Privacy policy
Who we are
The Novark Group ("Novark", "we", "our" and "us") is a Howden-backed business. It comprises:
- Novark — a technology platform established to modernise how institutional capital accesses and manages insurance risk.
- Novark Management Ltd. — a Bermuda incorporated insurance management and securities administration company, authorised and regulated by the Bermuda Monetary Authority. It is currently known as Alternative Risk Management (Bermuda) Limited.
- Novark Re Ltd. — a Bermuda based Class 3 insurer and segregated accounts company. It is currently known as ARM Insurance Ltd.
Novark combines specialist expertise with purpose-built technology to give market participants greater visibility, accountability and control throughout the transaction lifecycle.
Together with our affiliates, we may need to collect and process personally identifiable information in order to deliver our products and services. The entity responsible for information collected through this Site is Novark Management Ltd.
This privacy policy applies where we've collected personally identifiable information from or about you in our role as the organisation responsible for that information (a "data controller" under certain laws). It explains when, why and how we collect and process your personally identifiable information, the third parties we may need to share it with and why, what your rights are, and how you can exercise them with us. Unless stated otherwise here, this policy doesn't apply to the practices of companies we don't own or control, or to people we don't employ or manage. Except as described in this policy, we don't sell, rent, share or disclose your personally identifiable information to or with any other organisation.
We may revise this policy from time to time to reflect changes in how we process personally identifiable information, or to meet new requirements under applicable privacy laws. We encourage you to check our website ("Site") regularly, as the most current version will govern our use of your personally identifiable information, whether collected through our Site or through our other dealings with you. This policy was last updated on 7 September 2026.
1. Type and uses of information we collect from you
We, or vendors operating on our behalf, may need to collect and use information about you for a range of purposes — for example when you apply for a job, request information from us, or when we provide you, or a business you represent, with insurance management, insurance-linked securities (ILS) or alternative risk transfer administration services ("Services"). This information may include your name, title, date of birth, email address, phone number, residential address and information relating to your profession. In certain circumstances we may need to collect more sensitive personal information about you, but only where this is strictly necessary for the purpose in question and where we have a valid legal basis to do so, as explained under Section 3.
Children
We don't solicit, collect or maintain personally identifiable information from individuals we have actual knowledge are under the age of 13. If you're a parent or guardian and believe information about a child has been collected through our Site, please contact us.
2. Information automatically collected
When you visit our Site we may collect some information automatically, for example through the use of cookies as explained below. Collecting this information helps us better understand your needs and how well our Site is working, so we can keep improving your experience with us.
Links, embedded content and buttons
We may keep track of how you interact with links across our Site, or with our email notifications, to help improve our services and analyse how often a particular link was used. Our Site may contain links to other websites, embedded content that comes from or relates to other services, and buttons from services such as LinkedIn. These third parties may use cookies or other tracking technologies to collect information about you across the internet. You should check the privacy and cookie policies of those other websites and services, particularly before providing personally identifiable information.
Information from your device
We may, ourselves or through third-party service providers, collect information about your device — such as browser, operating system, IP address, country and other geolocation data, date and time of visit, device type, referring websites, the search queries you used to reach our Site, the pages you visit and your activity on them, and the time spent on our pages. Some of this may be collected using cookies, as explained below. We use this to improve our Site and its content, including to gather broad demographic data, identify trends, help diagnose server problems, and administer the Site.
Cookies
Our Site may use cookies. Cookies are small pieces of data a website can send to your browser, which may then be stored on your device. We may use both session and persistent cookies, on our own or through third-party service providers. Cookies may save your preferences while you're on our Site and help us understand which areas are most used. You can choose which non-essential cookies you're happy to accept through our cookie banner, or change your preferences in your browser settings.
Web beacons
We may use web beacons (also called single-pixel gifs) or similar technologies on the Site and in messages, newsletters or emails, including through third-party providers. These let us understand whether you've opened or acted on an email and which links you followed, count how many people visit certain pages, and compile aggregated statistics.
Combining of information
Except as set out in this policy, we generally don't combine information about you collected on the Site with information about you collected by other means.
