Privacy Policy

Global Privacy Policy

Last updated: April 2026

World Travel Protection Pty Ltd (company number: ABN 80 079 071 579),  World Travel Protection Canada Inc. (company number 131418865) and World Travel Protection Limited (company number: 10577959), (collectively “World Travel Protection”), divisions of the Cover-More Group Limited (company number: ABN 79 166 776 334), which is owned by Zurich Insurance Company AG (company number: Che-105.833.144), are committed to protecting the privacy and security of the personal information we collect in the course of providing products and services to our customers.  The World Travel Protection entities that are listed above each perform distinct services that may not apply to your situation.  This Global Privacy Policy is designed to encompass all of the services provided by each entity, so references to the sale of insurance policies, for example, may not apply to your specific situation.  However, the aim of this Global Privacy Policy is to inform you about the way in which we collect, process, and handle your personal information, as well as your rights and options.

World Travel Protection is the data controller for information that you provide for the purposes outlined below. World Travel Protection may share your personal data with or receive your personal data from other data controllers such as telehealth services and hospitals.

Purposes for Processing

World Travel Protection process your personal data for the following purposes:

Medical assistance

Technical assistance

Security assistance

Administering and/or servicing insurance policies

Handling a claim/working with an insurer to assess if a claim is covered by an insurance policy

Providing you with the services of Travel Assist by WTP

Cyber assistance

Legal Basis for Processing

We rely on the following legal bases under Article 6 GDPR for processing your personal data:

Consent

Performance of a contract

Vital interests

Legitimate interests

Under Article 9 GDPR, we rely on the following legal bases for processing your special category data:

Explicit consent

Vital interests where the data subject is physically or legally incapable of giving consent

Necessary for the provision of health or social care or treatment or the management of health or social care systems and services

Recipients of Data

Personal information may be shared with companies affiliated with the Zurich Insurance Group Ltd., and non-affiliated third parties in Canada, the United States, the United Kingdom, Australia and other countries abroad in order to fulfil the purposes outlined above, and as otherwise permitted or required by law. The following categories of recipients may be involved:

Telehealth Services

Hospitals

Repatriation service providers

Air Ambulances

Commercial Airlines

Translation Services

Insurers

Assistance Companies

Travel Assist

IT service providers 

Security and Cyber assistance services

Other World Travel Protection entities

Categories of Personal Data Processed

For the purposes outlined above, World Travel Protection collect, process, hold and store the following categories of personal data:

Identity Data: first name, surname, email address, home address, telephone number, mobile number, date of birth, gender, location, nationality, insurance details, copy of passport, copy of driving license, next of kin if customer is incapacitated, GHIC or EHIC card details

Financial Data: Credit card statement/s 

Medical Data: any information relating to existing medical conditions, current medical status, injuries sustained while travelling, medical diagnosis, details of assault

Travel Data: flight details, policy issued start date and end date, car rental information, motorbike rental information

Technical Data/Metadata: includes internet protocol (IP) address, unique mobile device identification numbers (such as your Media Access Control (MAC) address, and/or International Mobile Equipment Identity (IMEI), type of device, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our website

Transfer to a Third Country

World Travel Protection may transfer your personal data to other countries in the course of providing services to you. There is an intergroup agreement in place with the other entities of World Travel Protection. When transferring your personal data to countries that are outside of the European Economic Area (EEA) or the United Kingdom (UK), we will ensure that it is protected and that the transfer is lawful.  A Data Transfer Impact Assessment is conducted prior to the transfer, and we will ensure appropriate safeguards are in place in such as the UK International Data Transfer Agreement (IDTA), UK Addendum to EU Standard Contractual Clauses or Standard Contractual Clauses are implemented where required. In instances where data is transferred outside of the EEA or UK without the safeguards and mechanisms in place, we do so in accordance with our legal bases of fulfilling a contract, health and professional services and your explicit consent.

Retention of Data

WTP will retain your personal data in accordance with our record retention policy. This policy operates on the principle that we retain personal data for no longer than is necessary for the purpose for which it was collected. It is also kept in accordance with any legal requirements that are imposed on us. This means that the retention period for your personal data will vary depending on the type of personal data.

