Innovative benefits and risk solutions tailored to employers, associations, and global groups
Medical
Data Analytics
Specialty
Simple, direct, eCommerce insurance built for today’s marketplace
Advanced life and annuity solutions with specialized underwriting and boutique service
Expert support to help businesses stay prepared and resilient
Proprietary Advantage
Our underwriting division designs unique, market-leading programs only available through SPG.
Contractors / Infrastructure
Mainstreet
Transportation
Commercial
Our experts.
Our relationships.
Your advantage.
Innovative benefits and risk solutions tailored to employers, associations, and global groups
Medical
Data Analytics
Specialty
Simple, direct, eCommerce insurance built for today’s marketplace
Life & Annuity
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore
et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Services
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore
et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore
et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Proprietary Advantage
Our underwriting division designs unique, market-leading programs only available through SPG.
Contractors / Infrastructure
Mainstreet
Transportation
Commercial
Our experts.
Our relationships.
Your advantage.
Our Story
From idea, to business plan to a leading specialty MGA platform recognized as a top 20 global insurance broker. Our mission – reshape the landscape of specialty insurance.
SPG’s Leadership
Our leaders bring deep expertise and vision, shaping the future of specialty insurance and fostering partnerships built on trust and innovation.
Brand Portfolio
SPG unites a growing portfolio of specialty insurance brands, combining unique expertise and shared strength to deliver greater value together.
Partnering with SPG
Our approach to acquisitions is more than expanding our portfolio – it’s about customizing our partnerships to match the exact needs of each business we work with and crafting a community where every member embodies the principle of “Stronger Together”
This U.S. Privacy Policy ("Policy") describes how Specialty Program Group LLC, and its subsidiaries listed here (collectively "SPG") use your "Personal Information" (as defined below) both during and after our direct business relationship with you. This Policy applies to Personal Information that we may from time to time collect, use, and disclose in the course of SPG's business operations including (1) performing insurance brokerage or other insurance or financial industry services on your behalf, (2) making available our mobile applications and websites, including specialtyprogramgroup.com, (3) performing insurance, risk management, or employee benefits work on behalf of our Commercial Clients, and (4) contacting us, visiting a SPG location, registering for or attending a SPG event or using other services that link to this Policy. This Policy may be supplemented by additional privacy policies, terms, and notices relevant to the service and provided to you at or before the collection of your Personal Information. We take very seriously our privacy responsibilities to you, and we are committed to treating your Personal Information in a manner that is consistent with applicable law and this Policy. Please read this Policy carefully.
From time to time, we may change our privacy practices, which will require changes to this Policy. The latest version of this Policy will be posted on our websites, and the date it is effective will be displayed. We encourage you to look for updates and changes to this Policy when you access our websites. Your continued use of SPG's websites, mobile applications, and services following the posting of changes constitutes your acceptance of such changes with respect to your use of our websites, mobile applications, and services.
If you have special needs with regard to accessing the content of this Policy, contact us at: privacy.compliance@specialtyprogramgroup.com. Please include the words "Accessibility Issue" in your subject line and explain steps we can take to help you to review and understand this Policy.
Certain jurisdictions provide enhanced Personal Information rights to residents depending on the jurisdiction and the reason SPG is processing Personal Information
(A) Notice to California Residents. If you are a California resident, you may have privacy rights in addition to those outlined in this Policy. Due to the specific requirements under California privacy laws, please review the SPG Privacy Request Portal, to learn more about these additional rights.
(B) As of the publication of this Policy, consumer privacy laws have been passed in Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia. These state-level laws give residents privacy rights such as (a) rights to know, access, correct, port (i.e., transfer), or restrict processing of your Personal Information; (b) the right to opt-out of SPG selling your Personal Information; (c) the right to opt-out of certain automated decision-making based upon your Personal Information; and (d) the right to request that SPG delete your Personal Information. These rights, as well as any other rights described in this Policy, can be asserted by visiting the SPG Privacy Request Portal, administered by our parent company Hub International Limited.
(C) Residents of Colorado, Connecticut, Delaware. Iowa, Oregon, Texas, and Virginia have the right to appeal the outcome of a rights request to access, review, delete, or correct Personal Information. Assertions of these appeal rights can be made to: privacy.compliance@specialtyprogramgroup.com. Please include "Appeal of Outcome" and your state name in the subject line of your email message to initiate the appeal request.
(D) Certain state-level privacy rights may not apply to Personal Information under SPG's custody or control that is subject to certain federal and state laws regulating insurance or health or financial information.
