PRIVACY NOTICE
Personal data. Clear purpose. Accountable use.
-
This Privacy Notice explains how personal data is handled in connection with the Coastlight Global Risk website, communications, professional relationships, careers activity and related digital services.
Processing is organised around defined purposes, proportionate access, appropriate security and transparent legal bases.
-
Roman D. Stehling
Coastlight Global Risk
Hohe Bleichen 18
20354 Hamburg
GermanyEmail
privacy@coastlightglobalrisk.comWebsite
coastlightglobalrisk.comPrivacy enquiries
Questions, requests and concerns relating to personal data may be directed to:
-
Depending on the interaction, Coastlight may process personal data in the following contexts:
- access to and use of the website;
- security, stability and technical delivery;
- cookie and consent preferences;
- contact enquiries and correspondence;
- prospective and existing professional relationships;
- regulatory and professional obligations;
- events, meetings and executive communications;
- applications and research-career enquiries;
- complaints, disputes and rights requests;
- public research, source verification and professional records;
- protected client or case environments where separately agreed.
Each category is subject to its own purpose, data scope, legal basis, recipients and retention requirements.
-
When the website is accessed, technical information may be processed to deliver the requested pages, maintain security and diagnose faults.
This may include:
- IP address;
- date and time of access;
- requested page or resource;
- browser and device information;
- operating system;
- referring page;
- response and error information;
- security and network-event information.
The legal basis may include Coastlight’s legitimate interests in providing a secure, stable and functional website under Article 6(1)(f) GDPR.
Where technical storage or access on the user’s device is strictly necessary to provide the requested digital service, the relevant processing is handled under the applicable device-access rules.
-
The website may use cookies, local storage or comparable technologies for:
- essential website functions;
- security;
- language preferences;
- consent management;
- accessibility and interface preferences;
- analytics or other optional purposes where activated.
Technologies requiring consent are activated only after the relevant choice has been recorded.
Preferences can be reviewed through:
COOKIE SETTINGS
Cookie Settings
Further information is provided in the Cookie Policy.
COOKIE POLICY
-
When a person contacts Coastlight, the information provided is processed to understand and respond to the enquiry, organise follow-up and maintain an appropriate business record.
This may include:
- name;
- role and organisation;
- contact details;
- the content of the communication;
- related documents;
- meeting and follow-up information;
- professional interests and requirements.
The legal basis may be Article 6(1)(b) GDPR where the communication concerns pre-contractual or contractual steps, Article 6(1)(f) GDPR for professional communications and relationship management, or Article 6(1)(c) GDPR where legal obligations apply.
-
In connection with executive risk advisory, insurance intermediation and related professional work, Coastlight may process information concerning:
- company representatives and decision-makers;
- employees, contractors and professional contacts;
- insurers, underwriters, experts and service providers;
- policy, claim, financial and contractual contacts;
- regulatory and compliance participants;
- meeting, instruction, decision and approval records.
The precise processing depends on the agreed scope and the applicable professional and regulatory requirements.
Additional information may be provided for a specific engagement, protected environment, claim, project or data intake.
-
Where a person submits an application, research profile or expression of interest, Coastlight processes the information required to assess the potential relationship and communicate about it.
This may include:
- identity and contact information;
- curriculum vitae;
- academic and professional history;
- publications and research interests;
- references;
- correspondence and interview records;
- information provided voluntarily within the application.
The legal basis may include Article 6(1)(b) GDPR and applicable national employment-data rules.
Information is retained for the period required to complete the process and, where consent or another lawful basis applies, for an agreed period relating to future opportunities.
-
Personal data may be processed to:
- receive and assess complaints;
- respond to rights requests;
- establish, exercise or defend legal claims;
- meet professional and regulatory obligations;
- communicate with authorities, arbitration bodies, insurers, advisers or courts where appropriate.
The legal basis may include Article 6(1)(c) and Article 6(1)(f) GDPR.
-
Coastlight may process professional information from public and authoritative sources where this supports research, verification, market understanding, company analysis or professional contact.
Relevant data may include:
- name;
- professional role;
- organisation;
- public statements;
- official filings;
- authority or court records;
- publications;
- professional contact information;
- source and retrieval details.
The legal basis is assessed according to purpose, reasonable expectations, source, materiality and the rights of the individual concerned.
Where the information was not obtained directly from the individual, the transparency requirements of Article 14 GDPR are considered.
-
Depending on the processing activity, Coastlight relies on one or more of the following legal bases:
- consent — Article 6(1)(a) GDPR;
- steps before entering into a contract or performance of a contract — Article 6(1)(b) GDPR;
- compliance with a legal obligation — Article 6(1)(c) GDPR;
- legitimate interests — Article 6(1)(f) GDPR;
- another legal basis identified for the specific processing.
Where legitimate interests are relied upon, Coastlight considers the purpose, necessity and effect on the rights and interests of the individual.
Consent may be withdrawn at any time with future effect.
