Introduction and Scope

Ace Insurance Brokers Private Limited (“Ace”, “Company”, “we”, “us”, “our”) is committed to protecting the privacy and security of personal data collected from visitors to our Website (www.aceinsurance.com) and from individuals who contact us in connection with our services.

This Privacy Policy explains how we collect, use, store, share, and protect personal data in connection with the Website and our insurance broking services, in compliance with:

  1. The Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”);
  2. The Digital Personal Data Protection Act, 2023 (“DPDP Act”) and rules framed thereunder, to the extent applicable;
  3. The IRDAI Information and Cyber Security Guidelines, 2023 (“CS Guidelines”);
  4. The IRDAI (Insurance Brokers) Regulations, 2018;
  5. The Prevention of Money Laundering Act, 2002;
  6. The Consumer Protection Act, 2019;
  7. Any other applicable law or IRDAI regulation as may be in force from time to time.
    • This Policy applies to personal data of all individuals who access our Website, submit inquiries through Contact Forms, communicate with us by telephone or email, or otherwise interact with us in connection with the Website.
    • This Policy does not apply to data processed in connection with employment or recruitment, which is governed by our internal policy.

Identity and Contact Details of the Data Fiduciary

Data Fiduciary: Ace Insurance Brokers Private Limited

IRDAI Reg. No.: 246 (Composite Broker)

CIN: U74999DL2001PTC110729

Registered Address: 708 & 709, 7th Floor, Prakash Deep Building, 7 Tolstoy Marg, New Delhi – 110001, India

Grievance / Data Officer Email: grievance@aceinsurance.com

General Email: mail@aceinsurance.com

Telephone: 011-4236 3600

Our Role — Data Controller and Data Processor

Ace acts in different capacities depending on the context of data processing:

  • Data Fiduciary / Controller: When we collect and process personal data submitted through this Website (e.g., via Contact Forms, email, or telephone), Ace acts as the Data Fiduciary (equivalent to a data controller) and is responsible for determining the purposes and means of processing.
  • Data Processor: When we are engaged by a corporate client to provide insurance broking or risk advisory services, and that client provides us with personal data of their employees, dependents, or other individuals, Ace may act as a Data Processor operating under the instructions of the client (who is the Data Fiduciary). In such cases, processing will be governed by our contractual arrangements with the client and applicable law.

This Privacy Policy applies primarily to our role as Data Fiduciary in relation to Website visitors and direct inquiry contacts. If you are an employee, dependent, or beneficiary of a corporate client of Ace, please contact your employer for information about how your data is processed in that context.

Data About Third Parties

If you provide us with personal data relating to other individuals (for example, information about employees, dependents, co-insureds, or beneficiaries in the context of a group insurance inquiry), you confirm that:

  • You have the authority to provide that information on their behalf;
  • You have informed those individuals, or will do so promptly, of how their data will be used by Ace, by providing them with a copy of this Privacy Policy or otherwise making it available to them;
  • Where required by applicable law, you have obtained their consent or have another valid legal basis for sharing their data with us.
  • Ace will process such third-party data only for the purpose for which it was shared and in accordance with this Privacy Policy.

Personal Data We Collect

Data You Provide Directly: When you complete any Contact Form, callback request, grievance form, or newsletter subscription on our Website, we collect:

  • Identification data: Full name, Country;
  • Contact data: Email address, mobile/telephone number,
  • Inquiry data/ Subject: Details of the risk or insurance requirement you have described;

Data Collected Automatically: When you visit our Website, we automatically collect certain technical information: [TBD with IT/CISO.]

  • Device and browser data: IP address, browser type and version, operating system, device type;
  • Usage data: Pages visited, time spent, links clicked, referring website, search terms;
  • Location data: Approximate geographic location derived from IP address (not precise GPS location);
  • Cookie data: As described in Section 8 of this Policy.

Sensitive Personal Data or Information (SPDI): We generally do not intentionally collect SPDI through the Website. However, users may voluntarily provide data that qualifies as SPDI. Where such data is provided, we will handle it with heightened safeguards in compliance with the SPDI Rules and applicable law.

If you do provide SPDI through the Website, you acknowledge that you are doing so voluntarily and consent to its processing for the stated purpose.

How We Use Personal Data

 We use your personal data for the purposes set out below:

  • Respond to and manage your inquiry or service request;
  • Provide insurance broking, risk advisory, and related services;
  • Communicate with you about our services, regulatory developments, and knowledge resources (where consented);
  • Comply with IRDAI regulations, KYC/AML obligations, and other legal requirements;
  • Process personal data as necessary to establish, exercise, or defend legal rights, investigate fraud or misconduct, resolve disputes, and comply with applicable legal and regulatory obligations Manage grievances and disputes.

