Velonetic Online Privacy Notice
Last updated: 20 August 2026
Introduction
Velonetic is the trading name of Ins-sure Holdings Limited and Xchanging Claims Services Limited, both registered in England and Wales under company numbers 04202239 and 04306133. The registered office address for both companies is 110 Pinehurst Road, Farnborough Business Park, Farnborough, Hampshire, GU14 7BF, England.
We are committed to protecting and respecting your privacy.
This Privacy Notice describes Velonetic's approach to the collection, use, storage, sharing, retention, protection and transfer of personal information through our Resources and other related business activities.
This Privacy Notice explains how we collect, use, share, retain and protect personal information when you use our website, social media channels, online forms, surveys and other digital resources (collectively referred to as our "Resources"), as well as how we may process personal information in connection with our business activities and interactions with customers, business contacts, suppliers, contractors, applicants and employees.
It also explains your privacy rights and how to exercise them.
For the purposes of applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR) and the Data Protection Act 2018, Velonetic is the data controller of personal information collected through our Resources unless otherwise stated.
Velonetic is committed to maintaining an effective privacy and data protection programme designed to support compliance with applicable data protection legislation and promote trust, transparency and accountability in the handling of personal information.
Who this privacy notice applies to
This Privacy Notice applies to individuals whose personal information is processed through our Resources and other related business activities, including:
- Visitors to our website and users of our online Resources.
- Individuals who contact us, submit enquiries or request information.
- Customers, prospective customers and customer representatives.
- Business contacts and professional advisers.
- Suppliers, vendors, contractors, consultants and other third-party service providers.
- Representatives of our business partners and strategic partners.
- Individuals who participate in surveys, consultations, events, webinars or marketing activities.
- Individuals who engage with us through social media platforms.
- Current employees, former employees, agency workers, contractors and applicants, where they interact with our Resources or where this Privacy Notice is otherwise referenced.
In certain circumstances, Velonetic may collect personal information from organisations that we work with, publicly available sources, regulatory bodies, professional networks or other third parties. Where we do so, we will process such information in accordance with applicable data protection laws and the principles set out in this Privacy Notice.
Where a separate Employee Privacy Notice, Recruitment Privacy Notice or Supplier Privacy Notice applies, that notice will take precedence in respect of the specific processing activities described in that notice.
Our privacy principles
We are committed to:
- Lawfulness, fairness and transparency – Processing personal information in a lawful, fair and transparent manner.
- Data minimisation – Collecting only the personal information necessary for specified purposes.
- Purpose limitation – Using personal information only for legitimate and defined purposes.
- Accuracy – Taking reasonable steps to ensure personal information remains accurate and up to date.
- Storage limitation – Retaining personal information only for as long as necessary.
- Integrity and confidentiality – Protecting personal information through appropriate technical and organisational security measures.
- Accountability – Demonstrating compliance with applicable privacy legislation.
Privacy governance and accountability
Protecting personal information forms part of Velonetic's wider governance, risk and compliance framework.
Velonetic maintains policies, standards, procedures and controls designed to support compliance with applicable privacy, data protection and information security laws.
Privacy compliance is overseen by the Data Protection Officer and supported through appropriate governance, risk management and security processes. We regularly review our privacy programme, controls and procedures to promote the responsible collection, use, sharing, retention and protection of personal information.
Privacy forms part of our wider commitment to ethical business conduct, regulatory compliance and information security.
What personal information we collect
The personal information we collect depends on how you interact with our Resources.
Information you provide
This may include:
- Name
- Job title
- Employer or organisation
- Email address
- Telephone number
- Business contact details
- Survey and feedback responses
- Information submitted through forms, enquiries or communications
Information obtained from other sources
We may obtain personal information from third parties where permitted by law, including:
- Customers and business partners.
- Service providers.
- Publicly available sources.
- Regulatory bodies.
- Professional networking platforms.
- Industry directories.
We will only process such information for legitimate business purposes and in accordance with applicable law.
Information collected automatically
When you use our Resources, we may automatically collect:
- IP address.
- Browser type and version.
- Device identifiers.
- Operating system.
- Date and time of access.
- Language preferences.
- Referring website.
- Website usage information.
- Cookie identifiers.
- Approximate geographic location derived from IP address.
Special category data
We do not generally collect special category personal data through our Resources.
If special category data is provided, it will only be processed where a lawful basis and an applicable condition under data protection legislation applies.
How we use personal information
We may use personal information to:
- Provide and administer our Resources.
- Respond to enquiries and requests.
- Manage business and customer relationships.
- Conduct surveys and obtain feedback.
- Improve our Resources and user experience.
- Analyse website usage and engagement.
- Monitor performance and effectiveness of communications.
- Assess, monitor and improve the effectiveness, performance and security of our Resources.
- Develop, test and improve our services, systems and digital Resources.
- Conduct business continuity, operational resilience and risk management activities.
- Support audits, investigations, compliance monitoring and regulatory reporting.
- Maintain the security and integrity of our systems.
- Detect and prevent fraud, misuse and unlawful activity.
- Comply with legal, regulatory and contractual obligations.
- Communicate important service, operational or business-related updates.
- Establish, exercise or defend legal claims.
Lawful bases for processing
We process personal information only where we have a lawful basis to do so.
Depending on the circumstances, we may rely on:
Contract
Where processing is necessary to enter into or perform a contract with you or your organisation.
Legal obligation
Where processing is necessary to comply with applicable legal or regulatory requirements.
Legitimate interests
Where processing is necessary for our legitimate business interests, including:
- Operating, maintaining and improving our Resources and services.