3. Legal bases and purposes of processing
We only collect and use personal information where one of the legal bases below can be satisfied:
- Where the use of personal information is necessary to achieve a legitimate business interest — for example to arrange and administer Services for our clients (who may be your employer), to respond to third-party claimants, to give you access to one of our systems, to maintain accurate records, to identify opportunities to improve Services through data analytics, to facilitate internal reporting between Novark affiliates, to respond to internal and external queries, or to send you marketing in a professional context.
- Where the use of personal information is necessary to enter into or perform a contract — for example to take steps towards entering into an employment contract with you.
- Where the use of personal information is necessary to comply with a legal obligation — for example rules set by our supervisory authorities, detecting and preventing fraud, money laundering and other financial crime, fulfilling your rights under applicable privacy laws, handling complaints and legal claims, and meeting other regulatory requirements.
- Where the use of personal information is based on consent — for example if you permit us to contact you for marketing purposes.
For sensitive personal information, which may include health-related information, we only collect and process it where one of these narrower conditions is met:
- You've given us your explicit consent to use the information.
- The use is necessary to establish, exercise or defend a legal claim.
- The use is necessary to carry out employment obligations, where there's a basis for this in law.
- The use is necessary to arrange insurance or reinsurance and handle any associated claims.
4. Sharing of your information
Limited disclosure of information collected through the Site
We don't sell, rent or lease your information to others without your consent, except as set out in this policy. In general the information you provide is used to support your relationship with us and to improve our Site, products, services and communications. We may engage third-party service providers, consultants and independent contractors to perform functions and provide services for us, and may share information with them so they can do so — for example our email vendors, so they can contact you about our products and services or support job listings on the Site.
We may also use and disclose visitor information where we have reason to believe it's necessary to investigate, contact or bring legal action against someone who may be harming or interfering with our rights or property, our other visitors, or anyone else. We may disclose visitor information when required by subpoena, for government investigations, and when we otherwise believe in good faith the law requires it.
Third-party service providers used on our Site
We may use third-party services to help provide our services and to process enquiries. As at the date of this policy, this Site uses Netlify, which hosts the Site and receives the enquiries you send us through it, and Google Analytics, which tells us how the Site is used. Google Analytics runs only if you allow analytics cookies through our cookie banner; if you do not, it is never loaded and no request is made to Google. It sets cookies on your device and Google may use the data collected to prepare reports on the Site's activity. You can view Google's privacy policy at https://policies.google.com/privacy. This Site uses no advertising or marketing cookies. These providers may collect, store and share information as set out in their own privacy policies.
Disclosures of information collected by means other than the Site
Where applicable, we may disclose personal information to insurers, reinsurers, intermediaries and agencies, and to third-party vendors, for legal and security risk-management services such as credit reference, criminal record, fraud prevention and data validation, and where necessary to prevent and detect fraud, money laundering, sanctions breaches and terrorist financing. We may also disclose information to third-party service providers who help us run our IT and back-office systems, or who provide platforms we use or make available to you.
Business transfers
If we're involved in a bankruptcy, merger, acquisition, reorganisation or sale of assets, or a change in our ownership or control, your information may be transferred as part of that transaction.
Internal sharing
Depending on our relationship with you and the Services you receive, we may share your personal information with other companies within the Novark Group — described under "Who we are" above — or the wider Howden Group. This will generally be for the purposes below, and only where the minimum necessary information is shared:
- To receive administrative support from those companies, such as IT, HR, Finance and Compliance services.
- So those companies can provide market insight to insurers and reinsurers on a confidential basis, but only where personal information has been aggregated or anonymised.
- So we can offer you services available from another company in the group, but only where permitted under electronic marketing laws.
5. International transfers
For business purposes, to help prevent or detect crime, or where required by law, we may need to transfer your personal information to parties based overseas. Where we do, we'll ensure it's protected in line with applicable laws — for example by ensuring the overseas party is in a country considered to provide adequate protection, or by putting in place a formal and enforceable agreement that reflects any statutory requirements.
6. Retention of personal information
How long we keep personal information depends on its nature, the purpose it was obtained for, and how it was obtained. In most cases we'll keep your personal information for seven years after the end of our relationship with you, so we can handle any disputes, claims or complaints that may arise. In some cases we may need to keep it longer — for example where a relevant policy allows a longer claim-notification window — and in others we'll keep it for a shorter period, for example if you ask us for a quote but choose not to proceed.
