
Privacy Promise
Prudential HCL Health Insurance Limited ("Company", "we", "us", "our") takes the privacy and protection of your personal information seriously.
So, we have set out below information about our processing of your personal information in connection with our provision of products/services to you or when you otherwise interact with us, what rights you have, and how you can get in touch if you want to know more.
For the purpose of applicable data protection laws, the data controller/data fiduciary of your personal information is Prudential HCL Health Insurance Limited located at Suite 6, 48th Floor, Commerz III, International Business Park, Oberoi Garden City, Off Western Express Highway, Goregaon (East) Mumbai - 400063.
If you have any questions about anything in this Privacy Notice, or want to exercise any rights you may have, our contact information can be found in the section Contact Us.
For the purposes of this notice, "personal data" means any data about you by which you can be identified, such as your name, date of birth, and contact details. A detailed list of personal data is set out in Part A below.
We process your personal data only for lawful purposes, including where such processing is necessary to provide you with the product or service you have requested, for complying with applicable legal obligations, for purposes of our legitimate uses as permitted under applicable law, or where you have provided your consent, as required.
Where the provision of certain personal data is necessary for the delivery of our products and/or services, failure to provide such personal data may result in our inability to offer or continue to provide those products and/or services.
Submitting information, using our website or app, applying for a policy, signing up for a service, or acknowledging this Privacy Notice does not by itself mean that you have given consent for every processing activity described here.
Where we rely on your consent, we will ask for it in a manner that is free, specific, informed, unconditional and unambiguous, and through clear affirmative action.
Some processing may also be carried out where you voluntarily provide personal data for a specified purpose or where the processing is otherwise permitted as legitimate use under applicable law.
You acknowledge and agree that Company may, from time to time, amend and update this Privacy Notice in order to ensure it is consistent with future developments, industry trends and/or any changes in legal or regulatory requirements.
We encourage you to check our Privacy Notice from time to time on our website, as the version of our Privacy Notice which is displayed on our website takes precedence over all previous versions of our Privacy Notice.
We will also notify you of changes in accordance with relevant legal requirements.
This Privacy Notice should be read together with any product terms, proposal form, consent request, policy document, cookie preference notice, app notice, website notice or other notice that we may provide to you at the point of collection.
If there is any inconsistency, the more specific notice or consent request for the relevant processing activity will apply to that activity.
PART A – PERSONAL INFORMATION WE MAY PROCESS
| S.No. | Category | Personal Information Processed | Examples / Notes |
|---|---|---|---|
| 1 | Personal contact information | Personal and contact details | Title; full name; contact details such as personal and work email address, phone number, residential address; emergency contact information; contact details history |
| 2 | Government identifiers | Proof of identity and address | Aadhaar, PAN, passport, driving licence, birth certificate or other government-issued identifiers, where required or permitted. Aadhaar-related collection, authentication or offline verification will be carried out only in accordance with applicable Aadhaar laws, with appropriate notice, consent where required, alternative verification methods where applicable, and security safeguards. Aadhaar will not be treated as mandatory unless required or permitted under applicable law or the relevant regulatory process. |
| 3 | Age and gender | Date of birth, gender and/or age | Date of birth; gender; age |
| 4 | Nationality | Nationality and residential status | Nationality; residential status |
| 6 | Family and dependent information | Family, marital and dependent information | Family member names; marital status; family, lifestyle or social circumstances such as number of dependents or widow/widower status, if relevant to the product or service |
| 7 | Correspondence information | Records of contact with us | Phone records via customer service centre; proposal number; client number; online services or smartphone app details such as mobile phone location data, IP address and MAC address |
| 8 | Product information | Products and services held or of interest | Products and services held with us; products and services you have been interested in or have held; associated payment methods used |
| 9 | Usage and claims information | Product/service usage and claims information | Usage of products and services; claims; whether claims were paid out or not; related claim details; client number; claims number; policy number |
| 10 | Browser information | Browser and device-related information | Geolocation; website history; browsing time; masterID; IP address; cookie information |
| 11 | Social information | Social media information | Social media account; social media contact; social media history |
| 12 | Analytics information | Marketing analytics data | Analysis of data relating to marketing made to you, including communication history and whether you open messages or click links |
| 13 | Information related to marketing | Use of products or services held with Marketing Partners | Insurance policies; mortgage; savings or financial services and products |
| 14 | Third party claims information | Information obtained from third parties about claims and risk | Insurance risk; pricing; claims history; instances of suspect fraud; usage history |
| 15 | Third party insurance information | Insurance information obtained from third parties | Insurance policy information, including where consented |
| 16 | Health information | Health and medical information | Height; weight; ABHA number; other health and medical information |
| 17 | Financial details | Financial and policy-related information | Transaction and payment information; policy-related information; bank account information; tax information |
| 18 | Education and employment information | Education and employment-related information | Employment status; occupation; educational degrees; salary-related information such as salary range |
| 19 | Profiling information | Insights gained from analysis or profiling | Insights about you and our customers gained from analysis or profiling of customers |
| 20 | Third party transactions information | Information about another person using the service | Where a person other than the account holder uses the service, information about that person and the transaction |
PART B – Where we get your personal information
We’ll collect personal information from the following general sources:
- From you directly, your family members, associates, or beneficiaries of products and services, and, with your consent where required, from third parties (including other insurers, financial institutions, and banks) in connection with fact-finding and verification activities relating to you, and information generated about you when you use our products and services.
