Privacy Notice
1. Introduction
1.1 Who we are
The Just group of companies (“Just Group”) is made up of a number of different legal entities. The companies that operate as controllers include:
- Just Retirement Limited
- Just Retirement Money Limited
- Just Retirement Management Services Limited
- HUB Financial Solutions Limited
- HUB Pension Consulting Limited
- Partnership Life Assurance Company Limited (PLACL)
- Partnership Services Limited
- Partnership Group Holdings Limited
- Partnership Holdings Limited
- Partnership Home Loans Limited
Where one of our companies is responsible for using your personal data, it will be registered with the Information Commission (ICO), who are the data protection regulator in the UK.
This Privacy Notice is issued on behalf of the Just Group, so when we say “Just”, “we”, “us” or “our” in this Privacy Notice, we are referring to the relevant company in the Just Group responsible for processing your data. We have defined what we mean by “personal data” and “processing” in section 5 of this Privacy Notice.
All Just Group companies have the registered office address of Enterprise House, Bancroft Road, Reigate, Surrey RH2 7RP.
When you purchase a product or service from us, we will tell you which Just company is the data controller of your personal data.
Just Group is part of Brookfield Wealth Solutions Limited group of companies (“BWS”). In some circumstances, companies within BWS may also process your personal data. Where this is the case, we will make you aware of the relevant controller(s) and their responsibilities.
1.2 Purpose of this Privacy Notice
Here at Just, we take the protection and privacy of your personal data very seriously. We want to be clear about what personal data we hold and how we use it, so we have developed this Privacy Notice because we want you to feel confident about the privacy and security of your personal data.
We pride ourselves on being honest and transparent about how we use your personal data and how we will continue to use your personal data fairly and lawfully.
When we refer to relevant data protection laws and regulations, these are based on where you live.
We can make changes to this Privacy Notice from time to time to take into account changes in law or regulations, and if we change how we process your personal data. If we are required to do so under law or regulation, we will notify you about changes.
This Privacy Notice was last updated on 30 September 2026.
1.3. Our product‑specific privacy notices:
We offer a range of financial products and services. When you interact with us, you may be provided with additional privacy information that applies to a specific product or service and explains how your personal data is used in more detail. These notices are designed to work together with this Privacy Notice. However, if there are any differences between them, this Privacy Notice will apply, unless the other privacy information clearly says that it takes precedence over this Privacy Notice.
1.4 Who this notice is for
This document is intended for anyone who provides their personal data to Just or whose personal data we otherwise receive from other sources. You might be classified as any of the following:
- Website/advisor portal user;
- Potential customer/prospect;
- Existing customer;
- Former customer;
- General consumer;
- Member of a pension scheme (including Defined Benefit and bulk purchase annuity schemes);
- Someone whose data we receive in connection with a scheme or products (for example, dependants, beneficiaries, etc.)
- Someone who contacts us (for example, via phone, email or online forms);
- Financial adviser or intermediary;
- Trustee and/or their authorised representative; and/or
- Complainant or claimant.
