Submission Desk · Legal
Data Processing Addendum
Contents
1.Scope and roles
This Data Processing Addendum ("DPA") forms part of the Terms of Service between [Company Legal Name, LLC] ("Processor") and the Customer. It applies to personal information in Customer Data that we process on the Customer's behalf ("Customer Personal Data"), including information about insureds, their owners and employees, and underwriters.
The Customer is the controller (or "business", or "financial institution"). We are the processor (or "service provider"). If this DPA conflicts with the Terms, this DPA controls for Customer Personal Data.
This page summarizes our standard DPA. A countersigned copy is available on request from [privacy@yourdomain.com].
2.Details of processing
- Subject matter and purpose: providing the Service: storing documents, extracting risk summaries, drafting emails, creating Outlook drafts, recording what was sent, and tracking results.
- Duration: the term of the Terms, plus the retention periods below.
- Data subjects: the Customer's clients and prospects (insureds), their owners, officers, employees, and contacts; underwriters and other recipients; the Customer's personnel.
- Categories of data: names, contact details, business and financial information (revenue, payroll, property values, loss history), employment information, and email content and metadata, as contained in documents the Customer uploads.
- Sensitive data: not intended. The Customer should not upload special-category or sensitive identifiers unless necessary and permitted.
3.Processing on instructions
We process Customer Personal Data only on the Customer's documented instructions, which are the Terms, this DPA, and the Customer's use of the Service, unless the law requires otherwise (in which case we will tell the Customer first if lawful). We will not sell or share it, retain, use, or disclose it for any purpose other than providing the Service, or combine it with other data except as permitted by law. We will tell the Customer if we believe an instruction violates the law, and if we can no longer meet our obligations under the CCPA.
4.Confidentiality of personnel
Everyone we authorize to process Customer Personal Data is bound by confidentiality obligations, and access is limited to those who need it to provide, secure, or support the Service.
5.Subprocessors
The Customer authorizes the subprocessors listed on our Subprocessors page. We bind each by written terms at least as protective as this DPA and remain responsible for their performance. We will give at least 30 days' notice of a new subprocessor. The Customer may object on reasonable data protection grounds within that period; we will then work in good faith on an alternative, and if none is possible, the Customer may terminate the affected Service and receive a refund of any prepaid fees for it. Services the Customer connects under its own agreements (such as its own Claude account) are not our subprocessors.
6.Security measures (Annex)
We implement and maintain appropriate technical and organizational measures, including:
- TLS encryption in transit; encryption at rest for the database and file storage.
- AES-256-GCM encryption, with a dedicated key, for OAuth tokens and API keys.
- Per-customer data isolation enforced in every query; public database APIs locked by row-level security.
- Private file storage accessed only by server-side credentials.
- An append-only audit log of send-related actions.
- Least-privilege access for personnel and minimal OAuth scopes (no permission to send mail).
- Redaction of client data from application logs and error reports.
- Backups, vendor security review, and an incident response process.
See the Security Overview for more detail, including measures not yet in place.
7.Assistance with requests and assessments
Taking into account the nature of the processing, we will help the Customer respond to data-subject requests (such as access, correction, and deletion), including through self-service export and deletion tools, and will forward to the Customer any request we receive directly about Customer Personal Data. We will provide reasonable information to help with data protection impact assessments, regulator consultations, and the Customer's service-provider oversight obligations.
8.Security incident notice
We will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. The notice will describe what happened, the data and individuals likely affected, likely consequences, and the steps taken, with updates as we learn more. We will cooperate with the Customer's notification obligations to regulators and individuals.
9.Deletion or return
On termination, or on the Customer's request, we will let the Customer export Customer Personal Data and then delete it within 30 days (and from backups on their normal rotation), except the audit record of sent communications, which we keep for [7] years for the Customer's errors-and-omissions and recordkeeping needs, and any data we must retain by law. Retained data stays subject to this DPA.
10.Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA, including completed security questionnaires and, once available, third-party audit reports. If that is not sufficient, or a regulator requires it, the Customer may conduct an audit at its expense, on at least 30 days' notice, during business hours, no more than once a year, subject to confidentiality, and without access to other customers' data.
11.International transfers
Customer Personal Data is stored in the United States. Where the GDPR, UK GDPR, or Swiss law applies, the parties incorporate the European Commission's Standard Contractual Clauses [Module 2 (controller to processor) and, where applicable, Module 3], the UK International Data Transfer Addendum, and the necessary Swiss amendments, with the details in this DPA completing their annexes. [Docking clause, supervisory authority, and governing law of the SCCs to be completed.]
12.GLBA service-provider terms
To the extent Customer Personal Data includes nonpublic personal information under the Gramm-Leach-Bliley Act or state insurance privacy laws, we will use and disclose it only to carry out the services for which it was disclosed to us, as permitted by the GLBA's service-provider exception (15 U.S.C. § 6802(b)(2) and its implementing rules), and we will implement and maintain safeguards appropriate to protect it, consistent with the Customer's obligations under applicable safeguards rules and state insurance data security laws (including 23 NYCRR 500 where applicable). The Customer remains responsible for its own consumer privacy notices and opt-outs.