Data Received from a Third Party

Personal information may be collected from such sources as our affiliates, Travel Assist,  independent insurance brokers, other financial institutions, credit bureaus, government departments, claims organizations, a policyholder, a customer, a customer’s employee, a customer’s Travel Management Company (TMC), a claimant, a claimant’s employer or a claimant’s employee. We may collect personal information from persons who witnessed incidents, or persons retained by a claimant or by us in the process of administering or servicing a policy, providing assistance or security services or handling a claim. Such people might include physicians, lawyers, accountants, repair shops, consumer reporting agencies and appraisers as permitted or required by law.

Your health information, such as pre-existing medical conditions, is generally required to arrange travel insurance, to make a determination on a claim or to provide you with medical assistance.  If you make a telephone call into one of our service centres, the call may be recorded for training and quality control purposes. You will be informed if your call is being recorded.

If you provide health information to your agent or consultant to provide to us as part of the policy application or claims process, we rely on you having provided them with your consent to disclose this information to us. In addition, when you provide information, including sensitive information about other individuals on your travel insurance policy, we rely on you to inform them of the information you are providing, how we will use, hold, collect and disclose this information and on you obtaining their consent.

Technical and Organisational Measures

In order to secure your personal data, World Travel Protection have implemented appropriate technical and organisational measures. Access to personal information is limited to those with a specific “need to know” in order to provide products and services to policyholders and to others as permitted or required by law. We maintain contractual, physical, electronic and procedural safeguards to protect against the misuse of personal information under our control.

Data Subject Rights

Under the GDPR, as a data subject, you have the following rights which you can exercise with World Travel Protection at any time.

Right of Access

You have the right to access your personal information kept on file by us. To exercise this right, please send a request in writing to our Privacy Officer at the relevant address provided below. Please specify the kind of information you are seeking. You will be contacted by our Privacy Officer and asked to provide some form of identification to confirm your right to access this information.

Right of Rectification

You have the right to change or correct any personal information that we hold about you.

Right to Erasure

You have the right to request the deletion of the personal data that we hold about you. This is also known as the right to deletion or right to be forgotten.

Right to Restriction of Processing

You have a right to request that processing of personal data is restricted in certain circumstances. However, we shall still continue to process the personal data for storage purposes, for the establishment, exercise or defence of legal claims or with your consent.

Right to be Notified

You have the right to be informed about the uses of your personal data in a clear manner and be told the actions that can be taken if you feel your rights are being impeded. You also have the right to be informed of any rectification or erasure of your personal data under Articles 16, 17, and 18

Right to Data Portability

You have the right to request that your personal data file is sent electronically to a third party. This data will be provided in a commonly used, machine readable format, if doing so is technically feasible.

Right to Object

Where we are relying on legitimate interests as a legal basis to process your data, you have a right to object to such processing on grounds relating to your particular situation.

Right to withdraw consent

Where we rely on consent as a legal basis, you have the right to withdraw it at any time without affecting the lawfulness of processing based on consent before withdrawal.

Rights in relation to automated decision-making and profiling 

You have the right not to be subject to decisions based solely on automated processing (including profiling) which produce legal effects or similarly significantly affect you, unless exceptions apply.  We do not currently carry out such automated decision-making in relation to our services; if this changes, we will provide specific information and details of any right to human intervention, to express your views, or to challenge the decision.

Use of Artificial Intelligence

We are committed to the responsible use of artificial intelligence (AI).  We, or our third-party vendors, may use AI, which may involve processing your sensitive personal information, to improve or provide products or services to you, to develop and provide you with new products, services, features, or technologies, to prevent fraud, to improve performance and the customer experience, or for other uses in our business consistent with our Data and Responsible AI Commitment.  We may use AI in connection with our products or services to facilitate and service our business, including assisting in underwriting, pricing, rating, claims handling processes, risk management, or data management.  The type of AI we use may vary based on your relationship with us, by product or by service. We may also use AI enabled tools to support our employees and contractors in performing their roles, such as tools that assist with drafting, summarizing, analyzing, or retrieving information. These tools are used to support human decision making and do not replace appropriate human review or oversight. If you have any questions about our use of AI, please contact us by using the contact details listed below.