2. Your personal data
2.1 What personal data do we use?
We collect the following categories of personal data:
|
Category of personal data |
Examples |
|
Identity Data |
Full name; date of birth; age; sex; gender, biometrics, national insurance number |
|
Contact Data
|
Email address; telephone/mobile number; postal/home address including previous address; third party contacts such as a Power of Attorney or solicitor |
|
Family / Beneficiary Data
|
Full name, Contact Data, relationship details, beneficiary details |
|
Service / Product Data
|
Details associated with the services / products we provide you such as policy number; product selections; financial advice; benefit information; application and servicing records |
|
Health Data |
A form of Special Category Data comprising medical conditions including mental and physical capacity; disability information; medical treatment history |
|
Financial Data
|
Pension and retirement savings information; income and financial circumstances; bank account and payment details, bankruptcy history |
|
Criminal Offence Data
|
Criminal conviction records; DBS check results; details of alleged offences |
|
Background Checks/Legal Data
|
Legal documents and searches such as passport, birth and marriage certificates, employment details |
|
Lifestyle Data |
Financial goals, interests, social circumstances, employment details, retirement plans and other fact finding information |
|
Life Event Data |
Details of life events such as marriage or divorce; retirement; bereavement; changes to beneficiaries or dependants; changes affecting your financial circumstances; additional support needs |
|
Technical and Usage Data
|
IP/MAC address; device identifiers; website browsing/activity logs, cookies, analytics |
|
Communications Data
|
Details of email correspondence; call recordings; call summary notes; chat or messaging records |
|
Marketing Preferences Data
|
Email marketing opt-in/opt-out status; preferred communication channel; consent preferences for promotional communications |
|
Market Research, Feedback and User Experience Data
|
Customer satisfaction survey responses; product/service feedback; user testing results or focus group comments |
|
Special Category Data |
Data revealing or inferring Health Data; racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; genetic data; biometric data for identification. |
2.1.1 Where do we get your information from?
We may obtain your personal data including from any of the following:
- from you directly;
- from a legally appointed third party, such as a solicitor or an attorney acting under a Power of Attorney document;
- from your financial intermediary or adviser;
- where you are a member of a Defined Benefit pension arrangement, from pension scheme trustees, scheme administrators or employers, tracing agencies, appointed service providers or other authorised third parties where necessary to verify information or reconnect with scheme members or beneficiaries;
- from a doctor or other authorised medical professional when required (for example, as part of medical underwriting);
- from a family member or friend (for example, where you have been named as a beneficiary on someone else’s policy);
- from official sources, such as HM Revenue & Customs (HMRC), the Department for Work and Pensions (DWP), and social services;
- from other third parties, such as partner companies or identity verification sites; and/or
- if you visit our websites or portals, we may obtain information about you through the cookies and other online trackers on the site.
To use your personal data, data protection laws and regulations say that we must have a lawful basis to do so. At least one of the below must apply at all times:
- Contractual duty: the processing is necessary for the performance of a contract with you (or to take steps to enter into that contract at your request);
- Legal obligation: the processing is necessary to comply with laws or regulations;
- Legitimate interest: the processing is necessary in your, our or a third party’s legitimate interest. We consider and balance any potential impact on you and your rights (both positive and negative) before we process your personal data for our legitimate interests. We will not use your personal data where our legitimate interests are overridden by the impact on you;
- Recognised legitimate interest: the processing is necessary for a legitimate interest which is recognised under the data protection laws and regulations. This currently applies to our processing in the United Kingdom;
- Public task: the processing is necessary for tasks carried out in the public interest or the exercise of an official authority;
- Vital interest: the processing is necessary to protect your or another person’s vital interests; or
- Consent.
From time to time, we may need to obtain and use data about you that is considered to be more sensitive than other information about you (e.g. Health Data or biometric data used to identify you). This is referred to as ‘Special Category Data’ (see how this term is defined in section 5). Data protection laws state we must treat this type of information with more care and must meet more criteria to be able to use it.
To use your Special Category Data, or Criminal Offence Data, data protection laws and regulations say that we must satisfy a condition to do so. At least one of the below must apply at all times:
- Explicit consent; or
- Substantial public interest (including preventing or detecting unlawful acts; preventing fraud; suspicion of terrorist financing or money laundering; regulatory requirements relating to unlawful acts and dishonesty; statutory purposes, equality of treatment, safeguarding individuals at risk, safeguarding of economic well-being of certain individuals, insurance, occupational pensions)
See the next sections for details about why we use your personal data, and the lawful basis and condition (where applicable) for doing so.
