Effective Date: 20 July 2026
Privacy Policy
Official governance framework for Vestigo Insurance Brokers Pvt. Ltd. ensuring compliant and secure processing of personal data.
IRDAI RegistrationNo. 1131 (Direct Broker (General & Life))
Registration Validity15 January 2026 to 14 January 2029
Corporate Identity
CIN: U66220GJ2025PTC166605
Vestigo Insurance Brokers Pvt. Ltd.
Registered Office
SF 201, Status Complex, Opp. Amrapali Complex, Pani Tanki Road, Karelibaug, Vadodara - 390018, Gujarat, India
Privacy & Compliance Desk
enquiry@vestigoinsurance.com
www.vestigoinsurance.com
Clause 01
01. About this Policy
Vestigo respects privacy and is committed to processing personal data lawfully, fairly, transparently, and securely.
This Privacy Policy explains how we handle personal data when an individual visits our website, makes an enquiry, seeks or receives insurance broking or advisory services, participates in a corporate or group insurance programme, communicates with us, submits information for a quotation, policy, endorsement, renewal or claim, or otherwise interacts with Vestigo.
This Policy is intended to operate in accordance with applicable Indian law, including the Information Technology Act, 2000 and the rules framed under it, applicable insurance laws and IRDAI requirements, and the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as and when their respective provisions become applicable. If a specific notice, consent form, proposal form, insurer document or contractual term provides additional information for a particular processing activity, that document will supplement this Policy.
This Privacy Policy explains how we handle personal data when an individual visits our website, makes an enquiry, seeks or receives insurance broking or advisory services, participates in a corporate or group insurance programme, communicates with us, submits information for a quotation, policy, endorsement, renewal or claim, or otherwise interacts with Vestigo.
This Policy is intended to operate in accordance with applicable Indian law, including the Information Technology Act, 2000 and the rules framed under it, applicable insurance laws and IRDAI requirements, and the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as and when their respective provisions become applicable. If a specific notice, consent form, proposal form, insurer document or contractual term provides additional information for a particular processing activity, that document will supplement this Policy.
Clause 02
02. Scope
This Policy may apply to personal data relating to:
Website visitors, enquirers and prospective clients.
Individual policyholders, insured persons, proposers, nominees, beneficiaries and claimants.
Directors, partners, authorised representatives, employees and dependants connected with corporate or group clients.
Business contacts, insurer, reinsurer, third-party administrator, surveyor, hospital, healthcare, legal, accounting, technology and service-provider personnel.
Persons who visit our premises, attend meetings or events, or communicate with us through email, telephone, messaging platforms, online forms or social media
Any other individual whose personal data is lawfully provided to Vestigo for an insurance-related or legitimate business purpose.
Employee and shareholder information may also be governed by separate internal policies and notices.
Clause 03
03. Personal Data We May Collect
Depending on the service and context, Vestigo may collect the following categories of data.
Identity and contact data: name, age or date of birth, gender where relevant, photograph, signature, postal address, email address, telephone number and proof of identity or address.
Business and professional data: designation, employer, organisation, ownership or beneficial ownership, authorised signatory status, business profile, industry, assets, operations, locations, contracts and risk information.
Insurance and risk data: existing and proposed covers, policy details, sums insured, claims history, loss information, survey and inspection information, risk-management records and supporting documents.
Health and medical data: medical history, reports, prescriptions, hospital records, disability or health information where required for life, health, accident, employee-benefit or claim-related services.
Financial, KYC and transaction data: banking or payment information, PAN, tax or statutory identifiers, premium and refund information, financial statements, source-of-funds information and KYC or due-diligence documents where legally or operationally required.
Family, nominee and beneficiary data: relationship, contact details and other information required for policy issuance, administration or claims.
Communication and service data: emails, letters, call notes, meeting records, instructions, complaints, feedback and service history.
Website and device data: IP address, browser and device information, operating system, access times, referring pages, website interactions, security logs and cookie or similar technology data.
Premises and security data: visitor records and CCTV footage where security systems are lawfully deployed at our premises.
We seek to collect only data that is reasonably necessary for the relevant purpose. Health, financial and other sensitive information is handled with enhanced care and access restrictions.
Clause 04
04. How We Collect Personal Data
We may obtain personal data:
Directly from the individual through forms, emails, calls, meetings, website submissions or documents.
From an employer, group policyholder, authorised representative, family member, nominee, beneficiary or other person who is authorised to provide it.
From insurers, reinsurers, third-party administrators, surveyors, loss assessors, hospitals, healthcare providers, garages, investigators, legal advisers and other participants in the insurance lifecycle.
From lawful public sources, statutory databases, credit or identity-verification sources and business directories, where permitted.
Automatically through website, network, security and cookie technologies.
Clause 05
05. Purposes for Which We Use Personal Data
Vestigo may process personal data for one or more of the following purposes
Responding to enquiries and understanding insurance, risk and service requirements.
Seeking quotations, arranging, placing, servicing, renewing, modifying or cancelling insurance contracts.
Supporting policy administration, endorsements, certificates, enrolment, claims, surveys, loss assessment and grievance handling.
Providing risk advisory, claims advisory, employee-benefit administration and related lawful insurance-broking services.
Conducting identity, authority, KYC, beneficial-ownership, sanctions, fraud-prevention and other due-diligence checks.
Communicating service information, regulatory notices, policy or claim updates and other transaction-related messages.
Meeting legal, regulatory, audit, tax, accounting, record-keeping, inspection and reporting obligations.
Protecting clients, Vestigo, insurers and other stakeholders against fraud, cyber threats, unlawful conduct and security incidents.
Managing business continuity, quality assurance, training, complaints, disputes, legal claims and enforcement of rights.
Improving our services, website, processes and client experience through lawful and proportionate analysis, including aggregated or anonymised information.
Sending relevant service or marketing communications where permitted by law and the recipient has not opted out or where consent is required and has been obtained.
Clause 06
06. Consent and Other Permitted Processing
Where consent is the appropriate basis for processing, Vestigo will seek consent that is specific, informed and indicated through a clear affirmative action. Merely browsing a publicly accessible page will not, by itself, be treated as consent for unrelated processing or optional cookies.
An individual may withdraw consent by contacting us, subject to reasonable identity verification. Withdrawal will apply prospectively and may affect our ability to continue a service that necessarily depends on the relevant data. It will not require Vestigo to erase or stop using information that must be retained or processed to comply with law, regulation, a contract, a claim, a dispute, fraud prevention, or another legally permitted purpose.
Vestigo may also process data where permitted or required by applicable law, including for voluntarily provided data used for its stated purpose, contractual or pre-contractual activities, compliance with legal obligations, protection of rights, responding to emergencies, and other lawful uses.
An individual may withdraw consent by contacting us, subject to reasonable identity verification. Withdrawal will apply prospectively and may affect our ability to continue a service that necessarily depends on the relevant data. It will not require Vestigo to erase or stop using information that must be retained or processed to comply with law, regulation, a contract, a claim, a dispute, fraud prevention, or another legally permitted purpose.
Vestigo may also process data where permitted or required by applicable law, including for voluntarily provided data used for its stated purpose, contractual or pre-contractual activities, compliance with legal obligations, protection of rights, responding to emergencies, and other lawful uses.
Clause 07
07. Data About Other Persons
If you provide personal data about another person, you represent that you are authorised to do so and have provided any notice or obtained any consent required by law. For corporate and group insurance, the employer, group policyholder or authorised administrator is responsible for lawfully collecting and sharing member and dependant data with Vestigo and the relevant insurer. Vestigo may seek evidence of authority where appropriate.
Clause 08
08. Children and Persons Requiring Assistance
Our website and services are not directed at obtaining independent consent from children. Data relating to a person below eighteen years of age, or a person who lawfully acts through a guardian, should be provided by or with the involvement of a parent, lawful guardian, employer, group policyholder or other authorised person, as applicable. We process such data only for legitimate insurance, benefit, claim or legal purposes and with appropriate safeguards.
Clause 10
10. International and Cross-Border Processing
Certain insurance arrangements, overseas travel or employee-benefit programmes, global insurers or reinsurers, assistance services, claims, technology platforms or cloud services may require data to be accessed from or transferred outside India. Any such processing will be undertaken only where legally permitted and with contractual, technical and organisational safeguards appropriate to the circumstances. Vestigo will comply with any country restrictions or conditions notified under applicable Indian law.