"Personal Information" means any information that identifies you or can reasonably be linked to you or your household and includes data such as your name, postal address, email address, and telephone number. Due to the nature of our business as described further in the Section called "Information SPG Collects" below, Personal Information handled by SPG about you may also include:
Personal Information does not include aggregated or anonymous information which does not identify and cannot reasonably be used to identify you or your household. It also does not include other categories of information excluded by state or federal law.
We are generally unable to perform insurance brokerage or other insurance or financial industry services on your behalf without collecting, using, or disclosing your Personal Information, including sensitive Personal Information. Typically, you will provide your Personal Information directly to us as your broker, as part of a written application for insurance coverage. Other times, we may receive this and other Personal Information from third parties, including insurance carriers and other industry service providers, and other third parties with which you maintain a relationship (for example, your employer and providers of financial or medical services). We may also develop this information over time based on your direct or indirect interactions with us, such as through the use of cookies on our websites.
Please keep in mind that when you provide information to us on a third-party site or platform, the information you provide may be separately collected by the third-party site or platform. We encourage you to read the privacy policies of other sites and mobile applications that may collect your Personal Information.
When you hire SPG to broker insurance or advise you directly, we collect the amount and types of Personal Information that are required for us to perform or support services you requested. This includes information that may be required by an insurance carrier or an industry service provider in the course of providing you with insurance coverage or related services. If you use our websites, we may collect information about your device, browser and other information regarding your web usage using tracking tools described in this Policy. This information collection could include relevant market research designed to make our products and services better; this and other information may include the Personal Information as defined above. SPG also offers its products and services to organizations that act in the performance of their business or profession ("Commercial Clients"). For instance, if SPG performs insurance-related services for your employer (such as employee benefits, retirement, or risk management services), then SPG may need to collect and handle some of your Personal Information to perform those services. SPG refers to this work as our Commercial Business and in that situation, your employer would be a Commercial Client. In these cases, (1) SPG requires Commercial Clients (such your employer or retirement plan) to have appropriate authorization to provide your Personal Information to SPG, (2) SPG requires the client to provide the minimum amount of your Personal Information necessary for SPG to provide the requested services, and (3) SPG Processes the information pursuant to directions and security safeguards required by SPG's contract with the client. Please see "Information SPG Processes When Performing Services for Commercial Clients" below for more details.
When you visit any website, it may store or retrieve information on your browser, often in the form of cookies. Cookies are files which can store information in your computer hard drive or other devices and help us and our partners to better understand user behavior. We may use cookies and other web tracking technologies such as pixels, web beacons and session recording tools (collectively, "Web Tracking Technologies") on our websites and mobile applications. Information collected in this manner might be about you, your preferences, or your device; it is primarily used to allow the website to work as you expect it to and to provide a more personalized web experience. This information is also used for security and fraud prevention purposes, to identify which parts of our websites people have visited, to facilitate and measure the effectiveness of advertisements and web searches, and to improve user experiences. We may combine information derived from Web Tracking Technologies with information provided directly by you.
SPG uses different categories of cookies:
We generally only disclose your Personal Information to perform services on your behalf and provide you with the insurance products and services you expect from us. In addition, in order to operate our business and provide you with the services you request from us, information technology and other support service providers with which we maintain an arrangement may also have access to your Personal Information. Your Personal Information may be disclosed to third parties in connection with a merger, sale, or other transfer of organizational assets where Personal Information held by us about our clients is among the assets transferred.
We may from time to time disclose your Personal Information for the following reasons:
SPG's online formats may utilize certain types of automation which assist insurance carrier partners ("insurers") with their underwriting of insurance. Such automation may result in the use of your Personal Information by the insurer to create predictions about insurance products and premium pricing, and information about insurance carrier market categories that would be appropriate for you. The goal of such an interaction would be for you to receive one or more insurance quotations or estimations of premium and coverage details. Each insurer will have methodologies, including underwriting algorithms, to help with making underwriting decisions. Insurers' underwriting decisions for insurance coverage, and the use of data for making those decisions, are each subject to the applicable privacy policy and privacy rights request process of that insurer. Your Personal Information is protected and is utilized consistently with the purposes and categories of this Policy, and the intention of our use of this technology is that it operates without improper biases. Based on applicable law, you may have the rights to: (a) opt-out of the processing of your Personal Information by automated decision-making technology that produces a legal or consequential effect, (b) correct inaccurate Personal Information used by automated decision-making technology to make a consequential decision about you, and/or (c) appeal, via human review if technically feasible, an adverse consequential decision concerning you arising from the use of automated decision-making technology. If available in your area, these rights can be exercised through the SPG Consumer Privacy Request Portal.