Legal Basis for Processing

 The primary basis for processing data submitted through Contact Forms is your consent. The Company may also process personal data where such processing is necessary to comply with applicable law, respond to your requests, perform services requested by you, or for other purposes permitted under applicable law.

Sharing and Disclosure of Personal Data

Internal Sharing: Personal data may be shared within the Company on a need-to-know basis, including with our directors, officers, employees, and agents involved in providing the requested service.

Sharing with Insurers and Reinsurers: Where you have specifically requested us to obtain insurance quotations or place cover on your behalf, we may share relevant personal and business data with insurers and reinsurers. Such sharing shall be strictly for the purpose of obtaining quotations, placing risk, or administering the insurance contract. Once you engage us to place or service an insurance programme, you grant us a right to share your information with relevant insurers, reinsurers, and third-party administrators as operationally required to deliver and administer that programme — including for claims handling, policy endorsements, and renewals.

Service Providers and Processors: We may engage third-party data processors (e.g., IT/cloud service providers, CRM vendors, communication Websites) to support our operations. All such processors are contractually bound to process data only on our instructions, maintain confidentiality, and implement appropriate security measures.

Legal and Regulatory Disclosure: We may disclose personal data to:

  • IRDAI, IFSCA, or other regulatory authorities upon lawful demand;
  • Law enforcement agencies, courts, or tribunals in response to valid legal process;
  • Statutory authorities for KYC/AML compliance;
  • Any successor entity in connection with a merger, acquisition, or business reorganisation (with appropriate notice to affected data subjects).

No Sale of Data: We do not sell, rent, barter, or transfer your personal data to any third party for independent commercial or marketing purposes.

Data Retention

The Company retains personal data only for as long as necessary to fulfil the purposes for which it was collected, comply with applicable legal and regulatory requirements, resolve disputes, enforce contractual rights, and maintain appropriate business and security records. Upon expiry of the applicable retention period, personal data shall be securely deleted, destroyed, or anonymised in accordance with applicable law.

General retention practices are set out below, subject to applicable law, regulatory requirements, internal policies, and legitimate business needs:

  • Inquiry/Contact Form data (where no engagement follows): retained for such period as reasonably necessary to respond to the inquiry, maintain appropriate business records, resolve disputes, prevent fraud, or comply with applicable legal or regulatory requirements.
  • Data relating to insurance transactions: retained for such period as may be required under applicable IRDAI regulations, contractual obligations, and applicable law. For reference, IRDAI (Insurance Brokers) Regulations, 2018 (Regulation 28) prescribe a minimum retention period of 7 (seven) years.
  • KYC/AML records: retained for such period as may be required under the Prevention of Money Laundering Act, 2002, applicable rules thereunder, and IRDAI’s AML/CFT Guidelines as amended from time to time.
  • Technical, security, and system logs: retained for such period as may be required under applicable cybersecurity, data protection, or legal requirements, or as reasonably necessary for security monitoring, fraud prevention, incident investigation, and audit purposes. For reference, CERT-In Directions (2022) prescribe a minimum retention period of 180 (one hundred and eighty) days within Indian jurisdiction.
  • Data subject to legal hold, investigation, or dispute: retained for the duration of the relevant proceeding, investigation, or legal requirement and thereafter as permitted or required under applicable law.
  • Notwithstanding withdrawal of consent or any request for deletion, the Company may retain personal data where such retention is required or permitted under applicable law, regulatory obligations, or for establishment, exercise, or defence of legal claims.

In addition:

  • We apply the principle of data minimisation and retain only data that is necessary for the stated purpose.
  • Processing logs and associated traffic data are retained for a minimum of 1 (one) year from the date of processing, or as required under DPDP Rules, 2025.
  • Retention periods are reviewed annually and updated in accordance with changes in law and business requirements.
  • Upon expiry of the applicable retention period, data is securely deleted, anonymised, or archived in compliance with applicable law

Cookie Policy

Our Website uses essential cookies and similar technologies to support Website functionality, security, analytics, and user experience. Most browsers allow you to refuse cookies, delete existing cookies, or be alerted before cookies are placed. Instructions vary by browser — please consult your browser’s help function. Note that disabling cookies may impair certain Website functionalities.

Data Security

Information security is a business responsibility shared by all employees, contractors, and third parties of the Company. We maintain a comprehensive information security programme in accordance with the IRDAI Information and Cyber Security Guidelines, 2023. A designated Information Security function — comprising senior management personnel and key business units — oversees the implementation, monitoring, and review of security controls across the organisation.

