Old Mutual Thrive Privacy Policy
This policy sets out:
- Introduction
- The types of personal data that we collect
- How do we collect your personal data?
- Cookies
- How do we use your personal data and what legal basis do we have for processing your personal data?
- Purposes and basis of usage of data
- Who do we share your personal data with?
- Data Security
- Retention and storage of your personal data
- Changes to this Privacy Policy
- Third Party Links
- Your legal rights
- Contacting Us
Introduction
Thank you for choosing our wellness solution, Old Mutual Thrive. We (Old Mutual General Insurance Kenya as data controller) respect your privacy and we are committed to protecting your personal data and the sensitive personal data that you provide to us. This Privacy Policy describes how we collect, use, disclose, transfer, store or otherwise process your personal data and tells you about your privacy rights and how the law protects you regarding your use of Old Mutual Thrive and its Service. This Policy applies to all the products and services provided by Old Mutual Thrive, including applications, mini-programs, websites, SDK for third-party websites or applications, APIs and other forms that may be available in the future. For the full version of the Old Mutual Privacy Policy, please visit oldmutual.co.ke or contact us for a copy.
Personal data means any information relating to you as an identified or identifiable natural person. In order for us to provide the services you have requested from us; it is necessary that we collect and process personal data from you.
The types of personal data that we collect
For this product, we may collect and process additional personal data from you to provide scores and metrics you can use to track and improve your health. The types of data collected in order to provide this service include:
- Device Data: Device name, type, IMEI number, IP address
- Content Data: User Photo, Nickname
- Profile Data: Name, Age, Address, ID number
- Usage Data: Logins, information entries
- Marketing and Communications Data: Marketing Preferences
- Location Data: GPS information
- Health Data: steps, movement, diet, sleep, smoking and drinking information.
We also collect, use and share aggregated data such as statistical or demographic data for any purpose ("Aggregated Data"). Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific Mobile Application feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this Privacy Policy.
We may also collect, use, store, transfer or otherwise process personal data about you, in particular, information relevant to your insurance policy should you choose to purchase an insurance policy from us or if you wish to link your Thrive account with your insurance policy account.
How do we collect your personal data?
We will collect and process the following personal data about you:
Information that you give us
This is information (including Identity, Contact, and Marketing and Communications Data) that you consent to giving us about you by providing information through the social section, or by corresponding with us directly (for example, by email or chat) or through our third-party commercial partners. It includes information that you provide when you register to use Old Mutual Thrive, download My Old Mutual, subscribe to any of our Services, as defined below, or enter a competition, promotion or survey and when you report a problem with Old Mutual Thrive, or our Services. If you contact us, we will keep a record of that correspondence.
Information that we collect about you and your device
Each time you use Old Mutual Thrive we will automatically collect personal data including Device, Content and Usage Data. We collect this data using cookies and other similar technologies. Please see the section on cookies below for further details.
Location Data
We also use GPS technology to determine your current location. Some of our location-enabled Services require your personal data for the feature to work. If you wish to use the particular feature, you will be asked to consent to your data being used for this purpose. You can withdraw your consent at any time by disabling Location Data in your settings.
Information that we receive from your use of your device
We also collect personal data including Identity Data, Contact Data, Health Data, Location Data, Biometric Data; and through the use of the Mobile Application to provide a progress report, which contains your Old Mutual Thrive score, steps taken, calories burned, resting heart rate, sleep and distance covered. When your device syncs with our servers (including through background syncs on your Mobile Application), the forms of Data recorded on your device and transferred from your device to our servers are as follows:
- Device Data;
- Usage Data;
- Location Data;
- Health Data.
Information that we receive from other sources including third parties and publicly available sources
We will receive personal data about you from various third parties and public sources as set out below:
(i) Device Data, from the following parties:
(a) our Services through unique application numbers, when they are installed or updated;
(b) analytics providers, including Google and Apple that have operations globally;
(c) any other aggregator of wearables and fitness trackers.
(ii) Contact Data, from providers of technical and delivery services;
(iii) Identity and Contact Data, from data brokers or aggregators that may be based globally; and
(iv) Identity and Contact Data, from publicly available sources.
Cookies
We use cookies and/or other tracking technologies to distinguish you from other users of Old Mutual Thrive to remember your preferences. This helps us to provide you with a good experience when you use Old Mutual Thrive and allows us to improve Old Mutual Thrive.
Old Mutual generally uses such automatically collected information and data to estimate the audience size of the social section, gauge the popularity of various parts of the social section, track your usage/ traffic patterns and the number of sign-ups to the Old Mutual's promotional activities and special events and administer the social section.
