Written standards, applied before launch.

Insurance is a regulated market and personal data is regulated everywhere we operate. This page describes what we actually do, so that a partner or an insurer can decide whether our standard is one they can work with.

Person signing a document at a desk in an office

Please read this first

Nothing on this page is legal advice and it does not describe every obligation that may apply to your business. Insurers, intermediaries and publishers remain responsible for their own regulatory compliance, permissions and disclosures. This page describes the standards HS Ocean, S.L. applies to its own operation.

Six areas we work against.

Each has a named owner inside the company, a written procedure and a review schedule.

01

Consent and lawful basis

What a person was shown, the page it appeared on and the moment they agreed are recorded with the enquiry and kept with it.

02

Advertising standards

Partner creative and landing pages are reviewed against a written standard before a placement goes live and again on a schedule.

03

Objections and withdrawal

Requests apply across the whole network. Somebody who withdraws consent is removed from every line, not just one campaign.

04

Data protection

Secure handling, access limited by role, and a defined retention period for every enquiry we hold.

05

Monitoring

Placements are re-checked after launch, not only before it, and unusual submission patterns trigger a review.

06

Data subject rights

Access, rectification, erasure, restriction, portability and objection handled through a documented process.

A consent record is worthless if you cannot reproduce it.

Storing a boolean proves almost nothing. What matters is being able to show, months later, exactly what a person was told, on which page, and when.

  • The wording itself — as it appeared, not a reference to a template
  • The page — the address the enquiry actually came from
  • The moment — captured on submission and kept with the enquiry
  • The source — which partner and which channel
  • Enough context to show the disclosure rendered as intended

All of it travels with the enquiry to the receiving business, because the company making contact is the one that has to be able to demonstrate the basis for it.

Person holding a smartphone

Roles under the GDPR

Who is controller and who is processor changes depending on the stage of the journey. We set it out explicitly in the data protection terms attached to every agreement, rather than leaving it to be argued about later.

Language we do not allow.

Insurance advertising in Europe is closely watched, and rightly so. We keep a written standard and read partner copy against it before anything goes live.

The kinds of wording we rule out

The standard is kept as a specific list. Broadly it excludes:

  • Anything implying a policy or a price is already secured for that person
  • Superlative claims about premiums, providers, cover or service
  • Suggestions that acceptance is automatic or that no questions will be asked
  • Timing promises a marketing partner is in no position to make
  • Language that implies the partner is itself an insurer or an adviser
  • Any use of an insurer's brand or logo without written permission

How the check is applied

The standard is not an annex nobody reads. It is applied at three points:

  • Before launch — every placement is read against the list
  • On change — new creative or a revised page comes back for review
  • On a schedule — live placements are re-read on a rota

Partners receive the full written standard at onboarding. Where wording is borderline, the partner desk gives a direct answer rather than leaving it to interpretation.

Colleagues signing documents at a business meeting
Reviewed before launch
Analyst reviewing charts and documents
Re-checked on a rota
Colleagues working together in a modern office
One named owner per area

What we look at before a placement goes live.

What we reviewWhat we checkIf it does not pass
The landing pageWhether the disclosure is visible, how the form is built, the wording around consentA written list of changes, then another review
The creativeClaims, line-specific rules, whether it matches the pageRejected, with the exact wording identified
Who owns the siteA named company, a contactable owner, genuine contentDeclined where ownership cannot be established
The traffic sourceWhether the channel described is the channel we observeSuspended immediately pending an explanation
Consent captureWhether what is recorded matches what was shownHeld until it is corrected
After launchScheduled re-checks of live placements and of submission patternsPaused, a list of changes, then another review
How to ask
By email or by post
Identity
Confirmed before we act
Somebody acting for you
Accepted with written authority
Response
Within one month, extendable where the law allows
Cost
Nothing
If you disagree
You may complain to a supervisory authority

Data subject requests go to a person.

Anyone whose personal data we hold can ask for access, rectification, erasure or restriction, can object to processing, can ask for portability and can withdraw consent at any time. We run a documented intake for those requests with identity verification and a defined response time.

Full detail, including how to submit a request and what happens if we decline one, is on the your data rights page.

Compliance questions.

No. We are a marketing company and we do not carry out insurance distribution: we do not advise, propose or arrange contracts of insurance, and we take no part in administering or performing them. The regulated businesses that receive enquiries through us do that work under their own permissions.

It depends on the activity, and each one is set out in our Privacy Policy. For passing a consumer enquiry to an insurer the person asked to hear from, we rely on the consent obtained at the point of the enquiry, recorded as described above.

The placement is suspended immediately and the partner is told exactly what was at fault. Repeat breaches end the relationship. How long we have worked together does not change that.

Our processing and storage sit within the European Economic Area. Where a service provider would involve a transfer, it is covered by an appropriate transfer mechanism and set out in our Privacy Policy rather than left implicit.

Reasonable audit and information rights are part of the data protection terms attached to an agreement. In practice most insurers start with a questionnaire, and we would rather answer a thorough one early than discover a mismatch after an integration is built.

A named compliance function with the authority to suspend any placement or any delivery without commercial sign-off. That authority is the part that matters; without it a compliance function is decoration.

Send us the difficult questionnaire first.

If your onboarding process has a due diligence pack, send it before anything is built. We would rather answer it early than discover a mismatch later.