Privacy Statement

Date Last Updated: 23 May 2018

This privacy statement ("Privacy Statement") is issued by Tokio Millennium Re AG, for itself and on behalf of Tokio Solution Management Ltd., Shima Reinsurance Ltd. and Tokio Millennium Re (UK), Ltd. (collectively, "TMR" or we"). TMR is a company domiciled in Switzerland, with branches and affiliated companies in multiple countries. This Privacy Statement applies to the website located at www.tokiomillennium.com and all websites and pages thereof (each, a "TMR Site" and collectively, the "TMR Sites").

The TMR Sites may contain content relating to TMR and some or all of its branches and affiliated companies (such as local company descriptions, contact information, and disclosures), all of which is covered by the TMR Sites Terms of Use ("Terms of Use") and this Privacy Statement. This Privacy Statement is to be read together with, and forms a part of, the Terms of Use. This Privacy Statement describes the practices that TMR follows with respect to the privacy of visitors to the TMR Sites, the types of information collected, how we will use that information, and the rights you have in relation to it. However, this Privacy Statement does not apply to data that is processed or collected offline through any means or websites other than the TMR Sites.

By providing information to us or by using our products or services, including the TMR Sites, you agree to our collection, use and sharing of your information as described in this Privacy Statement.

From time to time, TMR may update this Privacy Statement. If we do, we will note near the top of this page the date that any changes are made and/or when they become effective. It is your responsibility to review carefully the then-current Privacy Statement each time you visit a TMR Site. Your continued use of the TMR Sites after the revised Privacy Statement is posted will tell us that you agree to the then-current Privacy Statement. If you do not accept the terms outlined in this Privacy Statement or the revised Privacy Statement, please do not provide us with your information or use the TMR Sites.

WHERE THE COMPANY HOLDS OR CONTROLS PERSONAL INFORMATION COLLECTED IN AUSTRALIA, IT COMPLIES WITH APPLICABLE AUSTRALIAN LAW INCLUDING THE AUSTRALIAN PRIVACY PRINCIPLES (APPS) IN THE PRIVACY ACT OF 1988, AS SET OUT IN THE TOKIO MILLENNIUM RE AG, AUSTRALIA BRANCH PRIVACY STATEMENT.

1. Definitions

For the purposes of this Privacy Statement, the terms below have the following definitions:

"EU Data Protection Legislation" means all applicable legislation relating to data protection in the European Economic Area (the "EEA"), Switzerland and the UK, including the EU General Data Protection Regulation 2016/679 ("GDPR") and all legislation implementing or made under or pursuant to or replacing or superseding the GDPR. Where this statement uses terms which are defined in the GDPR, the definitions set out in the GDPR will apply.

"Personal Information" is data relating to you from which you can be reasonably identified. Examples of Personal Information include your name, address, e-mail address, and phone number. Aggregated data and other information that is related to you but is studied as a group or is not identifiable to you is not considered to be Personal Information.

2. Data Controller

Tokio Millennium Re AG is the data controller responsible for the processing of your Personal Information collected from the TMR Sites under applicable law, including the EU Data Protection Legislation.

3. What Data is Collected?

If you are merely browsing the TMR Sites, TMR may collect certain information such as an IP address from your computer.

If you submit a registration form online on the TMR Sites or e-mail TMR directly via an email address provided on the TMR Sites, you may, by doing so, provide certain Personal Information to TMR.

a. Information you provide to us

We will, depending on the nature of your communication with TMR with respect to your visit to the TMR Sites, use your Personal Information to:

  • If you are making an enquiry about how our services could help your business, respond to any enquiry you may make and/or provide you with information that you request from us because it is in our legitimate interests to use your Personal Information to communicate with you to respond to your request and develop the relationship between us;
  • If you are making an enquiry about how your business could support or work with our business, consider how your business could support or work with our business because it is in our legitimate interests to use your Personal Information to consider whether it would be beneficial to work with your business;
  • If you are from an existing client, supplier or partner of ours and you are making an enquiry about your agreement or relationship with us, respond to you as an existing client, supplier or partner of ours in relation to a pre-existing agreement or relationship because it is in our legitimate interest to use your Personal Information to manage your business' relationship with us. It may also be necessary for us to:
    • use your Personal Information to perform an agreement with your business, where we would be unable to provide those services to or receive them from your business without that information (for example, if a particular service or information is to be provided to you at your business, we would be unable to provide that service or information unless we were able to use your Personal Information for that reason); and
    • use your Personal Information to comply with a legal obligation relating to how we manage our business or our relationship with your business;
  • If you are a member of the public and you are making an enquiry about whether you could work for us, consider and decide how to respond to your enquiry because it is in our legitimate interests to use your Personal Information to consider whether we have any suitable job vacancies and to contact you about them. It may also be necessary for us to use your Personal Information to comply with a legal obligation relating to how we manage our business; and
  • If you are making any other type of enquiry, we will use your Personal Information to consider and respond to your enquiry because it is in our legitimate interests to use your Personal Information in order to determine how to answer your query. Depending on the subject of your enquiry, it may also be necessary for us to use your Personal Information to comply with a legal obligation relating to how we manage our business or our relationship with your business.