The social section' server software will also record the domain name server address and track the pages you visit and store such information in cookies, and gather and store information such as internet protocol (IP) addresses, browser type, referring/exit pages, operating system, date/time stamp, and clickstream data in log files.
How do we use your personal data and what legal basis do we have for processing your personal data?
We use your personal data to provide you with access to Old Mutual Thrive and sometimes, our insurance services. In this regard, we rely on the following lawful basis for processing your personal data:In the event that you fail to provide us with your personal data when requested, we may not be able to perform the contract we have or that we wish to enter into with you. In that case, we may have to cancel a product or service you have with us. You have the right to withdraw your consent to our processing of your personal data at any time but please note, that your withdrawal will not affect the lawfulness of our processing of your personal data which was based on prior consent before your withdrawal or which is based on other legal basis for processing of your personal data. Please further note we may not be able to provide you with our products and services if you withdraw your consent.
• Performance of contract: Setting up an Old Mutual Thrive account for purposes of generating a wellness score and redeeming rewards based on your lifestyle and wellness habits such as walking, exercising, diet tracking. This wellness score may be used by a user for a potential contract of insurance.
The setting up and administering a contract of insurance by providing you with a quote based on your wellness score for the insurance policy, underwriting the risks to be insured or processing any claims that might be submitted under the policy;
• Legal and regulatory obligations: Compliance with our legal and regulatory obligations such as KYC obligations under different statutes including the Proceeds of Crime and Anti-Money Laundering Act (No.9 of 2009) and the Tax Procedures Act (No. 29 of 2015);
• Legitimate interests: for our legitimate business interests, including prevention and detection of fraud.
• Consent: We will also rely on your consent as a lawful basis for processing your personal data in the instances where we (a) process sensitive personal data outside Kenya; and (b) provide you with more information on our products and services.
Purposes and basis of usage of data
Purposes and basis of usage of data Purpose/activity: To install the My Old Mutual Application and register you as an Old Mutual Thrive user
Type of data used: Identity, Contact, Device
Lawful basis for processing: Contract
Purposes and basis of usage of data Purpose/activity: To verify your identity as you sign up for Old Mutual Thrive
Type of data used: National ID Number
Lawful basis for processing: Performance of a contract with you, necessary for our legitimate interest
Purposes and basis of usage of data Purpose/activity:
To deliver services to you, including but not limited to:
(i) the provision of a progress report, containing your Old Mutual Thrive Score and Old Mutual Thrive Mind Score, steps taken, calories burned, resting heart rate, sleep and distance covered, mental well-being self-assessments, and any challenges that present themselves;
(ii) member benefits in relation to your usage of Old Mutual Thrive;
(iii) a platform/forum for sharing insights and posting photos
(iv) a forum for posting advertisements, materials, messages, photos, views or comments or other information on Old Mutual Thrive;
(v) the opportunity to participate in special events hosted by the Old Mutual and Partners;
(vi) to generate a Diabetes Risk Score setting out an estimate of your statistical risk of diabetes and prediabetes and a Fiber/Fibre Score setting out an estimate of your daily fiber/fibre intake;
(vii) to enable you to track certain physiological and blood test data about yourself, including syncing such data with other health devices you are connected to such as wearables or other fitness trackers (such as mobile phones); and
(viii) to enable you to track and save the progress of various mental-health related exercises you participate in on the Platform Collectively (the “Services”)
Type of data used: Identity, contact, health, device, marketing and communications, location, biometric
Lawful basis for processing: Performance of a contract with you, necessary for our legitimate interests
Purposes and basis of usage of data Purpose/activity: To manage our relationship with you including notifying you of changes to the Old Mutual Thrive or any Services
Type of data used: Identity, contact
Lawful basis for processing: Performance of a contract with you
Purposes and basis of usage of data Purpose/activity:
To:
(i) administer and protect our business and the Old Mutual Thrive including troubleshooting, data analysis and system testing; and
(ii) to improve the accuracy of our risk profiling services to you
Type of data used: Identity, contact, device, health
Lawful basis for processing: Necessary for our legitimate interests (for running our business, provision and improvement of administration and IT services, network security)
Purposes and basis of usage of data Purpose/activity:
- To deliver relevant content, including newsletters, including stories / articles on well-being, health and fitness and advertisements to you
- To make recommendations, in the form of promotional materials or other formats, to you about goods or services which may interest you or enable you to avail of member benefits and also provide information on donations and contributions for charitable or non-profit making purposes that you may wish to make
- To measure and analyse the effectiveness of the advertising that we serve you
- To monitor trends so we can improve the Old Mutual Thrive
Type of data used: Identity, contact, device, content, profile, usage, marketing and communications, location
Lawful basis for processing: Your consent, necessary for our legitimate interests (to develop our products/Services and grow our business)
Old Mutual strives to collect only personal data which is necessary and adequate but not excessive in relation to the purposes set out above.
