Now Available: Active Cyber Insurance for Enterprises
Cyber Incident? Get Help

Global Privacy Policy

Coalition, together with its affiliates and subsidiaries, is a leading cyber insurance and security provider, empowering teams with the intelligence and protection needed to navigate the digital age. At Coalition, our mission is to protect the unprotected. We’ve engineered a privacy framework designed to uphold global standards for your data.  Our Privacy Policy (“Policy”) serves as the bedrock of our commitment to you. It outlines how we safeguard your information across our global operations, ensuring transparency, integrity, and security at every turn. Have questions? Our privacy team is here to help. Reach out to us anytime at privacy@coalitioninc.com. If you’re ready to exercise your privacy rights, we’ve made the process seamless and secure in accordance with global regulations. Just click here to do so.

I. Policy Application

This Policy applies to our websites and Platform (defined below), which facilitate communication regarding our company, products, and services. Information collected on our websites is used to provide access, maintain operations, enhance user experience, and personalize content delivery. Even if you visit our websites without logging into an account, we may still collect data related to your session. For detailed information on our data collection technologies and preference settings, please refer to our Cookies & Tracking Technologies Policy. This Policy also encompasses our cloud and online products and services, including Coalition Control(R), our risk management platform (the “Platform”). We collect usage data concerning these services, such as page views and user interactions, to optimize our offerings. Furthermore, this Policy applies to the scanning engine and security threat database we maintain for our threat detection services. This database may contain limited personal information related to individuals or actors involved in documented security incidents. Throughout this document, our websites, Platform, security threat database, and scanning engine are collectively referred to as the “Services.” Please note that our Services are directed towards our business customers and should not be used for personal, family, or household purposes.  As a result, we treat all personal information covered by this Policy as pertaining to individuals acting as a business representative, rather than in their personal capacity.  Coalition’s Services are not intended for, nor designed to attract, individuals under the age of majority in their jurisdiction of residence. Coalition does not knowingly collect personal information from any person who is under the age of majority in their jurisdiction of residence. If it comes to our attention through reliable means that a registered user is under the age of majority in their jurisdiction of residence, we will cancel that user’s account and/or access to our Services.

II. What Information Does Coalition Collect? 

When you use our Services, we may collect personal information that will help us provide those Services to you. Please see the table below for more information. 

Data Source

Data Categories

Specific Data Elements

Websites & Platform

Contact & Identity

Name, professional mailing address, email address, phone numbers (personal or professional), and password.

Occupational

Job title and other occupational information.

Company Information

Web address or domain name(s) of your organization.

Technical & Usage

Browser type/version, IP address, pages visited, date/time/duration of visit, diagnostic data, and cookie information.

User Content

Communications with Coalition, blog posts, comments, and user testimonials.

Insureds

Insurance History

Former insurance info, coverage held, and payment/claims history.

Claims & Incidents

Cyber incident details, compromised system information, and investigation data.

Service Activity

Number/frequency of logins and general interactions with Services.

Service Users

Financial/Billing

Preferred payment methods and billing/banking info (full credit card PANs are not stored).

Multimedia & Files

Photos, videos (with nicknames), spreadsheets, documents, and all uploaded files.

Interaction Content

Text, emails, chats, and comments created or received through the Platform or blog.

Security & Scanning

Public social network/torrent data and names/emails sharing a domain collected via automated scans.

Password Vaulting

Encrypted password codes for which Coalition does not have the encryption key.

Scanning Engine & Threats Database

Global Cyber Intelligence

Publicly accessible information about internet devices globally.

Targeted Data

Company names, domains, names of individuals, addresses, emails, passwords, and job titles.

Threat Monitoring

Data from honeypots and torrent activity related to network data sharing risks.

1. Coalition’s Chat Services

When using our Services, you may have the option to engage with chatbots such as CoalitionAI, or Broker and Security Copilots (each a “Copilot” and collectively, the “Copilots”), AI-powered education and chat features powered through third-party AI technology.

2. Copilot Framework

Category

Broker Copilot

Security Copilot

Target User

Appointed brokers in the U.S.

Businesses using Coalition Control

Core Function

Answers questions on cybersecurity best practices and policy coverage options.

Provides details on vulnerabilities, coverage contingencies, and issue resolution.

Training Data

Publicly-available Coalition documents and educational resources.

Integrated with cyber risk assessment and monitoring platform data.

3. Copilot Operations & Privacy Governance

Aspect

Details

Collected Data

— Usage Info: Activity, computer configuration, and performance metrics. — Log Info: IP addresses. — Tracking: Cookies and similar technologies (user-configurable).

Purpose of Use

To provide real-time responses, route inquiries to human reps, and prevent fraud/abuse.

Legal Basis

Processed based on legitimate interest in providing efficient educational responses.

Third-Party Processing

Powered by OpenAI; governed by a Data Processing Agreement (DPA).

