
-
individuals who communicate with us, submit information through our website or online forms, or otherwise interact with Unique Risks.
This Policy does not apply to information that is not personal information, such as anonymized, aggregated, or business information that cannot reasonably identify an individual.
2. What Personal Information We Collect
The personal information we collect depends on the product, service, transaction, relationship, or claim involved.
Personal information may include:
-
name, address, email address, telephone number, and other contact details;
-
date of birth, occupation, employment information, work history, professional credentials, or business role;
-
information about property, assets, liabilities, income, finances, banking, payment, credit, or premium-financing arrangements;
-
insurance application, underwriting, policy, renewal, endorsement, claims, loss history, and risk information;
-
information about directors, officers, employees, contractors, tenants, customers, claimants, injured persons, witnesses, or other individuals connected to an insurance risk or claim;
-
health, injury, disability, medical, or treatment information, where relevant to underwriting, claims, benefits, or risk assessment;
-
driver, vehicle, premises, business operations, inspection, loss-control, fraud-prevention, sanctions-screening, and compliance information;
-
communications with us, including emails, call notes, forms, submissions, complaints, and service inquiries;
-
website and technical information, such as IP address, browser type, device information, pages viewed, form submissions, cookies, analytics data, and similar online identifiers.
We limit the personal information we collect to what is reasonably necessary for the purposes identified in this Policy or otherwise disclosed at or before the time of collection.
3. How We Collect Personal Information
We may collect personal information directly from individuals or indirectly from other sources, including:
-
insurance brokers, agents, advisors, and intermediaries;
-
insurers, reinsurers, managing general agents, third-party administrators, adjusters, investigators, appraisers, inspectors, engineers, risk consultants, repairers, legal counsel, and other claims or insurance professionals;
-
employers, business entities, policyholders, applicants, claimants, witnesses, and other individuals involved in a policy, application, transaction, or claim;
-
credit bureaus, background-check providers, sanctions-screening providers, fraud-prevention databases, industry databases, public registries, courts, tribunals, government bodies, regulators, and law enforcement, where permitted by law;
-
applications, declarations, submissions, transactions, renewal materials, claims forms, websites, online forms, email, telephone, and other communications;
-
service providers and technology platforms used to support our business.
Where personal information is provided to us about another individual, the person providing the information must have the authority or consent necessary to do so, unless otherwise permitted by law.
4. Why We Use Personal Information
Unique Risks uses personal information for purposes that are reasonable and necessary for our insurance-related business, including to:
-
receive, review, quote, underwrite, decline, bind, issue, administer, renew, amend, cancel, or service insurance policies;
-
assess eligibility, coverage, risk, pricing, limits, deductibles, exclusions, and other underwriting terms;
-
communicate with brokers, insurers, reinsurers, policyholders, applicants, insureds, claimants, vendors, regulators, and other relevant parties;
-
investigate, manage, adjust, defend, settle, pay, subrogate, or otherwise administer claims;
-
obtain or provide reinsurance, risk transfer, policy administration, claims administration, inspection, loss-control, actuarial, legal, accounting, compliance, or other professional services;
-
verify identity, prevent fraud, detect misrepresentation, screen for sanctions, comply with anti-money laundering or other legal requirements, and manage business risks;
-
process payments, refunds, commissions, premiums, fees, taxes, and related accounting or financial transactions;
-
maintain business records, audit files, compliance records, underwriting files, claims files, and regulatory records;
-
respond to questions, access requests, correction requests, privacy complaints, legal demands, subpoenas, court orders, regulator requests, or law-enforcement requests;
-
operate, secure, monitor, improve, and administer our website, systems, data, platforms, records, and business operations;
-
compile statistics, perform portfolio analysis, conduct actuarial analysis, improve underwriting, assess performance, develop products, and support business planning, using de-identified or aggregated information where appropriate;
-
send service, transactional, renewal, administrative, or legal notices;
-
send marketing or business-development communications where permitted by law, subject to applicable consent and unsubscribe requirements.
We do not use personal information for purposes that are incompatible with the purposes for which it was collected, unless we obtain consent or are otherwise permitted or required by law.
5. Consent
Unique Risks collects, uses, and discloses personal information with consent, except where permitted or required by law.