- When you submit an application or registration form, or any other forms relating to any products and services offered and/or distributed by us.
- When a proposer submits a proposal for insurance intending to cover you.
- When you enter into any agreement or provide other documentation or information in respect of your interactions and transactions with us, or when you use our services.
- When you interact with our customer service officers, representatives, agents or appointed service providers (for example, via telephone calls, letters, face-to-face meetings, social media platforms, surveys, workshops and/or e-mails).
- When you use our electronic services, or interact with us via mobile services, social media accounts, digital platforms, any of our websites or web services.
- When you request us to contact you (whether pursuant to a request for more information, complaints, or any other purposes).
- From other intermediaries (for example, distributors, Business Partners) who we work with to provide products or services or quote to you.
- From Prudential Group if you already have a product or service with them, have applied for one, have held one previously, or for any other lawful purposes.
- From cookies, location services, and IP addresses when you visit our website or mobile app.
- When your images are captured by us via CCTV cameras while you are within any of our premises, or via photographs or videos taken by us, our representatives, or our agents when you attend our events.
- When we receive references from our Business Partners or third parties (for example, where you have been referred by them).
- When we receive information from third parties about you when you make payment through channels including, but not limited to, physical and digital payment kiosks.
- When we seek information from third parties about you in connection with the products and services you have applied for, including but not limited to information from other insurers, insurance associations, healthcare institutions, clinics, investigators, former employers, and relevant authorities.
- When you submit your personal data to us for any other reason.
- From other publicly available sources where relevant and appropriate.
PART C – Cookie Policy
This Cookie Policy describes how we use cookies and other similar technologies such as pixels, web beacons, scripts and tags in connection with our website and our products / services.
We use cookies for various purposes, including to distinguish you from other users of our website and gain insight on your interaction with content on our website. This helps us to provide you with a good experience when you use our website and also allows us to improve our website. A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer. You have the ability to accept or decline cookies by modifying the setting in your browser. If you would like to do this, please see the help menu of your browser.
We use both first-party and third-party cookies.
- First party cookies are cookies placed by us directly when you visit our website and use our services.
- Third party cookies are cookies set by third parties (e.g. analytics providers, advertisers and business partners).
Cookies are broadly categorized as follows:
- Strictly necessary cookies: These are cookies that are essential to the functioning and the operation of our website / provision of our services. They include, for example, cookies that enable you to log into our secure website;
- Analytical/performance cookies: These allow us to recognise and count the number of visitors to our website and to see how visitors move around our website when they are using it. This helps us to improve the way our website works, for example, by ensuring that users are finding what they are looking for easily;
- Functionality cookies: These are used to recognise you when you return to our website. This enables us to personalise our content for you, greet you by name and remember your preferences (for example, your choice of language or region).
- Marketing cookies: These cookies are used to learn more about your interaction with content on our website to deliver relevant advertising to you. These cookies remember what you have looked at on our website and we may share this information with our Business Partners.
Consent: By continuing to use our website, you agree to our use of cookies. You can manage or disable cookies at any time through your browser settings.
