Privacy Notice
On this page
- Key points
- 1. About this Privacy Notice
- 2. Who we are
- 3. Personal information we may collect
- 4. How we use personal information
- 5. Our lawful bases
- 6. Business communications and direct marketing
- 7. Website infrastructure, analytics and cookies
- 8. Who we may share information with
- 9. Separate controllers and third-party privacy notices
- 10. International transfers
- 11. How long we retain personal information
- 12. Security
- 13. Automated decision-making and artificial intelligence
- 14. Your data-protection rights
- 15. Data-protection complaints
- 16. Insurance and regulated complaints
- 17. Children
- 18. Third-party websites and services
- 19. Changes to this Privacy Notice
- 20. Contact us
How Yeti Engines Ltd collects, uses, stores and shares personal information in connection with yetiengines.com.
This Privacy Notice applies to the Yeti Engines B2B marketing website and our business enquiries and relationships. It does not replace the separate privacy information provided when an individual enters a consumer insurance comparison journey.
Version: 1.3
Effective from: 16 September 2026
Last updated: 16 September 2026
Key points
Yeti Engines Ltd is the controller responsible for personal information covered by this Privacy Notice.
This Notice applies principally to the Yeti Engines business-to-business marketing website, partner and provider enquiries, controlled demonstrations and related business communications.
It does not govern:
- Yeti Compare or a consumer insurance quote, comparison, retrieval or results journey;
- a white-label or co-branded consumer journey;
- a partner dashboard, client portal, production API or live software service;
- policy purchase, administration or claims handling; or
- personal information Yeti processes solely on another organisation's documented instructions.
Separate privacy information will apply to those activities before they are made available.
We do not sell personal information. Submitting a business enquiry does not, by itself, subscribe you to general marketing. Please do not send consumer quote data, policyholder information, claims information, pet medical information, credentials or live production data through the marketing Website.
For privacy requests or complaints, email privacy@yetiengines.com.
1. About this Privacy Notice
1.1 Scope
This Privacy Notice explains how Yeti Engines Ltd may collect, use, store, disclose and otherwise process personal information when you:
- visit the Website;
- contact us about a founding-partner pilot, referral, co-brand, white-label opportunity, provider integration or another commercial opportunity;
- communicate with us as a publisher, pet brand, retailer, charity, insurer, broker, intermediary, technology provider, investor, supplier, adviser or other business contact;
- request or receive access to a controlled demonstration, prototype, evaluation environment or non-production material;
- expressly accept our Website Terms of Use, Evaluation Terms or another set of terms where an acceptance mechanism is provided;
- attend a call, meeting, demonstration or event involving Yeti;
- report a vulnerability or security concern;
- make a complaint or exercise a data-protection right; or
- otherwise interact with us in connection with the Website or a prospective business relationship.
1.2 Website covered
The Website covered by this Privacy Notice includes:
- yetiengines.com;
- any www or other canonical version of yetiengines.com;
- any subdomain of yetiengines.com that links to this Notice; and
- any replacement domain on which this Notice is published.
1.3 Activities covered
This Notice principally concerns:
- the Yeti Engines marketing Website;
- prospective publisher, provider, broker, insurer, integration, supplier and commercial relationships;
- controlled non-production demonstrations and evaluations;
- regulatory or commercial onboarding connected with a prospective relationship; and
- related communications, record keeping, security and legal matters.
1.4 Activities not covered
This Notice does not govern personal information processed through:
- Yeti Compare;
- a consumer quote, comparison, retrieval or results journey;
- a publisher-branded or white-label consumer journey;
- a live partner dashboard, production API, client portal or software service;
- an insurer's, broker's or other provider's website;
- policy purchase, payment, administration or claims handling; or
- another service where a separate privacy notice is displayed.
Those activities involve different information, purposes, recipients, retention requirements and regulatory responsibilities. Appropriate separate privacy information will be provided before any such activity is made available.
1.5 Processing for another organisation
Where Yeti processes personal information solely on the documented instructions of a publisher, insurer, broker, client or other organisation, Yeti may act as that organisation's processor.
In that situation:
- the relevant organisation is normally responsible for deciding how and why the information is used;
- its privacy notice will normally apply to the individual concerned; and
- Yeti's processing will be governed by the applicable contract and data-processing terms.
1.6 Legal effect
This Privacy Notice provides information about our use of personal information. It does not create contractual rights beyond those provided by applicable law.
Nothing in this Notice limits any right or protection that cannot lawfully be limited.
2. Who we are
2.1 Controller
Yeti Engines Ltd is the controller responsible for the personal information described in this Privacy Notice.