Governments are increasingly granting consumers certain rights regarding their Personal Information. SPG honors requests in accordance with and to the extent required by applicable consumer privacy laws, which may vary depending on where you live. Depending on your state of residence, your rights may include:
(A) Right to Know: You have the right to request that we provide you (i) the categories or specific pieces of Personal Information we collected about you; (ii) the categories of sources from which we collected your Personal Information; (iii) the business or commercial purposes for which we collected, sold, or shared your Personal Information; (iv) the categories of Personal Information we disclosed to Service Providers or third parties for a business purpose and the categories of Service Providers and third parties to whom we disclosed it; and (v) the categories of third parties to whom we sold/shared your Personal Information and the categories of Personal Information sold/shared to each category of third party.
(B) Right to Access: You have the right to access and inspect Personal Information about you or be provided with a copy of the information we hold about you. SPG may take additional steps to verify your identity before it provides access to Personal Information that is sensitive, or the unauthorized disclosure of which could create a substantial risk of potential harm to the subject of the data.
(C) Right to Correct: If you believe that Personal Information about you is inaccurate, then you may request that SPG correct the information. When you make this request, please (i) identify the specific information that you believe is inaccurate, (ii) provide the information that should replace the inaccurate data, and (iii) provide documentation related to your proposed correction. We will correct the information if we determine, based on the totality of the circumstances, that the correction you requested is more likely than not accurate. SPG may decide to delete the allegedly inaccurate information instead of correcting it.
(D) Right to Deletion: You have the right to request that we delete Personal Information we collected about you. Under applicable consumer privacy laws, SPG is not required to honor a deletion request in certain situations, such as where SPG needs to maintain the information to: (i) complete a requested or reasonably anticipated transaction, (ii) prevent security incidents or fraud, (iii) comply with litigation holds and establish, exercise, or defend legal claims, and (iv) comply with SPG's regulatory and licensing obligations.
(E) Data Portability: You have the right under the laws of certain jurisdictions to request that Personal Information about you be provided in an electronic format to you or a third party of your choice.
(F) Disclosing the Recipients of Personal Information: Consumers in certain jurisdictions have the right to request that SPG disclose to them the categories of third parties to whom SPG has disclosed their Personal Information. In limited jurisdictions, SPG may be required to provide you with a list of specific third parties that have received Personal Information about you.
(G) Right to Restrict Processing/Right to Limit Use and Disclosure of Sensitive Personal Information: Some jurisdictions allow you to request that SPG limit the use of your Sensitive Personal Information to only certain specified purposes such as (i) providing to you the goods and services you reasonably expect, (ii) complying with legal obligations, exercising legal claims or rights, and defending legal claims, (iii) preventing security incidents or fraud, or (iv) verifying or maintaining the quality or safety of goods or services we provide. Other jurisdictions require SPG to obtain your consent to process Sensitive Personal Information about you; the definitions of Sensitive Personal Information vary by jurisdiction. SPG processes these types of requests subject to any exceptions permitted by law. If you reside in a jurisdiction that requires us to obtain your consent before processing Sensitive Personal Information on your behalf, SPG may take additional steps to contact you before treating your request as a revocation of consent to avoid unintended consequences, such as the cessation of processing your Personal Information for a SPG product or service that you requested. You may choose to withdraw your consent at any time; however, we may be unable to provide the product or service you requested without the necessary information.
(H) Right to Opt-Out from the Sale or Sharing of Personal Information/Do Not Sell or Share My Personal Information Request: You have the right to direct us to not sell or share for marketing and/or targeted advertising purposes your Personal Information with affiliates or non-affiliates. We will process requests subject to any applicable exceptions and extensions permitted by law.
(I) Right to Opt-Out of Automated Decision-Making and Profiling: Consumers in certain jurisdictions have the right to direct SPG to not process their Personal Information for automated decision-making or profiling that produces legal or other consequential effects. For instance, SPG and its insurance carrier partners may conduct assessments using models and information technology solutions: (i) to determine whether you are eligible to receive the insurance-related product or service you requested and (ii) to calculate your premiums. This process may involve information about your behaviors or making calculated predictions about you which are related to the product or service you requested. If you exercise this right prior to the application process, SPG may not be able to process your application for a product or service.
(J) Opt-Out of SPG Sharing Creditworthiness Information with SPG Affiliates: You may request that SPG not share with its affiliates information that bears on your eligibility for credit or insurance, including information about your credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living. This opt-out right does not extend to the sharing of (i) information about first-hand transactions or experiences between you and SPG, or (ii) opinions based solely upon those first-hand transactions or experiences.
