Privacy Policy
Effective Date: August 31, 2026
Open Insurance Inc. (“Open Insurance,” “we,” “us,” or “our”) provides an AI-powered platform that centralizes and organizes commercial real estate insurance data, including policies, certificates of insurance, statements of value, loss runs, claims, and property data (the “Platform”). This Privacy Policy describes how Open Insurance collects, uses, shares, and protects personal information through our websites that link to this Privacy Policy (including openinsured.com), the Platform, our marketing activities, live events, and the other activities described in this Privacy Policy (collectively, the “Service”).
This Privacy Policy also includes our data protection and security commitments (see Section 6) and additional disclosures for residents of certain U.S. states (see Section 10) and individuals located in the European Economic Area and United Kingdom (see Section 14).
NOTICE AT COLLECTION FOR U.S. STATE RESIDENTS: The categories of personal information we collect are described in Section 1, the purposes for which we use them in Section 2, the categories of recipients in Section 3, and our retention criteria in Section 7. We do not use personal information for targeted or cross-context behavioral advertising, and, except as described in Section 10 regarding visitor identification services, we do not sell or share personal information. See Section 10 (State Privacy Rights Notice) for your rights under applicable state privacy laws and how to exercise them, including how to opt out.
NOTICE TO EUROPEAN USERS: See Section 14 (Notice to European Users) for additional information for individuals located in the European Economic Area or United Kingdom.
1. Personal Information We Collect
Information You Provide to Us
- Contact data, such as your first and last name, email address, phone number, professional title, company name, and business mailing address.
- Account data, such as the username and password you set to establish an account on the Platform, your role and permissions, and other information you add to your account profile.
- Communications data, such as the contents of your exchanges with us when you contact us through the Service, request a demo, respond to our outreach, subscribe to our newsletter or educational content (including Insurance Academy materials), or communicate with us by email, phone, social media, or otherwise.
- Marketing data, such as your preferences for receiving marketing communications and details about your engagement with them.
- Event and promotion data, such as information you share when you register for or attend an event, webinar, or promotion we host or sponsor.
- Other data not specifically listed here, which we will use as described in this Privacy Policy or as otherwise disclosed at the time of collection.
Customer Data Uploaded to the Platform
Our customers upload insurance and property documents to the Platform, such as insurance policies, endorsements, certificates of insurance, statements of value, loss runs, claims records, and property and building condition data (“Customer Data”). Customer Data may incidentally contain personal information, such as the names, business contact details, and signatures of brokers, adjusters, property contacts, insureds, or other individuals appearing in insurance documents.
We process Customer Data on behalf of and at the direction of the customer that uploaded it, under the terms of our agreement with that customer. If your personal information appears in Customer Data and you have questions or requests concerning it, please contact the customer that uploaded the information; we will support our customers in responding to such requests as required by our agreements and applicable law. Section 5 (Our Role in Processing Customer Data) explains this further.
Information Collected Automatically
We, our service providers, and our business partners may automatically log information about you, your computer or mobile device, and your interactions over time with the Service and our communications, such as:
- Device data, such as your computer or mobile device’s operating system type and version, browser type, screen resolution, device type, IP address, unique identifiers, language settings, and general location information such as city, state, or geographic area.
- Online activity data, such as pages you viewed, how long you spent on a page, the website you visited before browsing to the Service, navigation paths, access times, and duration of access.
- Communication interaction data, such as whether you open our emails or click links within them. We may collect this through pixel tags embedded invisibly in our emails.
Some of this automatic collection is facilitated by cookies and similar technologies. For more information, see our Cookie Policy.
Visitor Identification
Like many business-to-business companies, we use third-party visitor identification and enrichment services that use information collected automatically from visitors to our websites, such as IP address and device identifiers, to identify the company, and in some cases the individual business contact, associated with a visit, and to provide us with related business contact information from their databases. We use this information to understand who is interested in our Service and to follow up with relevant business outreach from our team. We do not use this information for targeted or cross-context behavioral advertising. You can learn about your choices regarding this practice in Section 8 (Your Choices) and Section 10 (State Privacy Rights Notice).