Our details are:
Yeti Engines Ltd Company number: 17266550 Registered in: England and Wales
Registered office:
5 Ribblesdale Place Preston England PR1 8BZ
Yeti Engines Ltd (FRN 1061516) is an Appointed Representative of Innovative Risk Labs Ltd, which is authorised and regulated by the Financial Conduct Authority (FRN 609155).
General enquiries: our team Privacy requests and complaints: privacy@yetiengines.com Security reports: security@yetiengines.com
2.2 Definitions
In this Privacy Notice:
- Yeti, we, us and our mean Yeti Engines Ltd;
- personal information and personal data mean information relating to an identified or identifiable individual;
- Principal means an authorised firm responsible for regulated activity carried on by Yeti as an appointed representative, where the relevant appointment is effective;
- Group Company means a company that directly or indirectly controls, is controlled by, or is under common control with Yeti Engines Ltd, including Heyworth & Co Group Ltd; and
- Website has the meaning given in section 1.2.
3. Personal information we may collect
3.1 General
The information we collect depends on how you interact with us and which Website functions are available at the relevant time.
3.2 Business contact and enquiry information
When you use the enquiry form on this website, the details you enter (your topic, name, company, work email address and message) are sent to Yeti and delivered to our team by email through an email-delivery service provider acting on our behalf. We use them to respond to and manage your enquiry. The form contents are not stored in your browser storage. To protect the form against automated abuse, we also process limited technical information, such as your IP address, the time of submission and the page you submitted from. If the form cannot be sent, it instead prepares an email draft in your browser, and we receive that enquiry only if you send it through your own email provider. The on-page product examples do not collect personal information or request live insurance quotations.
When you contact or communicate with us, we may collect:
- your name;
- your work email address;
- a personal email address where you choose to use one;
- your telephone number;
- your job title, occupation or role;
- the organisation you represent;
- your organisation's website and business address;
- your organisation type;
- the nature of your organisation's audience, products, services or insurance activities;
- information about a proposed referral, co-brand, white-label, integration, pilot, distribution or provider relationship;
- approximate audience, traffic, conversion, commercial or timing information;
- information about your current pet-insurance or comparison arrangements;
- preferred commercial or technical model;
- the content of correspondence, forms and messages;
- documents, presentations or attachments you provide;
- written notes relating to calls, meetings or demonstrations;
- communication and marketing preferences; and
- other information you choose to provide.
3.3 Commercial, integration and due-diligence information
Where discussions progress, we may collect or create information concerning:
- commercial requirements and proposed terms;
- projected or historic traffic, conversion, revenue or audience data;
- brand, content, distribution and customer-journey requirements;
- technical architecture, systems, APIs, security requirements and integration dependencies;
- provider, insurer, broker, intermediary or publisher relationships;
- regulatory status, permissions, operating model and compliance requirements;
- conflicts, sanctions, fraud, financial-crime or reputational checks where appropriate;
- security and supplier-assurance questionnaires;
- meeting records, decisions, approvals and actions;
- draft proposals, pilot plans, statements of work and contracts; and
- information reasonably needed to assess, approve, structure or manage a prospective relationship.
Some of this information may be commercially confidential. It may also contain personal information relating to directors, employees, representatives, advisers or other business contacts.
3.4 Controlled demonstrations and evaluation access
Where we provide access to a controlled demonstration, prototype, preview, sandbox or evaluation environment, we may process:
- your name and work contact details;
- your organisation and role;
- access invitations and authentication information;
- the terms or confidentiality commitments you accepted;
- the date, time, duration and source of access;
- pages, materials, functions or resources viewed;
- device, browser, IP address and security information;
- actions taken within the environment;
- feedback, questions and evaluation notes; and
- records needed to detect misuse, protect intellectual property and administer access.
Unless we expressly agree otherwise in writing, controlled demonstrations and evaluation environments must use synthetic, test or anonymised information only.
3.5 Calls, meetings, demonstrations and transcription
We may process:
- meeting invitations and attendance information;
- call or meeting notes;
- follow-up actions and decisions;
- correspondence and documents shared during the meeting; and
- audio, video or transcripts where recording or transcription is used.
Where a call or meeting is recorded or transcribed, we will provide additional notice at or before recording where required.
3.6 Technical and Website information
When you access the Website, we and our hosting, network, content-delivery, security or technical providers may process limited technical information, including:
- your IP address;
- the date and time of a request;
- the page, resource or file requested;
- the referring page or website;
- browser type and version;
- device type;
- operating system;
- approximate geographic information derived from an IP address;
- HTTP request and response information;
- diagnostic and error information;
- security and bot-detection information;
- consent or preference information where relevant; and
- information used to identify unusual, malicious or automated traffic.
Technical information may be processed through hosting, network, firewall, content-delivery, diagnostic and security logs even where the Website does not place non-essential cookies on your device.