(K) Opt-Out of Receiving Marketing Communications from SPG via Email: You have the right to unsubscribe from receiving communications of a marketing nature from SPG via email.
(L) Opt-Out of Receiving Automated Phone Calls and Text Messages from SPG: You have the right to request that SPG refrain from calling you or sending text messages to you using automated dialing systems.
(M) Right to Appeal: If we deny, in full or in part, your request to exercise a privacy right, and if you live in a jurisdiction that affords you the right, you may appeal SPG's decision. To initiate an appeal, send an email to privacy.compliance@specialtyprogramgroup.com that includes in the subject line the phrase "Privacy Appeal" and your state of residence; in the body of the email, please identify the decision you are appealing and the grounds of your appeal. If SPG denies your appeal, you may contact your state Attorney General to inquire about additional appeal rights.
(N) Right of Non-Discrimination: You have the right to not be discriminated against for exercising your privacy rights.
To exercise any of these privacy rights, to make a related request, or to ask any question concerning this Privacy Policy, please contact us via any of the following methods:
Please include your name, address, telephone number, and email address whenever you contact us. Depending upon the nature of your request, SPG may require you to provide additional information to verify your identity and authority to access or direct the processing of the Personal Information that is the subject of the request. SPG may deny certain privacy requests with respect to your Personal Information if we cannot verify your identity. You may also use an authorized agent to submit a request to exercise your privacy rights on your behalf. If you have an authorized agent submit a request on your behalf, SPG will require (i) you to provide the authorized agent with written permission to act on your behalf, and (ii) your agent to verify their identity directly with SPG. SPG may deny a privacy-related request from an agent that does not meet these requirements.
There may be situations where we cannot grant a particular request --- for example, if you ask us to delete your transaction data but we are legally obligated to keep a record of that transaction to comply with law or if we are unable to verify your identity through standard and reasonable means. We may also decline to grant a request where doing so would undermine our legitimate use of data for anti-fraud and security purposes, such as when you request deletion of an account that is being investigated for security concerns. Other reasons your privacy request may be denied could be that granting the request would jeopardize the privacy of others; that the request is substantively frivolous or vexatious; or that granting the request would be highly impractical in the context of our legitimate business purposes. If we are unable to fulfill your privacy request to access, review, delete or correct your Personal Information, we will provide you with an explanation
SPG gives you the ability to opt-out of cookies that are not essential to the services of the SPG-controlled websites and applications you use. This option is presented by SPG's Cookie Preference Center when you visit our websites (i) for the first time and (ii) after you clear your browser cache.
Your computers or devices also have tools within their browsers that allow you to manage your acceptance of cookies. These can include the ability to disable or block non-essential cookies, remove cookies, automatically accept cookies, or notify you when a cookie is received. Refer to "https://allaboutcookies.org/how-to-manage-cookies" for detailed explanations by browser (e.g., Google Chrome). Generally, disabling or rejecting cookies can negatively impact your user experience (e.g., because certain features of our website may not be available).
SPG uses both Adobe and Google as website service providers. To learn about Adobe Analytics privacy practices or to opt-out of Adobe cookies which are used to facilitate reporting, visit Adobe Privacy Center. To learn more about Google's privacy practices, visit the Google Privacy Center. To access and use the Google Analytics Opt-out Browser Add-on, visit Google Opt-out.
In certain jurisdictions, you have the right to opt-out of the use, sharing, and sale of your Personal Information for targeted advertising purposes by broadcasting an opt-out preference signal, such as the Global Privacy Control ("GPC"), on browsers or extensions that support the GPC signal. A list of GPC-enabled available browsers or extensions is available here: https://globalprivacycontrol.org/#download. If you choose to use the GPC signal, you will need to turn it on for each supported browser or browser extension you use. Your request to opt-out will be linked to your browser identifier only. For more information about how to opt-out of the sale or sharing of your Personal Information, see the "Do Not Share or Sell My Personal Information Notice" below.
In the preceding twelve (12) months, we have shared information for cross-contextual behavioral advertising or targeted advertising purposes which might be considered a "sale" of Personal Information as defined by the laws of some jurisdictions. SPG does not knowingly sell the Personal Information of minors.
In an increasing number of jurisdictions, you can request that SPG not: (a) sell your Personal Information, (b) share it with third parties for cross-context behavioral advertising purposes, or (c) process it for targeted advertising purposes.
