Submission Desk · Legal
Privacy Policy
The short version
We collect what we need to run Submission Desk: your account details, the documents and client information you upload, and basic usage logs. Your clients' information is yours; we process it only on your behalf, as your GLBA service provider. We access your Outlook only to create drafts and read back the messages you send from them. We never sell or share personal information for advertising, use no tracking cookies, and never train AI on your data. You can download your data or delete your account from Settings at any time; we keep only the audit record of what was sent, for a fixed period.
This summary is for convenience. The full text below controls.
Contents
- Who we are and our role
- Information we collect
- Where it comes from
- How we use it
- Legal bases (EEA and UK)
- How we use Microsoft and Outlook data
- AI processing
- How we share it
- Do Not Sell or Share My Personal Information
- Global Privacy Control
- How long we keep it
- Security
- International transfers
- Your privacy rights
- How to exercise your rights
- Gramm-Leach-Bliley Act (GLBA)
- Children
- Data breach notification
- Changes to this policy
- Contact
1.Who we are and our role
Submission Desk is operated by [Company Legal Name, LLC] ("we", "us"), [Street, City, State ZIP]. This policy explains how we handle personal information in connection with the Service and our website.
We play two different roles, depending on whose information it is:
- Controller (business) for information about you as our customer and user: your account, profile, preferences, and how you use the Service.
- Processor (service provider) for the content you upload or create in the Service ("Customer Content"), including information about your clients (insureds), their owners and employees, and underwriters. We process Customer Content only on your instructions, under our Data Processing Addendum. If you are an insured or an individual named in a broker's file, the broker is responsible for that information and you should contact them first; we will help them respond.
2.Information we collect
| Category | Examples | Role |
|---|---|---|
| Account identifiers | Name, business email address, Microsoft account identifier, agency name, title, phone, email signature. | Controller |
| Microsoft profile | Basic profile from Microsoft sign-in (name, email, account ID). We do not receive your Microsoft password. | Controller |
| Customer Content | Uploaded documents and extracted text: ACORD forms, loss runs, statements of values, financials such as revenue and payroll, dec pages; risk summaries, broker notes, voice samples, underwriter contacts, drafts, and market results. May include names, contact details, and other personal information of an insured's owners and employees. | Processor |
| Email content and metadata | Drafts we create in your Outlook, and the one sent message we read back for each draft: recipients, subject, body, attachment names, timestamps, message IDs. | Processor |
| Connection credentials | OAuth tokens for Outlook and for the Claude connector, and an Anthropic API key if you add one. Stored encrypted. | Controller |
| Usage and log data | IP address, browser and device type, pages and actions, timestamps, error logs, AI usage counts (tokens), and the audit log of send-related actions. | Controller |
| Cookies and local storage | A session cookie that keeps you signed in, a short-lived cookie during Outlook connection, and display preferences stored in your browser. | Controller |
We do not intentionally collect sensitive personal information about you beyond your account credentials. Customer Content may contain sensitive information about insureds (for example, financial information); we process it only to provide the Service to you.
3.Where it comes from
- You, when you sign up, fill in your profile, upload documents, and use the Service.
- Microsoft, when you sign in with a Microsoft account or connect Outlook.
- Claude (Anthropic), when you use the Claude connector and Claude saves summaries or drafts back to your account at your direction.
- Your browser and device, automatically, when you use the Service.
4.How we use it
- To provide the Service: sign you in, store and extract your documents, draft emails, create Outlook drafts, and track results.
- To keep an accurate audit record of what was sent, for your errors-and-omissions defense and compliance.
- To secure the Service: detect and prevent fraud, abuse, and security incidents.
- To support you, and to send service, security, and legal notices.
- To measure AI usage and cost, and to maintain and fix the Service.
- To comply with law and enforce our Terms.
We do not use Customer Content for advertising, sell it, or use it to train AI models. We do not use automated decision-making that produces legal or similarly significant effects about you.
