Introduction
ATS Corporation, operating as Autoviq, is committed to protecting the privacy and
security of your personal data. This Data Protection Policy explains how we collect, use, store,
and protect your information when you use our car insurance comparison services.
As a UK-based company, we process personal data in accordance with the UK General Data
Protection Regulation (UK GDPR) and the Data Protection Act 2018. We take our data protection
obligations seriously and have implemented appropriate technical and organisational measures to
ensure compliance.
Data Controller
Data Controller: ATS Corporation
Company Number: ATS001
Registered Address: 730 Fountain Street North, Building #2, Cambridge, ON N3H
4R7, Canada
We are responsible for determining the purposes and means of processing your personal data. If
you have any questions about how we handle your data, please contact our Data Protection
Officer.
Data Protection Contact:
Cheryl E. Bird
Email: cheryl@autoviq.com
Phone: +1 (519) 653-6500
Legal Basis for Processing
We process your personal data under the following legal bases as defined by UK GDPR:
Contract
Performance (Article 6(1)(b))
Processing is necessary to provide our insurance comparison services at your request. This
includes generating quotes based on your information and sharing data with insurance providers.
Legitimate
Interests (Article 6(1)(f))
We may process your data where it is necessary for our legitimate interests, provided these are
not overridden by your rights. This includes:
- Improving our services and user experience
- Fraud prevention and security
- Direct marketing (with your consent)
- Legal compliance and regulatory reporting
Consent (Article
6(1)(a))
Where we rely on consent, you have the right to withdraw it at any time. This applies to
marketing communications, non-essential cookies, and certain data processing activities.
Legal Obligation
(Article 6(1)(c))
We process data where required to comply with legal obligations, including financial
record-keeping, regulatory reporting, and responding to lawful requests from authorities.
Categories of Personal Data
We collect and process the following categories of personal data:
Identity Data
- Full name
- Date of birth
- Gender
- Marital status
Contact Data
- Email address
- Phone number
- Home address
- Postcode
Driving Data
- Driving licence number
- Licence type and entitlements
- Driving history and convictions
- Years of driving experience
Vehicle Data
- Vehicle registration
- Make, model, and variant
- Year of manufacture
- Vehicle identification number (VIN)
- Security features and modifications
- Estimated annual mileage
Financial Data
- Bank details (for payments to insurers)
- Payment card information
Technical Data
- IP address
- Browser type and version
- Device information
- Operating system
- Usage patterns and preferences
Special Category Data
Some personal data is classified as "special category" under UK GDPR and requires additional
protection. This may include:
- Health information (medical conditions affecting driving)
- Criminal convictions (driving offences)
We process special category data under Article 9(2) of UK GDPR, specifically:
- Explicit consent (9(2)(a)): Where you have
given us explicit consent to process such data.
- Insurance purposes (9(2)(b)): Processing
necessary for insurance purposes based on Union or Member State law.
We implement additional safeguards for special category data and only collect what is necessary
for providing our services.
Data Recipients
We share your personal data with the following categories of recipients:
Insurance
Providers
To provide comparison quotes, we share your information with FCA-authorised insurance companies
in our network. Each provider will process your data under their own privacy policy.
Service Providers
We use carefully selected third-party processors who handle data on our behalf:
- Website hosting and cloud services
- Analytics and tracking providers
- Customer communication platforms
- Payment processing services
- IT support and maintenance
Legal and
Regulatory Bodies
We may disclose data to law enforcement, regulators, or other authorities as required by law or
to protect our legal rights.
International
Transfers
If we transfer data outside the UK, we ensure appropriate safeguards are in place, such as:
- Adequacy decisions by the Information Commissioner's Office
- Standard Contractual Clauses approved by the ICO
- Binding Corporate Rules where applicable
Data Retention Periods
We retain your personal data only for as long as necessary to fulfil the purposes outlined in
this policy. Our retention periods are based on:
- Legal and regulatory requirements
- The nature of the data and why it was collected
- Contractual obligations
- Our legitimate business needs
Specific Retention Periods:
- Quote comparison data: Up to 7 years
(financial services requirements)
- Contact form submissions: 24 months
- Analytics data: 26 months
- Marketing preferences: Until consent is
withdrawn
When data is no longer needed, we securely delete or anonymise it in accordance with our data
retention schedule.
Your Data Protection Rights
Under UK GDPR, you have the following rights regarding your personal data:
Right to Access
(Subject Access Request)
You have the right to request a copy of the personal data we hold about you. We must respond
within 30 days and provide the information in a commonly used electronic format.
Right to
Rectification
You can request correction of inaccurate or incomplete personal data. We will verify the
information and make corrections promptly.
Right to Erasure
("Right to be Forgotten")
You can request deletion of your personal data in certain circumstances, such as when the data
is no longer necessary or you withdraw consent. This right is subject to legal retention
requirements.
Right to
Restriction of Processing
You can request that we limit processing of your data in specific situations, such as while
disputes about data accuracy are resolved.
Right to Data
Portability
You have the right to receive your data in a structured, machine-readable format and transmit it
to another controller where technically feasible.
Right to Object
You can object to processing based on legitimate interests or for direct marketing purposes. We
will stop processing unless we demonstrate compelling legitimate grounds.
Rights Related to
Automated Decision-Making
You have the right not to be subject to solely automated decisions that significantly affect
you. Our quote comparison uses automated processes, but final decisions are made by you and the
insurers.
To exercise any of these rights:
Email: cheryl@autoviq.com
Phone: +1 (519) 653-6500
Post: Data Protection, ATS Corporation, 133 Creek Road, London, SE8 3BU
We may require proof of identity before processing your request. All requests are handled free
of charge within 30 days.
Security Measures
We implement appropriate technical and organisational measures to protect your personal data:
- Encryption: SSL/TLS encryption for all data
transmission
- Access Controls: Strict access controls
limiting employee access to data on a need-to-know basis
- Network Security: Firewalls, intrusion
detection, and regular security monitoring
- Secure Storage: Data stored in
ISO-certified
data centres with physical security
- Regular Audits: Annual security assessments
and penetration testing
- Staff Training: Regular data protection and
security awareness training
- Incident Response: Documented procedures
for
responding to data breaches
Data Breach Notification
In the event of a personal data breach, we will:
- Notify the Information Commissioner's Office (ICO) within 72
hours of becoming aware of the breach
- Document all personal data breaches and their effects
- Notify affected individuals when the breach is likely to
result in a high risk to their rights and freedoms
- Provide clear information about the nature of the breach and
remedial measures
Data Protection Impact Assessment
Where processing is likely to result in high risk to individuals' rights and freedoms, we
conduct a Data Protection Impact Assessment (DPIA) before processing begins. This includes:
- Systematic description of processing activities
- Assessment of necessity and proportionality
- Identification and assessment of risks
- Measures to address risks and ensure protection
Supervisory Authority
Our primary supervisory authority is the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Website: https://ico.org.uk
ICO Registration: ZA123456 (pending registration update)
You have the right to lodge a complaint with the ICO if you believe we have processed your data
incorrectly or not complied with data protection laws.
Policy Updates
We review this Data Protection Policy regularly and update it as necessary to reflect changes in
our practices or legal requirements. The "Last Updated" date at the top of this page indicates
when the policy was last revised.
For significant changes, we will notify you through email or a prominent notice on our website.
We encourage you to review this policy periodically to stay informed about how we protect your
data.