PART D – How we use your personal information and why
This section identifies the personal information we collect from you and the purposes of processing. It also identifies the legal basis under which we process your personal information (where applicable under data protection laws). To the extent the data protection laws in your jurisdiction do not recognize legitimate use (as defined under Digital Personal Data Protection Act,2023) or another legal basis specified in the table below for a particular purpose, you consent to our processing of your personal information by consenting and acknowledging this Privacy Notice.
Customer data we process
| S.No. | When we use your information | Personal information we may use | Why we use it | Legal basis / why permitted legitimate use applies |
|---|---|---|---|---|
| 1 | When you ask for a quote, enquire about our products or request information | Your name, contact details, age, location and preferences. | To respond to your enquiry, explain suitable health insurance products and provide the information or quote you requested. | Permitted legitimate use: you give these details to receive a quote or response. Consent is sought for marketing where required. |
| 2 | When you apply for a policy | Identity and contact details, proposal form details, family or nominee details, financial information, health declarations and medical history. | To receive and assess your application, evaluate eligibility, suggest suitable policy options and decide whether we can offer cover. | Permitted legitimate use: you submit the application for assessment. Consent is sought for health/medical or additional processing where required. |
| 3 | When we verify your identity and complete KYC, AML or fraud checks | Government identifiers such as PAN, Aadhaar where permitted, passport or driving licence, address proof, bank details and verification records. | To verify your identity, complete regulatory checks, prevent misuse and comply with legal or regulatory requirements. | Permitted legitimate use/legal compliance: identity checks are needed to verify you, prevent misuse and meet KYC/AML obligations. |
| 4 | When a pre-policy medical examination or tele-medical evaluation is needed | Health vitals, lab reports, doctor notes, tele-medical recordings and related medical evaluation records. | To arrange medical examinations, verify health information and support underwriting decisions. | Consent + permitted legitimate use: medical checks are needed to assess the application you submit. |
| 5 | When we underwrite, price or assess risk | Application details, health information, past claims, risk indicators, relevant industry data and risk scores. | To assess risk and decide coverage, premium, exclusions, waiting periods or other policy terms. | Permitted legitimate use: underwriting is needed to decide cover, premium and policy terms. Consent/notice applies for health data, profiling or automated support where required. |
| 6 | When you pay premiums or we process refunds | Payment details, e-mandate information, premium history, transaction records, bank account details and tax information. | To collect premiums, set up mandates, reconcile payments, process refunds and maintain financial records. | Permitted legitimate use/legal compliance: payment data is needed to collect premiums, process refunds and maintain statutory financial records. |
| 7 | When we issue, activate and service your policy | Policy number, coverage details, policy documents, preferences, communication history and service request records. | To issue policy documents, activate benefits, maintain your policy, process changes and send service communications. | Permitted legitimate use: policy data is needed to issue, activate and service your policy. Legal compliance applies to required records/disclosures. |
| 8 | When you renew, port or change your policy | Current policy details, claim history, portability request details, additional health information where required and correspondence. | To renew coverage, process portability requests, update policy terms and communicate renewal or portability options. | Permitted legitimate use: renewal/portability data is needed to act on your request. Consent applies for optional campaigns or new health data where required. |
| 9 | When you make a claim or request pre-authorisation | Claim forms, hospital and TPA records, bills, prescriptions, diagnostic reports, medical records, investigation findings and payment details. | To process, verify, investigate, approve, reject or settle claims and related payments. | Permitted legitimate use/legal compliance: claim data is needed to verify, process and settle claims. Consent applies for medical/third-party collection where required. |
| 10 | When you raise a complaint, grievance or appeal | Complaint details, policy or claim references, emails, letters, call records and supporting documents. | To respond to complaints, handle claims appeals and manage regulatory, ombudsman or legal escalations. | Permitted legitimate use/legal compliance: complaint data is needed to resolve your grievance and handle regulator/ombudsman escalation. |
| 11 | When we share risk with reinsurers, co-insurers or insurance partners | Limited policy details, risk summaries, claims summaries and other information necessary for risk sharing. | To arrange reinsurance, co-insurance or other risk sharing and manage insurance operations. | Permitted legitimate use: limited sharing is needed for reinsurance/co-insurance and risk management. Legal compliance applies where required. |