5.Legal bases (EEA and UK)
Where the GDPR or UK GDPR applies, we rely on these legal bases for the data we control:
- Contract: to provide the Service you signed up for.
- Legitimate interests: to secure, maintain, and improve the Service and to keep an audit record, balanced against your rights.
- Legal obligation: to keep records and respond to lawful requests.
- Consent: where we ask for it; you can withdraw it at any time.
For Customer Content, the broker (as controller) determines the legal basis.
6.How we use Microsoft and Outlook data
When you connect Outlook, we ask Microsoft for these delegated permissions: User.Read, Mail.ReadWrite, offline_access, openid, email, and profile. We do not request permission to send mail.
Our commitments for Microsoft data
- We access your mailbox only to create drafts you asked for, and to read back the messages sent from those drafts so we can record what was sent. We do not browse, index, or read the rest of your mailbox.
- We never send email for you. You send from Outlook yourself.
- We do not use Microsoft data for advertising, do not sell it, and do not use it to train AI models (ours or anyone else's).
- We transfer it only as needed to provide the Service, for security, or to comply with law.
- No person at [Company Legal Name, LLC] reads it, except with your explicit consent (for example, for support), when needed for security purposes such as investigating abuse, or to comply with law.
You can disconnect Outlook in the Service at any time; we then delete our stored tokens. Microsoft doesn't let apps revoke your consent for you, so we link you to your Microsoft account's app permissions page to remove it there too.
7.AI processing
AI helps extract risk summaries and draft emails. How your data reaches the AI depends on which option you choose (see AI Use & Transparency):
- Claude connector (primary). You connect your own Claude account. Claude reads your submission data through the connector at your request and saves results back. Claude runs under your own Anthropic plan and Anthropic's terms and privacy policy, which govern what Anthropic does with that data.
- In-app AI (optional). If you add your own Anthropic API key, or if we enable our key for your account, we send document text and related Customer Content to Anthropic's API under Anthropic's commercial terms, which do not permit training on that data by default. Anthropic is then our subprocessor.
If you use neither option, no Customer Content is sent to an AI provider.
8.How we share it
We share personal information only:
- with subprocessors that host and run the Service for us, under contracts that restrict their use of it (see Subprocessors);
- with services you connect (Microsoft, Anthropic), at your direction;
- when required by law, legal process, or to protect rights, safety, and security (we will notify you of requests for Customer Content where lawful);
- in a merger, acquisition, or sale of the business, subject to this policy; and
- with your consent.
9.Do Not Sell or Share My Personal Information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the past 12 months. We use no advertising cookies, analytics trackers, or tracking pixels, and we have no actual knowledge of selling or sharing the personal information of anyone under 16.
Because there is nothing to opt out of, no action is needed. If you would still like to record an opt-out request, email [privacy@yourdomain.com] and we will honor it if our practices ever change.
10.Global Privacy Control
We honor Global Privacy Control (GPC) and similar browser opt-out signals as a valid request to opt out of sale and sharing for that browser and, if you are signed in, for your account. Since we neither sell nor share, the signal doesn't change how the Service works, but we treat it as your standing choice.
11.How long we keep it
- Account and Customer Content: while your account is active. Keeping prior submissions is what lets next year's renewal start from last year's package.
- After a deletion request: we delete or de-identify it within 30 days, and it ages out of encrypted backups on their normal rotation of [35] days.
- Audit log: the record of communications you sent and related actions is kept for [7] years from creation, even after other data is deleted, because it exists for errors-and-omissions defense and regulatory recordkeeping.
- Security and server logs: up to [90] days, unless needed longer to investigate an incident.
- OAuth tokens and API keys: deleted as soon as you disconnect the service.
We may keep information longer where the law requires it or to resolve disputes.