2.2 Our purpose for using your personal data and our lawful basis for doing so
|
Purpose of processing |
Types of personal data |
Lawful basis |
|
To contact and communicate with you: We use this information to provide you with the products or services you have asked for and to communicate with you about them.
|
|
in each case, to communicate with you regarding our products or services where your privacy interests, rights and freedoms are not overridden. |
|
To provide you with products or services: Occasionally, we may need to ask you for information about your health or medical conditions, both past and present. There are a few reasons that we may need to do so, including: · The product that you're enquiring about or purchasing is based on medical underwriting, and we are required by law to ask you about your health;
|
|
in each case, to provide you with our products or services where your privacy interests, rights and freedoms are not overridden. Special Category Data:
|
|
To provide you with additional support: We want to ensure that everyone can access the products, services and help that they need, when they need it, in a way that works for them.
|
|
in each case, to provide you with additional support relating to our products or services where your privacy interests, rights and freedoms are not overridden. Special Category Data:
|
|
To carry out background and identity checks: We may be required to carry out background and identity checks to provide you with products or services.
|
|
in each case, to allow us to provide you with our products or services where your privacy interests, rights and freedoms are not overridden. Special Category Data and Criminal Offence Data:
|
|
To track your use of our website or portals: To keep everything working on our website or portals as they should, keep our technology and your data safe and provide useful insights to help improve our services.
|
|
to keep everything working on our website or portals where your privacy interests, rights and freedoms are not overridden. |
|
To send marketing communications to you: We’d like to keep you up to date on relevant information, articles, events, services and products that we think may be of interest to you or that relate to your existing relationship with us. We may also share information about products and services of third parties. We will only send you marketing where we are permitted to do so under data protection laws and regulations. You can update your marketing preferences at any time by contacting us directly.
We’ll never sell your data for marketing purposes. In line with the Financial Conduct Authority’s Consumer Duty standards, we’re required to send you ‘transactional’ communications which are factual only and are separate to marketing emails. |
|
to provide you with marketing where your privacy interests, rights and freedoms are not overridden.
|
|
To undertake market research and feedback: We may also ask you to take part in market research or to provide your feedback and opinions. |
|
to better understand the market and our role within it where your privacy interests, rights and freedoms are not overridden. |
|
To investigate any actual or suspected criminal activity (including to prevent and detect fraud) |
|
to investigate any actual or suspected criminal activity, including to better minimise fraud, that could be damaging for us and for you, where your privacy interests, rights and freedoms are not overridden Special Category Data and Criminal Offence Data:
|
|
To comply with regulatory, legal and security requirements |
|
to maintain compliance standards in line with regulatory expectations and security requirements where your privacy interests, rights and freedoms are not overridden.
Special Category Data: Substantial public interest (including regulatory requirements relating to unlawful acts and dishonesty, preventing or detecting unlawful acts; preventing fraud; suspicion of terrorist financing or money laundering; safeguarding individuals at risk, safeguarding of economic well-being of certain individuals). |
|
To enforce our rights under our contracts and defend claims |
|
to protect our legal interests where your privacy interests, rights and freedoms are not overridden. Special Category Data: Substantial public interest (including preventing or detecting unlawful acts; preventing fraud; suspicion of terrorist financing or money laundering; safeguarding individuals at risk, safeguarding of economic well-being of certain individuals, insurance, occupational pensions). |
|
To manage and improve our day-to-day business operations and the services and products we provide to you |
|
manage and improve our day-to-day business operations and the services and products we provide to you where your privacy interests, rights and freedoms are not overridden
Special Category Data: Substantial public interest (equality of treatment, insurance, occupational pensions) |
2.3 How long will you keep my data for?
We’ll only ever keep your personal data for as long as it is required, and this may differ depending on the reason we asked for or required your information in the first place. However, our standard retention periods are:
- up to 18 months for enquiries of services, products or advice that is not proceeded with;
- up to 7 years after the end of the product, service or contract;
- If you are a Defined Benefit member: Indefinitely for defined benefit pension transfer advice. When we stop providing our services, we will then keep your personal data for up to 7 years from the date that the last beneficiary of the group of policyholders you are associated with has died. This lets us meet our legal and regulatory obligations to exercise, manage or defend legal rights and claims.