| 12 | When we coordinate with hospitals, TPAs and healthcare providers | Pre-authorisation details, provider interactions, treatment and claim information, verification data and supporting medical records. | To manage hospital networks, process cashless treatment or reimbursement claims and verify treatment or provider information. | Permitted legitimate use: provider/TPA exchanges are needed for servicing, pre-authorisation and claims. Consent applies for health data where required. |
| 13 | When you opt in to wellness, tele-consultation or value-added health services | Wellness data, steps or vitals, consultation notes, service usage records and consent records. | To provide optional wellness, preventive health, tele-consultation or value-added services you choose to use. | Consent: wellness and value-added health services are optional and used only when you opt in. |
| 14 | When you contact us or participate in surveys | Call recordings, transcripts, emails, chat records, feedback, survey responses and service interaction history. | To respond to your requests, improve service quality, train our teams and maintain service records. | Permitted legitimate use: interaction records are needed to respond, improve service and maintain evidence. Consent/notice applies for recording, surveys or marketing where required. |
| 15 | When we detect, prevent or investigate fraud or misuse | Fraud risk indicators, alerts, policy and claim links, claims trends, investigation records and relevant industry fraud information. | To protect customers, detect suspicious claims or misuse, investigate fraud and maintain the integrity of insurance services. | Permitted legitimate use/legal compliance: fraud checks are needed to protect customers, verify claims and prevent misuse. |
| 16 | When we report to regulators, respond to audits or comply with law | Policy and claim summaries, financial records, AML reports, audit records, regulatory submissions and correspondence. | To meet legal, regulatory, audit, tax, accounting and reporting obligations. | Legal compliance: disclosures and records are needed to meet regulatory, audit, tax, accounting and reporting obligations. |
| 17 | When we secure our systems and digital channels | Security logs, login and access records, device and system activity, incident details and breach investigation records. | To monitor security, investigate alerts, protect our digital channels and notify affected persons or authorities where required. | Legal obligation/permitted legitimate use: security logs are needed to protect systems, investigate incidents and notify breaches. |
| 18 | When we keep records accurate and manage retention or deletion | Correction requests, update records, policy records, retention schedules, deletion logs and proof of deletion. | To keep your information accurate, update or correct records, retain information only as needed and securely delete or archive it when appropriate. | Legal obligation/permitted legitimate use: records are needed for accuracy, retention, deletion and data-rights handling. |
| 19 | When you use our website, app, cookies or tracking technologies | Device details, cookie identifiers, IP address, website or app usage, browser information, geolocation where enabled and preference records. | To operate and secure our website or app, remember preferences, improve performance, understand usage and support analytics or marketing where consented. | Permitted legitimate use: essential cookies run and secure the site/app. Consent applies for non-essential analytics or marketing cookies. |
| 20 | When you create or use a digital account | Account details, login information, OTP records, session details, authentication logs, device information and security records. | To create and manage online accounts, authenticate logins, protect your account and prevent unauthorised access or misuse. | Permitted legitimate use: account and login data is needed to authenticate you and protect your account. |
| 21 | When you choose to receive communications through WhatsApp or similar channels | Mobile number, WhatsApp identifiers, communication preferences and records of messages sent or received. | To send service, transactional or permitted marketing communications through your chosen channel. | Permitted legitimate use: channel data is needed for service messages through the channel you choose. Consent applies for WhatsApp/marketing where required. |
| 22 | When we monitor portfolio performance, loss ratios or pricing patterns | Proposal, underwriting and policy data such as age, gender, sum insured, income, education, occupation, location, pre-existing disease information and health parameters such as BP or HbA1C, where relevant. | To monitor loss ratios, identify unusual patterns, improve underwriting models and support pricing or repricing exercises. | Permitted legitimate use: portfolio analytics supports pricing, risk control and insurance operations. Consent/notice applies for identifiable profiling or decisions affecting you. |
| 23 | When we work with banks, partners or digital ecosystems for insurance offers | Demographic, geographic, behavioural, app or partner ecosystem data, which may be anonymised, aggregated or used at cohort level, and identifiable information where lawfully shared. | To identify relevant customer groups and run agreed health-insurance offers or journeys with partners. | Permitted legitimate use: partner data supports insurance offers in journeys you engage with. Consent applies for identifiable sharing or targeted secondary use. |