Data Retention

Transcripts are retained for one (1) year, unless required longer for legal/client issues.

User Rights

Right to request transcript copies or deletion of conversation history via privacy@coalitioninc.com.

III. How Does Coalition Use the Information that it Collects?

Coalition uses the information that we collect for the following purposes:

Category

Processing Purposes

Service Delivery & Management

— Provide or fulfill Services to you. — Establish and verify your identity. — Handle and resolve billing transactions. — Activate, maintain, and service your account or insurance policy. — Develop, operate, maintain, and enhance the Services.

Communication & Support

— Send security alerts, support, and administrative messages. — Provide policy-related updates, billing notices, and confirmations of changes via mail or email. — Contact you by phone or email regarding late payments or factors affecting your policy.  — Respond to your questions, inquiries, comments, and instructions.

Marketing & Personalization

— Offer updates, notices, and promotional materials related to products, Services, or sales (where permissible by law). — Provide customized third-party advertisements and content. — Personalize Services by remembering information for future visits.

Analysis & Optimization

— Track and analyze de-identified data for third-party service providers. — Monitor and analyze the effectiveness of Services and third-party marketing. — Monitor aggregate Platform metrics such as total visitors and pages viewed.

Security & Incident Response

— Protect the rights, privacy, safety, or property of Coalition, you, or others. — Prevent, identify, and deter fraudulent, unauthorized, or illegal activity and cyberattacks. — Assist you and your employer in responding to a cyber incident. — Notify you of potential security vulnerabilities.

Legal & Compliance

— Comply with applicable laws, lawful requests, and legal processes (e.g., subpoenas). — Enforce applicable Terms of Use and contractual requirements. — Facilitate audits of internal processes for legal and policy compliance. — Investigate and defend legal claims.

General

— For other purposes to which you may consent. — As otherwise required or permitted by law.

1. What Information is Shared with Third Parties?

We will not use or disclose your personal information to non-affiliated third parties except as disclosed in this Policy. For a full list of our subprocessors, please visit Coalition Subprocessors.

Category

Entities Involved

Types of Information Shared

Purpose of Disclosure

Payment Processing

Stripe, Inc.

Name, email, billing address, transaction amount/date, and financial data (credit card/bank details).

To process payments, verify identity, prevent fraud, and comply with regulatory obligations.

Insurance Claims

Insurers, agents, law enforcement, courts, and government agencies.

Personal information relevant to a claim.

To process and investigate insurance claims.

Service Providers

Website hosts, developers, customer support, and marketing vendors.

Information necessary to complete specific business services.

Hosting, maintenance, transcription, billing, account management, and claims support.

Promotional Partners

Third-party promotional partners and app providers.

Name, company name, and business email address.

To facilitate promotional offers (only with affirmative consent) or for account creation in third-party apps.

Legal & Safety

Government agencies, courts, and outside legal parties.

Information reasonable or necessary to protect rights or comply with orders.

To comply with law, respond to subpoenas, defend against claims, and prevent illegal activity.

Business Transfers

Potential buyers, merger partners, or financing entities.

All collected user information, including personal data.

To facilitate a merger, acquisition, reorganization, or sale of assets.

External Parties (Anonymized)

Third-party analysts or researchers.

Aggregated and anonymized data (e.g., software vulnerability trends).

To report on cyber risks and statistics without identifying individuals.

Key Data Protection Standards

  • Financial Security: Coalition does not store full payment card details; all financial data is submitted directly to Stripe.

  • Vendor Accountability: Third-party providers are contractually required to maintain confidentiality, secure personal data, and comply with privacy laws.

  • Marketing Transparency: Identifiers are shared with promotional partners only if the user affirmatively consents to an offer.

  • Anonymization: Underwriting data used in public reports is stripped of personal identifiers to remain anonymous.

IV. How Does Coalition Protect Your Information? 

We take the security of your data seriously. We implement appropriate technical, physical, and administrative safeguards designed to protect your personal information from unauthorized access, loss, misuse, alteration, or destruction. However, please remember that no security system or internet transmission is ever 100% secure. While we do our absolute best to protect your data, we cannot guarantee its absolute security. Because of this, we recommend taking special care with the information you share with us, and minimizing the amount of sensitive personal data you send via email.

1. Breach Notification

In the unfortunate event of a confirmed data breach that impacts your personal information, we will notify you and the relevant regulatory authorities in accordance with our legal obligations under applicable local, state, federal, and international laws.

2. Contact Us

If you have reason to believe that your interaction with us is no longer secure, or that your personal data has been compromised, please contact us immediately:

V. Your Privacy Rights

Depending on where you live, you have specific rights regarding your personal information. These generally include the right to access, correct, update, or delete the data we hold about you. Please refer to the Section in this Policy entitled, “Specific Jurisdictional Notices”, for more information specific to jurisdictional privacy laws that may apply to you.