To exercise your rights to opt-out of SPG selling or sharing your Personal Information for cross-context behavioral advertising purposes and/or processing it for targeted or personalized advertising purposes, take the following steps:
Your cookie selections are specific to the device, website, and browser you're using, and your selections are deleted whenever you clear your browser's cache. If you use another device or browser, you will need to opt-out on each device and browser. Blocking or clearing cookies from your browser may remove your opt-out settings, requiring you to opt-out again. After you have opted-out, you may still see advertisements for SPG's products and services because not all advertisements are placed using cookies or Personal Information. For example, you may see contextual ads online such as those based on the topic and content of a webpage you visit; some advertisements published to third party websites are simply made visible to all visitors to that website.
SPG retains certain records of your Personal Information as necessary to operate our business and comply with our legal and regulatory obligations. Such records are retained for legally defined retention periods that may extend beyond the period for which we provide the Services to you or to our Commercial Clients. We have implemented appropriate measures to confirm that Personal Information is securely disposed of when no longer required.
Our website contains links to third party sites. If you click on one of those links, you will be taken to websites we do not control. This Policy does not apply to the information practices of those sites. You should read the privacy policies of those other websites carefully. We are not responsible for those third-party sites. Links to third party sites do not constitute or imply endorsement by us of the linked site or any material displayed on those sites.
To the extent that SPG provides mobile application access for your use, please note that your Personal Information may be collected. In addition to being subject to this Policy, your use of a downloaded application provided by SPG may also be subject to the privacy terms and conditions of the providers and developers of the application. SPG may have access to and utilize certain data collected by such providers or developers. SPG may utilize such data to better service your account, to improve the performance of the application, as well as for the other purposes set forth in this Policy.
SPG websites are not intended for children under 13 years of age. No one under age 13 may provide any information through our websites, and we do not knowingly collect Personal Information from children under thirteen. If you are under thirteen, do not use or provide any information on this website or otherwise provide any information about yourself to us, including your name, address, telephone number, email address, or any screen or username you may use. If we learn we have collected or received Personal Information from a child under thirteen without verification of parental consent, we will use commercially reasonable efforts to delete that information. If you believe we might have any information from or about a child under thirteen without parental consent, please contact us at the mailing address shown beneath the heading "Your Privacy Rights and How to Exercise Them."
When SPG provides services to its Commercial Clients, SPG may collect, from the client, information about the client's business operations and Personal Information about you and your relationship with that client. For example, SPG offers services to employers and retirement plans, among others. During the course of providing these services, SPG (i) is informed that you are the client's employee or plan's participant, and (ii) receives Personal Information about you including, your name, contact details, date of birth, gender, marital status, certain financial information (like premiums you paid), employment details, benefit coverage, and other types of data described in the "Definition And Exclusions of Personal Information" and "Information SPG Collects" sections above. SPG may also collect data from public information sources including social media and other websites, government agencies, third-party service providers, and business partners. When SPG processes this information, it does so as the Commercial Client's data processor and only handles the Personal Information to provide its services to the Commercial Client. Accordingly, if you submit to SPG a Data Subject Access Right ("DSAR") Request (e.g., if you seek to exercise your privacy rights to access, correct, or delete Personal Information about you) concerning information provided to SPG by a Commercial Client, SPG will notify you that you must submit your DSAR Request directly to the Commercial Client.
We maintain technical and organizational security measures reasonably designed to protect the security of your Personal Information against loss, misuse, and unauthorized access, disclosure, or alteration. SPG International Limited and its affiliates take steps to secure your Personal Information with appropriate levels of security around storage and use. Despite this, the security of information cannot be guaranteed. If you have reason to believe that your Personal Information maintained by us is no longer secure, please immediately notify us utilizing the contact information set forth above. In the event of a breach impacting your Personal Information, we intend to provide you with notification to the extent required by applicable law.
Effective Date: August 1, 2024
This Privacy Notice for California Residents (this "Notice") supplements the information contained in the SPG Privacy Policy (the "Policy") and is provided on behalf of Specialty Program Group LLC and its subsidiaries listed here.
This Notice provides our "notice at collection" and provides certain mandated disclosures about our treatment of California residents' information, both online and offline. We adopt this Notice to comply with the California Consumer Privacy Act of 2018 as supplemented by the California Privacy Rights Act of 2020 (collectively, the "CCPA") and any terms defined in the CCPA have the same meaning when used in this Notice (unless separately defined in this Notice or the Policy). This Notice applies solely to residents of the State of California as defined in the CCPA ("California Residents") who do business with us directly and/or visit the mobile apps and websites of Specialty Program Group LLC and its subsidiaries ("our websites").
We reserve the right to amend this Notice at our discretion and at any time. When we make changes to this Notice, we will post the updated Notice on the websites and update the Notice's effective date. We encourage you to look for updates and changes to this Notice when you access our websites. Your continued use of our websites and mobile applications following the posting of changes constitutes your acceptance of such changes with respect to your use of the websites and mobile applications.