12.Security
We use TLS in transit, encryption at rest for the database and file storage, additional AES-256-GCM encryption for OAuth tokens and keys, strict per-account data isolation, and an append-only audit log. No system is perfectly secure. Details, including what isn't in place yet, are in our Security Overview.
13.International transfers
We store data in the United States (our database and file storage are in the U.S. East region). If you are outside the U.S., your information will be transferred to and processed in the U.S. For transfers from the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum), [or the EU-U.S. Data Privacy Framework where applicable], together with supplementary safeguards. Contact us for a copy.
14.Your privacy rights
Your rights depend on where you live. We extend the core rights below to all users regardless of location. If your request concerns Customer Content (for example, you are an insured), we will refer it to or help the broker who controls that data.
California (CCPA/CPRA)
- Right to know and access the categories and specific pieces of personal information we collect, the sources, purposes, and the categories of recipients (described in this policy).
- Right to delete personal information we collected from you, subject to legal exceptions (such as the audit log).
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing: we don't sell or share (see above).
- Right to limit use of sensitive personal information: we use sensitive personal information (such as account credentials) only for purposes permitted without a right to limit, such as providing and securing the Service.
- Non-discrimination: we won't deny service, charge different prices, or provide a different quality of service because you exercised your rights.
- Authorized agents: you may use an authorized agent. We may require written, signed permission and may ask you to verify your identity directly.
- Verification: we verify requests by matching them to your signed-in account or the email address on file, and may ask for more information if needed. We respond within 45 days (extendable by 45 more with notice).
EEA and UK (GDPR / UK GDPR)
You have the right to access, rectify, erase, restrict, or object to processing of your personal data, to data portability, and to withdraw consent at any time. You may also lodge a complaint with your local data protection authority. [If required, name the EU/UK representative here.]
Other U.S. states
Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others) may have rights to confirm, access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale, and certain profiling. We don't engage in targeted advertising, sale, or such profiling. If we deny your request, you may appeal by replying to our decision or emailing [privacy@yourdomain.com] with "Appeal" in the subject; we respond to appeals within the time required by your state's law, and you may contact your state attorney general if you disagree.
15.How to exercise your rights
- Download your data: Settings → Privacy & data → Download my data (a JSON export).
- Delete your account: Settings → Privacy & data → Delete account. We process deletion within 30 days, subject to the retention described above.
- Correct your data: edit your profile and content directly in the Service.
- Anything else, or if you can't sign in: email [privacy@yourdomain.com].
16.Gramm-Leach-Bliley Act (GLBA)
Insurance brokers and agencies are "financial institutions" under the GLBA and state insurance privacy laws. When you upload nonpublic personal information about your clients, [Company Legal Name, LLC] acts as your service provider. We use and disclose that information only to perform services for you, as permitted by the GLBA's service-provider exception, and we maintain safeguards designed to protect it.
You remain responsible for your own obligations to your clients, including delivering any required privacy notices, honoring opt-outs, and meeting state insurance privacy and data security requirements (such as laws based on NAIC model acts, and New York DFS 23 NYCRR 500 where it applies to you), including your own oversight of service providers. We will reasonably assist, for example by answering security questionnaires.
17.Children
The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect personal information from children under 16 (or 13 for U.S. federal purposes). If you believe a child has given us personal information, contact [privacy@yourdomain.com] and we will delete it.
18.Data breach notification
If we become aware of a security breach affecting your personal information or Customer Content, we will notify affected customers without undue delay, and for Customer Content within 72 hours of confirming it, with the information you need to meet your own notification obligations. We will also notify individuals and regulators where the law requires us to.
19.Changes to this policy
We will post updates here and change the "Last updated" date. For material changes, we will notify you by email or in the Service before they take effect and, where required, ask for your consent.
20.Contact
Privacy questions and requests: [privacy@yourdomain.com]
Privacy contact: [Name or role of privacy contact / DPO, if appointed]
Mail: [Company Legal Name, LLC], Attn: Privacy, [Street, City, State ZIP]