LEGAL · SRMG
Privacy Policy
Syndicate Risk Management Group ('SRMG', 'we', 'us', 'our') is committed to protecting your privacy and maintaining the security of any personal information you provide us with. This statement outlines how we ensure this and how we comply with data protection legislation.
This Privacy Policy explains any areas of our website which may affect your privacy and personal details — how they are processed, collected, managed, and stored — and how your rights under GDPR (General Data Protection Regulation) and other applicable data protection laws are protected.
01 —
Information we collect
We collect information you provide through our forms and communications: identity and contact details, vessel and operation details, policy numbers, claims details including incident descriptions and attachments, and messaging metadata from WhatsApp or chat. We use it to respond to inquiries and provide the services you request.
We do not store credit card details or sell or rent your personal information. We share information with service providers and relevant insurers as needed to provide requested services, and where required by law.
02 —
Keeping your information secure
Our servers are protected using HTTPS and SSL technology. Any data provided by you to us will be as secure as it can be. We are fully aware of our responsibilities regarding data under GDPR and applicable data protection legislation.
If we ask an external organisation to provide a service for us (for example our forms handler or customer relationship management platform), we will always ensure that they have appropriate security measures in place.
03 —
Cookies and optional services
We use essential cookies and browser storage to run this site and remember your language and cookie preferences. Optional chat loads only if you select “Accept all”. Selecting “Essential only” leaves optional chat disabled. You can change your choice through “Cookie preferences” in the footer.
Our service providers include Formspree for form processing and email delivery, Salesforce for CRM, Respond.io and WhatsApp Business for messaging, and Lovable for hosting. These services process information needed for their functions. External services you choose to visit have their own privacy policies. Optional analytics, if added, will respect the same consent choice; Plausible is planned and is not identified here as an active analytics processor.
04 —
Social media profiles
We maintain official profiles on social media channels — specifically Instagram at @syndicateriskmanagement. We advise our users to verify the legitimacy of any profile purporting to be our company before interacting with it. Our social media profiles will never ask for passwords or personal financial details.
05 —
External web links
This website contains links to external websites. We are not responsible for the privacy practices or the content on these sites. Our users are encouraged to be aware that when they leave this website, they should read the privacy policy of each website that collects personal data. This Privacy Policy applies only to information collected by us.
06 —
Spam policy
We are strongly against spam. We only contact our clients when they have requested to receive communication or there is a need to update them on information about services they have requested from us.
07 —
How long we keep personal information (Data retention)
We keep personal information only as long as needed for the purposes described in this Policy — and, because we are a licensed insurance brokerage, certain records must be kept for legally mandated periods even if you ask us to delete them sooner. In general:
Quote requests and new-business submissions that do not result in a placement are kept only as long as needed to handle the request, meet applicable legal obligations, and resolve related disputes, then deleted or anonymized.
Client, policy, and claims records (including submissions, policy documents, correspondence, and claims files): retained for the duration of the client relationship and thereafter for the record-retention periods required by applicable insurance laws and regulations in the jurisdictions where we are licensed, and as needed to defend or pursue legal claims within applicable limitation periods.
Marketing and general inquiries (contact form, chat, newsletter interactions) are retained only as long as necessary for the interaction or subscription, subject to applicable legal obligations. You may opt out of marketing at any time.
Website logs and analytics are retained in identifiable form only as long as needed for security, operation and any applicable legal obligations.
When a retention period ends, we delete or irreversibly anonymize the information within a reasonable period, except where a legal hold applies.
08 —
Your privacy rights and how to exercise them
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to restrict or object to certain processing, and to withdraw consent. These include rights under the EU and UK GDPR, under the California Consumer Privacy Act as amended (CCPA/CPRA), and under other state and national laws.
How to submit a request: email office@srmg.co with the subject line “Privacy Request”, or write to our Miami office. We will verify your identity before acting on a request.
Timing: we respond within the period required by the applicable law — within one month under GDPR/UK GDPR (extendable as permitted), and within 45 days under CCPA/CPRA (extendable once).
The insurance-records exception: where law requires us to retain records (for example, insurance record-keeping regulations, anti-fraud and anti-money-laundering obligations, or defense of legal claims), we will retain what the law requires, tell you that we have done so, delete what we lawfully can, and restrict the retained data from any other use.
No discrimination: we will not deny services or treat you differently for exercising privacy rights.
Appeals and complaints: you may appeal a refusal by replying to our decision, and you may lodge a complaint with your supervisory authority (in the EU/UK, your data-protection authority; in California, the California Privacy Protection Agency or Attorney General).
09 —
Contact us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us:
Syndicate Risk Management Group 111 NE 1st Street, Suite 8987 Miami, FL 33132, USA Email: office@srmg.co Phone: +1 (305) 500 0844
Additional offices: San Diego, London, Athens, Istanbul.
10 —
Changes to this policy
We may update this Policy from time to time. Updates will be posted on this page with a revised date.
6 October 2026: updated insurance-record retention, privacy rights, information categories, service providers and cookie preferences.
11 —
Languages
This Privacy Policy is provided in nine languages for convenience. In the event of any inconsistency, the English-language version controls, to the extent permitted by applicable law.
Last revised: 6 October 2026