If you have special needs with regard to accessing the content of this Notice, we recommend that you or someone on your behalf, contact us by email at: privacy.compliance@specialtyprogramgroup.com. Please indicate "Accessibility Request" in your subject line to help us to identify this request.
Generally, Personal Information under the CCPA and in this Notice means information that identifies (whether directly or indirectly) you, such as your name, postal address, email address, and telephone number. Due to the nature of our business, Personal Information we collect may also include:
Personal Information as defined under the CCPA does not include:
Certain types of Personal Information are considered "Sensitive Personal Information" under the CCPA. Specifically, Sensitive Personal Information is a specific type of Personal Information defined specifically as its own category under California law in the CCPA as information that reveals a consumer's:
The following categories of Personal Information and/or Sensitive Personal Information may have been collected from California Residents within the last twelve (12) months. Personal Information that falls under the definition of Sensitive Personal Information under the CCPA has been noted in the second column below.
| Category | California Sensitive Personal Information may be considered to be within this Category (YES or NO) | Examples of Personal Information | Collected |
|---|---|---|---|
| A. Identifiers | YES | A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver's license number, passport number, or other similar identifiers. | YES |
| B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80I). | YES | A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories. | YES |
| C. Protected classification characteristics under California or federal law. | YES | Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information). | YES |
| D. Commercial information. | NO | Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. | YES |
| E. Biometric information. | YES | Genetic, physiological, behavioral and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns and sleep, health, or exercise data. | NO |
| F. Internet or other similar network activity. | NO | Browsing history, search history, information on a consumer's interaction with a website, application, or advertisement. | YES |
| G. Precise geolocation data. | YES | Physical location or movements within a geographic area that is equal to or less than the area of a circle with a radius of 1,850 feet. | YES |
| H. Sensory data. | YES | Audio, electronic, visual, thermal, or similar information. | YES |
| I. Professional or employment-related information. | NO | Current or past job history. | YES |
| J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)). | YES | Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records. | YES |
| K. Inferences drawn from other personal information. | YES | Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities and aptitudes. | YES |
We may obtain the categories of Personal Information listed above from the following categories of sources:
We may from time to time use your Personal Information for the following reasons:
Under the CCPA, the Sharing of Personal Information means sharing, disclosing, disseminating, making available or otherwise communicating a consumer's Personal Information to a third party for uses such as targeted advertising for the benefit of the business.
California residents have certain rights under the CCPA around limiting the Sharing of their Personal Information.
The CCPA addresses two distinct categories of information disclosure by businesses, differentiating the Sharing of Personal Information for a Commercial Purposes from the Disclosure of Personal Information for a Business Purpose, as described below.
The CCPA defines the Sharing of Personal Information for a Commercial Purpose as including the sale or sharing of a customer's Personal Information for monetary or other consideration paid to the sharing business.
In accordance with that definition, in the preceding twelve (12) months, SPG has Shared Personal Information for a Commercial Purpose as disclosed within the Policy, including specifically as described in our Cookie Notice and Notice of Other Web Technologies in relation to sharing personal information for cross-contextual behavioral advertising or targeted advertising.
As provided by the CCPA, California consumers have the right to opt-out of the "sale" of personal information to third parties. To opt-out of the "sale" or "sharing" of personal information related to targeted advertising, interest based advertising and cross context behavioral advertising, take the following steps:
Your cookie selections are specific to the particular device, browser, and website you use. If you use another device or browser, you will need to opt out on each device and browser. Blocking or deleting cookies from your browser may remove your opt-out settings, requiring you to opt-out again.
The CCPA excludes from the definition of Sharing Personal Information any use of Personal Information which was requested by you (the customer), including the expected and typical use of that information by a third party for the reasonably necessary purposes to achieve the requested service. Such an information transfer is considered the Disclosure of Personal Information for a Business Purpose under the CCPA.
In the preceding twelve (12) months, we may have Disclosed the following categories of Personal Information for a Business Purpose:
Category A: Identifiers
Category B: California Customer Records Personal Information categories
Category C: Protected classification characteristics under California or federal law
Category D: Commercial information
Category F: Internet or other similar network activity
Category H: Sensory Data
Category I: Professional or employment-related information
Category J: Non-public education information
Category K: Inferences drawn from other Personal Information
We may Disclose to the following categories of third parties your Personal Information for a Business Purpose to perform services on your behalf and to provide you with the insurance products and services you expect from us:
In the preceding twelve (12) months, we have sold or shared Personal Information as defined by the CCPA, as described herein and in our Cookie Notice and Notice of Other Web Technologies in the Policy in relation to sharing personal information for cross-contextual behavioral advertising or targeted advertising.