1. Exceptions to Your Rights

Please note that these rights are not absolute. In line with global privacy laws, we may legally decline or limit your request if fulfilling it would:

  • Violate the privacy or rights of another person.

  • Expose information that cannot be disclosed for legal, security, or confidential business reasons.

  • Involve information protected by legal privilege (such as solicitor-client or litigation privilege).

2. How to Exercise Your Rights

If you would like to make a request to exercise any of your rights, or if you have a privacy-related concern, please contact us using the details provided in the "Complaints and Contact Information" section below. We will respond to your request within the timeframes required by your local laws.

VI. How Long We Keep Your Personal Information

We only keep your personal information for as long as necessary to fulfill the purposes we collected it for, including providing our services, operating your account, and satisfying any legal, accounting, or reporting requirements.

1. How We Determine Retention Periods

To decide exactly how long to keep your data, we evaluate several key factors:

  • The nature of the data: The amount, type, and sensitivity of the personal information.

  • Risk assessment: The potential risk of harm from unauthorized use or exposure.

  • The purpose of processing: Why we need the data, and whether we can achieve those goals through other means.

  • Legal and business needs: Our ongoing legal obligations, statutory limitation periods, and legitimate business interests (such as defending or prosecuting legal claims, as outlined in the "How We Use Information" and "How We Share Information" Sections in this Policy).

Once your information is no longer required for these purposes, we will either securely delete it, permanently anonymize it, or, if deletion is not immediately possible (for example, because the data is stored in backup archives), securely store it and isolate it from any further processing.

VII. International Transfers of Personal Information

Coalition is a global company headquartered in the United States, and we work with service providers operating around the world. Because of this, your personal information may be transferred to, stored, or processed in the United States and other countries outside of your home country territory. Please note that while your data is in the United States, it may be subject to lawful access requests by U.S. government, courts, or law enforcement authorities pursuant to local U.S. laws. Please be aware that data protection laws vary by country. The laws in the places where your data is processed may not offer the same level of protection as those in your home country, and under local laws, your information may be accessible to law enforcement or regulatory authorities.

1. How We Protect Your Data Internationally

Whenever we transfer your personal information across borders, we take strict steps to ensure it receives a similar, high level of protection. This includes:

  • Contractual Safeguards: Using approved legal mechanisms, such as the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, to bind our global partners to strict data protection standards.

  • Vendor Vetting: Ensuring our international service providers maintain rigorous security measures to protect your data.

  • Assessments: Where personal information is transferred across borders, we conduct formal Privacy Impact Assessments (PIAs), Data Protection Impact Assessments (DPIAs) and Transfer Impact Assessments (TIAs) as applicable and necessary to ensure appropriate contractual, technical, and administrative safeguards are in place.

2. Questions About Global Transfers?

If you would like more information about our international data transfer practices or the specific safeguards we have in place, please contact us at privacy@coalitioninc.com or see the "Complaints and Contact Information" section below.

VIII. Specific Jurisdictional Notices

1. For Australian Residents 

To comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), this section outlines our data practices and your privacy rights under Australian law, as detailed below. A. Summary of Our Data Practices To keep this policy easy to read, we have detailed our data collection, use, and retention practices in the main sections of this Policy. You can quickly jump to them using the links below:

B. Your Rights under the Privacy Act and APPs You may access personal information about you that we hold and seek the correction of such information.  This is described in the section entitled, “Your Privacy Rights”.  Australian residents should note that under the Privacy Act there is no right to request the deletion of your personal information. You may complain about a perceived breach by us of the APPs.  This is detailed in the section of this Policy entitled, “Complaints and Contact Information”, along with how we handle such a complaint.  At all times, privacy complaints:

  • Will be treated seriously;

  • Will be dealt with promptly;

  • Will be dealt with in a confidential manner; and 

  • Will not affect your existing obligations or affect the commercial arrangements between you and us.

We will commence an investigation into your complaint.  You will be informed of the outcome of your complaint following completion of the investigation. C. Cross-Border Data Transfers and Storage Your personal information will be transferred, stored, and processed outside of your home province or territory, primarily in our offices and cloud-hosted data centers located in the United States. For more information, please refer to the Section in this Policy entitled, “International Transfers of Personal Information”.  Before disclosing any personal information to an overseas recipient, we take reasonable steps to ensure the overseas recipient complies with the APPs or is bound by a substantially similar privacy scheme unless you consent to the overseas disclosure or is required or permitted by law. D. Automated Decision-Making and Profiling As part of our underwriting and application workflows, we utilize automated decision-making (ADM) processes, including machine learning (ML), to analyze risk parameters, detect potential fraud patterns, and determine insurance premium pricing.  Initial assessments are made solely by technological means without human involvement or review. The logic involves comparing your provided risk criteria (e.g., previous claims history, identity validation, anti-money laundering indicators, and credit parameters) against industry risk averages (profiling) to evaluate fraud vulnerabilities and cumulative risk patterns. This automated processing is strictly necessary for entering into an insurance contract with us. The potential results of this ML component may be that your quote is declined at the initial phase or advanced for further assessment, which may include a human review.

