Privacy Notice
Logo
Search
Menu

Privacy Notice

Not a promotional message. Important update to Just's privacy notice

Privacy Notice

1. Introduction 

 1.1 Who we are 

The Just group of companies (“Just Group”) is made up of a number of different legal entities. The companies that operate as controllers include: 

  • Just Retirement Limited 
  • Just Retirement Money Limited 
  • Just Retirement Management Services Limited 
  • HUB Financial Solutions Limited 
  • HUB Pension Consulting Limited 
  • Partnership Life Assurance Company Limited (PLACL) 
  • Partnership Services Limited 
  • Partnership Group Holdings Limited 
  • Partnership Holdings Limited
  • Partnership Home Loans Limited

Where one of our companies is responsible for using your personal data, it will be registered with the Information Commission (ICO), who are the data protection regulator in the UK.

This Privacy Notice is issued on behalf of the Just Group, so when we say “Just”, “we”, “us” or “our” in this Privacy Notice, we are referring to the relevant company in the Just Group responsible for processing your data. We have defined what we mean by “personal data” and “processing” in section 5 of this Privacy Notice.

All Just Group companies have the registered office address of Enterprise House, Bancroft Road, Reigate, Surrey RH2 7RP.

When you purchase a product or service from us, we will tell you which Just company is the data controller of your personal data. 

Just Group is part of Brookfield Wealth Solutions Limited group of companies (“BWS”). In some circumstances, companies within BWS may also process your personal data. Where this is the case, we will make you aware of the relevant controller(s) and their responsibilities.

1.2 Purpose of this Privacy Notice 

Here at Just, we take the protection and privacy of your personal data very seriously. We want to be clear about what personal data we hold and how we use it, so we have developed this Privacy Notice because we want you to feel confident about the privacy and security of your personal data. 

We pride ourselves on being honest and transparent about how we use your personal data and how we will continue to use your personal data fairly and lawfully. 

When we refer to relevant data protection laws and regulations, these are based on where you live.

We can make changes to this Privacy Notice from time to time to take into account changes in law or regulations, and if we change how we process your personal data. If we are required to do so under law or regulation, we will notify you about changes.

This Privacy Notice was last updated on 30 September 2026.

1.3. Our product‑specific privacy notices:

We offer a range of financial products and services. When you interact with us, you may be provided with additional privacy information that applies to a specific product or service and explains how your personal data is used in more detail. These notices are designed to work together with this Privacy Notice. However, if there are any differences between them, this Privacy Notice will apply, unless the other privacy information clearly says that it takes precedence over this Privacy Notice.

1.4 Who this notice is for 

This document is intended for anyone who provides their personal data to Just or whose personal data we otherwise receive from other sources. You might be classified as any of the following: 

  • Website/advisor portal user; 
  • Potential customer/prospect; 
  • Existing customer; 
  • Former customer; 
  • General consumer; 
  • Member of a pension scheme (including Defined Benefit and bulk purchase annuity schemes); 
  • Someone whose data we receive in connection with a scheme or products (for example, dependants, beneficiaries, etc.)
  • Someone who contacts us (for example, via phone, email or online forms);
  • Financial adviser or intermediary;
  • Trustee and/or their authorised representative; and/or
  • Complainant or claimant.

2. Your personal data 

2.1 What personal data do we use? 

We collect the following categories of personal data:           

Category of personal data

Examples

Identity Data 

Full name; date of birth; age; sex; gender, biometrics, national insurance number

Contact Data 

 

Email address; telephone/mobile number; postal/home address including previous address; third party contacts such as a Power of Attorney or solicitor

Family / Beneficiary Data

 

Full name, Contact Data, relationship details, beneficiary details

Service / Product Data

 

Details associated with the services / products we provide you such as policy number; product selections; financial advice; benefit information; application and servicing records

Health Data

A form of Special Category Data comprising  medical conditions including mental and physical capacity; disability information; medical treatment history

Financial Data

 

Pension and retirement savings information; income and financial circumstances; bank account and payment details, bankruptcy history

Criminal Offence Data

 

Criminal conviction records; DBS check results; details of alleged offences

Background Checks/Legal Data

 

Legal documents and searches such as passport, birth and marriage certificates, employment details

Lifestyle Data

Financial goals, interests, social circumstances, employment details, retirement plans and other fact finding information

Life Event Data

Details of life events such as marriage or divorce; retirement; bereavement; changes to beneficiaries or dependants; changes affecting your financial circumstances; additional support needs

Technical and Usage Data

 

IP/MAC address; device identifiers; website browsing/activity logs, cookies, analytics

Communications Data

 

Details of email correspondence; call recordings; call summary notes; chat or messaging records

Marketing Preferences Data

 

Email marketing opt-in/opt-out status; preferred communication channel; consent preferences for promotional communications

Market Research, Feedback and User Experience Data

 

Customer satisfaction survey responses; product/service feedback; user testing results or focus group comments

Special Category Data

Data revealing or inferring Health Data; racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; genetic data; biometric data for identification.