- In some circumstances, we may need to retain your information even where you exercise your data protection rights, including the right to erasure. This may be necessary to comply with legal, regulatory, contractual, audit, fraud prevention, litigation, pensions administration or record-keeping obligations.
2.4 Sharing and transferring data
We may need to share some of your personal data with other companies including:
- Other companies within the Just Group or our parent company.
- Other financial companies that we work with to provide our services, such as financial intermediaries, advisers, introducers, brokers, providers, underwriters, reinsurers and/or other authorised business partners;
- Our technology providers, or other support services such as product administration, IT support services, data analysis, etc;
- Companies that process payments on our behalf;
- Regulators and/or public authorities, who have a legal right to request and process your personal data; and/or
- Other companies in the event we undergo a reorganisation or are sold to, merged with, or transferred to, a third party.
- If you are a member of a Defined Benefit pension scheme, scheme trustees, administrators, trustees’ professional advisers (including actuarial and legal advisers), AVC solution providers, tracing agencies, third-party administrators, financial intermediaries, reinsurers and other service providers where necessary to provide and manage the scheme arrangement, including risk transfer and ongoing administration.
- Product providers, underwriters and reinsurers for purposes including risk assessment, fraud prevention and detection, regulatory compliance, administration, management information, business reporting, statistical analysis, product performance monitoring and onward reinsurance arrangements.
- Third parties if required by law, by a court order, if we believe that such action is necessary to prevent fraud or cybercrime, or to protect the right, property or personal safety of any person. Third parties such as public authorities and service providers where we believe there may be a risk of harm to you or to provide you with assistance, as well as your financial advisor, nominated representative or another person authorised to act or communicate on your behalf.
We will only share your Special Category Data with third parties with your explicit consent, unless legal or safeguarding obligations require us to do so.
2.5 Transfer of data outside the UK
We may be required to transfer your personal data to product providers and/or other third parties who help us to run our day-to-day business or provide our products and services. Sometimes, these recipients (or their processors) are based outside of the UK and may not be held to the same high standards of data protection laws and regulations as we are.
If we transfer your personal data outside of the UK, we will do so in compliance with the relevant data protection laws and regulations which may require us to rely on: (a) a lawful exception to the rules for overseas transfers (for example, you have given your explicit consent); (b) a decision that the laws of the country provide an adequate level of protection of your personal data (known as an adequacy decision); or (c) appropriate safeguards in respect of the transfer (for example, by putting in place standard contractual clauses or international data transfer agreements approved under data protection laws and regulations).
Please contact us if you would like further information on the measures taken to safeguard your data.
2.6 Automated decision-making (ADM) and profiling
Automated decision-making involves using personal data, analysis and algorithms to make decisions about you.
There are times when we use automated means to make decisions (without a human or human intervention) that may have a significant impact on you. For example:
- Running anti-money laundering and sanctions checks, as part of our legal requirements; or
- Quotes, underwriting, lending and actuarial calculations to determine what products and rates we can offer to you.
If a decision is made solely by automated means and has a legal or similarly significant effect on you, you have the right to:
- ask for the decision to be reviewed by a person;
- share your views; and
- challenge the outcome.
2.7 How we use Artificial Intelligence (AI)
We may use AI in areas such as underwriting, risk assessment, fraud prevention, data validation, information verification, quality assurance, data integrity checking and supporting operational activities. Where we use AI involving personal data, we apply governance and risk-based controls appropriate to the use case and in compliance with data protection laws and regulation. These may include human oversight, testing, monitoring, security controls and contractual requirements for suppliers.