2. For California Residents 

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you specific rights regarding your personal information. This section explains how we handle your data and how you can exercise your rights. A. Summary of Our Data Practices

To keep this policy easy to read, we have detailed our data collection, use, and retention practices in the main sections of this Policy. You can quickly jump to them using the links below:

B. Your CCPA Rights As a California resident, you have the right to request that we:

  • Know & Access: Provide details on the personal information we collect, use, and share about you.

  • Correct: Fix any inaccurate personal information we hold.

  • Delete: Erase your personal information (subject to certain legal exceptions).

  • Non-Discrimination: We will never discriminate or retaliate against you for exercising your privacy rights.

C. Using an Authorized Agent

You can designate an authorized agent to make these requests on your behalf. To protect your data, we will require the agent to provide written, signed proof of your permission, and we may still ask you to verify your identity with us directly. D. Opt-Out of Sale or Sharing (Do Not Sell or Share My Info) We do not sell your personal information for money. However, like many online companies, we use website tracking tools that may be considered "selling" or "sharing" under California law.

  • How to Opt-Out: You can opt-out of this digital tracking by broadcasting a browser-based opt-out signal, such as the Global Privacy Control (GPC).

  • Minors: We do not knowingly sell or share the personal information of anyone under 16 years old.

E. Sensitive Personal Information We only collect and use sensitive personal information for standard operational purposes that a consumer would reasonably expect (such as providing our services). Because we do not use this data for any secondary purposes, we do not need to offer a "Limit the Use of Sensitive Personal Information" option. F. How to Exercise Your Rights To submit a request or ask a question about your California privacy rights, please email us at privacy@coalitioninc.com or visit the "Complaints and Contact Information" section below.

3. For Canadian Residents 

This section provides mandatory supplemental disclosures to Canadian residents pursuant to the federal Personal Information Protection and Electronic Documents Act (PIPEDA), the Alberta Personal Information Protection Act (PIPA), the British Columbia PIPA, and Quebec’s Act respecting the protection of personal information in the private sector (Law 25). A. Accountability and Privacy Officer We have designated a Privacy Officer who is responsible for overseeing our compliance with Canadian privacy laws. If you have any questions, concerns, or requests regarding your personal information, you may contact our Privacy Officer/Responsable de la protection des renseignements personnels directly at: Name: Cara Thompson Title: Privacy Officer / Responsable de la protection des renseignements personnels Email: privacy@coalitioninc.com Address:  548 Market St #94729 San Francisco, California 94104-5401 USA B. Consent, Sensitivity, and Purpose Limiting We collect, use, and disclose your personal information strictly with your consent, or as otherwise permitted or required by applicable Canadian law.

  • Form of Consent: The form of consent we seek (express or implied) depends on the sensitivity of the data and your reasonable expectations. Because our Services involve underwriting, insurance applications, and cyber-incident response, we will typically seek express, explicit consent for processing sensitive commercial, technical, financial, or cyber-incident data.

  • Withdrawal of Consent: You have the right to withdraw or vary your consent at any time, subject to legal or contractual restrictions and reasonable notice. To do so, contact us at privacy@coalitioninc.com or through our form here. Please note that withdrawing consent may prevent us from providing you with our insurance products, platform access, or emergency services. If you opt out of marketing communications, we will still send you critical transaction, security, and administrative service messages.

C. Cross-Border Data Transfers and Storage Your personal data will be transferred, stored, and processed outside of your home province or territory, primarily in our offices and cloud-hosted data centers located in the United States. For more information, please refer to the Section in this Policy entitled, “International Transfers of Personal Information”. D. Automated Decision-Making and Profiling As part of our underwriting and application workflows, we utilize automated decision-making (ADM) processes, including machine learning (ML), to analyze risk parameters, detect potential fraud patterns, and determine insurance premium pricing.  The logic involves comparing your provided risk criteria (e.g., previous claims history, identity validation, anti-money laundering indicators, and credit parameters) against industry risk averages (profiling) to evaluate fraud vulnerabilities and cumulative risk patterns. This automated processing is strictly necessary for entering into an insurance contract with us. The potential results of this ML component may be that your quote is declined at the initial phase or advanced for further assessment, which may include a human review. If you are a resident of Quebec or another province with similar statutory protections, you have the right to be informed when a decision is made about you using purely automated processing. You have the right to request information regarding the personal data used to make the decision, the primary factors and logic that led to the result, and the right to have the decision reviewed by a human member of our underwriting team. You may exercise this right by contacting privacy@coalitioninc.com. E. Your Rights: Access, Correction, and Deletion You possess specific statutory rights regarding the personal information we hold about you:

  • Right to Access: You may request access to the personal information we hold about you and receive an account of how it has been used or disclosed. 