If we do not know you or your role at your business, we may also use your Personal Information to confirm your identity and the business that you work for, as well as your role at that business. We do this because it is in our legitimate interests to make sure that your enquiry is genuine and is not being made for fraudulent reasons or is spam. We may also do this because we may be subject to legal obligations which require us to confirm the details that you provide us with before entering into a relationship with you.

We will let you know where you must provide us with Personal Information in order to perform an agreement with your business or to comply with a legal obligation. If you do not provide us with the Personal Information in these circumstances, we will be unable to respond to your enquiry and/or engage in further communications with you.

b. Information we automatically collect about you

The TMR Sites will automatically gather data about your visit, such as your IP address and browser type. We may collect this data automatically through the use log files. This automatic data is primarily used for website administration and statistical analysis. It also allows us to monitor the use and performance of the TMR Sites and may be used to ensure that content from the TMR Sites is presented in the most effective manner for you.

To the extent this information constitutes Personal Information, we use it to ensure that content from TMR Sites is presented in the most effective manner for you because it is in our legitimate interests to improve our customers' online experience in relation to the TMR Sites.

4. Disclosure of your Information

We may share your Personal Information with others to confirm your identity and/or respond to your query for the purposes identified in Section 3 above. As a result, we may check your Personal Information by searching for your name and that of your business in publicly available and private databases of businesses and individuals, which will use the details entered by us to provide us with the search results. For example, we may use databases such as those retained by LinkedIn or Companies House for this purpose.

We may disclose your Personal Information to third parties who have agreed in writing to provide an adequate level of privacy protection for the following reasons:

a. where the transfer is necessary to fulfil your request and involves a TMR affiliate and other divisions; and/or

b. where such disclosure has been requested by you.

We may also disclose your Personal Information to the following third parties for the following reasons:

a. as required by a court order or any other legal or regulatory requirement in order to comply with a legal obligation; and/or

b. in order to enforce or apply our Terms of Use, this Privacy Statement and other agreements; and/or

c. to protect our rights, property, safety and the rights, property and safety of others. This includes exchanging information with other companies and organisations for the purpose of fraud protection and credit risk reduction. We may process the Personal Information for this purpose to comply with a legal obligation and also because it is in our legitimate interests and that of others to prevent fraud.

We will let you know where you must provide us with Personal Information so that we can use it and/or share it with third parties to comply with a legal obligation. If you do not provide us with the Personal Information in these circumstances, we will be unable to respond to your enquiry and/or engage in further communications with you.

5. Records of Personal Information

TMR has in place a policy regarding the storage of your Personal Information and will only store the Personal Information as long as TMR consider it necessary or beneficial for the purposes set out in this Privacy Statement or for regulatory, audit or record-keeping purposes.

We will keep a record of the Personal Information that we receive from you in order to answer your enquiry or to respond to your request for further information. We will keep a copy of your Personal Information held for the specific purpose for which it was provided, until the subject matter of your enquiry has come to an end and we no longer need to comply with a legal obligation that requires us to retain your Personal Information. We will delete our copy of your Personal Information by in accordance with TMR's document retention policy from the end of our discussions with although we may retain a record of the existence of the relationship, to the extent that and for so long as we are required to do so by law. For example, if you have contacted us to ask for the processing of your Personal Information to be erased, we will retain a record of your request in order to ensure that we comply with your wishes.

6. Storage and Transfer of Personal Information to Other Countries

If you are located in the EEA, the UK and/or Switzerland and provide data or information to TMR, it may be transferred to, processed in, stored at or accessible from a destination outside the EEA, the UK and/or Switzerland such as the United States, Bermuda, Japan and Australia. By submitting your Personal Information, you agree to this transfer, processing and storing. We will take all steps reasonably necessary to ensure your data is treated securely and in accordance with this Privacy Statement.