3. Your data rights
Under data protection law and regulation, you have specific rights as follows:
- Your right of access: You have the right to ask us about the information we hold about you, how we use it and for copies of your personal data;
- Your right to rectification: You have the right to ask us to correct personal data that you think is inaccurate. You also have the right to ask us to complete information that you think is incomplete;
- Your right to erasure: You have the right to ask us to erase your personal data in certain circumstances;
- Your right to restriction of processing: You have the right to ask us to limit the processing of your personal data in certain circumstances;
- Your right to object to processing: You have the right to oppose to the processing of your personal data in certain circumstances;
- You have the right to object to marketing and your personal data used for marketing purposes;
- Your right to data portability: You have the right to ask that we transfer the personal data you gave us to another organisation, or to you, in certain circumstances; and
- Your right to withdraw consent: When we use consent as our lawful basis you have the right to withdraw your consent.
If you make a rights request, we have one calendar month to respond to you. That time may be paused if we need any additional information or to confirm your identity.
- Your right to make a complaint (“data protection complaints”): In the United Kingdom, you also have the right to make a complaint to us if you have any concerns about how we handle your personal data.
For data protection complaints, the legal timeline is slightly different: We will acknowledge your complaint within 30 (thirty) days and aim to respond without undue delay.
Requests for copies of your personal data will normally be provided free of charge. However, where requests are repetitive, manifestly unfounded or excessive, we may charge you a reasonable fee to cover the administrative costs of providing the information or may refuse to act on the request.
To make a data protection rights request or a data protection complaint please contact us using the contact details in section 4 of this Privacy Notice.
For more information about your rights you can contact the data protection regulator, the Information Commission (ICO) – www.ico.org.uk
4. How to contact us
You can contact us at any time:
You can contact us anytime for any of the following reasons:
- To ask questions or share comments about this Privacy Notice;
- To ask for more information about how your data is used,
- To change your preferences,
- To exercise any of your data rights,
- To make a complaint; and/or
- To express a concern.
You can contact us by:
- By Email: dataprotection@wearejust.co.uk
- By Post: Data Protection Officer, Just Group plc, Enterprise House, Bancroft Road, Reigate, Surrey, RH2 7RP
If you are not satisfied with our response or how we have managed your data, you also have the right to lodge a complaint with the data protection regulator for your area of residency:
- For the UK: Information Commission (ICO).
Address: Information Commission, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Website: ico.org.uk/make-a-complaint
- For Jersey: Jersey Office of the Information Commissioner (JOIC)
Address: 2nd Floor, 5 Castle Street, St. Helier, Jersey, JE2 3BT
Helpline: +44 (0)1534 716 530
Website: jerseyoic.org
- For Guernsey: Office of the Data Protection Authority (ODPA)
Address: Block A, Lefebvre Court, Lefebvre Street, St Peter Port, Guernsey, GY1 2JP
Helpline: +44 (0)1481 742 074
Website: odpa.gg
- For the Isle of Man: Isle of Man Information Commissioner
Address: Isle of Man Information Commissioner, P.O. Box 69, Douglas, Isle of Man, IM99 1EQ
Helpline: +44 (0)1624 693 260
Website: inforights.im
5. Definitions
5.1 What is personal data?
Under the UK GDPR, ‘personal data’ is referred to as ‘information relating to an identified or identifiable natural person’. Really, it’s just information about you.
Personal data can include (but is not limited to) your:
- name;
- date of birth and/or age;
- residential address;
- email address;
- telephone number;
- location or tracking data, such as IP address;
- National Insurance Number (NINO), passport number and other unique identifiers;
- policy number; and/or
- physical, physiological, genetic, mental, economic, cultural or social identity details.
5.2 What is processing?
‘Processing’ refers to any action that we take with your personal data. It includes (but isn’t limited to):
- obtaining;
- recording (either electronically or on physical documents);
- storing;
- amending;
- organising or restructuring;
- sharing (both internally and in some instances, with other companies);
- accessing;
- using your data in quotations, policy administration, analysis and reporting; and/or
- deletion.