Our technical and organisational security measures include:

  • Secure Sockets Layer (SSL) / Transport Layer Security (TLS) encryption for all data transmissions;
  • Encryption and other appropriate security controls of personal data at rest;
  • Role-based access controls and multi-factor authentication for staff accessing personal data;
  • Regular vulnerability assessments, penetration testing, and security audits;
  • An incident response plan with defined procedures for breach detection, containment, and notification;
  • Annual security awareness training for all employees with data access;
  • Vendor due diligence and contractual safeguards for all data processors.

The Company maintains appropriate technical and organisational security measures designed to protect personal data from unauthorised access, disclosure, alteration, misuse, or loss. In the event of a personal data breach, the Company shall take such actions, including notifications to relevant regulatory or governmental authorities and affected Data Principals, as may be required under applicable law and regulatory requirements.

Personal data may be processed or stored on servers located outside India by authorised service providers, subject to appropriate contractual and security safeguards and compliance with applicable law. 

Your Rights

As a Data Principal, you have the following rights under applicable Indian law, including the DPDP Act:

  1. Right to Access: Request confirmation and a copy of the personal data we hold about you.
  2. Right to Correction and Completion: Request correction of inaccurate or incomplete personal data.
  3. Right to Erasure: Request deletion of your personal data, subject to our legitimate retention obligations under IRDAI regulations and applicable law.
  4. Right to Withdraw Consent: Withdraw consent at any time. Withdrawal does not affect prior lawful processing.
  5. Right to Grievance Redressal: Lodge a complaint with our Grievance Officer, who will respond within timelines prescribe by applicable law.
  6. Right to Nominate: Nominate a person to exercise your rights in case of death or incapacity.

To exercise these rights, contact our Grievance Officer as detailed in the section below.

Children’s Privacy

This Website is not directed at children under the age of 18 years. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected personal data from a person under 18, we will take reasonable steps to delete such data promptly. If you believe a minor has provided us with personal data, please contact us immediately.

Updates to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will post the revised Policy on this page with an updated “Last Reviewed” date and, where appropriate, notify you by email or prominent notice on the Website.

We encourage you to review this Privacy Policy periodically. Your continued use of the Website after changes are posted constitutes your acceptance of the revised Policy.

Standalone Consent Notice — DPDP Rules Complianc

The consent notice presented to you at the point of data collection (i.e., within or immediately adjacent to each Contact Form on this Website) constitutes a standalone, independently understandable notice, presented in clear and plain language. It is not contingent on your reading of this full Privacy Policy or the Terms of Use, and is accessible directly on the relevant page of the Website.

Governing Law

This Privacy Policy shall be governed by and construed in accordance with the laws of India. Any disputes arising in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of courts in New Delhi, India.

Force Majeure

While the Company implements reasonable technical and organisational safeguards to protect personal data in accordance with applicable law and industry standards, you acknowledge that no method of transmission over the internet or electronic storage is completely secure, and the Company cannot guarantee absolute security of any information transmitted through the Website. Accordingly, any transmission of personal data is at your own risk, and the Company shall not be liable for any loss, unauthorised access, alteration, disclosure, or misuse of information arising from events beyond its reasonable control, including Force Majeure events.

For the purposes of this Policy, “Force Majeure” means any event or circumstance beyond the reasonable control of the Company, including but not limited to widespread telecommunications or internet failures, cyber incidents or cyber-attacks not arising from the Company’s gross negligence, wilful misconduct, or failure to implement reasonable security measures, malware or ransomware attacks by third parties, power outages, system failures, governmental actions, natural disasters, pandemics, labour disruptions, civil unrest, war, or acts of God.

Users acknowledge that they have not relied upon any representation, warranty, or statement not expressly set out on the Website or in written communications formally issued by the Company.

For the purposes of this Policy, “Force Majeure” means any event or circumstance beyond the reasonable control of the Company, including but not limited to widespread telecommunications or internet failures, cyber incidents or cyber-attacks not arising from the Company’s gross negligence, wilful misconduct, or failure to implement reasonable security measures, malware or ransomware attacks by third parties, power outages, system failures, governmental actions, natural disasters, pandemics, labour disruptions, civil unrest, war, or acts of God.

The Company reserves the right to suspend, restrict, or block access to the Website in the event of suspected misuse, automated abuse, security threats, or violation of these Terms.

This Privacy Policy shall be read together with Company’s Terms of Use.

Scroll to Top