You have the right to opt out of the use of your personal information for targeted advertising purposes. You may download one of the supported browsers or extensions to send the Global Privacy Control ("GPC") signal, which will transmit your request to opt-out of targeted advertising automatically. A list of GPC enabled available browsers or extensions is available here: https://globalprivacycontrol.org/#download.
Your computers or devices also have tools within their browser settings that allow you to manage your acceptance of cookies. These can include the ability to disable or block cookies, remove cookies, automatically accept cookies or to notify you when a cookie is received. Generally disabling or rejecting cookies can impact your user experience; Certain features of our website may not be available if all cookies are disabled, and therefore, disabling, particularly of strictly necessary cookies, may not be available.
In addition, for recruitment and/or employment purposes, in the past twelve (12) months we have collected or may have collected and retained the following categories of Personal Information as necessary from California residents. Personal Information that falls under the definition of Sensitive Personal Information under the CCPA has been noted in the second column below:
| Category | California Sensitive Personal Information may be considered to be within this Category (YES or NO) | Examples of Personal Information | Collected |
|---|---|---|---|
| Additional personal details, contact details and identifiers. | YES | Additional personal details for recruitment/employment purposes, such as national identification number, Social Security number, insurance information, marital/civil partnership status, domestic partners, dependents, emergency contact information, and military history; professional/personal calendar availability/scheduling information for meeting/communication purposes. | YES |
| Education information and professional or employment-related information. | NO | Information about your education and professional or employment-related information, such as your employment history. | YES |
| Sensitive data for recruitment purposes. | YES | Certain types of sensitive information when permitted by local law or with your consent, such as health/medical information (including disability status), trade union membership information, religion, race or ethnicity, minority flag, and information on criminal convictions and offences. We collect this information for specific purposes, such as health/medical information in order to accommodate a disability or illness (subject to legal limits on the timing of collection of such information and other applicable limitations) and to provide benefits; background checks and diversity-related Personal Information (such as race or ethnicity) in order to comply with legal obligations and internal policies relating to diversity and anti-discrimination. | YES |
| Documentation required under immigration laws. | YES | Data on citizenship, passport data, and details of residency or work permit (a physical copy and/or an electronic copy). | YES, as to employees, some job candidates, and contractors of Specialty Program Group LLC |
| Financial information for payroll/benefits purposes. | YES | Your banking and other relevant financial details we need for payroll/benefits purposes. | YES |
| Talent management information. | YES | Information necessary to complete a background check, details on performance decisions and outcomes, performance feedback and warnings, e-learning/training programs, performance and development reviews (including information you provide when asking for/providing feedback, creating priorities, updating your input in relevant tools), driver's license and car ownership information, and information used to populate biographies. | YES |
| Requested recruitment information. | NO | Information requested to provide during the recruitment process, to the extent allowed by applicable law. | YES |
| Recruitment information you submit. | NO | Information that you submit in résumés / CVs, letters, writing samples, or other written materials (including photographs). | YES |
| Information generated by us during recruitment. | NO | Information generated by interviewers and recruiters related to you, based on their interactions with you or basic Internet searches where allowed under applicable law. | YES |
| Recruitment information received from third parties. | NO | Information related to you provided by third-party placement firms, recruiters, or job-search websites, where applicable. | YES |
| Audiovisual information processed during recruitment. | YES | Photograph, and images/audio/footage captured on CCTV or other video systems when visiting our office or captured in the course of recruitment events or video recruitment interviews. | YES |
| Recommendations. | NO | Recommendations related information provided on your behalf by others. | YES |
| Employment history and background checks. | YES | Information about your prior employment, education, and where applicable and allowed by applicable law, credit history, criminal records or other information revealed during background screenings. | YES |
| Diversity related information. | YES | Information about race / ethnicity / religion / disability / gender and self-identified LGBT status, for purposes of government reporting where required by law, as well as to understand the diversity characteristics of our workforce, subject to legal limits. | YES |
| Assessment information. | YES | Information generated by your participation in psychological, technical or behavioral assessments. You will receive more information about the nature of such assessments before your participation in any of them. | YES |
SPG retains certain records of your Personal Information as necessary to operate our business and comply with our legal and regulatory obligations. Such records are retained for legally defined retention periods that may extend beyond the period for which we provide the Services to you. We have implemented appropriate measures to confirm that Personal Information is securely disposed when no longer required.