3.7 Analytics information
Where Website analytics are enabled, we may collect or receive information about Website use, including:
- page views and approximate visitor numbers;
- pages visited and general navigation paths;
- referring websites or campaigns;
- general geographic region;
- browser, operating-system, device and screen information;
- outbound-link activity;
- file downloads;
- interactions with selected Website elements; and
- technical performance information.
We do not intend to configure Website analytics to collect:
- names, email addresses or telephone numbers;
- enquiry or correspondence contents;
- form-field contents;
- credentials or security secrets;
- consumer quote or policy information;
- acceptance-record identifiers; or
- special-category or criminal-offence information.
If analytics are introduced, the provider, configuration, technologies used and available controls will be described in our Cookies & website technologies notice.
3.8Terms, acknowledgement and approval records
Where the Website or a controlled process asks you to accept or acknowledge terms, notices or restrictions, we may record:
- the date and time;
- the document, version and effective date;
- the page, form, environment or function used;
- the method of acceptance or acknowledgement;
- confirmation that the relevant control was selected;
- a related submission, invitation, request or audit reference;
- the privacy information made available at that time; and
- limited technical information reasonably required to demonstrate authenticity or integrity.
We do not create an individual acceptance record merely because someone browses the public Website. An individual record is created only where an express acceptance or acknowledgement mechanism is used.
3.9 Rights, complaints, regulatory and security information
Where you exercise a legal right, make a complaint, report a concern or become involved in a regulatory or security matter, we may collect:
- your identity and contact details;
- evidence of identity or authority;
- details of the request, complaint, incident or report;
- correspondence and supporting documents;
- technical information and evidence;
- investigation notes and internal decisions;
- actions considered or taken;
- information shared with or received from advisers, insurers, auditors, a Principal, regulators or authorities; and
- the outcome and follow-up record.
3.10 Information received from other sources
We may receive limited personal information from:
- a colleague or representative of your organisation;
- a Group Company;
- a publisher, pet brand, retailer, charity, insurer, broker, intermediary or technology provider;
- a Principal or prospective Principal;
- a client, supplier, referral source or professional adviser;
- a publicly available business source;
- a professional-networking service;
- a security researcher; or
- a person authorised to act on your behalf.
Where required, we will provide appropriate privacy information within the applicable period.
3.11 Information you should not send through the marketing Website
Unless we have specifically requested it and appropriate arrangements are in place, do not send us:
- consumer or policyholder quote information;
- insurance policy, payment or claims information;
- pet medical records or detailed pet-health information linked to an owner;
- names, contact details or other personal information concerning your customers, members or audience;
- passwords, authentication credentials or private encryption keys;
- payment-card information;
- confidential source code;
- live production-system access details;
- special-category personal information;
- criminal-offence information;
- information subject to another person's confidentiality rights;
- exploitable vulnerability details that should instead be sent through the security-reporting route; or
- information that you are not authorised to disclose.
If this type of information is sent without being requested, we may restrict access to it, return it, securely delete it, move it to an appropriate controlled channel, or retain only what is reasonably necessary to deal with the communication, protect legal rights or comply with law.
4. How we use personal information
4.1 Purposes
We may use personal information to:
- operate, maintain, secure and deliver the Website;
- provide requested Website content and functionality;
- understand, assess and respond to enquiries;
- identify the organisation and representative contacting us;
- assess whether a proposed partner, provider, pilot or integration opportunity is suitable;
- arrange calls, meetings, demonstrations and evaluations;
- prepare proposals, pilot plans, estimates and commercial terms;
- conduct proportionate commercial, technical, security, conflict, fraud, sanctions, financial-crime, regulatory and reputational checks;
- determine the proposed operating and regulatory model for a relationship;
- seek or support Principal, insurer, broker, intermediary, compliance or other approvals;
- communicate with prospective, current and former partners, providers, suppliers, advisers and business contacts;
- manage prospective and existing business relationships;
- follow up on enquiries, meetings and previous discussions;
- administer controlled demonstration or evaluation access;
- record and demonstrate acceptance of Website Terms, Evaluation Terms, confidentiality obligations or other terms;
- maintain contractual, commercial, operational, regulatory, accounting and legal records;
- manage financial-promotion, compliance, audit or oversight processes where applicable;
- understand Website use and performance;
- improve the Website, proposition, materials and user experience;
- identify and investigate errors, misuse, fraud, security threats and prohibited activity;
- investigate vulnerability and security reports;
- prevent unwanted, duplicate, abusive or fraudulent communications;
- maintain suppression or do-not-contact records;
- respond to data-protection requests and complaints;
- establish, exercise or defend legal rights;
- comply with legal, regulatory, accounting, tax, insurance and corporate requirements;
aa. manage an investment, funding, business sale, restructuring or transfer;
ab. protect Yeti, Group Companies, prospective and current partners, providers, suppliers and Website visitors;
ac. send relevant business communications where permitted by law; and
ad. carry out other purposes reasonably compatible with those described above.