Old Mutual Thrive is not intended for children and we do not knowingly collect personal data relating to children.
If we require your personal data for a purpose other than those set out hereinabove, we shall request your prescribed consent to the same.
Old Mutual strives to collect only personal data which is necessary and adequate but not excessive in relation to the purposes set out above.
Old Mutual Thrive is not intended for children and we do not knowingly collect personal data relating to children.
If we require your personal data for a purpose other than those set out hereinabove, we shall request your prescribed consent to the same.
Who do we share your personal data with?
In connection with the above purposes, we may share your personal data with third parties located within and outside Kenya such as our affiliates, public authorities or governments when required by law, our third-party service providers who help us manage our products and services including those service providers who maintain our IT and office systems, provide commercial customer communications services, provide application processing, fraud monitoring, call center and/or other customer services. In that connection, we will take adequate steps to protect your personal data including entering into agreements with third party recipients of your personal data (as applicable) governing protection of personal data.
Old Mutual shall take all practicable steps to keep all of your personal data confidential and/or undisclosed other than in accordance with this Privacy Policy and the Privacy Policy.
Personal data collected via Old Mutual Thrive may be transferred, stored, and processed in any country in which Old Mutual operates. By using the Old Mutual Thrive, you agree to, consent to, and authorise the Old Mutual to disclose and/or transfer your personal data under the circumstances stated above, as well as to any transfer of your personal data outside of the country in which you are located.
Data security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. We have also put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
All personal data provided by you is only accessible by the authorised personnel of the Old Mutual or its authorised third parties, and such personnel shall be instructed to observe the terms of this Privacy Policy when accessing such personal data. You should safeguard your unique username and password by keeping them secret and confidential and by never sharing these details with anyone.
The Old Mutual follows generally accepted industry standards to protect the personal data submitted by you in Old Mutual Thrive, both during transmission and once Old Mutual receives it. However, no method of transmission over the internet, or method of electronic storage, is completely secure. Therefore, while the Old Mutual strives to protect your personal data against unauthorised access, Old Mutual cannot guarantee its absolute security.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator when we are legally required to do so.
Retention and storage of your personal data
We will only retain your personal data for as long as may be necessary to fulfil the purpose we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting obligations.
Below schedules show the various retention and disposal guidelines to be followed for the different types of records.
Changes to this Privacy Policy
Old Mutual reserves the right to update, revise, modify, or amend this Privacy Policy at any time it deems necessary. This version was last updated on 12th March 2024. It may change and if it does, these changes will be posted on this page and where appropriate, notified to you by email OR when you next start Old Mutual Thrive on My Old Mutual Mobile Application. The new policy may be displayed on-screen and you may be required to read and accept the changes to continue your use of Old Mutual Thrive.
It is important that the personal data that we hold about you is accurate and current. Please keep us informed if your personal data changes during our relationship with you.
Third Party Links
Old Mutual Thrive may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. Please note that these websites and any services that may be accessible through them have their own privacy policies and that the Company does not accept any responsibility or liability for these policies or for any personal data that may be collected through these websites or services. Please check these policies before you submit any personal data to these websites or use these services.
Your legal rights
You have the right to:
• be informed of the use to which your personal data is to be put as we have endeavoured to outline in this Privacy Policy and our Privacy Policy;
• request access to your personal data that we hold about you;
• object to the processing of all or part of your personal data;
• request correction of inaccurate, false or misleading data that we hold about you; and
• request deletion of false or misleading data that we hold about you.
Contacting Us
If you have any concerns about the use of your personal data, questions about this Privacy Policy or our Privacy Policy including any requests to exercise your legal rights under the law, please contact us using the details set out below:
Email address: oldmutualthrive@Oldmutual.co.ke
Postal address: PO Box 43013, 00100, Nairobi, Kenya
Physical address: Old Mutual Tower, Upper Hill Road, Upper Hill, Nairobi, Kenya
Telephone number: +254 711 065 100
We will respond to your questions or concerns in a timely manner and in compliance with the relevant laws.