Legal
Effective date: 30 June 2026 · Download PDF version
American & Overseas Reinsurance Management Company Ltd. (BMA Registration No. 15510) (“American & Overseas”, “we”, “us”, or “our”) is a licensed insurance manager regulated by the Bermuda Monetary Authority (“BMA”) under the Insurance Act 1978 of Bermuda.
We are committed to protecting the privacy and personal information of all individuals with whom we interact, including clients, prospective clients, business contacts, counterparties, service providers, and visitors to our website. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information in accordance with the Personal Information Protection Act 2016 (“PIPA”) of Bermuda.
As a BMA-regulated entity, we also operate in compliance with applicable international data protection frameworks relevant to the jurisdictions in which our clients and counterparties are located, including but not limited to the United States, the United Kingdom, the European Union, and Asia-Pacific markets.
By engaging with us, accessing our website, or providing us with your personal information, you acknowledge that you have read and understood this Privacy Policy.
For the purposes of PIPA and applicable data protection laws, American & Overseas acts as a “controller” (also referred to as an “organisation” under PIPA) in respect of the personal information we collect and process. This means we are responsible for deciding how and why personal information about you is used.
Where we engage third-party service providers who process personal information on our behalf, those parties act as processors and are required by contract to process personal information only on our documented instructions and with appropriate security safeguards.
Our principal activities as an insurance manager include the management of captive and specialty reinsurance structures on behalf of clients domiciled across multiple international jurisdictions. In this capacity, we may receive and process personal information relating to clients, their officers, directors, beneficial owners, insureds, and other related parties.
The personal information we collect will depend on your relationship with us. We collect and process the following categories of personal information:
As a BMA-regulated entity, we are required by law to collect and verify certain information for Know Your Customer (KYC), Anti-Money Laundering (AML), and regulatory compliance purposes. This may include:
When you visit our website, we may automatically collect certain technical information, including:
We do not routinely collect sensitive personal information (as defined under PIPA, including health data, biometric data, or information revealing racial or ethnic origin). Where such information is required for a specific regulatory or legal purpose, we will obtain your explicit consent in advance and will clearly explain the purpose for collection.
We collect personal information from the following sources:
We use personal information for the following purposes, each supported by a lawful basis under PIPA:
| Purpose | Description | Lawful basis (PIPA) |
|---|---|---|
| Insurance management services | Providing captive and specialty reinsurance management services to clients | Performance of a contract / Legitimate interest |
| Regulatory compliance (KYC/AML) | Fulfilling BMA-mandated obligations including KYC, AML, sanctions screening, and regulatory reporting | Legal obligation |
| Client onboarding | Establishing the client relationship, conducting due diligence, and setting up accounts and structures | Performance of a contract / Legal obligation |
| Communication and administration | Responding to enquiries, managing correspondence, and administering our business relationship | Legitimate interest |
| Risk and actuarial analysis | Assessing and managing insurance and reinsurance risk on behalf of clients | Performance of a contract / Legitimate interest |
| Legal and regulatory reporting | Complying with court orders, regulatory requests, tax obligations, and mandatory disclosure requirements | Legal obligation |
We will not use your personal information for purposes that are incompatible with those stated above without first notifying you and, where required, obtaining your consent.
We do not make decisions about you that have a significant legal or similarly significant effect based solely on automated processing of your personal information. Where automated tools are used (for example, in sanctions screening), the output is always reviewed by a qualified member of our team before any decision is made.
As an internationally active insurance manager serving clients across the United States, United Kingdom, Europe, Asia, and other markets, we may transfer personal information across borders in the ordinary course of our business. Such transfers may occur when:
Where personal information is transferred outside Bermuda, we take steps to ensure that appropriate safeguards are in place, which may include:
Where you are a client or contact based in the United States, European Union, United Kingdom or Asia, we will also seek to ensure compliance with applicable data protection requirements of those jurisdictions to the extent relevant to our processing activities.
We may share your personal information with the following categories of recipients, always on a need-to-know basis and subject to appropriate contractual and security safeguards:
We do not sell, rent, or otherwise commercialise your personal information to third parties.
We maintain appropriate technical and organisational measures to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
In the event of a personal information breach that poses a risk of harm to individuals, we will notify the Privacy Commissioner of Bermuda and affected individuals in accordance with our obligations under PIPA and any other applicable law.
We retain personal information for as long as is necessary to fulfil the purposes for which it was collected, to comply with our legal and regulatory obligations, and to protect our legitimate interests. Our standard retention periods are as follows:
| Category | Retention period | Basis |
|---|---|---|
| Client relationship records | Duration of engagement + 7 years | Legal / Regulatory obligation |
| KYC / AML documentation | Duration of relationship + 6 years (minimum) | BMA / PIPA / BFIU requirement |
| Regulatory filings and correspondence | 7 years | Insurance Act / BMA requirement |
| Financial records | 7 years | Companies Act / Tax obligation |
| Website visitor data (logs) | 12 months | Security / Legitimate interest |
When personal information is no longer required, it will be securely deleted, anonymised, or destroyed in accordance with our data disposal procedures.
Under PIPA and, where applicable, other data protection laws relevant to your jurisdiction, you have the following rights in relation to your personal information:
To exercise any of these rights, please contact us using the details in Section 13 below. We will respond within 30 days of receiving your request. We may need to verify your identity before processing your request.
Please note that certain rights may be limited or overridden where we are required by law to retain or process your information, or where the exercise of a right would adversely affect the rights and freedoms of others.
Our website may use cookies and similar tracking technologies to enhance your browsing experience and to gather aggregate statistical information about website usage. Cookies are small text files stored on your device when you visit our website.
We use the following types of cookies:
You can control and manage cookies through your browser settings. Disabling certain cookies may affect the functionality of our website. By continuing to use our website, you consent to our use of cookies as described above. For more detail, see our Cookie Policy.
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those websites and encourage you to review their privacy policies separately.
If you have any questions, concerns, or requests relating to this Privacy Policy or the handling of your personal information, please contact our Privacy Officer:
We reserve the right to update or amend this Privacy Policy from time to time to reflect changes in our business practices, applicable law, or regulatory requirements. Any material changes will be posted on our website with an updated effective date. We encourage you to review this Policy periodically.
Where changes are material and affect the way we process your personal information, we will notify you directly where we have your contact details and where required by applicable law.
Continued use of our website or services following the posting of changes constitutes your acceptance of the Privacy Policy.
Effective Date: 30 June 2026 · Next Review: 30 June 2027