Consent may be express or implied, depending on the sensitivity of the information, the reasonable expectations of the individual, the purposes involved, and the surrounding circumstances.
By applying for insurance, requesting a quote, renewing a policy, submitting a claim, communicating with us, providing information to a broker or other intermediary for submission to Unique Risks, or otherwise using our products or services, individuals consent to the collection, use, and disclosure of personal information for the purposes described in this Policy and any related application, consent, authorization, or notice.
Where information is sensitive, such as health, financial, banking, claims, injury, disability, or similar information, we will seek express consent where appropriate or where required by law.
An individual may withdraw consent, subject to legal, contractual, regulatory, underwriting, claims, and business restrictions. If consent is withdrawn, Unique Risks may be unable to provide, continue, renew, underwrite, administer, or service a product, policy, claim, or requested service.
6. Disclosure of Personal Information
Unique Risks may disclose personal information where reasonably necessary for the purposes described in this Policy, including to:
-
insurance brokers, agents, advisors, and intermediaries;
-
insurers, prospective insurers, reinsurers, retrocessionaires, pools, syndicates, and insurance-market participants;
-
claims adjusters, appraisers, investigators, engineers, inspectors, medical professionals, repairers, restoration contractors, defence counsel, coverage counsel, experts, and other claims service providers;
-
third-party administrators, underwriting platforms, rating platforms, policy administration providers, document-management providers, data-hosting providers, cloud providers, IT providers, cybersecurity providers, payment processors, accounting providers, auditors, consultants, mailing providers, and other service providers;
-
credit bureaus, premium-finance companies, sanctions-screening providers, fraud-prevention organizations, industry databases, and other risk-management providers;
-
regulators, self-regulatory organizations, government agencies, law enforcement, courts, tribunals, dispute-resolution bodies, or other authorities, where required or permitted by law;
-
purchasers, prospective purchasers, lenders, investors, insurers, advisors, or other parties in connection with a financing, restructuring, merger, sale, transfer, or other business transaction involving all or part of our business;
-
any other person or organization with consent or where permitted or required by law.
We do not sell personal information.
7. Service Providers and Third-Party Processing
Unique Risks may use third-party service providers to support our business operations, including technology, hosting, storage, email, cybersecurity, document management, rating, policy administration, claims administration, payment processing, accounting, legal, compliance, analytics, and other business services.
Where personal information is transferred to a service provider for processing, Unique Risks remains responsible for that information while it is under our control. We use contractual, administrative, technical, and organizational safeguards designed to require service providers to protect personal information and use it only for authorized purposes.
Service providers may be located in Canada or in other jurisdictions. Personal information processed or stored outside Canada may be subject to the laws of those jurisdictions, including lawful access by courts, law enforcement, regulators, or government authorities.
8. Cross-Border Transfers
Unique Risks may store, process, or access personal information in Canada or other jurisdictions, including through insurers, reinsurers, cloud providers, technology vendors, claims vendors, or other service providers.
Where personal information is transferred outside Canada, we take reasonable steps to ensure that it receives a comparable level of protection, including through contractual safeguards and vendor due diligence where appropriate.
Individuals may contact our Privacy Officer for information about our use of service providers outside Canada.
9. Safeguards
Unique Risks uses reasonable physical, organizational, administrative, and technical safeguards appropriate to the sensitivity of the personal information we handle.
These safeguards may include:
-
restricted access to offices, systems, files, and records;
-
role-based access controls and user authentication;
-
encryption, firewalls, monitoring tools, malware protection, and other security technologies;
-
policies, procedures, employee training, and confidentiality obligations;
-
vendor due diligence and contractual privacy and security obligations;
-
secure disposal, deletion, or anonymization of personal information when no longer required;
-
incident-response procedures for suspected or actual privacy breaches.
Only employees, contractors, representatives, or service providers who require access for authorized business purposes are permitted to access personal information.
Despite our safeguards, no system or method of transmission or storage is completely secure. We encourage individuals and business partners to use care when transmitting personal information.
10. Accuracy
Unique Risks takes reasonable steps to ensure that personal information used to make decisions about individuals is as accurate, complete, and up to date as necessary for the purposes for which it is used.
Individuals may request correction of personal information that they believe is inaccurate or incomplete. Where appropriate, we will correct the information or annotate the record to reflect the requested correction.
