1. Who we are
This Privacy Policy explains how HS Ocean, S.L. (“HS Ocean”, “we”, “us”) processes personal data in connection with this website and with the marketing services we provide to businesses.
HS Ocean, S.L.Gran Via de les Corts Catalanes, 613
08007 Barcelona
Spain
Email: contactus@hsocean.eu
HS Ocean is a marketing company. We are not an insurance undertaking, an insurance intermediary, a bank or a lender. We do not underwrite risk, issue policies, price cover, handle claims or advise anybody on which insurance to buy.
Data protection questions and requests can be sent to contactus@hsocean.eu. Please put “Data protection” in the subject line so that the message reaches the right team on the day it arrives.
2. Our role: controller or processor
Which role we occupy depends on the activity, and we prefer to state it plainly rather than leave it to be argued about later.
- We act as controller for personal data relating to this website, to business contacts at insurers, intermediaries and publishers, to recruitment, and for our own decisions about how consumer enquiries are checked, filtered and to which business they are passed.
- We act as processor where a client instructs us to process personal data on its behalf under written data protection terms. In that case the client's own privacy notice governs the processing and its instructions bind us.
- Independent controllers — once a consumer enquiry has been passed to an insurer, intermediary or comparison platform, that business decides for itself how it uses the data and becomes an independent controller with its own privacy notice.
The applicable role, and the corresponding terms, are set out in the agreement with each client rather than assumed.
3. Personal data we process
3.1 Business contacts
- Name, employer, job title, business email address and business telephone number.
- The content of correspondence with us, including attachments you choose to send.
- Records of contractual and commercial dealings, including agreements, invoices and statements.
3.2 Consumer enquiries
Where a person completes an insurance enquiry on a partner website that participates in our network, the data passed to us typically includes:
- Contact details such as name, email address, telephone number and postal area.
- The information relevant to the line of business concerned, for example vehicle details for motor cover or property characteristics for home cover.
- Consent context: the wording displayed, the address of the page it appeared on and the date and time it was accepted.
- Source context: which partner and which channel the enquiry came from, and basic technical information about the submission.
We do not operate consumer-facing enquiry forms on this website.
3.3 Website data
- IP address, browser type and version, operating system, language preference and screen characteristics.
- Pages viewed, time on page, referring address and basic interaction events.
- Cookie and local storage identifiers, as described in our Cookie Policy.
3.4 Recruitment
Where you apply for a role, we process the CV and covering information you send, our notes from any conversation, and the outcome of the process.
3.5 Special category data
We do not seek to collect data revealing health, racial or ethnic origin, political opinions, religious belief, trade union membership, genetic or biometric data, or data concerning sex life or sexual orientation. Health and protection enquiries are structured to capture only the general information a regulated business needs in order to make contact, and never a medical history. Please do not send special category data to us by email.
4. Purposes and lawful bases
We process personal data only where a lawful basis under Article 6 of the GDPR applies.
| Purpose | Personal data | Lawful basis |
|---|---|---|
| Passing a consumer enquiry to a business the person asked to hear from | Contact details, enquiry information, consent context | Consent given at the point of the enquiry (Art. 6(1)(a)) |
| Checking enquiries: verification, duplicate control, objection lists, fraud review | Contact details, enquiry information, source context | Legitimate interests in providing an honest service and preventing fraud (Art. 6(1)(f)) |
| Keeping records that evidence consent and delivery | Consent context, delivery records | Legal obligation and legitimate interests (Art. 6(1)(c) and (f)) |
| Managing client and partner relationships | Business contact data, correspondence, commercial records | Performance of a contract and legitimate interests (Art. 6(1)(b) and (f)) |
| Business marketing to companies | Business contact data | Legitimate interests, with an objection route in every message (Art. 6(1)(f)) |
| Operating and improving this website | Website data | Legitimate interests; consent where cookies require it (Art. 6(1)(f) and (a)) |
| Recruitment | Application data | Steps prior to a contract and legitimate interests (Art. 6(1)(b) and (f)) |
| Accounting, tax and responding to lawful requests | Commercial records as required | Legal obligation (Art. 6(1)(c)) |
Where we rely on consent, it can be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before it. Where we rely on legitimate interests, we have carried out and documented a balancing assessment and you may ask us for a summary of it at contactus@hsocean.eu.
We do not carry out automated decision-making that produces legal effects or similarly significantly affects an individual, and we do not build consumer advertising profiles from data collected through this website.
5. Who receives personal data
We disclose personal data only in the circumstances below.