 

2.1.1 Where do we get your information from? 

We may obtain your personal data including from any of the following: 

  • from you directly; 
  • from a legally appointed third party, such as a solicitor or an attorney acting under a Power of Attorney document; 
  • from your financial intermediary or adviser; 
  • where you are a member of a Defined Benefit pension arrangement, from pension scheme trustees, scheme administrators or employers, tracing agencies, appointed service providers or other authorised third parties where necessary to verify information or reconnect with scheme members or beneficiaries;
  • from a doctor or other authorised medical professional when required (for example, as part of medical underwriting);
  • from a family member or friend (for example, where you have been named as a beneficiary on someone else’s policy); 
  • from official sources, such as HM Revenue & Customs (HMRC), the Department for Work and Pensions (DWP), and social services; 
  • from other third parties, such as partner companies or identity verification sites; and/or
  • if you visit our websites or portals, we may obtain information about you through the cookies and other online trackers on the site.

To use your personal data, data protection laws and regulations say that we must have a lawful basis to do so. At least one of the below must apply at all times: 

  • Contractual duty: the processing is necessary for the performance of a contract with you (or to take steps to enter into that contract at your request); 
  • Legal obligation: the processing is necessary to comply with laws or regulations; 
  • Legitimate interest: the processing is necessary in your, our or a third party’s legitimate interest. We consider and balance any potential impact on you and your rights (both positive and negative) before we process your personal data for our legitimate interests. We will not use your personal data where our legitimate interests are overridden by the impact on you;
  • Recognised legitimate interest: the processing is necessary for a legitimate interest which is recognised under the data protection laws and regulations. This currently applies to our processing in the United Kingdom;  
  • Public task: the processing is necessary for tasks carried out in the public interest or the exercise of an official authority; 
  • Vital interest: the processing is necessary to protect your or another person’s vital interests; or 
  • Consent. 

From time to time, we may need to obtain and use data about you that is considered to be more sensitive than other information about you (e.g. Health Data or biometric data used to identify you). This is referred to as ‘Special Category Data’ (see how this term is defined in section 5). Data protection laws state we must treat this type of information with more care and must meet more criteria to be able to use it. 

To use your Special Category Data, or Criminal Offence Data, data protection laws and regulations say that we must satisfy a condition to do so. At least one of the below must apply at all times:

  • Explicit consent; or
  • Substantial public interest (including preventing or detecting unlawful acts; preventing fraud; suspicion of terrorist financing or money laundering; regulatory requirements relating to unlawful acts and dishonesty; statutory purposes, equality of treatment, safeguarding individuals at risk, safeguarding of economic well-being of certain individuals, insurance, occupational pensions)

See the next sections for details about why we use your personal data, and the lawful basis and condition (where applicable) for doing so. 

2.2 Our purpose for using your personal data and our lawful basis for doing so

Purpose of processing

Types of personal data

Lawful basis

To contact and communicate with you:

We use this information to provide you with the products or services you have asked for and to communicate with you about them. 

 

  • Identity Data
  • Contact Data
  • Communications Data

 

  • Contractual
  • Legal obligations
  • Consent
  • Legitimate interest and recognised legitimate interest,

in each case, to communicate with you regarding our products or services where your privacy interests, rights and freedoms are not overridden. 

To provide you with products or services:

Occasionally, we may need to ask you for information about your health or medical conditions, both past and present. There are a few reasons that we may need to do so, including: 

·         The product that you're enquiring about or purchasing is based on medical underwriting, and we are required by law to ask you about your health;

  • The product that you're enquiring about or purchasing may be enhanced by medical underwriting, and you may be able to get a better deal by providing us with your medical information;
  • Identity Data
  • Contact Data
  • Communications Data
  • Family / Beneficiary Data
  • Service / Product Data
  • Health Data
  • Financial Data
  • Criminal Offence Data
  • Background Checks/Legal Data
  • Lifestyle Data
  • Life Event Data
  • Special Category Data
  • Contractual
  • Legal obligations
  • Consent
  • Legitimate interest, and recognised legitimate interest,

in each case, to provide you with our products or services where your privacy interests, rights and freedoms are not overridden.