Clause 12
12. Information Security
Vestigo uses reasonable and proportionate physical, administrative and technical safeguards designed to protect personal data against unauthorised access, use, disclosure, alteration, loss or destruction. Measures may include access controls, authentication, encryption or secure transfer methods where appropriate, endpoint and network protection, logging, backup, vendor controls, confidentiality obligations, training and incident-response procedures.
No system, transmission or storage method is completely secure. Vestigo therefore cannot guarantee absolute security, but will continue to assess risk and improve safeguards in line with applicable requirements and the nature of the information processed.
No system, transmission or storage method is completely secure. Vestigo therefore cannot guarantee absolute security, but will continue to assess risk and improve safeguards in line with applicable requirements and the nature of the information processed.
Clause 13
13. Personal Data Breach and Security Incident Response
Vestigo maintains procedures to identify, contain, investigate, remediate and document suspected security incidents and personal data breaches. Where a notification or report is legally required, Vestigo will notify the relevant authority, regulator, insurer, client or affected individual in the manner and within the timeframe prescribed by applicable law. Notifications may be delayed or limited where law-enforcement, security or legal requirements so require.
Clause 14
14. Retention and Disposal
Insurance-broking books, records and documents will ordinarily be preserved for at least seven years from the end of the relevant financial year, or for any longer period required by applicable law, IRDAI direction, insurer arrangement, audit, investigation, litigation, claim or contractual obligation. Records relating to pending claims, disputes, proceedings or investigations may be retained until final disposal and completion of any required preservation period.
Other personal data is retained only for as long as reasonably necessary for the purpose for which it was collected and for legitimate legal, regulatory, security and business requirements. When retention is no longer required, data will be securely deleted, destroyed, de-identified or anonymised, subject to backup and archival deletion cycles.,
Other personal data is retained only for as long as reasonably necessary for the purpose for which it was collected and for legitimate legal, regulatory, security and business requirements. When retention is no longer required, data will be securely deleted, destroyed, de-identified or anonymised, subject to backup and archival deletion cycles.,
Clause 15
15. Your Choices and Rights
Subject to applicable law, identity verification and lawful exceptions, an individual may request:
A summary of personal data being processed and relevant processing information.
Correction, completion or updating of inaccurate or incomplete personal data.
Erasure of personal data that is no longer necessary and is not required to be retained.
Withdrawal of consent where processing is based on consent.
cessation of promotional communications
Grievance redressal concerning our handling of personal data
Nomination of another individual to exercise rights in circumstances recognised by applicable law.
A request may be refused, restricted or deferred where it is repetitive, manifestly unfounded, affects the rights of another person, compromises security or confidentiality, or conflicts with a legal, regulatory, contractual, claims, fraud-prevention, investigation or record-retention requirement. We will provide an appropriate response in accordance with applicable law.
Clause 16
16. Communications and Marketing Preferences
Vestigo may send communications necessary to respond to an enquiry, administer a service, provide policy or claim information, comply with law or protect security. Such service communications cannot always be opted out of while the relevant relationship continues. Promotional communications may be stopped by using the unsubscribe option, replying with an opt-out request, or writing to enquiry@vestigoinsurance.com. We may retain limited suppression information to honour an opt-out request.
Clause 17
17. Third-Party Websites and Platforms
Our website may link to insurer, regulator, service-provider or other third-party websites. Vestigo does not control those platforms and this Policy does not govern their privacy practices. Users should review the privacy notices of those third parties before submitting personal data.
Clause 18
18. Changes to this Policy
Vestigo may amend this Privacy Policy to reflect changes in law, regulation, technology, services or business practices. The revised version will be posted on the website with an updated effective or last-updated date. Material changes may also be communicated through an appropriate additional notice where required.
Privacy Contact & Grievance Redressal
For privacy questions, consent withdrawal, statutory rights requests, or grievances, write directly to our official Grievance Contact.
• Include "Privacy Request" in the email subject line.
• Acknowledgement: Within 3 working days.
• Resolution: Within 15 working days.