11. Retention and Disposal
Unique Risks retains personal information only as long as reasonably necessary for the purposes for which it was collected, or as required or permitted by law, regulation, contract, professional standards, insurance-market requirements, audit obligations, claims obligations, limitation periods, or legitimate business needs.
Retention periods may vary depending on the type of information, the insurance product, the policy period, the existence of claims, regulatory requirements, and legal limitation periods.
When personal information is no longer required, we will securely destroy, delete, de-identify, anonymize, or otherwise dispose of it in a manner appropriate to its sensitivity.
12. Access to Personal Information
Individuals have the right to request access to personal information about them that is under Unique Risks’ control, subject to legal restrictions.
In some circumstances, access may be limited or denied, including where disclosure would reveal personal information about another individual, reveal confidential commercial information, compromise an investigation, breach privilege, interfere with legal proceedings, or where the information cannot be disclosed for legal, security, regulatory, or other reasons permitted by law.
If access is denied, we will provide written reasons, unless prohibited by law.
13. Correction of Personal Information
Individuals may request correction of personal information that they believe is inaccurate, incomplete, or out of date.
Where appropriate, Unique Risks will correct the information. If we do not agree that a correction is required, we may annotate the record to reflect the correction request.
14. Privacy Breaches
Unique Risks maintains procedures to respond to suspected or actual privacy breaches involving personal information.
If a breach of security safeguards involving personal information under our control creates a real risk of significant harm to an individual, Unique Risks will notify affected individuals and report the breach to the Office of the Privacy Commissioner of Canada, as required by law.
We may also notify other organizations, regulators, insurers, reinsurers, brokers, service providers, law enforcement, or government authorities where required or appropriate to reduce the risk of harm, comply with legal obligations, or manage the incident.
Unique Risks will maintain records of privacy breaches as required by law.
15. Website, Cookies, and Analytics
Unique Risks may collect certain information when individuals visit our website or use online forms, including IP address, browser type, device information, operating system, referring website, pages visited, time spent on pages, links clicked, form submissions, and similar technical information.
We may use cookies, analytics tools, and similar technologies to operate our website, improve functionality, understand usage, maintain security, and support business communications.
Individuals may be able to adjust browser settings to block or delete cookies. Some website features may not function properly if cookies are disabled.
Where we use third-party analytics, advertising, or tracking technologies, those providers may process information in accordance with their own privacy terms.
16. Marketing and Electronic Communications
Unique Risks may send business, service, administrative, renewal, claims, transactional, or legal communications as part of our insurance-related activities.
We may also send marketing or business-development communications where permitted by law. Individuals may unsubscribe from commercial electronic messages by using the unsubscribe mechanism in the message or by contacting us.
Even if an individual unsubscribes from marketing communications, we may continue to send service, transactional, legal, claims, renewal, policy, or account-related communications where permitted or required.
17. Privacy Officer and Accountability
Unique Risks has designated a Privacy Officer responsible for overseeing privacy compliance and responding to privacy inquiries, access requests, correction requests, and complaints.
Rodney Spurrell COO
Unique Risks Ltd.
Unit 107 – 1939 Ironoak Way, Oakville ON, Canada, L6H 3V8
rod.spurrell@uniquerisks.com
Unique Risks maintains privacy policies, procedures, and safeguards designed to support compliance with applicable privacy laws.
18. Questions, Access Requests, Correction Requests, and Complaints
Individuals may contact our Privacy Officer to:
-
ask questions about this Privacy Policy;
-
request access to their personal information;
-
request correction of their personal information;
-
withdraw consent, subject to legal and contractual limits;
-
make a privacy complaint.
We will respond to requests within the time required by applicable law. We may need to verify identity before responding to an access or correction request.
If an individual is not satisfied with our response, they may contact the Office of the Privacy Commissioner of Canada.
19. Changes to this Privacy Policy
Unique Risks may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, technology, insurance products, or business operations.
The updated version will be posted on our website or otherwise made available. The “Last Updated” date will indicate when the Policy was most recently revised.
Continued use of our products, services, website, or other interactions with Unique Risks after the Policy is updated constitutes acceptance of the revised Policy, where permitted by law.