- Managing customer, supplier and business relationships.
- Conducting business administration and operational activities.
- Maintaining network, system and information security.
- Preventing fraud, cyber threats and unlawful activity.
- Managing corporate governance, risk and compliance obligations.
- Protecting and exercising legal rights.
Where we rely on legitimate interests, we assess the impact on individuals and ensure that such interests are not overridden by their rights and freedoms.
Consent
Where required by law, we will request your consent before processing personal information.
You may withdraw your consent at any time.
A more detailed explanation of the lawful basis relied upon for a specific processing activity can be provided on request.
Marketing Communications
We may send business-related communications to existing customers, contacts and stakeholders where permitted by law.
Where consent is required under the Privacy and Electronic Communications Regulations (PECR), we will obtain your consent before sending marketing communications.
You can opt out of receiving marketing communications at any time by:
- Selecting the unsubscribe option included in electronic communications; or
- Contacting us using the details provided below.
Opting out of marketing communications will not affect essential service, contractual or regulatory communications.
Cookies and similar technologies
We use cookies and similar technologies to support the operation, security and performance of our Resources.
Strictly necessary cookies may be placed without consent where required to provide services requested by you.
All non-essential cookies, including analytics, functionality and targeting cookies, will only be used where appropriate consent has been obtained.
You may manage your cookie preferences at any time through our cookie consent tool.
How we share personal information
We may share personal information with:
Service providers
Third-party suppliers, contractors and service providers who support our business operations and provide services on our behalf.
Group companies and strategic partners
Where necessary to deliver services, support operational activities or fulfil legitimate business purposes.
Professional advisers
Legal advisers, auditors, insurers and other professional advisers.
Regulatory authorities and law enforcement agencies
Where required by law, regulation, court order or legal process.
Corporate transactions
In connection with mergers, acquisitions, restructuring, financing, asset sales or similar business transactions.
With your consent
Where you have explicitly authorised us to share your personal information.
We require recipients to protect personal information and process it in accordance with applicable data protection laws.
International transfers
Personal information may be transferred to and processed in countries outside the United Kingdom.
Where this occurs, we will ensure that appropriate safeguards are implemented, including:
- UK adequacy regulations.
- Intra Group Data Transfer Agreements (IGDTAs).
- The UK Addendum to EU Standard Contractual Clauses.
- Other legally recognised transfer mechanisms.
Where personal information is transferred internationally, we assess privacy and security risks and implement appropriate contractual, organisational and technical safeguards designed to protect personal information.
Copies of relevant safeguards may be requested using the contact details provided below.
Data protection by design and default
Velonetic seeks to incorporate privacy considerations into the design, development and operation of its systems, products, services and business processes.
Where appropriate, privacy assessments, risk reviews and control measures are undertaken to ensure personal information is processed in accordance with applicable privacy and data protection requirements.
How we protect personal information
We implement appropriate technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Security measures include:
- Access controls.
- Encryption where appropriate.
- Security monitoring.
- Secure system administration.
- Staff training and awareness.
- Regular review of security controls.
We regularly assess the effectiveness of our technical and organisational measures, taking into account the nature, scope, context and purposes of processing and the risks posed to individuals.
How long we keep personal information
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, including:
- Providing services.
- Managing business relationships.
- Meeting legal and regulatory obligations.
- Resolving disputes.
- Defending legal claims.
Retention periods are determined in accordance with our Records Retention Schedule and applicable legal requirements.
When personal information is no longer required, it will be securely deleted, anonymised or otherwise disposed of in accordance with our records management and information governance requirements.
Automated decision-making and profiling
We do not carry out solely automated decision-making or profiling through our Resources that produces legal effects or similarly significant effects on individuals.
AI and emerging technologies
Velonetic may use artificial intelligence-enabled tools to support certain business, operational and administrative activities. Where AI technologies are used, they remain subject to appropriate human oversight, governance, risk management and security controls. Velonetic does not use AI systems to make solely automated decisions that produce legal effects or similarly significant effects on individuals.
Children's privacy
Our Resources are intended for business and professional use and are not directed at children.
We do not knowingly collect personal information from children under the age of 13.
Your rights
Subject to applicable law, you may have the right to:
- Access your personal information.
- Request correction of inaccurate personal information.
- Request deletion of personal information.
- Request restriction of processing.
- Object to processing based on legitimate interests.
- Object to direct marketing.
- Request transfer of personal information to another organisation.
- Withdraw consent where consent is relied upon.
- Not be subject to certain forms of automated decision-making.
- Lodge a complaint with a supervisory authority.
To exercise any of these rights, please contact us using the details below.
Complaints
We encourage you to contact us first if you have concerns about how we process your personal information so that we can investigate and seek to resolve the matter.
You can do this by sending an email to [email protected]
We will acknowledge and investigate complaints in accordance with our Data Protection Complaints Procedure.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection matters.
Information Commissioner's Office (ICO)
Website: Information Commissioner's Office
Telephone: 0303 123 1113
External websites and social media
Our Resources may contain links to third-party websites, platforms and applications.
We are not responsible for the privacy practices of third parties. We encourage you to review their privacy notices before providing personal information.
Changes to this privacy
We may update this Privacy Notice from time to time to reflect changes in applicable laws, regulations, regulatory guidance, industry standards, technology or business operations.
Where appropriate, we will take reasonable steps to notify individuals of significant changes.
The latest version will always be made available through our Resources.
Contact us
If you have any questions about this privacy notice, wish to exercise your privacy rights, or have concerns about how your personal information is handled, please contact:
Data Protection Officer
Email: [email protected]