-
Personal data may be accessible to recipients and service providers where required for the defined purpose.
These may include:
- website, hosting, security and content-delivery providers;
- translation and language-service providers;
- consent-management and analytics providers;
- email, communication and collaboration providers;
- document, storage and workflow providers;
- insurers, underwriters, loss adjusters and claims participants;
- legal, tax, accounting, technical and other professional advisers;
- authorities, courts and arbitration bodies;
- counterparties authorised within a professional relationship.
Access is limited according to purpose, role and necessity.
Service providers processing data on Coastlight’s behalf are subject to the applicable contractual and data-protection requirements.
-
The Coastlight Global Risk website is hosted and operated through Squarespace. Squarespace provides the website platform, technical delivery and built-in website functionality. In providing these services, technical data such as IP addresses, device and browser information, requested pages, timestamps and cookie identifiers may be processed. Squarespace Analytics is used to understand website traffic and interaction with the public website.
Cloudflare provides DNS, security and content-delivery services. In this context, Cloudflare may process limited connection and security data, particularly IP addresses and request metadata, to route traffic, protect the website against malicious activity and maintain network security.
Weglot is used to provide translated versions of the website. To generate and deliver translations, Weglot processes website content and may process technical information including IP addresses, requested URLs, language preferences and related request data. Original and translated website content may be stored within the Weglot service.
A consent-management platform is used to record and manage preferences relating to cookies and similar technologies. Technologies requiring consent are activated in accordance with the preference selected through Cookie Settings.
Where information is submitted through a website form or sent by email, the information provided is processed to respond to the enquiry, manage the relevant communication and, where applicable, prepare or administer a professional relationship.
Verify Independently may provide links to external research sources and third-party websites. When an external link is opened, the relevant third party may receive technical connection data and process information under its own privacy terms.
Interactive Coastlight components operate within the website and use the existing website infrastructure to provide the relevant functionality. They do not by themselves establish a professional relationship with Coastlight.
-
Some service providers or recipients may process data outside the European Economic Area (EEA).
Where personal data is transferred internationally, Coastlight uses the transfer mechanism required for the relevant destination and relationship. This may include:
- an adequacy decision;
- the European Commission’s Standard Contractual Clauses;
- another lawful transfer mechanism;
- supplementary technical, organisational or contractual measures where appropriate.
The applicable transfer mechanism depends on the relevant provider, destination and processing relationship.
-
Personal data is retained for the period required by the relevant purpose and any applicable legal, professional, evidential or contractual obligation.
Retention is assessed with reference to:
- the duration of the enquiry or relationship;
- statutory retention duties;
- professional documentation requirements;
- limitation periods;
- complaint, claim and dispute requirements;
- security and audit needs;
- consent and agreed future-contact periods;
- the continuing relevance of the record.
When the relevant basis ends, data is deleted, anonymised, archived or restricted as appropriate.
-
Coastlight applies technical and organisational measures proportionate to the sensitivity, purpose and risk of the processing.
The approach includes purpose limitation, least-privilege access, controlled systems, information separation, appropriate transfer routes, integrity and version controls, and accountable review.
Further information is available in:
INFORMATION SECURITY
-
Subject to the applicable legal requirements, individuals may have the right to:
- receive information about processing;
- request access to personal data;
- request correction of inaccurate data;
- request deletion;
- request restriction of processing;
- receive data in a portable format;
- object to processing based on legitimate interests;
- withdraw consent with future effect;
- lodge a complaint with a supervisory authority;
- receive the safeguards relating to certain international transfers;
- obtain human intervention where Article 22 GDPR applies.
A request may be submitted through the data-protection contact above.
Identity verification may be required to protect the individual and the relevant data.
-
Where processing is based on Article 6(1)(f) GDPR, the individual may object on grounds relating to their particular situation.
Where personal data is processed for direct marketing, the individual may object to that processing at any time.
-
Coastlight does not use the public website to make decisions based solely on automated processing that produce legal effects or similarly significant effects within the meaning of Article 22 GDPR.
AI-supported professional work remains subject to human review and decision authority, as described in Coastlight’s Responsible AI Principles.
-
Individuals may lodge a complaint with a competent data-protection supervisory authority.
For a controller established in Hamburg, the relevant authority may be:
THE HAMBURG COMMISSIONER FOR DATA PROTECTION AND FREEDOM OF INFORMATION
Ludwig-Erhard-Str. 22
20459 Hamburg
Germany
Email:
mailbox@datenschutz.hamburg.de
Official complaint route:
Submit a complaint or report a data-protection concern
The right to contact another competent supervisory authority remains unaffected.
-
The Coastlight website and professional services are directed towards business and professional audiences.
-
This Notice may be updated when processing activities, service providers, legal requirements or Coastlight’s operating model change.
The current version is identified by its preparation and review date.
PREPARED ON
24 July 2026
LAST REVIEWED
24 July 2026
-
-
Responsible data use keeps purpose, access, provenance and human accountability connected throughout the information lifecycle.