  • Right to Rectification: If you demonstrate that the personal information we hold about you is inaccurate, incomplete, or outdated, we will amend it immediately and notify relevant third parties to whom the inaccurate data was originally transmitted.

  • Right to Deletion (Erasure/Anonymization): You have the right to request that we delete or permanently anonymize your personal information when it is no longer required for the purposes for which it was collected, subject to our statutory records retention obligations under applicable Canadian insurance regulations.

F. Complaints and Regulatory Recourse

If you are unsatisfied with how we handle your personal information or a privacy request, we encourage you to contact our Privacy Officer first. You also have the absolute right to lodge a formal complaint with the appropriate privacy regulatory body in your jurisdiction. For more information, please refer to the Section in this Policy entitled, “Complaints and Contact Information”. 

4. For Data Subjects Located in the UK, EEA & Switzerland 

This section provides mandatory supplemental disclosures to data subjects residing in the European Economic Area (EEA), the United Kingdom (UK), and Switzerland (collectively, “Europe”), pursuant to the EU GDPR, the UK GDPR, and the Swiss Federal Act on Data Protection (“FADP”). A. Coalition Establishments in the EU and UK Coalition has a permanent establishment in the European Union through its European subsidiary, Coalition Insurance Solutions GmbH, which is registered and headquartered in Frankfurt, Germany. Coalition Risk Solutions Ltd is Coalition’s primary operating entity in the UK. It is an appointed representative of Davies MGA Services Limited, a firm authorised and regulated by the UK’s Financial Conduct Authority. B. Data Protection Officer  Coalition has appointed Cara Thompson as Data Protection Officer (DPO) pursuant to applicable privacy laws. Our DPO is registered with applicable data supervisory authorities and may be reached at privacy@coalitioninc.com. For further information, please refer to the Section of this Policy entitled, “Complaints and Contact Information”. C. Sources of Personal Data We collect personal data from the following categories of sources:

  • Directly from you or your employer during the insurance policy application, underwriting, or cyber-incident response processes;

  • Through your direct communications with us (emails, support tickets, calls);

  • Via your commercial transactions and usage history on our Platform and Services; and

  • From third-party social media networks and advertising partners via cookies and similar tracking technologies. D. Purposes and Legal Bases for Processing

Under data protection laws we must explicitly state the legal basis we rely upon to process your personal data. We process your data under the following lawful frameworks:

  • Performance of a Contract We process your personal data where it is necessary to enter into or perform a contract with you, including under our Terms of Use, to:

    • Provide, fulfill, and manage our Services, accounts, and insurance policies;

    • Verify your identity and process billing/premium transactions;

    • Deliver critical account communications, security alerts, and administrative updates; and

    • Deliver emergency cyber-incident response services to you or your employer.

  • Legitimate Interests We process personal data where it is necessary for our legitimate business interests (or those of a third party), provided your fundamental rights do not override those interests. These interests include:

    • Ensuring robust network, information, and system security;

    • Developing, optimizing, and enhancing our platform metrics, functionality, and services;

    • Personalizing your user experience and remembering your site preferences;

    • Pursuing, establishing, or defending legal claims; and

    • Conducting aggregate internal audits and business performance analytics.

  • Compliance with Legal Obligations We process personal data when required to comply with binding statutory and regulatory obligations, including:

    • Responding to lawful requests, subpoenas, or warrants from competent law enforcement and financial regulatory authorities; and

    • Maintaining corporate financial records and corporate transparency compliance.

  • Consent We rely on your explicit, freely given consent for:

    • Deploying non-essential cookies, tracking technologies, and customized behavioral advertising; and

    • Delivering direct electronic marketing materials, updates, and promotional communications. (Note: You have the right to withdraw your consent for these activities at any time by utilizing the "unsubscribe" links in our emails or by contacting us at privacy@coalitioninc.com. Withdrawal does not affect the lawfulness of processing carried out prior to your withdrawal.)

E. Special Categories of Personal Data and Criminal Offense Data To the extent that our underwriting processes or cyber-incident response services require us to handle special category data (e.g., biometric, health, or sensitive technical data that reveals sensitive attributes) or data relating to fraud/criminal convictions, we process such data strictly:

  • Pursuant to your explicit consent (Art. 9(2)(a) GDPR);

  • Where necessary for the establishment, exercise, or defense of legal claims (Art. 9(2)(f) GDPR); or

  • Where authorized under applicable UK, Member State, or Swiss law governing the insurance sector (e.g., Schedule 1 of the UK Data Protection Act 2018 for fraud prevention and underwriting).