4.2 No sale of personal information
We do not sell personal information or trade it as a commodity.
4.3 No consumer insurance decisions through this Website
Personal information collected through the marketing Website is not used to:
- calculate a consumer insurance premium;
- determine consumer eligibility for an insurance policy;
- rank or personalise consumer insurance results;
- make a claims decision; or
- make another solely automated decision producing legal or similarly significant effects for a consumer.
Separate privacy information will apply before a consumer quote or comparison service processes personal information.
4.4 Enquiry sharing
We do not ordinarily disclose the substantive contents of a first-contact enquiry to an unrelated publisher, insurer, broker, intermediary or commercial partner unless:
- you authorise the disclosure;
- the proposed disclosure is apparent from your request and appropriate information is provided beforehand;
- the information is anonymised or aggregated so that it no longer identifies you; or
- disclosure is required or permitted by law, regulation or a valid oversight requirement.
5. Our lawful bases
5.1 General
We must have a lawful basis for processing personal information. The basis used depends on the information, circumstances and purpose.
The lawful bases available under current UK data-protection law include consent, contract, legal obligation, vital interests, public task, recognised legitimate interests and legitimate interests.
5.2 Lawful-basis summary
| Processing purpose | Lawful basis normally relied on |
|---|---|
| Operating, securing and maintaining the Website | Legitimate interests |
| Responding to business enquiries and arranging discussions | Legitimate interests and, where applicable, steps at your request before entering a contract |
| Assessing a publisher, provider, pilot, integration or commercial opportunity | Legitimate interests and, where applicable, steps before entering a contract |
| Preparing proposals, pilots, estimates and commercial terms | Legitimate interests and, where applicable, steps before entering a contract |
| Administering controlled demonstrations and evaluation access | Legitimate interests, contract or steps before entering a contract |
| Recording acceptance of terms, confidentiality restrictions or notices | Legitimate interests and, where applicable, contract |
| Conducting security, conflict, fraud, sanctions, financial-crime, regulatory and reputational checks | Legitimate interests, recognised legitimate interests where applicable, and legal obligation where required |
| Sharing relevant information with a Principal for onboarding, approval, oversight, audit, complaints or regulatory purposes | Legitimate interests, contract and legal obligation where applicable |
| Website measurement and improvement | Legitimate interests, unless consent or another basis is required |
| Fraud prevention, security and vulnerability handling | Legitimate interests, recognised legitimate interests where applicable, and legal obligation where applicable |
| Accounting, tax, corporate and regulatory compliance | Legal obligation and legitimate interests |
| Establishing, exercising or defending legal claims | Legitimate interests and, where applicable, legal obligation |
| Direct marketing | Legitimate interests or consent, together with compliance with electronic-marketing rules |
| Processing based on a specific permission you give us | Consent |
5.3 Legitimate interests
Relevant legitimate interests may include:
- operating, maintaining, securing and improving the Website;
- responding to enquiries and discussing prospective opportunities;
- assessing, developing and managing commercial relationships;
- protecting confidential information, systems and intellectual property;
- administering controlled demonstrations and evaluation environments;
- conducting proportionate due diligence;
- maintaining an accurate relationship and decision history;
- recording express acceptance of terms and notices;
- preventing duplicate, unwanted, abusive or fraudulent communications;
- detecting fraud, misuse and security incidents;
- meeting insurer, broker, publisher, Principal and supplier due-diligence expectations;
- resolving complaints and disputes;
- establishing, exercising and defending legal rights; and
- sending relevant business-to-business communications where permitted.
Where appropriate, we consider the purpose and necessity of the processing, the nature of the information, what an individual may reasonably expect, possible effects on the individual and available safeguards.
5.4 Steps before entering into a contract
We may process information where necessary to take steps at your request before entering into a contract, including where you ask us to:
- assess a proposed relationship or integration;
- provide information about Yeti Engines;
- arrange a meeting or demonstration;
- provide access to evaluation materials;
- prepare a proposal, pilot plan or estimate; or
- discuss possible contractual or commercial terms.
5.5 Contract
Where you contract with us as an individual, we may process information where necessary to perform or administer that contract.
Where the contract is with your employer, company or another organisation, we will generally rely on legitimate interests or another appropriate lawful basis when processing your business contact information.
5.6 Legal obligations
We may process personal information where necessary to comply with legal or regulatory obligations concerning matters such as:
- data protection;
- tax, accounting and corporate administration;
- financial promotions and regulatory oversight;
- court or tribunal proceedings;
- regulator, law-enforcement or public-authority requests;
- fraud, sanctions and financial crime; and
- legally required records.