- Insurers, intermediaries and comparison platforms — a consumer enquiry is passed to the business or businesses the person asked to hear from, together with the consent and source context described in section 3.2. Those businesses are independent controllers once they receive it.
- Publishers and media partners — performance information relating to traffic they supplied, for reconciliation and quality purposes. This is aggregated wherever aggregate data is sufficient.
- Service providers acting as processors — hosting, security, email, communication tooling, verification services, analytics and professional advisers. Each is bound by a written agreement that permits processing only on our instructions.
- Professional advisers, auditors and insurers of our own business — where necessary and proportionate.
- Public authorities and courts — where disclosure is required by law or necessary to establish, exercise or defend legal claims.
- A counterparty or successor — in connection with a merger, acquisition, financing or transfer of business, subject to appropriate safeguards.
We do not sell personal data, we do not operate a data brokerage, and we do not disclose personal data to third parties for their own unrelated marketing.
6. International transfers
Our processing and storage take place within the European Economic Area.
Where a service provider would involve a transfer of personal data outside the EEA, we do so only where the European Commission has recognised the destination as providing an adequate level of protection, or under Standard Contractual Clauses together with any supplementary measures identified by a transfer impact assessment. Details of current transfers, and a copy of the relevant safeguards, are available on request.
7. Retention
We keep personal data only for as long as it is needed for the purpose it was collected for, and then delete or anonymise it. Periods are set by written policy and reviewed on a schedule; they are not open-ended.
| Category | Retention | Why |
|---|---|---|
| Consumer enquiry data | For the period agreed with the receiving business, and no longer than needed to evidence the delivery | To answer questions about a specific enquiry |
| Consent records | Retained for as long as necessary to demonstrate the basis for contact, and in line with limitation periods | Accountability under Art. 5(2) GDPR |
| Objection and suppression records | Retained for as long as we operate, in minimised form | So that an objection continues to be honoured |
| Business contact and contract data | For the relationship and then in line with statutory commercial and tax periods | Contract management and legal obligation |
| Website and analytics data | Short retention, as set out in the Cookie Policy | Website operation and measurement |
| Recruitment data | For the process, and thereafter only with the candidate's agreement | Filling the role and future openings |
An objection record is deliberately kept rather than deleted: if we deleted it, we would no longer know that the person had asked not to be contacted. It is held in the minimum form needed for that purpose alone.
8. Security
We maintain technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, access limited by role and logged, credential management, segregation of environments, supplier due diligence, backup and restoration procedures, and staff training.
We operate a documented procedure for personal data breaches, including assessment, notification to the competent supervisory authority within 72 hours where required, and notification to affected individuals and clients where the threshold is met.
No system is completely secure. While we work to protect personal data, we cannot warrant absolute security, and any transmission of information to us over the internet carries inherent risk.
9. Your rights
Subject to the conditions in the GDPR, you have the right to:
- Be informed about how your personal data is used — which is the purpose of this document.
- Access the personal data we hold about you and receive a copy of it.
- Rectification of inaccurate or incomplete personal data.
- Erasure of personal data where one of the grounds in Article 17 applies.
- Restriction of processing in the circumstances set out in Article 18.
- Data portability where processing is based on consent or contract and carried out by automated means.
- Object to processing based on legitimate interests, and to object at any time to direct marketing.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with a supervisory authority.
Requests can be sent to contactus@hsocean.eu or to the postal address in section 1. There is no charge. We respond within one month, extendable by a further two months for complex requests where we notify you of the reason. Full detail of the process is on our data rights page.
If you are not satisfied with how we have handled a request, you may complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es) or to the supervisory authority of the EU member state where you live or work.
10. Cookies
This website uses a small number of cookies and similar technologies. What each one does, how long it lasts and how to control it is set out in our Cookie Policy.
11. Children
This website and our services are addressed to businesses and to adults. We do not knowingly process the personal data of children. Enquiry journeys in our network are designed for adults arranging their own cover, and we do not accept partner placements aimed at minors. If we learn that we hold data relating to a child, we delete it without delay.
12. Third-party websites
This website links to third-party websites, including those of partners, clients and service providers. We do not control those websites and we are not responsible for their content or their handling of personal data. Please read the privacy notice of any website you visit.
13. Changes to this policy
We update this policy when our processing changes or when the law requires it. The date at the top of this page shows the current version. Where a change is material we will draw attention to it, and where consent is required we will ask for it again rather than assume it.
Questions, requests and complaints about this policy should be sent to:
HS Ocean, S.L.Gran Via de les Corts Catalanes, 613
08007 Barcelona
Spain
Email: contactus@hsocean.eu