If you fail to provide personal data required by law or necessary to perform a contract when requested, we may be unable to provide our Services or issue an insurance policy. F. International Data Transfers Coalition is headquartered in the United States, and your personal data will be transferred to, stored, and processed in the US. The data protection laws in the US may differ from those in your home jurisdiction. To ensure your personal data receives an adequate level of protection, we do not rely on "commercially reasonable" standardizations; instead, we implement formal legal safeguards for all European cross-border transfers. For more information, please refer to the Section in this Policy entitled, “International Transfers of Personal Information”. G. Automated Decision-Making (ADM) and Profiling  We utilize automated decision-making and machine learning (ML) models during the initial evaluation of insurance applications to assess risk, verify eligibility, and calculate customized premiums. This initial phase occurs solely through algorithmic processes without direct human review. The logic involves comparing your provided risk criteria (e.g., previous claims history, identity validation, anti-money laundering indicators, and credit parameters) against industry risk averages (profiling) to evaluate fraud vulnerabilities and cumulative risk patterns. This automated processing is strictly necessary for entering into an insurance contract with us (pursuant to Art. 22(2)(a) GDPR).  The potential results of this ML component may be that your quote is declined at the initial phase or advanced for further assessment, which may include a human review. Your Safeguards: If an automated assessment results in a quote being declined or heavily adjusted, you have the explicit right to contest the decision, express your point of view, and request human intervention and review by contacting our underwriting team at privacy@coalitioninc.com. H. Coalition Reinsurance Coalition Re acts as a reinsurance intermediary. In this capacity, we may process personal data to administer reinsurance agreements, support primary insurers with loss/risk metrics, execute mandatory sanctions screening, and prevent cumulative risk exposure. The primary insurer with whom you hold your policy remains the principal Data Controller for the overarching processing of your insurance policy. We advise you to review your primary insurer's privacy policy to fully understand their data handling practices. We process this reinsurance data under the legal bases of contractual necessity, regulatory compliance, and our legitimate interests in preventing systemic market wrongdoing. I. Your Statutory Rights If you are located in the EEA, the UK, or Switzerland, you possess the following statutory rights under applicable privacy laws:

  • Right of Access: Request a copy of the personal data we hold about you.

  • Right to Rectification: Request that we correct inaccurate or incomplete data.

  • Right to Erasure ("Right to be Forgotten"): Request deletion of your data, subject to exemptions where we must retain data to comply with legal, regulatory, or defensive claims obligations.

  • Right to Restriction: Request that we restrict the processing of your data under specific statutory conditions.

  • Right to Object: Object to the processing of your personal data when based on our legitimate interests. You have an absolute right to object to direct marketing at any time.

  • Right to Data Portability: Request the transfer of your data to you or a third party in a structured, commonly used, and machine-readable format.

To exercise any of these rights, please contact us at privacy@coalitioninc.com, or through our form here. If you believe our processing violates data protection laws, you have the right to lodge a complaint with a competent supervisory authority. For more information, please refer to the Section in this Policy entitled, “Complaints and Contact Information.”

IX. Complaints and Contact Information

Coalition is committed to safeguarding your personal data and ensuring transparent access to our privacy team. If you have any questions about this Privacy Policy, wish to exercise any of your statutory data protection rights, or would like to lodge a formal inquiry regarding our data handling practices, please contact our privacy team at privacy@coalitioninc.com or the local corporate affiliate assigned to your region in the Global Privacy Directory in Section B below.  Coalition will acknowledge receipt of your complaint within thirty (30) days of receiving it.  We will investigate the matter and keep you informed of its progress without undue delay.  We will also notify you for the final outcome of the investigation without undue delay.

A. Independent Regulatory Recourse

We appreciate the opportunity to resolve any privacy concerns directly with you. However, you maintain an absolute right to lodge a complaint with a data protection authority, supervisory authority, or independent dispute resolution body in your country or region. Below is the directory of competent regulators for each region in which we operate.

B. Global Privacy Directory

The following comprehensive chart consolidates Coalition's regional corporate contact details alongside their corresponding regulatory fallback authorities.

Jurisdiction

Local Corporate Entities & Contact Details

Regulatory Recourse/Privacy Commissioner

Australia

Coalition Insurance Solutions Pty Ltd Coalition Incident Response Pty Ltd  Level 18, 347 Kent Street Sydney, NSW 2000 Australia privacy@coalitioninc.com

Office of the Australian Information Commissioner (OAIC) Mailing Address: GPO Box 5288, Sydney NSW 2001 Telephone: 1300 363  Email: oaicintake@oaic.gov.au Website: www.oaic.gov.au Australian Financial Complaints Authority (AFCA) Mailing Address: Box 3, Melbourne VIC 3001 Telephone: 1800 931 678 Email: info@afca.org.au  Website: https://www.afca.org.au/make-a-complaint