Special Category Data:

  • Explicit consent
  • Substantial public interest (including safeguarding of economic well-being of certain individuals, insurance, occupational pensions).

 

To provide you with additional support:

We want to ensure that everyone can access the products, services and help that they need, when they need it, in a way that works for them. 

 

  • Health Data
  • Financial Data
  • Life Event Data
  • Family / Beneficiary Data
  • Special Category Data

 

  • Contractual
  • Legal obligations
  • Consent
  • Legitimate interest and recognised legitimate interest,

in each case, to provide you with additional support relating to our products or services where your privacy interests, rights and freedoms are not overridden.

Special Category Data:

  • Explicit consent
  • Substantial public interest (including statutory purposes, equality of treatment, safeguarding individuals at risk, safeguarding of economic well-being of certain individuals). 

To carry out background and identity checks:

We may be required to carry out background and identity checks to provide you with products or services.  

 

  • Identity Data
  • Contact Data
  • Financial Data
  • Background Checks/Legal Data
  • Lifestyle Data
  • Criminal Offence Data
  • Special Category Data

 

  • Contractual
  • Legal obligations
  • Consent
  • Legitimate interest and recognised legitimate interest,

in each case, to allow us to provide you with our products or services where your privacy interests, rights and freedoms are not overridden.

Special Category Data and Criminal Offence Data:

  • Explicit consent
  • Substantial public interest (including preventing or detecting unlawful acts; preventing fraud; suspicion of terrorist financing or money laundering). 

To track your use of our website or portals:

To keep everything working on our website or portals as they should, keep our technology and your data safe and provide useful insights to help improve our services. 

 

  • Technical and Usage Data 

 

  • Legal obligations
  • Consent
  • Legitimate interest

to keep everything working on our website or portals where your privacy interests, rights and freedoms are not overridden.

To send marketing communications to you:

We’d like to keep you up to date on relevant information, articles, events, services and products that we think may be of interest to you or that relate to your existing relationship with us. We may also share information about products and services of third parties.

We will only send you marketing where we are permitted to do so under data protection laws and regulations. You can update your marketing preferences at any time by contacting us directly.

 

We’ll never sell your data for marketing purposes. In line with the Financial Conduct Authority’s Consumer Duty standards, we’re required to send you ‘transactional’ communications which are factual only and are separate to marketing emails.

  • Marketing Preference Data 
  • Identity Data
  • Contact Data
  • Communications Data
  • Service / Product Data

 

  • Consent
  • Legitimate interest,

to provide you with marketing where your privacy interests, rights and freedoms are not overridden.

 

To undertake market research and feedback:

We may also ask you to take part in market research or to provide your feedback and opinions.

  • Identity Data
  • Contact Data
  • Communications Data
  • Market Research, Feedback and User Experience Data
  • Consent
  • Legitimate interest,

to better understand the market and our role within it where your privacy interests, rights and freedoms are not overridden. 

To investigate any actual or suspected criminal activity (including to prevent and detect fraud)

  • Identity Data
  • Contact Data
  • Service / Product Data
  • Background Checks/Legal Data
  • Special Category Data
  • Criminal Convictions Data
  • Legal obligations
  • Legitimate interest,

to investigate any actual or suspected criminal activity, including to better minimise fraud, that could be damaging for us and for you, where your privacy interests, rights and freedoms are not overridden 

Special Category Data and Criminal Offence Data:

  • Substantial public interest (including regulatory requirements relating to unlawful acts and dishonesty,  preventing or detecting unlawful acts; preventing fraud; suspicion of terrorist financing or money laundering). 

To comply with regulatory, legal and security requirements

  • Identity Data
  • Contact Data
  • Communications Data
  • Service / Product Data
  • Background Checks/Legal Data
  • Technical and Usage Data
  • Special Category Data

 

  • Legal obligations
  • Legitimate interest,

to maintain compliance standards in line with regulatory expectations and security requirements where your privacy interests, rights and freedoms are not overridden.

 

Special Category Data:

Substantial public interest (including regulatory requirements relating to unlawful acts and dishonesty, preventing or detecting unlawful acts; preventing fraud; suspicion of terrorist financing or money laundering;  safeguarding individuals at risk, safeguarding of economic well-being of certain individuals). 

To enforce our rights under our contracts and defend claims

  • Identity Data
  • Contact Data
  • Communications Data
  • Service / Product Data
  • Special Category Data

 

 

  • Legitimate interest,

to protect our legal interests where your privacy interests, rights and freedoms are not overridden.