Right to Complain to the Supervisory Authority

You have the right to lodge a complaint with the Information Commissioner’s Office and more details can be found here: www.ico.org.uk

Information Commissioner’s Office

Wycliffe House

Cheshire, UK

SK9 5AF

Telephone: 0303 123 1113

Fax: 01625 524510

https://ico.org.uk/make-a-complaint/

Office of the Privacy Commissioner of Canada

30 Victoria Street

Gatineau, Quebec

K1A 1H3

Information:
http://www.priv.gc.ca/index_e.asp  (English)

http://www.priv.gc.ca/index_f.asp  (Francais)

Office of the Australian Information Commissioner

GPO Box 5218

Sydney NSW 2001

Information: https://www.oaic.gov.au/privacy

To exercise any of the above rights, please contact our Privacy Officer using the contact details below.

Rights of Data Subjects under GDPR are not absolute. While data subjects have the above rights under GDPR, in certain situations those rights cannot be granted. For example, the right to restrict data processing does not apply is when data are processed for the purposes of the prevention, investigation, detection or prosecution of criminal offences. The same applies to the processing of personal data in the prevention of threats to public security.

Data subjects have the right to access their personal data file, although not if that access adversely affects the rights and freedoms of others. As applicable, personal information provided by you will be held and used in accordance with the requirements of the UK which incorporates the EU General Data Protection Regulation.

Children’s Privacy

World Travel Protection is concerned about children’s privacy. This section of our privacy policy explains our information practices in connection with information provided by all children under the age of 18 whose parent or guardian’s consent we require for certain uses of their information (“Child” or “Children“).

We support the Children’s Online Privacy Protection Act (“COPPA”) and other frameworks like the General Data Protection Regulation and the “UK GDPR” (together, the “GDPR“). Our goal is to minimize the information gathered from and disseminated about Children while allowing us to provide the Services for which they are covered under policies of insurance.

Collection of Childrens’ Data

We require parental/guardian consent to collect personal information about Children for the purposes of providing the Services.   Children’s personal information is used for the same purposes as set out above.

How is Personal Information About Children Used?

We use personal information to administer or service a policy; administer a claim; provide assistance and security services; comply with the law; and as otherwise permitted by law.  The transfer of Children’s personal information to an affiliate or third party for processing purposes is defined as a “use” of your personal information.

World Travel Protection uses the personal information of Children solely for the purposes for which that consent was required.  All other sections of this Privacy Policy apply to the personal information of Children.

Additional Information if you are resident in California or Nevada

What Are My Privacy Rights as a California Resident?

If you are a California resident, California law may provide you with additional rights regarding our use of your personal information; subject to exclusions from the rights granted under California law with respect to certain information governed by certain sector-specific privacy laws.

Subject to certain exceptions under California law, California residents may have the following rights with respect to their personal information collected by World Travel Protection:

The right to know and access. California residents have the right to request we disclose (i) a copy of the personal information that we collect about you; (ii) the categories of personal information that we collected about you in the preceding 12 months; (iii) the categories of purposes for which such personal information was disclosed in the preceding 12 months; (iv) the categories of sources such personal information was collected for; and (v) the categories of third parties such personal information may have been shared with.

The right to deletion. California residents have the right to request that we delete the personal information that we or our vendors collected about you. There may be circumstances under which we will be unable to delete your personal information, such as if we need to comply with our legal obligations or complete a transaction for which your personal information was collected. If we are unable to comply with your request for deletion, we will let you know the reason why.

The right to equal service. If a California resident chooses to exercise any of these rights, we will not discriminate against the California resident in anyway. However, if a California resident exercises certain rights, such California resident may be unable to use or access certain features of the Sites.

Exercising California Resident Rights

To exercise any of these rights, please contact our Privacy Officer using the contact details below. In connection with submitting a request, you must provide the following information: name, email, phone number, state of residence, and policy number and you must state what type of request you are making.

We have the right to require you to provide written permission granting authority to your representative and for your agent to verify its identity directly with us, and we may deny a request from your representative who does not submit proof of authorization as we request.

A California resident may only make a verifiable consumer request for access or data portability twice within a 12-month period. The request must provide sufficient information that allows us to reasonably verify the requestor is the person about whom we collected personal information or an authorized representative and describe the request with sufficient detail that allows us to properly understand, evaluate, and respond to it. We cannot respond to a request or provide personal information if we cannot verify the identity or authority to make the request.