5.7 Consent
We may rely on consent where this is appropriate or legally required.
Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before consent was withdrawn and does not prevent processing under another lawful basis where one applies.
5.8 Recognised legitimate interests
Where permitted by applicable data-protection law, we may rely on a recognised legitimate interest for processing that falls within one of the purposes specified by law, such as certain fraud-prevention, safeguarding, emergency or public-task-related disclosures.
5.9 Vital interests
We may process personal information where necessary to protect the vital interests of an individual or another natural person, for example in a genuine emergency involving a risk to life. We expect this basis to apply only in exceptional circumstances.
5.10 Public task
We may process personal information where necessary for the performance of a task carried out in the public interest or in the exercise of official authority, where that task or authority has a clear basis in law. We do not currently expect this to be a routine basis for processing through this Website, but it may apply in specific circumstances.
6. Business communications and direct marketing
6.1 Enquiry-related communications
We may contact you about:
- an enquiry you have made;
- a proposed pilot, partnership, integration or provider relationship;
- a current, prospective or previous business relationship;
- matters reasonably connected with your organisation; or
- another matter where contact is permitted by law.
6.2 No automatic marketing subscription
Submitting a Website enquiry does not, by itself, subscribe you to general marketing communications.
We may send communications directly related to your enquiry, requested demonstration, proposed opportunity or existing relationship.
We will send broader promotional updates only where:
- you have made a separate marketing choice;
- an applicable business-to-business marketing rule permits the communication; or
- another lawful and fair basis applies.
6.3 Electronic marketing
For business-to-business electronic marketing, the rules may differ depending on whether the recipient is:
- a corporate subscriber, such as a limited company; or
- an individual subscriber, such as a sole trader or certain partnerships.
Where consent or the soft opt-in is required, we will rely on it only where the relevant conditions are met.
Electronic marketing will include a practical way to opt out where required.
6.4 Objections and suppression
You may object to direct marketing at any time.
Where a valid objection is received, we may retain limited information on a suppression list so that the objection continues to be respected.
7. Website infrastructure, analytics and cookies
7.1 Website delivery and security
We may use cloud hosting, application hosting, content-delivery, domain, networking, firewall, bot-management, monitoring and security providers to deliver and protect the Website.
These providers may process technical information such as IP addresses, request details, device information, security signals, diagnostics and logs.
The production Website may use infrastructure in the United Kingdom together with global edge, security or software-as-a-service providers. Relevant international-transfer safeguards are described in section 10.
7.2 Website analytics
No optional analytics or advertising scripts are currently installed on this marketing website. The Cookies & website technologies notice describes the current implementation.
We may use privacy-focused Website analytics to understand general Website use, traffic sources, content performance and visitor journeys.
We would not deliberately configure any analytics service to receive enquiry contents, form-field values, credentials, consumer quote information or other unnecessary identifying information.
If analytics are introduced, the provider, configuration, retention period, technologies used and available controls will be described in our Cookies & website technologies notice.
7.3Cookies and similar technologies
The Website may use cookies, browser storage, scripts, tags or similar technologies where necessary or appropriate to:
- deliver pages or requested functionality;
- maintain security;
- manage traffic;
- remember a choice requested by a visitor;
- prevent misuse;
- measure Website use and performance; or
- provide another Website function.
Where consent or another user control is required, the relevant technology will be handled through an appropriate consent or preference mechanism.
7.4 Advertising and cross-site tracking
At the effective date of this Notice, the Website does not use advertising pixels, cross-site behavioural advertising or remarketing technologies.
We will update the Cookies & website technologies notice and implement any legally required consent controls before introducing those technologies.
8. Who we may share information with
8.1 General
We may share personal information only where reasonably necessary and where an appropriate lawful basis applies.
8.2 Hosting, infrastructure, security and analytics providers
We may share or permit processing by providers of:
- cloud and application hosting;
- content delivery, domain and network services;
- web application firewall, bot management and security;
- monitoring, error reporting and diagnostic services;
- backups and business continuity;
- Website analytics and measurement; and
- related technical services required to operate and protect the Website.
8.3 Communication and operational providers
We may use providers of:
- business email;
- calendars, video meetings and transcription;
- cloud storage and document management;
- project and task management;
- customer or business relationship management;
- electronic signatures and terms-acceptance records;
- security and supplier-assurance systems;
- professional communications; and
- general business administration.
8.4 Group Companies
We may share information with Heyworth & Co Group Ltd, Yeti Digital Ltd or another Group Company where reasonably necessary to:
- administer the group;
- respond to an enquiry relating to a Group Company, product or service;
- provide technical, operational, administrative or security support;
- develop, demonstrate, maintain or support the Website or Platform;
- manage intellectual property;
- protect legal rights;
- manage financial or corporate affairs; or
- complete an investment, restructuring or business transaction.