Special Category Data:

Substantial public interest (including preventing or detecting unlawful acts; preventing fraud; suspicion of terrorist financing or money laundering; safeguarding individuals at risk, safeguarding of economic well-being of certain individuals, insurance, occupational pensions). 

To manage and improve our day-to-day business operations and the services and products we provide to you

  • Identity Data
  • Contact Data
  • Communications Data
  • Service / Product Data
  • Market Research, Feedback and User Experience Data
  • Special Category Data

 

  • Legitimate interest,

manage and improve our day-to-day business operations and the services and products we provide to you where your privacy interests, rights and freedoms are not overridden

 

Special Category Data:

Substantial public interest (equality of treatment, insurance, occupational pensions)

 

2.3 How long will you keep my data for? 

We’ll only ever keep your personal data for as long as it is required, and this may differ depending on the reason we asked for or required your information in the first place. However, our standard retention periods are: 

  • up to 18 months for enquiries of services, products or advice that is not proceeded with; 
  • up to 7 years after the end of the product, service or contract; 
  • If you are a Defined Benefit member: Indefinitely for defined benefit pension transfer advice. When we stop providing our services, we will then keep your personal data for up to 7 years from the date that the last beneficiary of the group of policyholders you are associated with has died. This lets us meet our legal and regulatory obligations to exercise, manage or defend legal rights and claims. 
  • In some circumstances, we may need to retain your information even where you exercise your data protection rights, including the right to erasure. This may be necessary to comply with legal, regulatory, contractual, audit, fraud prevention, litigation, pensions administration or record-keeping obligations.

2.4 Sharing and transferring data 

We may need to share some of your personal data with other companies including: 

  • Other companies within the Just Group or our parent company.
  • Other financial companies that we work with to provide our services, such as financial intermediaries, advisers, introducers, brokers, providers, underwriters, reinsurers and/or other authorised business partners; 
  • Our technology providers, or other support services such as product administration, IT support services, data analysis, etc; 
  • Companies that process payments on our behalf; 
  • Regulators and/or public authorities, who have a legal right to request and process your personal data; and/or
  • Other companies in the event we undergo a reorganisation or are sold to, merged with, or transferred to, a third party. 
  • If you are a member of a Defined Benefit pension scheme, scheme trustees, administrators, trustees’ professional advisers (including actuarial and legal advisers), AVC solution providers, tracing agencies, third-party administrators, financial intermediaries, reinsurers and other service providers where necessary to provide and manage the scheme arrangement, including risk transfer and ongoing administration.
  • Product providers, underwriters and reinsurers for purposes including risk assessment, fraud prevention and detection, regulatory compliance, administration, management information, business reporting, statistical analysis, product performance monitoring and onward reinsurance arrangements.
  • Third parties if required by law, by a court order, if we believe that such action is necessary to prevent fraud or cybercrime, or to protect the right, property or personal safety of any person. Third parties such as public authorities and service providers where we believe there may be a risk of harm to you or to provide you with assistance, as well as your financial advisor, nominated representative or another person authorised to act or communicate on your behalf.

We will only share your Special Category Data with third parties with your explicit consent, unless legal or safeguarding obligations require us to do so.

2.5 Transfer of data outside the UK 

We may be required to transfer your personal data to product providers and/or other third parties who help us to run our day-to-day business or provide our products and services. Sometimes, these recipients (or their processors) are based outside of the UK and may not be held to the same high standards of data protection laws and regulations as we are. 

If we transfer your personal data outside of the UK, we will do so in compliance with the relevant data protection laws and regulations which may require us to rely on: (a) a lawful exception to the rules for overseas transfers (for example, you have given your explicit consent); (b) a decision that the laws of the country provide an adequate level of protection of your personal data (known as an adequacy decision); or (c) appropriate safeguards in respect of the transfer (for example, by putting in place standard contractual clauses or international data transfer agreements approved under data protection laws and regulations).

Please contact us if you would like further information on the measures taken to safeguard your data.

2.6 Automated decision-making (ADM) and profiling 

Automated decision-making involves using personal data, analysis and algorithms to make decisions about you.

There are times when we use automated means to make decisions (without a human or human intervention) that may have a significant impact on you. For example: 

  • Running anti-money laundering and sanctions checks, as part of our legal requirements; or 
  • Quotes, underwriting, lending and actuarial calculations to determine what products and rates we can offer to you. 

If a decision is made solely by automated means and has a legal or similarly significant effect on you, you have the right to:

  • ask for the decision to be reviewed by a person;
  • share your views; and
  • challenge the outcome.