We will endeavour to confirm receipt of a request within 10 days following submission and provide information about how we will process the request. We will endeavour to respond to a verifiable consumer request within 45 days of its receipt. If we require more time (up to an additional 45 days), we will provide notice in writing explaining the reason for the extended time period.  We may deliver our written response by mail or electronically, at your option.

Any disclosures we provide will only cover the 12-month period preceding the request receipt date. If we deny a request, we will provide a response explaining the reasons we cannot comply with a request, if applicable.

Sharing of California Resident Personal Information

We may have collected and disclosed the following categories of personal information from a California resident for a business purpose in the preceding 12 months:

Various identifiers, including, name, address, online identifier, Internet Protocol (IP) address, email address, account name, or other similar identifiers.

Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)), including, telephone number or financial information.

Geolocation data, including, physical location or movements. Protected classification characteristics, including, race, colour, national origin, marital status, sex, veteran or military status.

Personal records, such as, power of attorney, family history or power of attorney.

Information received from a government entity or other third party.

We may collect the above categories of personal information directly from you, indirectly as you interact with our website, from or through other third-party sources, including our customers, or through email or other electronic messages between you and our website.

In the prior 12 months, we may have disclosed the categories of personal information set forth above for one or more of the purposes set forth in this privacy policy.  We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.

Sale of California Resident Personal Information

In the prior 12 months, we have not sold personal information of a California resident.

“Shine the Light” Law

California’s “Shine the Light” law, Civil Code section 1798.83, requires certain businesses to respond to requests from California consumers asking about the business’ practices related to disclosing personal information to third parties for the third parties’ direct marketing purposes. To make such a request, please contact our Privacy Officer using the contact details below.

How We Respond to “Do Not Track” Signals

Our website does not respond to DO NOT Track signals.  Third parties cannot collect any other personally identifiable information from our website unless you provide it to them directly.

What Are My Privacy Rights as a Nevada Resident?

Nevada residents may have certain rights to opt-out of sales of their personal information under Nevada Revised Statutes Chapter 603A. However, please know World Travel Protection does not sell data triggering this Nevada statute’s opt-out requirements. If you have questions with respect to this right, please contact our Privacy Officer using the contact details below.

Your privacy on the internet and when using mobile devices What Are My Choices?

Location Information: With your consent, we may collect information about your actual location when you use our mobile applications, such as Travel Assist v2 by WTP, and when you request or purchase products or services. You may stop the collection of this information at any time by changing the settings on your mobile device; but note that some features of our mobile applications may no longer function if you do so.

Native Applications on Mobile Device: Some features of our mobile applications may require access to certain native applications on your mobile device, such as the camera, photo album and the address book applications. If you decide to use these features, we will ask you for your consent prior to accessing the applications and collecting associated information. Note that you can revoke your consent at any time by changing the settings on your device.

Cookies: Most web browsers are set to accept cookies by default. If you prefer, you can usually choose to set your browser to remove or reject browser cookies. Please note that if you choose to remove or reject cookies, this could affect the availability and functionality of the website.

Push Notifications: With your consent, we may send push notifications or alerts to your mobile device. You can deactivate these messages at any time by changing the notification settings on your mobile device or within our mobile applications.

What if I have a question, concern or complaint?

Please contact our Privacy Officer using the information provided below.

North America Privacy Officer

100 King Street West Suite 5350

Toronto, Ontario, M5V 3H5, Canada

Telephone:   +1 416-977-3565

Toll-Free:   +1-800-667-2523

Email: Privacy.zurich.canada@zurich.com

United Kingdom and European Privacy Officer

Parkview, 82 Oxford Road,

Uxbridge, UB8 1UX, UK

Telephone:   +44 20 8156 2640

Email: emeaprivacy@worldtravelprotection.com

Australia and New Zealand Privacy Officer

Level 15, 340 Adelaide Street,

Brisbane QLD 4000, Australia

Telephone: +61 2 8907 5250

Toll Free: 1-866-236-5009

Email: privacy@worldtravelprotection.com

This privacy policy is stand-alone document. You may receive privacy policies, statements or notices from other parties. The terms of this privacy policy do not modify, supersede, revise, or amend the terms of other privacy policies, statements or notices received from other parties. We may update this privacy policy from time to time.