Canada

Canada Insurance Solutions Canada Inc. 1600-925 West Georgia Street Vancouver BC V6C 3L2 Canada  Quebec Office: 1020 Rue Bouvier, Suite 400 Quebec, QC G2K 0K9 Canada 

privacy@coalitioninc.com Coalition Incident Response Canada Inc. 1600-925 West Georgia Street Vancouver BC V6C 3L2 Canada privacy@coalitioninc.com Coalition Claims Solutions Canada, Inc. 333 Bay Street, Suite 3400 Toronto, ON M5H 2S7 Canada  Quebec Office: 1020 Rue Bouvier, Suite 400 Quebec, QC G2K 0K9 Canada Privacy Officer:  Cara Thompson privacy@coalitioninc.com 

Federal: Office of the Privacy Commissioner of Canada (OPC) Mailing Address: 30 Victoria Street, Gatineau, QC K1A 1H3 Telephone: 1-800-282-1376 (Toll-free) or 819-994-5444 Email: The OPC does not accept official complaints or general inquiries via standard public email for security reasons. Online requests and statutory complaints must be submitted securely through the OPC Online Complaint Form. Website: www.priv.gc.ca Quebec: Commission d'accès à l'information du Québec (CAI) Montréal Office (Main Branch) - Mailing Address:  2045 Stanley Street, Suite 900, Montréal, QC H3A 2V4 Québec City Office- Mailing Address: 525 René-Lévesque Boulevard East, Suite 2.36, Québec, QC G1R 5S9 Telephone: 1-888-528-7741 (Toll-free) or 514-873-4196 (Montréal) Email: renseignements@cai.gouv.qc.ca Website: www.cai.gouv.qc.ca Alberta: Office of the Information and Privacy Commissioner of Alberta (OIPC) Mailing Address: #410, 9925 109 Street NW, Edmonton, AB T5K 2J8 Telephone: 1-888-878-4044 (Toll-free) or 780-422-6860 Email: generalinfo@oipc.ab.ca  Website: oipc.ab.ca British Columbia: Office of the Information and Privacy Commissioner for British Columbia (OIPC) Mailing Address: PO Box 9038, Stn. Prov. Govt., Victoria, BC V8W 9A4 Physical Location: 4th Floor, 947 Fort Street, Victoria, BC V8V 3K3 Telephone: 250-387-5629 (For toll-free calling within BC, dial Service BC at 1-800-663-7867 and request a transfer to the number listed). Email: info@oipc.bc.ca (For case filings or complex documentation: commissioner@oipc.bc.ca) Website: www.oipc.bc.ca

Denmark

Coalition Insurance Solutions GmbH Coalition Incident Response Germany GmbH (Denmark) Business Center Lyngby Lyngby Hovedgade 10C 2800 Lyngby Denmark Data Protection Officer:  Cara Thompson privacy@coalitioninc.com

If you want to complain to the Danish Data Protection Agency (“Datatilsynet”), the Datatilsynet recommends that you use this form because it helps them to provide the information they need to process your complaint. However, you are also welcome to complain by contacting them in another way. For instance, you may write to the following postal address, or contact them by telephone or email:

Carl Jacobsens Vej 35 2500 Valby Telephoning:  +33 19 32 00 Emailing: dt@datatilsynet.dk Website: https://www.datatilsynet.dk/

France

Coalition Insurance Solutions GmbH Coalition Incident Response Germany GmbH (France) 58 rue de la Victoire  75009 Paris Data Protection Officer:  Cara Thompson privacy@coalitioninc.com

Commission Nationale de l’Informatique et des Libertés (CNIL) Address: 3 Place de Fontenoy TSA 80715 75334 Paris Cedex 07 France Telephone (Main Switchboard): +33 (0)1 53 73 22 22 Website: * French: www.cnil.fr * English Version: www.cnil.fr/en

Germany

Coalition Insurance Solutions GmbH Coalition Incident Response Germany GmbH Thurn-und-Taxis-Platz 6 D-60313 Frankfurt, Germany Data Protection Officer: privacy@coalitioninc.com

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit Address: Postfach 3163 65021 Wiesbaden Germany Telephone: +49 (0)611 1408-0 Email: poststelle@datenschutz.hessen.de (For secure PGP encrypted emails, their public key can be found on their website). Website: datenschutz.hessen.de Secure Online Form: If you want to submit an inquiry or lodge an official privacy complaint securely without using unencrypted email, you can use their official Hessen Online Contact and Complaint Portal.

