Skip to content

Privacy Policy

Niche Box Group Ltd is committed to protecting any personal details we hold about you, being clear on how and why they are used, and respecting your privacy in everything we do. We understand that your privacy is important to you and you care about how your personal data is used. This includes:

  • Customers
  • Suppliers
  • Employees
  • Any other individual/group we hold personal data about

We will only collect and use personal data in ways that are described here, and in a way that is consistent with our obligations and your rights under the law. Please read this Privacy Policy carefully and ensure that you understand it.

Niche Box Group Ltd outsources all scheme administration and claims administration to Rightpath Insurance Solutions Ltd. Rightpath Insurance Solutions Limited is registered in England under company number 06411430, registered address: New Century House, 17-21 New Century Road, Laindon, SS15 6AG, UK. The following websites are owned and operated by Rightpath Insurance Solutions Ltd, on behalf of Niche Box Group Ltd:


Definitions and interpretation

In this Policy the following terms shall have the following meanings:

  • “Cookie” means a small text file placed on your computer or device by our website when you visit certain parts of our website and/or when you use certain features of our website. Details of the Cookies used by our website are set out in Part 14 of this privacy policy.
  • “Cookie Law” means the relevant parts of the Privacy and Electronic Communications (EC Directive) Regulations 2003.

What is personal data?

Personal data is defined by the General Data Protection Regulation (EU Regulation 2016/679) (“GDPR”) as ‘any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier’.

Personal data is, in simpler terms, any information about you that enables you to be identified. Personal data covers obvious information such as your name and contact details, but it also covers less obvious information such as identification numbers, electronic location data, and other online identifiers.

What does this policy cover?

This privacy policy explains the following:

  • How do we use your personal data?
  • How it is collected?
  • How is it held?
  • How is it processed?
  • What are your rights under the law relating to your personal data?

This privacy policy also applies to your use of our website. Our website may contain links to other websites. Please note that we have no control over how your data is collected, stored, or used by other websites and we advise you to check the privacy policies of any such websites before providing any data to them.

What are my rights?

Under the GDPR, you have the following rights, which we will always work to uphold:

  • The right to be informed about our collection and use of your personal data. This privacy policy should tell you everything you need to know, but you can always contact us to find out more or to ask any questions.
  • The right to access the personal data we hold about you.
  • The right to have your personal data rectified if any of your personal data held by us is inaccurate or incomplete.
  • The right to be forgotten, i.e. the right to ask us to delete or otherwise dispose of any of your personal data that we have.
  • The right to restrict (i.e. prevent) the processing of your personal data.
  • The right to object to us using your personal data for particular purpose or purposes.
  • The right to data portability. This means that, if you have provided personal data to us directly, we are using it with your consent or for the performance of a contract, and that data is processed using automated means, you can ask us for a copy of that personal data to re-use with another service or business in many cases.

For more information about our use of your personal data or exercising your rights as outlined above, please contact us.

Further information about your rights can also be obtained from the Information Commissioner’s Office (ICO) or your local Citizens Advice Bureau. If you have any cause for complaint about our use of your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office.

What data do we collect?

We may collect some or all of the following personal data and non-personal data (please also see our cookie policy) The data collected will depend on the type of service we are providing:

  • When purchasing a new policy or looking to obtain a quote this may include, but is not limited to your name, address, email, phone number or date of birth.
  • Payment information in order to process your quotation.
  • When making a claim this may include, but is not limited to your name, address, email, phone number, date of birth, claims and insurance information and/or health information,
  • When visiting our website we record your IP address, when you visited, which pages visited, plus information regarding your device, operating system and browser. This is commonly gathered data by websites utilizing tools such as cookies and web beacons.

All data collected when applying for a Niche Box Group Ltd Insurance product or service will be used to help benefit you and tailor any communications with you. We will also only offer you products and services with which you may be interested in, subject to you choosing to receive marketing.

How do you use my personal data?

Under the GDPR, we must always have a lawful basis for using personal data. This may be because the data is necessary for our performance of a contract with you, because you have consented to our use of your personal data, or because it is in our legitimate business interests to use it. Your personal data may be used for the following purposes:

  • Provide you with a quote, automated decision by evaluating risk and matching you with the appropriate policy and premium.
  • Administer and service your policy.
  • Provide you with insurance and fulfil any contractual obligations.
  • Assess and administer any claims that you make under your policy with us including requesting your feedback on our performance.
  • Process any insurance renewal.

Who do we share your information with?

With any information collected, we do not sell this to anyone. Information may be shared with trusted partners, service providers and regulators such as marketing agencies, web hosts, subsidiary companies who provide a service, regulatory bodies, courts, law enforcement agencies or partner companies who will handle complaints, queries or claims.

How long will you keep my personal data?

We will only keep your personal information for as long as reasonably necessary to fulfil the relevant purposes set out in this privacy policy and in order to comply with our legal and regulatory obligations. The time period we retain your personal information for will differ depending on the nature of the personal information and what we do with it. How long we keep personal information is primarily determined by our regulatory obligations. We typically keep policy and claims records for up to 10 years from the end of our relationship with you. In some cases, such as if there is a dispute or a legal action we may be required to keep personal information for longer.

Sub Processors & Third Party Policies

Below is a list of sub-processors we utilise in order to carry out our services;

Sub Processor Type of Data Shared Reason
ATICS Claim data Cloud service provider
Amazon Web Services Claim documents, Cookies and website data. Secure file storage and cloud services provider. Also used to host Nichebox domains and DNS records.
Google Ads Customer email addresses Marketing, advertising and business development
Office 365 Internal company data Emails and team collaboration
HSBC Net Payment details (bank account number/sort code and name of beneficiary) Payment processing
Stripe Payment details (bank account number/sort code and name of beneficiary) Allows us to make and receive payments.
Ideal Postcodes Customer address Autocompletes address details based on input of postcode during claim set up and policy sale.
Loqate Account number and sort code Validates bank account information and returns name of bank. Used for collecting payment details in order to make claim payments.
Rightpath Solutions Ltd. Personal data (claimants and employees), claimant's health information, claimant's insurance data. Group level network, telecomms, claim systems and system administration, compliance, security, marketing. Claims services.

Third Party Privacy Policies:

Contacting us about your data

You can request any personal details Niche Box Group Ltd holds about you at any time or if you’d like to contact us regarding your data. Our current Data Protection Officer is:

Data Protection Officer: Matthew Tomkins
Post: PO Box 6430, Basildon SS14 0QT, UK
Policy Documents
Browse important policy documentation. You can view documents in your web browser or download them to your computer.