A Group Company may act:
- as Yeti's processor where it handles information only on Yeti's documented instructions; or
- as a separate controller where it determines its own purposes and methods of processing.
8.5 Principal, regulatory and compliance recipients
Where relevant to onboarding, approval, oversight, financial promotions, audit, complaints, regulatory reporting or legal obligations, we may share information with:
- Innovative Risk Labs Ltd, our current Principal;
- the Principal's employees, compliance personnel, auditors, consultants or professional advisers;
- the Financial Conduct Authority or another regulator;
- an insurer, broker, intermediary or capacity provider involved in an approved operating model; and
- another person whose review or approval is reasonably required for the proposed activity.
Where Yeti Engines Ltd and Innovative Risk Labs Ltd each determine their own purposes and methods of processing, each acts as an independent controller and Innovative Risk Labs Ltd's own privacy information applies to its processing.
8.6 Publishers, insurers, brokers and commercial counterparties
We may share relevant business contact or opportunity information with a prospective or actual publisher, insurer, broker, intermediary, technology provider or other counterparty where:
- the disclosure is necessary to assess, structure, approve or perform a proposed relationship;
- you have authorised it;
- the proposed sharing has been explained or is reasonably apparent in context;
- the information is anonymised or aggregated; or
- disclosure is required or permitted by law or regulation.
We will not ordinarily forward the full contents of an unsolicited first-contact enquiry to an unrelated commercial counterparty merely because it may be interested.
8.7 Professional advisers, consultants and insurers
We may share information with solicitors, barristers, accountants, auditors, insurers, brokers, tax advisers, regulatory advisers, data-protection advisers, technical consultants and other professional advisers.
8.8 Authorities and legal recipients
We may disclose information to courts, tribunals, regulators, law-enforcement bodies, tax authorities, public authorities, insolvency practitioners and other persons where disclosure is required or permitted by law.
8.9 Business transactions
We may share information with prospective or actual purchasers, investors, funders, lenders, transaction advisers, counterparties or successors in connection with an investment, sale, acquisition, merger, restructuring, financing, insolvency process or transfer of assets or business operations.
We will seek to limit disclosure to what is reasonably necessary and use confidentiality or other safeguards where appropriate.
9. Separate controllers and third-party privacy notices
9.1 Independent controllers
A Principal, insurer, broker, publisher, professional adviser, regulator or other recipient may act as an independent controller where it determines how and why it uses personal information.
Its own privacy notice and legal responsibilities apply to that processing.
9.2 Insurer and provider websites
If a person later uses Yeti Compare or continues to an insurer's, broker's or provider's website, separate privacy information will explain:
- which organisations receive the consumer's information;
- the purposes and lawful bases;
- whether information is used for pricing, eligibility, fraud prevention or policy administration;
- retention periods;
- international transfers; and
- the individual's rights and complaint routes.
This marketing Website Privacy Notice does not replace that information.
10. International transfers
10.1 General
Some service providers, Group Companies, professional advisers or commercial counterparties may process personal information outside the United Kingdom.
Global edge, security, email, meeting, analytics, monitoring and other cloud services may involve processing in multiple jurisdictions.
10.2 Safeguards
Where rules concerning restricted international transfers apply, we will use or rely on an appropriate legal mechanism.
Depending on the provider and circumstances, this may include:
- UK adequacy regulations;
- the UK Extension to the EU-US Data Privacy Framework where the recipient participates;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved standard contractual clauses;
- approved standard contractual clauses;
- another recognised transfer framework; or
- another mechanism permitted by law.
We may carry out transfer assessments, review provider terms and implement additional contractual, technical or organisational safeguards where required.
You may contact us for further information about safeguards applying to a particular category of transfer.
11. How long we retain personal information
11.1 General approach
We keep personal information only for as long as reasonably required for the relevant purpose, subject to legal, contractual, regulatory, accounting, security and claims-related requirements.