The CCPA at Section 7011 (e)(2) provides California Residents with specific rights regarding their Personal Information:
(A) Access. The right to know what Personal Information the business has collected about the consumer, including the categories of Personal Information, the categories of sources from which the Personal Information is collected, the business or commercial purpose for collecting, selling, or sharing Personal Information, the categories of third parties to whom the business discloses Personal Information, and the specific pieces of Personal Information the business has collected about the consumer;
(B) Deletion. The right to delete Personal Information that the business has collected from the consumer, subject to certain exceptions;
(C) Correction. The right to correct inaccurate Personal Information that a business maintains about a consumer;
(D) Opt-out of Sale or Sharing. If the business sells or shares Personal Information, the right to opt-out of the sale or sharing of their Personal Information by the business;
(E) Limitation on the Use of Sensitive Personal Information. If the business uses or discloses sensitive Personal Information for reasons other than those set forth in section 7027, subsection (m), the right to limit the use or disclosure of sensitive Personal Information by the business; and
(F) Non-discriminatory Treatment. The right not to receive discriminatory treatment by the business for the exercise of privacy rights conferred by the CCPA, including an employee's, applicant's, or independent contractor's right not to be retaliated against for the exercise of their CCPA rights.
The following sections describe these CCPA rights in further detail and explain how to exercise those rights.
You have the right to request that we disclose certain information to you about our collection and use of your Personal Information over the past twelve (12) months. Once we receive and confirm your verifiable consumer request for Access rights (see "Exercising Access, Data Portability and Deletion Rights"), we will disclose to you to the extent reasonably available, and to the extent that we can continue to protect your data while providing such disclosure:
In addition to the rights listed above, you may request limitations on the use of your Sensitive Personal Information consistent with the terms and limitations described in the CCPA, and pursuant to Civil Code Section 1798.120 et.seq. Limited use of Sensitive Information may continue to include those uses which the average consumer would reasonably expect in context, and for uses which are reasonably necessary and proportionate for our business.
You have the right to request that we delete any of your Personal Information that we collected from you and retained. Once we receive and confirm your verifiable consumer request (see "Exercising Access, Data Portability and Deletion Rights"), we will delete your Personal Information from our records, unless an exception applies.
We may deny your deletion request in whole or in part for other reasons and exceptions described in the CCPA.
To exercise the access, data portability and deletion rights described above, please submit a verifiable consumer request to us by:
To protect your information and privacy, only you, or someone legally authorized to act on your behalf, may make a verifiable consumer request related to your Personal Information. Please indicate in your subject line "California Privacy Rights Request" so that we can better respond to you. Designated agents making any request will be required to provide signed permission for the agent to submit a request. In addition, when an authorized agent submits a request, we may also require that you verify your own identity directly to us or confirm with us that you have requested that the agent to submit the request. You may also make a verifiable consumer request on behalf of your minor child.
You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must:
We cannot provide you with Personal Information if we cannot verify your identity or authority to make the request and confirm the Personal Information relates to you. We will only use Personal Information provided in a verifiable consumer request to verify the requestor's identity or authority to make the request.
We will acknowledge receipt of your request within ten (10) days. We will endeavor to respond in substance to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time, we will inform you of the extension period which may not exceed an additional forty-five (45) days beyond the original forty-five (45) day period.
Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request's receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your Personal Information that is readily usable and should allow you to transmit the information from one entity to another entity without significant hindrance.
We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
California's "Shine the Light" law (Civil Code Section § 1798.83) permits users of our website who are California Residents to request certain information regarding our disclosure of Personal Information to third parties for their direct marketing purposes. To make such a request, please write us at the mailing address shown beneath the heading "Contact Information for Requests under this Notice."
If you have any questions or comments about this Notice, the ways in which we collect and use your Personal Information described herein, and in the Policy, your choices, and rights regarding such use, or wish to exercise your rights under California law, please contact us at:
Postal Address:
Chief Legal Officer
Specialty Program Group LLC
150 N Riverside Plaza, 17th Floor
Chicago, IL 60606
Or by:
Please indicate the purpose of your Email in the subject line, for instance "California Privacy Rights Request," so that we can identify your Email properly.
There may be situations where we cannot grant a particular request --- for example, if you ask us to delete your transaction data but we are legally obligated to keep a record of that transaction to comply with law, or if we are unable to verify your identity through standard and reasonable requirements. We may also decline to grant a request where doing so would undermine our legitimate use of data for anti-fraud and security purposes, such as when you request deletion of an account that is being investigated for security concerns. Other reasons your privacy request may be denied could be that granting the request would jeopardize the privacy of others; that the request is substantively frivolous or vexatious; or that granting the request would be highly impractical in the context of our legitimate business purposes.