| 24 | When we provide quotations for corporate, MSME, SME or group health insurance | Employer and employee information required for group quotation, such as employee demographics, coverage-related information and relevant dependent or member details. | To prepare quotations, assess group risk and support corporate, MSME, SME or group health insurance proposals. | Permitted legitimate use: employee/member data is needed to prepare requested group or corporate quotations. Extra notice/consent may apply depending on collection route. |
| 25 | When you interact with conversational AI or chatbot services, including WhatsApp-based support | Customer identifiers, mobile number, conversation content, policy or service references and other information you share during the interaction. | To support conversational customer service, policy assistance, servicing requests and related interactions over WhatsApp or similar channels. | Permitted legitimate use: chatbot data is needed to answer your service request. Consent/notice applies for optional channels or cross-border processing where required. |
| 26 | When you use our website, app or end-to-end digital journeys | Account details, device details, journey data, proposal data, policy data, authentication records and related digital interaction records. | To operate digital journeys for quotes, proposals, policy servicing, renewals, claims, grievances and other customer interactions. | Permitted legitimate use: digital journey data is needed to provide quote, proposal, servicing, renewal, claim and grievance journeys. |
| 27 | When we use AI or automated tools to support claims, service or operations | Information required for the relevant use case, which may include claims data, service interaction data, policy references, conversation data, workflow data and fraud or anomaly indicators. | To support claims processing, customer assistance, workflow automation, service quality, anomaly detection and other identified AI-enabled use cases. | Permitted legitimate use: AI support is used to assist service, claims and operations. Consent/transparency applies where profiling or automated support may affect you. |
| 28 | When we communicate with you across the policy lifecycle | Name, mobile number, email, address, proposal number, policy number, coverage details, premium, tenure, underwriting status, service requests, claim status, renewal or portability details, communication preferences and communication logs. | To send quote, proposal, underwriting, policy issuance, servicing, renewal, portability, claims, grievance and other service-related communications. | Permitted legitimate use: communication data is needed for service updates across the policy lifecycle. Consent applies for promotional messages or optional channels. |
Agent data we process
| S.No. | When we process your information | Types of Personal Data | Why we use it | Legal Basis |
|---|---|---|---|---|
| 1 | When you apply to become an insurance agent or intermediary associated with us | Name, photograph, date of birth, contact details, address, educational qualifications, PAN, Aadhaar or other identity documents, employment history, references and CV/resume details | To assess your application, verify eligibility, conduct evaluations and determine whether to engage or appoint you as an agent | Falls under permitted legitimate use for evaluating and responding to your application, and legal/regulatory compliance where required |
| 2 | When we conduct identity verification, KYC, due diligence and background checks | Identity documents, address proof, PAN, Aadhaar (where permitted), photograph, regulatory registration details, declarations, screening results and verification records | To verify your identity, prevent fraud, assess suitability, comply with regulatory requirements and protect our customers and business | Falls under legal/regulatory compliance and permitted legitimate use for fraud prevention, due diligence and risk management |
| 3 | When we register, appoint or onboard you as an agent | Agent code, licensing details, agreement records, appointment records, digital signatures, contact information and onboarding documentation | To establish our relationship with you, create agent records, register you with regulators where required and manage your appointment | Falls under contractual necessity, legal/regulatory compliance and permitted legitimate use for agent administration |
| 4 | When we provide training, assessments, examinations and certifications | Training records, attendance data, examination results, certification details, competency assessments and learning management system records | To train, certify and assess agents and maintain required competency standards | Falls under legal/regulatory compliance and permitted legitimate use for training and agent development |
| 5 | When we provide access to our systems, portals and digital platforms | Login credentials, usernames, authentication records, IP addresses, device information, access logs and user activity records | To create and manage accounts, provide secure access and protect our systems and information assets | Falls under permitted legitimate use and legal obligations relating to information security and system administration |
| 6 | When we allocate leads, manage sales activities and support customer acquisition | Agent identifiers, sales allocations, lead management records, customer interaction records, communication logs and business activity information | To manage business development activities, allocate leads, support customer engagement and monitor sales performance | Falls under permitted legitimate use for managing insurance distribution activities |