11.2 Normal retention periods
| Information category | Normal retention approach |
|---|---|
| Unsuccessful or inactive initial business enquiries | Normally up to 3 years after the last meaningful contact |
| Developed publisher, provider, broker, insurer, pilot, integration or commercial discussions | Normally up to 6 years after the last meaningful contact or the proposed relationship ends |
| Controlled demonstration and evaluation access records | Normally up to 3 years after access ends, or up to 6 years where needed to protect confidential information, intellectual property or legal rights |
| Website Terms, Evaluation Terms, confidentiality and other acceptance records | Normally 6 years after the associated enquiry, access or relationship ends |
| Contracts, transaction, invoice, payment, tax and accounting records | Normally 6 years after the relevant financial year or relationship, subject to applicable requirements |
| Records relating to regulated insurance business, Principal oversight, financial-promotion approval, regulatory audit or regulated complaints | At least 7 years where the applicable agreement, law or regulatory requirement requires it |
| Business contact and relationship records | While the relationship remains active and normally up to 3 years afterwards, unless a longer period is justified |
| Direct-marketing records | While marketing remains relevant and lawful; minimal suppression information may be kept for as long as needed to respect an objection |
| Technical, hosting, firewall, diagnostic and security logs | Normally up to 12 months, unless required for an incident, investigation, dispute or claim |
| Data-protection rights and complaint records | Normally 6 years after the matter closes |
| Security and vulnerability reports | Normally up to 6 years after closure where needed for accountability, repeated-issue analysis or legal rights |
| Aggregate Website analytics | Normally up to 3 years, depending on the service configuration and continued usefulness |
| Anonymised or aggregated information | May be retained for longer where it no longer identifies an individual |
11.3 Exceptions
We may retain information for longer where reasonably necessary because:
- a complaint, dispute, investigation or legal claim exists or is reasonably anticipated;
- a legal or regulatory hold applies;
- law, regulation, a Principal, an insurer, insurance requirements or a binding contractual obligation requires it;
- the information is relevant to fraud, sanctions, misuse, security or the protection of systems and legal rights; or
- deletion is temporarily impracticable because information is held in a secure backup or archive.
11.4 Deletion, anonymisation and backups
When identifiable information is no longer reasonably required, it may be:
- deleted;
- anonymised;
- aggregated;
- securely archived with restricted access; or
- allowed to expire through ordinary system, archive or backup cycles.
Backup information is not ordinarily restored except for business continuity, disaster recovery, security or technical necessity. Where restored, applicable deletion and restriction decisions will be reapplied where reasonably practicable.
11.5 Erasure requests
You may ask us to erase personal information.
The right to erasure is not absolute. We may retain information where a lawful basis or other lawful reason remains, including:
- legal or regulatory obligations;
- tax, accounting, corporate or insurance requirements;
- the rights of another person;
- freedom of expression and information; or
- the establishment, exercise or defence of legal claims.
12. Security
12.1 Measures
We use organisational and technical measures intended to protect personal information against:
- unauthorised access;
- accidental loss;
- misuse;
- alteration;
- inappropriate disclosure; and
- destruction.
The measures used depend on the nature of the information, systems involved, likelihood and severity of the risk, available technology and proportionality.
Measures may include:
- access restrictions and least-privilege controls;
- authentication and multi-factor authentication;
- encryption in transit;
- infrastructure and supplier controls;
- software and dependency updates;
- firewall, rate-limiting and bot-management controls;
- security and administrative logging;
- backups and recovery arrangements;
- confidentiality obligations;
- vulnerability management;
- environment separation and use of synthetic data in non-production systems; and
- incident-response arrangements.
12.2 Data minimisation
We seek to minimise the personal information included in:
- Website analytics;
- technical logs;
- security telemetry;
- demonstrations and test environments;
- business presentations; and
- development and support materials.
12.3 No absolute guarantee
No internet service, system or electronic communication can be guaranteed to be completely secure.
You are responsible for choosing an appropriate method when sending sensitive or confidential information to us.
12.4 Security reports
Security concerns should be sent to security@yetiengines.com.
Please do not include unnecessary personal information, credentials, live consumer information or destructive exploit activity in an initial report.
13. Automated decision-making and artificial intelligence
13.1 No solely automated significant decisions
We do not currently use personal information collected through the marketing Website to make decisions producing legal or similarly significant effects through solely automated processing.
13.2 Security and spam controls
We may use automated tools to:
- detect spam, bots, malware and abusive traffic;
- identify security anomalies;
- prioritise technical alerts; and
- protect the Website and controlled environments.
These activities do not ordinarily produce legal or similarly significant effects for an individual.
13.3 Artificial-intelligence use
We do not intentionally use personal information submitted through the Website to train general-purpose artificial-intelligence models.
Where an approved AI-assisted or transcription tool is used for business administration, meeting support, drafting or summarisation, we will:
- use it only where a lawful basis applies;
- minimise the personal and confidential information provided;
- apply appropriate supplier and access controls; and
- provide additional notice where required.
Live consumer quote data, policyholder data, credentials and production secrets must not be submitted to general-purpose AI tools through this Website process.
14. Your data-protection rights
14.1 Rights
Depending on the circumstances, processing and lawful basis used, you may have the right to:
- ask whether we process your personal information;
- obtain a copy of personal information we hold about you;
- correct inaccurate or incomplete information;
- ask us to erase personal information;
- ask us to restrict processing;
- object to processing;
- receive certain information in a portable format;
- withdraw consent where processing is based on consent; and
- complain about how personal information has been handled.