2.7 How we use Artificial Intelligence (AI)

We may use AI in areas such as underwriting, risk assessment, fraud prevention, data validation, information verification, quality assurance, data integrity checking and supporting operational activities. Where we use AI involving personal data, we apply governance and risk-based controls appropriate to the use case and in compliance with data protection laws and regulation. These may include human oversight, testing, monitoring, security controls and contractual requirements for suppliers.

3. Your data rights 

Under data protection law and regulation, you have specific rights as follows: 

  • Your right of access: You have the right to ask us about the information we hold about you, how we use it and for copies of your personal data; 
  • Your right to rectification: You have the right to ask us to correct personal data that you think is inaccurate. You also have the right to ask us to complete information that you think is incomplete; 
  • Your right to erasure: You have the right to ask us to erase your personal data in certain circumstances;
  • Your right to restriction of processing: You have the right to ask us to limit the processing of your personal data in certain circumstances; 
  • Your right to object to processing: You have the right to oppose to the processing of your personal data in certain circumstances;
  • You have the right to object to marketing and your personal data used for marketing purposes; 
  • Your right to data portability: You have the right to ask that we transfer the personal data you gave us to another organisation, or to you, in certain circumstances; and 
  • Your right to withdraw consent: When we use consent as our lawful basis you have the right to withdraw your consent.

If you make a rights request, we have one calendar month to respond to you. That time may be paused if we need any additional information or to confirm your identity. 

  • Your right to make a complaint (“data protection complaints”): In the United Kingdom, you also have the right to make a complaint to us if you have any concerns about how we handle your personal data.

For data protection complaints, the legal timeline is slightly different: We will acknowledge your complaint within 30 (thirty) days and aim to respond without undue delay.

Requests for copies of your personal data will normally be provided free of charge. However, where requests are repetitive, manifestly unfounded or excessive, we may charge you a reasonable fee to cover the administrative costs of providing the information or may refuse to act on the request. 

To make a data protection rights request or a data protection complaint please contact us using the contact details in section 4 of this Privacy Notice. 

For more information about your rights you can contact the data protection regulator, the Information Commission (ICO) – www.ico.org.uk 

4. How to contact us 

 You can contact us at any time:

You can contact us anytime for any of the following reasons: 

  • To ask questions or share comments about this Privacy Notice; 
  • To ask for more information about how your data is used, 
  • To change your preferences, 
  • To exercise any of your data rights,
  • To make a complaint; and/or 
  • To express a concern. 

You can contact us by:

  • By Email: dataprotection@wearejust.co.uk 
  • By Post: Data Protection Officer, Just Group plc, Enterprise House, Bancroft Road, Reigate, Surrey, RH2 7RP 

If you are not satisfied with our response or how we have managed your data, you also have the right to lodge a complaint with the data protection regulator for your area of residency:

  • For the UK: Information Commission (ICO).

Address: Information Commission, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Helpline: 0303 123 1113

Website: ico.org.uk/make-a-complaint

  • For Jersey: Jersey Office of the Information Commissioner (JOIC)

Address: 2nd Floor, 5 Castle Street, St. Helier, Jersey, JE2 3BT

Helpline: +44 (0)1534 716 530

Website: jerseyoic.org

  • For Guernsey: Office of the Data Protection Authority (ODPA)

Address: Block A, Lefebvre Court, Lefebvre Street, St Peter Port, Guernsey, GY1 2JP

Helpline: +44 (0)1481 742 074

Website: odpa.gg

  • For the Isle of Man: Isle of Man Information Commissioner

Address: Isle of Man Information Commissioner, P.O. Box 69, Douglas, Isle of Man, IM99 1EQ

Helpline: +44 (0)1624 693 260

Website: inforights.im

5. Definitions 

5.1 What is personal data? 

Under the UK GDPR, ‘personal data’ is referred to as ‘information relating to an identified or identifiable natural person’. Really, it’s just information about you. 

Personal data can include (but is not limited to) your: 

  • name; 
  • date of birth and/or age; 
  • residential address; 
  • email address; 
  • telephone number;  
  • location or tracking data, such as IP address;  
  • National Insurance Number (NINO), passport number and other unique identifiers; 
  • policy number; and/or 
  • physical, physiological, genetic, mental, economic, cultural or social identity details. 

5.2 What is processing? 

‘Processing’ refers to any action that we take with your personal data. It includes (but isn’t limited to): 

  • obtaining; 
  • recording (either electronically or on physical documents); 
  • storing; 
  • amending; 
  • organising or restructuring; 
  • sharing (both internally and in some instances, with other companies); 
  • accessing; 
  • using your data in quotations, policy administration, analysis and reporting; and/or 
  • deletion.