7. Your rights
Data protection and privacy laws give you rights relating to your personal information. Below is a list of rights commonly found in many privacy laws, including those in Bermuda, the UK and EU. Their applicability generally depends on the law that applies to your relationship with Novark and the reason your personal information is being used. To enquire about a right, exercise a right (generally at no cost to you) or make a complaint, please use the contact details in Section 9.
Subject to what's legally permissible, we'll make all reasonable efforts to fulfil your request within one month of receipt, or to ask you for more information so we can. In some circumstances — for example where we owe a duty of confidentiality to others — we may be required or entitled not to fully address a request. Where we can't, we'll explain why as soon as reasonably practicable.
| Right | Description |
|---|---|
| Access | You can ask for a copy of the personal information we hold about you, along with meaningful information on how it's used and who we share it with. In some cases we may not be able to provide all of it; where that's so, we'll explain why unless the law prevents us. |
| Rectification | You can ask us to correct inaccurate or incomplete personal information. We'll confirm when this is done, or explain if there's a valid reason it can't be. |
| Erasure | You can ask us to delete your personal information in certain circumstances, for example where we no longer need it for the purpose we collected it. We'll confirm when this is done, or explain if we can't due to a compelling overriding reason. |
| Restrict processing | You can ask us to restrict processing of your personal information in certain circumstances. We'll confirm when this is done, or explain if we can't. |
| Data portability | In certain circumstances you can ask us to transfer your personal information to you or a nominated third party in a common, machine-readable format. We'll act on your instruction and confirm, or explain if there's a valid reason we can't. |
| Object | You can object to us using your personal information for direct marketing — just use the unsubscribe link in any email, or get in touch. You can also object to us processing your personal information for a legitimate business interest, as explained in Section 3. We'll confirm the processing has stopped, or explain why we believe our interest outweighs yours. |
| Automated decision-making | You can object to decisions made by purely automated means that produce legal or similarly significant effects about you. If you do, we'll arrange for someone to assess the decision and confirm the outcome to you. |
You may also have the right to raise complaints or concerns with a supervisory authority if you're unhappy with how we've responded to a privacy-related query, request or complaint. The relevant contact details are below.
| Location | Novark entity | Supervisory authority |
|---|---|---|
| Bermuda | Novark Management Ltd. (currently Alternative Risk Management (Bermuda) Limited) and Novark Re Ltd. (currently ARM Insurance Ltd.) | Office of the Privacy Commissioner for Bermuda — https://www.privacy.bm |
| United Kingdom, if we offer services to or monitor individuals in the UK | Novark Management Ltd. (currently Alternative Risk Management (Bermuda) Limited) | Information Commissioner's Office — https://www.ico.org.uk |
| European Economic Area, if we offer services to or monitor individuals in the EEA | Novark Management Ltd. (currently Alternative Risk Management (Bermuda) Limited) | The supervisory authority where you live or work — see the European Data Protection Board's members list at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en |
8. Security
We take commercially reasonable steps to protect data transmitted through our Site, and we rely on our third-party vendors to secure the services they provide. We can't and don't guarantee the security of any information you transmit to us or from our online products or services. You transmit information to us at your own risk and should take all necessary precautions. In the event of an unforeseen compromise of any data in our possession, Novark will comply with all applicable laws on reporting such an event to the appropriate parties.
Subject to terms of use
This policy is also subject to the terms set out in any website terms of use or legal disclaimers we publish, including all provisions on warranty disclaimers, limits of liability, and dispute resolution such as jurisdiction and forum. Novark does not currently publish separate website terms of use.
9. Contacting us
If you'd like to discuss this policy, exercise one of your rights, or have any related questions or concerns, please get in touch using the form on our homepage. Alternatively, you can write to us at:
- Novark Management Ltd. (currently Alternative Risk Management (Bermuda) Limited)
Exchange House, 2nd Floor
110 Pitts Bay Road
Pembroke HM08, Bermuda
If you're making a complaint, please include as much information as possible so we can investigate promptly. We'll acknowledge your complaint without undue delay and no later than 30 days. We'll keep you updated throughout, and give you a clear explanation of our findings, any actions we take, and the outcome. If you remain dissatisfied, you can escalate to the relevant supervisory authority as explained in Section 7.
Copyright © 2026 Novark Management Ltd. All rights reserved.