Where we pass your Personal Information from a location inside the EEA, UK or Switzerland to parties located outside the EEA, UK or Switzerland that do not offer adequate protection as determined by the European Commission, the UK and/or Swiss authorities, if they are not subscribed to an approved data protection framework, such as the EU-US Privacy Shield, that permits us to transfer the Personal Information to them from a location inside the EEA, UK or Switzerland, we will enter into agreements which enable us to transfer the Personal Information to them and that enable you to exercise your rights in accordance with EU Data Protection Legislation. A copy of the applicable terms of these agreements can be obtained by emailing us at communications@tokiomillennium.com.

Please do not provide your Personal Information to TMR if you do not want this information to be transferred to the United States, Bermuda, Japan, Australia or to other countries, or if the laws in your country restrict these types of transfers. Your provision of Personal Information to TMR through the TMR Sites means that you agree to the terms of this Privacy Statement.

7. Your Rights

With respect to the Personal Information that TMR collects about you from the TMR Sites, you may have the right to:

a) request access to that Personal Information; and/or

b) where Personal Information is inaccurate or incomplete, ask for Personal Information to be rectified or completed;

In addition, if your Personal Information is subject to EU Data Protection Legislation, you may have the right to:

c) receive a copy of the Personal Information that you have provided to TMR in a structured, commonly used and machine readable format so that you can share it with others;

d) request the transfer of your Personal Information to another party;

e) ask that Personal Information be erased;

f) object to us processing your Personal Information by asking for the processing of that Personal Information to be restricted or stopped. For example, if TMR uses Personal Information for marketing purposes; and/or

g) make a complaint to a European data protection authority about the manner in which TMR processes your Personal Information.

Please contact TMR to exercise these rights or for additional information at communications@tokiomillennium.com.

8. Data Security

TMR places importance on protecting your Personal Information and takes precautions to protect such information. For example, if your Personal Information is subject to EU Data Protection Legislation, then we will protect such information in accordance with Article 32 of the GDPR and as required by EU Data Protection Legislation.

However, you should keep in mind that the protection of your data cannot be entirely guaranteed when communicated via the Internet. Third parties may, under certain circumstances, have the technological ability to penetrate network security without authorization and eavesdrop on communications. Please be aware that communication of information by e-mail typically takes place without encryption and thus is subject to interception by third parties through the Internet. You agree that you will not hold TMR or any TMR affiliate or service provider liable for any damages resulting from any loss of privacy or security occurring in connection with any communications over the Internet.

9. Links to Third Party Websites

The TMR Sites may contain links to websites owned by other companies. Because TMR has no control over the privacy practices or content of these linked sites, we recommend that you carefully review the privacy statement and practices of each website you visit. TMR is not responsible for the content or privacy practices of websites owned by other companies. In addition, this Privacy Statement does not apply to any websites not part of the TMR Sites, even if such website contains links to a TMR Site.

10. Children's Privacy

TMR does not seek to, nor knowingly collect, information from children who are under 13 years of age. By using the TMR Sites, you represent that you are not under 13 years of age. If a child has provided us with Personal Information, a parent or guardian of that child may contact us to have the information deleted from our records. To do so, contact TMR through the information provided below.

11. California Residents: Your California Privacy Rights

If you are a California resident, you may have the right to request and receive certain information about our disclosure of your Personal Information to third parties for their direct marketing purposes, and your choices with respect to such disclosures. Because it is our policy not to share your Personal Information with third parties for their own marketing purposes unless you are first given the opportunity to opt-out of such sharing, we are exempt from having to meet this requirement. If you still wish to learn more about our compliance with this requirement, please contact us using by emailing communications@tokiomillennium.com.

12. Do Not Track Requests

TMR does not track its users across third party websites, nor does it allow third parties to directly collect Personal Information on the TMR Sites. As such, the TMR Sites do not respond to browser "Do Not Track" requests.

13. Contact Us

If you have any questions, comments or complaints about TMR's collection, use or disclosure of Personal Information, or if you believe that TMR has not complied with this Privacy Statement or the applicable law, please contact TMR as set out below.

If you are not satisfied with the outcome of TMR's assessment of your complaint, you may be able to refer your complaint to the relevant regulator under applicable law.

For questions regarding this Privacy Statement, please contact TMR by e-mail at communications@tokiomillennium.com or by mail to Tokio Millennium Re AG, Beethovenstrasse 33, 8002 Zurich, Switzerland, Attention: Head of Group Compliance.