Gibraltar

Coalition Risk Solutions Ltd. Coalition Incident Response UK Ltd. 34-36 Lime Street London UK EC3M 7AT

Data Protection Officer: privacy@coalitioninc.com

Gibraltar Regulatory Authority Address: Office of the Data Protection Authority - Information Commissioner, Suite 603 Europort, Gibraltar Telephone: +350 20074636 Email: privacy@gra.gi Website: https://www.gra.gi/

The Bailiwick of Guernsey (Crown Dependency)

Coalition Risk Solutions Ltd. Coalition Incident Response UK Ltd.  34-36 Lime Street London UK EC3M 7AT Data Protection Officer:  Cara Thompson privacy@coalitioninc.com

Office of the Data Protection Authority Address: The Office of the Data Protection Authority, Block A, Lefebvre Court, Lefebvre Street, St Peter Port, GY1 2JP Telephone: +44 (0) 1481 742074 Email: info@odpa.gg Website: https://www.odpa.gg/

Isle of Man (Crown Dependency)

Coalition Risk Solutions Ltd. Coalition Incident Response UK Ltd.  34-36 Lime Street London UK EC3M 7AT Data Protection Officer:  Cara Thompson privacy@coalitioninc.com

Isle of Man Information Commissioner Address: Isle of Man Information Commissioner P.O. Box 69, Douglas, Isle of Man, IM99 1EQ   Telephone: +44 1624 693260 Email: ask@inforights.im Website: https://www.inforights.im/

The Bailiwick of Jersey (Crown Dependency)

Coalition Risk Solutions Ltd. Coalition Incident Response UK Ltd.  34-36 Lime Street London UK EC3M 7AT Data Protection Officer:  Cara Thompson privacy@coalitioninc.com

Jersey Office of the Information Commissioner Address: Jersey Office of the Information Commissioner, 2nd Floor 5 Castle Street, St. Helier Jersey JE2 3BT Telephone: +44 1534 716530 Email: enquiries@jerseyoic.org Website: https://jerseyoic.org/

Sweden

Coalition Insurance Solutions GmbH Coalition Incident Response Germany GmbH Thurn-und-Taxis-Platz 6 D-60313 Frankfurt, Germany Data Protection Officer: privacy@coalitioninc.com

Swedish Authority for Privacy Protection (“Integritetsskyddsmyndigheten”) Address: Integritetsskyddsmyndighete, Box 8114, 104 20 Stockholm, Sweden Telephone: +46 (0)8 657 61 00 Email: imy@imy.se Website: https://www.imy.se/en/about-us/contact-us/

United Kingdom

Coalition Risk Solutions Ltd. Coalition Incident Response UK Ltd. 34-36 Lime Street   London UK   EC3M 7AT Data Protection Officer: Cara Thompson  privacy@coalitioninc.com

Information Commissioner's Office (ICO) Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF,United Kingdom Telephone: 0303 123 1113  Welsh Language Line: 0330 414 6421 Email: casework@ico.org.uk (Note: For specific case filings or general queries where you prefer not to use the webform). Website: www.ico.org.uk Secure Online Complaints: The ICO strongly prefers that data subjects lodge official privacy complaints or record statutory data breaches using their secure guided ICO Complaint Portal. Live Chat: For quick inquiries, the ICO hosts an interactive Live Chat function directly on their main website, which is active Monday through Friday, 9:00 AM to 5:00 PM (UK time).

United Kingdom

Coalition Insurance Solutions, GmbH (Coalition Solutions) 34-36 Lime Street   London UK   EC3M 7AT Data Protection Officer: Cara Thompson  privacy@coalitioninc.com

Information Commissioner's Office (ICO) Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF,United Kingdom Telephone: 0303 123 1113  Welsh Language Line: 0330 414 6421 Email: casework@ico.org.uk (Note: For specific case filings or general queries where you prefer not to use the webform). Website: www.ico.org.uk Secure Online Complaints: The ICO strongly prefers that data subjects lodge official privacy complaints or record statutory data breaches using their secure guided ICO Complaint Portal. Live Chat: For quick inquiries, the ICO hosts an interactive Live Chat function directly on their main website, which is active Monday through Friday, 9:00 AM to 5:00 PM (UK time).

United States

Coalition, Inc. Coalition Incident Response, Inc. Coalition Insurance Solutions, Inc. Coalition Insurance Company Coalition Reinsurance Services, LLC 548 Market St #94729 San Francisco, California 94104-5401 USA privacy@coalitioninc.com

Federal Trade Commission (FTC) Address: 600 Pennsylvania Avenue, NW, Washington, DC 20580 Federal Trade Commission Consumer Response Center Phone: 1-877-FTC-HELP (1-877-382-4357) Websites: Main Agency Site: www.ftc.gov Data Breach/Privacy Complaint Intake: reportfraud.ftc.gov California Privacy Protection Agency (CPPA) Address: 400 R Street, Suite 350, Sacramento, CA 95811 California Privacy Protection Agency (CPPA) - CA.gov Telephone: (916) 572-2900 Website: cppa.ca.gov Secure Complaint Portal: privacy.ca.gov/submit-a-complaint California Department of Justice (Office of the Attorney General) Address: P.O. Box 944255, Sacramento, CA 94244-2550 Telephone: (800) 952-5225 Website: oag.ca.gov/privacy

X. Notification of Policy Changes 

We may make changes to this Policy from time to time to accommodate new Services, industry practices, regulatory requirements and other applicable purposes. We encourage you to review this Policy periodically to ensure that you understand how we collect, use and share information.