| 7 | When you solicit insurance business, assist customers or submit proposals | Agent code, licensing information, sales records, proposal sourcing information, interaction history and customer servicing records linked to you | To process proposals, issue policies, monitor sourcing activity and administer insurance operations | Falls under contractual necessity, legal/regulatory compliance and permitted legitimate use for insurance operations |
| 8 | When we calculate commissions, incentives and process payments | Bank account details, PAN, GST details (where applicable), commission records, payment history, incentive information and tax records | To calculate earnings, process payments, administer incentives and comply with tax and accounting requirements | Falls under contractual necessity and legal/regulatory compliance for tax, accounting and financial reporting |
| 9 | When we assess performance and business quality | Sales performance metrics, persistency information, productivity measures, quality scores, targets, achievements and customer feedback relating to agent performance | To measure performance, administer incentives, improve service quality and support business planning | Falls under permitted legitimate use for performance management and business operations |
| 10 | When we monitor compliance with legal, regulatory and internal requirements | Audit records, compliance findings, licensing information, call monitoring records, investigation reports, declarations and surveillance records | To monitor compliance, investigate misconduct, prevent mis-selling and meet regulatory obligations | Falls under legal/regulatory compliance and permitted legitimate use for risk management and governance |
| 11 | When we record or monitor calls and communications | Voice recordings, call transcripts, chat messages, emails, communication logs and quality review records | To monitor service quality, investigate complaints, provide training and maintain records of communications | Falls under permitted legitimate use for quality assurance and legal/regulatory compliance where applicable |
| 12 | When we prevent, detect or investigate fraud, misconduct or security incidents | Investigation records, access logs, device information, fraud indicators, complaint records, surveillance outputs and audit trails | To protect customers, prevent fraud, investigate misconduct and maintain the integrity of insurance operations | Falls under permitted legitimate use and legal/regulatory compliance for fraud prevention and security |
| 13 | When we communicate with you, conduct events or administer engagement programmes | Contact details, communication preferences, event participation records, photographs, videos and recognition programme records | To communicate with you, manage events, administer incentive programmes and support agent engagement activities | Falls under permitted legitimate use and consent where required for optional activities |
| 14 | When we handle grievances, complaints, whistleblowing reports or investigations involving you | Complaint records, investigation materials, correspondence, statements, disciplinary records and supporting evidence | To investigate matters, resolve disputes and take appropriate corrective or disciplinary action | Falls under legal/regulatory compliance and permitted legitimate use for governance and dispute resolution |
| 15 | When we respond to regulators, courts, law enforcement agencies or legal proceedings | Identity information, financial information, licensing records, investigation files, communications and supporting documents | To comply with legal obligations, respond to lawful requests and establish, exercise or defend legal rights | Falls under legal/regulatory compliance and legal claims requirements |
| 16 | When your appointment ends, is terminated or becomes inactive | Exit documentation, settlement records, final commission information, access removal records, investigation files and performance history | To manage offboarding, settle dues, deactivate access, maintain records and comply with applicable requirements | Falls under contractual necessity, legal/regulatory compliance and permitted legitimate use |
| 17 | When we retain, archive, secure or delete agent records | Any information maintained during the agent relationship, retention schedules, deletion requests, audit logs and archival records | To comply with retention obligations, maintain audit trails, support legal requirements and securely dispose of information when no longer required | Falls under legal obligations and permitted legitimate use for record management and governance |
PART E – Who we share your personal information with and why
We’ll share your personal information within the Prudential Group and with our Business Partners, for any of the purposes set out in Part D. If you have a joint policy, the other person may receive your personal information too.
We may process or allow processing of your personal information outside India where this is necessary for providing services, technology support, security, customer service, analytics, group support or other purposes described in this Privacy Notice.
Where personal data is transferred or made available outside India, we will comply with applicable data protection laws and any transfer-related requirements notified by the Government of India, including any restrictions on transfer to specified countries or territories. We will also use appropriate contractual, technical and organisational safeguards for such processing.
We work with many external parties in order to provide you with a seamless experience in relation to any products and/or services you have purchased from us. In the ordinary course of business, we may be required to disclose personal data to such external parties and these external parties may be located overseas.