Information from Third-Party Sources
We may combine personal information we receive from you with personal information we obtain from other sources, such as public sources (government agencies, public records, professional and company websites, social media platforms), data providers and enrichment services, our customers, marketing and event partners, and service providers that help us operate the Service or our business. We may also receive personal information in connection with an actual or prospective business transaction, such as a financing, merger, or acquisition.
2. How We Use Your Personal Information
We may use your personal information for the following purposes or as otherwise described at the time of collection:
Service delivery and operations. To provide, operate, and maintain the Service; establish and maintain your account; enable security features of the Service; communicate with you about the Service, including service announcements, updates, security alerts, and support messages; and respond to your requests, questions, and feedback.
Service improvement and analytics. To analyze usage of the Service, improve the Service and our business, understand how visitors interact with our websites and communications, and develop new products and services.
Marketing. To send you direct marketing communications about our products, services, events, and educational content, and to conduct relevant business outreach based on interest in our Service, including outreach informed by the visitor identification practices described above. You may opt out of marketing communications as described in Section 8 (Your Choices).
Events and promotions. To administer events, webinars, and promotions, and to communicate with you about them.
Compliance and protection. To comply with applicable laws, lawful requests, and legal process; protect our, your, or others’ rights, privacy, safety, or property (including by making and defending legal claims); audit our internal processes; enforce the terms that govern the Service; and prevent, identify, investigate, and deter fraudulent, harmful, unauthorized, unethical, or illegal activity, including cyberattacks.
Aggregated, de-identified, and anonymized data. We may create aggregated, de-identified, or anonymized data from personal information by removing information that makes the data identifiable to a particular individual. We may use and share such data for our lawful business purposes, including analyzing and improving the Service, benchmarking, and promoting our business. We will not attempt to re-identify de-identified data, except to test whether our de-identification processes comply with applicable law.
We do not use your personal information for targeted or cross-context behavioral advertising, and we do not use automated decision-making that produces legal or similarly significant effects concerning you.
3. How We Share Your Personal Information
We may share your personal information with the following parties, or as otherwise described in this Privacy Policy or at the time of collection:
- Affiliates. Any current or future corporate affiliates of Open Insurance Inc., for purposes consistent with this Privacy Policy.
- Service providers. Third parties that provide services on our behalf or help us operate the Service or our business, such as cloud hosting, data extraction and AI processing, information technology, security, customer support, email delivery, marketing and sales tools, and analytics. We contractually require our service providers to protect personal information and restrict their use of it to the services they provide to us.
- Visitor identification providers. The third-party visitor identification and enrichment services described in Section 1, to which we disclose identifiers such as IP address and device data and which may use that information to provide identification and enrichment services, including by reference to their own databases. Some state laws may treat this disclosure as a “sale” of personal information; see Sections 8 and 10 for your opt-out choices.
- The customer that controls your workspace. If you use the Platform through an account provisioned by an Open Insurance customer (for example, your employer or a company you work with), that customer and its administrators may access information associated with your use of that workspace.
- Professional advisors. Lawyers, auditors, bankers, insurers, and other professional advisors, in the course of the professional services they render to us.
- Authorities and others. Law enforcement, government authorities, and private parties, as we believe in good faith to be necessary or appropriate for the compliance and protection purposes described above.
- Business transferees. Counterparties and their advisors in connection with actual or prospective business transactions, such as investments in or financings of Open Insurance, or a merger, acquisition, sale of assets, or similar transaction, and any acquirer, successor, or assignee of Open Insurance, including in an insolvency, bankruptcy, or receivership.
We do not sell personal information for monetary consideration, and we do not share personal information with third parties for targeted or cross-context behavioral advertising. Please see Section 10 for how certain state laws may characterize our use of visitor identification services and the opt-out we provide.
4. Tracking Technologies
Some of our automatic data collection is facilitated by cookies, pixel tags, and similar technologies. For information about the technologies we use and your choices for controlling them, please see our Cookie Policy. We also use pixel tags in our emails to understand engagement with our communications; most browsers and email clients allow you to block images to prevent this.
Do Not Track. