01
Consent and lawful basis
What a person was shown, the page it appeared on and the moment they agreed are recorded with the enquiry and kept with it.
Insurance is a regulated market and personal data is regulated everywhere we operate. This page describes what we actually do, so that a partner or an insurer can decide whether our standard is one they can work with.

Please read this first
Nothing on this page is legal advice and it does not describe every obligation that may apply to your business. Insurers, intermediaries and publishers remain responsible for their own regulatory compliance, permissions and disclosures. This page describes the standards HS Ocean, S.L. applies to its own operation.
Each has a named owner inside the company, a written procedure and a review schedule.
01
What a person was shown, the page it appeared on and the moment they agreed are recorded with the enquiry and kept with it.
02
Partner creative and landing pages are reviewed against a written standard before a placement goes live and again on a schedule.
03
Requests apply across the whole network. Somebody who withdraws consent is removed from every line, not just one campaign.
04
Secure handling, access limited by role, and a defined retention period for every enquiry we hold.
05
Placements are re-checked after launch, not only before it, and unusual submission patterns trigger a review.
06
Access, rectification, erasure, restriction, portability and objection handled through a documented process.
Storing a boolean proves almost nothing. What matters is being able to show, months later, exactly what a person was told, on which page, and when.
All of it travels with the enquiry to the receiving business, because the company making contact is the one that has to be able to demonstrate the basis for it.
Roles under the GDPR
Who is controller and who is processor changes depending on the stage of the journey. We set it out explicitly in the data protection terms attached to every agreement, rather than leaving it to be argued about later.
Insurance advertising in Europe is closely watched, and rightly so. We keep a written standard and read partner copy against it before anything goes live.
The standard is kept as a specific list. Broadly it excludes:
The standard is not an annex nobody reads. It is applied at three points:
Partners receive the full written standard at onboarding. Where wording is borderline, the partner desk gives a direct answer rather than leaving it to interpretation.



| What we review | What we check | If it does not pass |
|---|---|---|
| The landing page | Whether the disclosure is visible, how the form is built, the wording around consent | A written list of changes, then another review |
| The creative | Claims, line-specific rules, whether it matches the page | Rejected, with the exact wording identified |
| Who owns the site | A named company, a contactable owner, genuine content | Declined where ownership cannot be established |
| The traffic source | Whether the channel described is the channel we observe | Suspended immediately pending an explanation |
| Consent capture | Whether what is recorded matches what was shown | Held until it is corrected |
| After launch | Scheduled re-checks of live placements and of submission patterns | Paused, a list of changes, then another review |
Anyone whose personal data we hold can ask for access, rectification, erasure or restriction, can object to processing, can ask for portability and can withdraw consent at any time. We run a documented intake for those requests with identity verification and a defined response time.
Full detail, including how to submit a request and what happens if we decline one, is on the your data rights page.
No. We are a marketing company and we do not carry out insurance distribution: we do not advise, propose or arrange contracts of insurance, and we take no part in administering or performing them. The regulated businesses that receive enquiries through us do that work under their own permissions.
It depends on the activity, and each one is set out in our Privacy Policy. For passing a consumer enquiry to an insurer the person asked to hear from, we rely on the consent obtained at the point of the enquiry, recorded as described above.
The placement is suspended immediately and the partner is told exactly what was at fault. Repeat breaches end the relationship. How long we have worked together does not change that.
Our processing and storage sit within the European Economic Area. Where a service provider would involve a transfer, it is covered by an appropriate transfer mechanism and set out in our Privacy Policy rather than left implicit.
Reasonable audit and information rights are part of the data protection terms attached to an agreement. In practice most insurers start with a questionnaire, and we would rather answer a thorough one early than discover a mismatch after an integration is built.
A named compliance function with the authority to suspend any placement or any delivery without commercial sign-off. That authority is the part that matters; without it a compliance function is decoration.
If your onboarding process has a due diligence pack, send it before anything is built. We would rather answer it early than discover a mismatch later.