We only disclose your personal data, where appropriate and necessary, for one or more of the above-mentioned Purposes or as permitted by law. The external parties we may disclose your personal data to include, but are not limited to, the following:
- within the Prudential Group and distribution partners / brokers / business partners / applicable group policyowners to facilitate the conduct of our business, carrying out our business activities and servicing you in relation to the products and services offered to you where appropriate and relevant;
- our third-party service providers, sub-contractors of third-party service providers, contractors and vendors – which could include accountants, auditors, lawyers, IT service providers, business consultants, claim investigators, event managers, debt collection service providers, other such third-party service providers and sub-contractors of such third-party service providers which may assist us in carrying out our business activities. All third party service providers providing services for us are prohibited from retaining, using, or disclosing your personal information for any purpose except where strictly necessary for the Purposes;
- Hospitals, medical institutions, clinics, financial institutions, credit card companies, credit reference agencies, industry bodies, other insurance and re-insurance companies – to facilitate the processing of your applications, claims or any other insurance-related information or procedures;
- public and governmental authorities, including regulatory authorities and law enforcement agencies – to comply with legal process, to respond to requests from such parties, to detect and prevent fraud and to protect our business operations;
- your family, relatives, appointed executors, appointed trustees, appointed administrators, and their professional advisers – in connection with your will(s) or the administration of your estate;
- any business partner, investor, assignee or transferee (actual or prospective) – to facilitate business asset transactions (which may extend to any merger, acquisition or asset sale) involving any of the Prudential Group;
- any social media and/or advertising platform providers such as Google and Facebook if you have consented to receiving marketing, advertising and promotional information; and
- any other party whom you authorize us to disclose your personal data to.
PART F – ACCURACY AND PROTECTION OF PERSONAL DATA
We will take reasonable efforts to ensure that any personal data we have about you is accurate and complete. However, this means that you must also ensure the accuracy of the personal data provided by you and update us of any changes to the personal data that you had initially provided to us in a timely fashion.
We will also take reasonable efforts to protect the personal data in our possession by making reasonable security arrangements to prevent unauthorized access, collection, use, disclosure, copying, modification, disposal or any similar risks.
PART G – Third Party Sites
Our website may contain links to other websites operated by third parties, which may be co-branded with our logo or trademark, even though they are not operated or maintained by us. We are not responsible for the privacy practices of such third parties that are linked to our website. Once you have left our website, we strongly encourage you to refer to the applicable privacy policy of the third-party website to determine how they will handle any information they collect from you.
PART H – Security
We implement and update technical and physical security measures to safeguard your personal information against loss, misuse or unauthorized access on an ongoing basis. Our protective measures include firewalls, data encryption, and access controls. However, please be aware that transmitting information over the Internet is not completely secure, and no data storage system can be guaranteed to be entirely safe. While we strive to protect your personal information, we cannot guarantee the security of data transmitted to our sites; any transmission is at your own risk. We encourage you to recognize the important role you play in maintaining the security and confidentiality of your personal information.
PART I – Retention
We do not keep your data for longer than is necessary to fulfil the Purposes as stated herein.
Your personal information will be stored either for as long as you (or your joint policyholder) are our customer, or longer if required by law or as is otherwise necessary for us to fulfil the Purposes above.
PART J – Know your customer
We may collect certain personal information from you to verify your identity and comply with legal and regulatory obligations, including KYC and anti-money laundering requirements under applicable laws, IRDAI requirements and the Prevention of Money Laundering framework. This process helps us ensure that we are dealing with genuine individuals, prevent fraud or misuse and maintain accurate records.
Where Aadhaar or Aadhaar-related information is used for KYC, authentication or offline verification, we will do so only in accordance with applicable Aadhaar laws and regulatory requirements. We will provide appropriate notice, seek consent where required, use alternative verification methods where applicable, and apply appropriate security safeguards. Aadhaar will not be treated as mandatory unless required or permitted under applicable law or the relevant regulatory process.
These checks may also be carried out for a joint policy holder or person(s) that you provide personal information on. Should we ever lose contact with you, we may use these agencies to verify your contact information to help us get back in touch.
Any transfer of your personal information will always be done securely.
PART K – Use of artificial intelligence enabled technologies
We may use artificial intelligence enabled technologies, including generative AI and natural language processing tools, to support limited activities connected with our products, services, communications, claims, customer support, fraud detection support, operational efficiency, quality assurance and internal administrative processes.
These technologies may help us review communications, summarise information, respond to queries, support customer service, assist with claims workflows, identify unusual patterns, improve service quality and support internal processes. Where we use these technologies, they may process personal data contained in communications, documents, claims submissions, customer interactions or other information provided to us. We apply appropriate safeguards when personal data is processed using these technologies. The use of AI-assisted tools does not necessarily mean that decisions are made solely by automated means. Human review and oversight may form part of the process where appropriate.
