1. Purpose & Scope
This Data Processing Addendum ("Addendum") applies where InsuranceGain.Ai processes personal data in connection with referrals to a carrier, quote and policy status reporting, insurer portal access, and related marketplace services. It supplements our Terms of Service and Privacy Policy and any separate agreement with a carrier or partner. If this Addendum conflicts with another agreement, the agreement that provides greater protection for personal data controls.
2. Definitions
"Controller" — the party that determines the purposes and means of processing personal data.
"Processor" — the party that processes personal data on documented instructions from a controller.
"Personal Data" — information relating to an identified or identifiable natural person processed in connection with the Services.
"Subprocessor" — a third party engaged by InsuranceGain.Ai to process Personal Data in support of the Services.
Other capitalized terms have the meanings given in the Terms of Service or applicable data-protection law.
3. Roles of the Parties
For shopper-initiated quote and referral activity, InsuranceGain.Ai generally determines the purposes of processing as an independent controller. Where we process Personal Data strictly on documented instructions from a carrier or partner, we act as a processor and the carrier or partner remains the controller. Each party is responsible for its own compliance with applicable data-protection law, including providing any required notices and establishing a lawful basis for processing.
4. Subject Matter & Duration
Processing covers shopper account details, quote requests, coverage preferences, referral and policy status, premium-payment records, earning activity, and insurer portal credentials. Processing continues for the duration of the relationship and any retention period described in the Privacy Policy.
5. Nature & Purpose of Processing
- Generating, ranking, saving, and explaining quote options.
- Routing shoppers to a selected carrier and attributing the referral.
- Reporting aggregate referral, conversion, and return-visit metrics to insurers.
- Operating accounts, earning credits, premium-payment records, and support conversations.
- Securing the service, preventing fraud, and meeting legal obligations.
6. Categories of Data & Data Subjects
Data subjects are shoppers, insurer portal users, and carrier applicants. Categories include identifiers (name, email, phone), location at ZIP-code level, insurance preferences, referral and policy status, payment amounts and dates (not card or account numbers), and portal account credentials. The Services are not designed to receive special categories of data such as health records, and carriers should not transmit them to us.
7. Documented Instructions
Where we act as processor, we process Personal Data only on the controller's documented instructions, including as described in this Addendum and the controller's configuration and use of the Services, unless law requires otherwise. We will inform the controller if we believe an instruction infringes applicable data-protection law.
8. Aggregate Reporting Only
Insurers receive only aggregate impact figures — such as shoppers sent, site visits reached, policies completed, and return rates. InsuranceGain.Ai does not disclose individual shopper identities or policy-level personal data to insurers through the portal. Any disclosure of identified shopper data to a carrier occurs only when the shopper chooses to continue to that carrier's own site or application.
9. Confidentiality
We ensure that persons authorized to process Personal Data are bound by confidentiality obligations and receive appropriate training on their responsibilities.
10. Security Measures
We apply administrative, technical, and organizational safeguards appropriate to the risk, including:
- Encryption of data in transit.
- Row-level data isolation so each account can access only its own records.
- Least-privilege service access and individual credentials for portal users.
- Server-side verification of membership and role before any portal or admin data is returned.
- Logging of security events and referral activity for abuse detection.
11. Subprocessors
We use hosting, database, AI, and communications providers to operate the marketplace. These providers process data only to deliver their services to us and under contractual confidentiality and security obligations. We remain responsible for their performance of those obligations. Carriers may request the current list of subprocessors through the support channel.
12. Data Subject Requests
Where we act as processor, we will reasonably assist the controller in responding to access, correction, deletion, portability, or restriction requests, taking into account the nature of the processing. If we receive a request directly relating to processing we perform for a controller, we will direct the requester to that controller where practicable.
13. Incident Notification
If we become aware of a personal-data breach affecting data we process as processor, we will notify the affected controller without undue delay and provide information reasonably available about the nature, scope, and likely consequences of the breach, and the measures taken to address it.
14. International Transfers
Data may be processed in the United States or other locations where our service providers operate. Where required, transfers rely on appropriate safeguards consistent with applicable data-protection law, such as standard contractual clauses.
15. Audits & Records
On reasonable written request, we will make available information reasonably necessary to demonstrate compliance with this Addendum. Where that information is insufficient, a controller may conduct an audit no more than once per year, at its own expense, on reasonable notice, subject to confidentiality and without disruption to the Services or access to other customers' data.
16. Deletion & Return
On termination of the relationship, and subject to legal retention duties, we will delete or return Personal Data processed on a controller's instructions within a reasonable period, and certify deletion on request.
17. Contact
Questions about this Addendum, subprocessor lists, or processing records may be sent through the support channel displayed in your account.