These rights are subject to legal conditions, limitations and exemptions.
14.2 Identity and scope
We may request information reasonably required to:
- verify your identity;
- confirm your authority to act for another person;
- identify the information concerned; or
- clarify the scope of a request.
We will not request more information than is reasonably necessary.
14.3 Fees
We do not ordinarily charge a fee.
A reasonable fee may be charged, or a request may be refused, where permitted by law, including where a request is manifestly unfounded or excessive.
14.4 Response times
We respond to rights requests within the periods required by applicable data-protection law.
The usual period is one month after receiving the request and any information reasonably required to confirm identity or authority.
Where permitted by law, the period may be extended by up to two further months where a request is complex or a person has made a number of requests. Where an extension applies, we will provide information about it within the initial statutory period.
14.5 Right to object
You have the right to object where we process personal information on the basis of legitimate interests.
This right is subject to the applicable legal test. Processing may continue where there are compelling legitimate grounds that override your interests, rights and freedoms, or where processing is required to establish, exercise or defend legal claims.
You may object to direct marketing at any time.
Where a valid direct-marketing objection is received, we may retain limited information on a suppression list to ensure that the objection continues to be respected.
14.6 How to exercise a right
Email privacy@yetiengines.com using the subject line Data Protection Request.
You may also write to the postal address in section 20.
15. Data-protection complaints
15.1 How to complain
You may make a data-protection complaint by:
- emailing privacy@yetiengines.com using the subject line Data Protection Complaint;
- using our complaints route; or
- writing to the postal address in section 20.
A complaint may be made through another channel. We will not refuse to consider a complaint solely because it was not submitted using the suggested route.
15.2 Helpful information
It is helpful, but not mandatory, to provide:
- your name and contact details;
- a description of the concern;
- relevant dates or communications;
- the outcome you are seeking; and
- supporting information.
15.3 Our process
We will:
- acknowledge receipt within 30 days;
- take appropriate steps to investigate without undue delay;
- keep you appropriately informed where required; and
- communicate the outcome without undue delay.
We may request further information or evidence of identity or authority where reasonably necessary.
15.4 Information Commissioner's Office
You also have the right to complain to the Information Commissioner's Office, the UK regulator for data protection and information rights.
Information about making a complaint is available on the ICO website.
You are not required to complete Yeti's complaints process before contacting the ICO, although raising the matter with us first may allow it to be resolved more quickly.
16. Insurance and regulated complaints
16.1 Separate route
A complaint about a consumer insurance quote, comparison journey, provider hand-off, insurance distribution activity, policy or claim is not a data-protection complaint merely because it concerns information about an individual.
Where relevant, those complaints must be made through our applicable consumer or regulated complaints route.
16.2 Principal involvement
Where a complaint concerns activity carried on under a Principal's responsibility, we may need to:
- notify the Principal;
- share relevant complaint and customer information;
- obtain further information;
- cooperate with the Principal's investigation; and
- retain the record for the applicable regulatory period.
The applicable consumer privacy notice and complaints information will explain the relevant arrangements before a regulated consumer service goes live.
17. Children
The Website is principally intended for businesses and professional users and is not directed at children.
We do not intentionally seek to collect personal information from children through the Website.
If we become aware that personal information concerning a child has been provided in circumstances where it should not have been, we may investigate and take appropriate action.
18. Third-party websites and services
The Website may contain links to websites, products, platforms or services operated by other organisations.
Those organisations are responsible for their own privacy practices where they determine how and why personal information is processed.
This Privacy Notice does not govern personal information collected independently by another organisation. You should review the relevant third party's privacy information where appropriate.
19. Changes to this Privacy Notice
We may update this Privacy Notice where:
- the Website changes;
- a service, demonstration, provider or technology is introduced or removed;
- a supplier changes;
- our processing activities change;
- a regulatory appointment or operating model changes;
- the law, regulation or regulatory guidance changes;
- our business or Group structure changes; or
- clarification is considered appropriate.
The current version will be identified by its version number, effective date and last-updated date.
Changes apply from the effective date stated in the updated Notice.
Where required, additional privacy information will be provided before personal information is used for a materially different purpose.
Separate privacy information will be provided before Yeti Compare, a consumer quote journey or another live regulated consumer service processes personal information.
20. Contact us
Questions, requests and complaints concerning this Privacy Notice or our use of personal information may be sent to:
Privacy requests and complaints: privacy@yetiengines.com
General enquiries: our team
Security reports: security@yetiengines.com
Suggested subject lines:
- Data Protection
- Data Protection Request
- Data Protection Complaint
- Security Report
Post:
Yeti Engines Ltd
5 Ribblesdale Place
Preston
England
PR1 8BZ
Postal correspondence may be marked for the attention of the directors.