PART L – Automated decisions and profiling
We, Prudential HCL Health Insurance Limited, our Business Partners and our Marketing Partners may use automated tools, analytics models or profiling to support limited activities such as underwriting, risk assessment, fraud monitoring, service routing, claims workflow support, anomaly detection, repricing analysis, customer assistance and similar operational use cases.
Where an automated tool or profiling activity may materially affect you, we will provide appropriate information at the relevant point in the journey and apply safeguards appropriate to the use case.
PART M – Use of your sensitive personal information
For certain products or services, we may need to process health information, medical records, biometric identifiers or other information that may be sensitive in nature. Such processing will be undertaken for the applicable purposes described in Part D of this Privacy Notice, including in connection with the relevant product, service, claim, medical evaluation, regulatory requirement or other purpose explained to you. Where consent is required for such processing, we will seek it separately at the point of collection or through an appropriate consent request form or digital journey. If any additional information, consent, notice or other requirement is needed to process your sensitive personal information, we will communicate this to you in advance.
PART N – You’re in control
SSubject to applicable law and verification of your identity, you may exercise the following rights in relation to your personal data:
- Right to access information about personal data: request a summary of the personal data being processed by us, the processing activities undertaken and information about sharing of your personal data, as available under applicable law.
- Right to correction, completion and update: ask us to correct inaccurate or misleading personal data, complete incomplete personal data or update your personal data..
- Right to erasure: ask us to erase personal data where permitted under applicable law. We may retain information where retention is necessary for the specified purpose, insurance servicing, claims handling, regulatory, legal, audit or other lawful requirements.
- Right to grievance redressal: raise a grievance with us about the processing of your personal data or the exercise of your rights.
- Right to nominate: nominate another individual who may exercise your rights in the event of your death or incapacity, in the manner prescribed under applicable law.
- Right to withdraw consent: withdraw consent where processing is based on consent. Withdrawal will not affect processing already carried out before withdrawal. Depending on the nature of the processing, withdrawal may affect our ability to provide or continue certain products, services, benefits, digital journeys, communications or optional features.
- Other requests: Rights such as portability, objection or restriction of processing are not standalone rights under the India’s privacy laws. Where PHI chooses to support any broader group or customer service standard, this will be handled subject to applicable law, feasibility and PHI’s internal processes.
You can exercise these rights by contacting us using the details in the Contact Us section.
If your grievance is not resolved through PHI’s grievance redressal process, you may have the option to approach the Data Protection Board of India once the applicable mechanism is prescribed or established.
PART O – Advertising
We may work with third-party platforms or service providers to display advertisements or send marketing communications where permitted and, where required, with your consent. These activities may involve cookies, pixels or similar technologies, and are subject to the cookie preferences and consent choices described in Part C. We will not knowingly target advertising to children through our website/app journeys and will apply age-gating or other controls where appropriate.
PART P – Contact Us
If want to exercise your rights in Part N or if you require any other information about any other part of this notice, you can contact us in several different ways.
We may monitor or record calls or any other communication we have with you. This might be for training, for security, or to help us check for quality.
For customers and agents, contact us at:
Prudential HCL Health Insurance Limited
Suite 6, 48th Floor, Commerz III, International Business Park, Oberoi Garden City, Off Western Express Highway, Goregaon (East), Mumbai 400063, India
If you wish to contact PHI about a Data Protection concern, please write to The Data Privacy Officer at:privacy.indiahealth@prudentialhealth.in
You may also contact us through PHI’s website’s contact us page.
PART Q – Language
Except as otherwise prescribed by law, in the event of any discrepancy or inconsistency between the English version and local language version of this Privacy Notice, the English version shall prevail.
PART R – Terms Used
Prudential Group means Prudential plc, Prudential Holdings Limited and any other affiliates of Prudential plc. Prudential Plc is not affiliated in any manner with Prudential Financial, Inc. a company with principal place of business is in United States of America or with the Prudential Assurance Company, a subsidiary of M&G Plc, a company incorporated in United Kingdom.
Business Partners means service providers, accountants, distributor, auditors, IT service and platform providers, intermediaries, reinsurers, investment managers, agents, pension trustees (and other stakeholders), scheme advisors, introducers, selected third party financial and insurance product providers, and our legal advisers.
Marketing Partners means our service providers, intermediaries, pension trustees (and other stakeholders), scheme advisors, introducers and selected third party financial and insurance product providers.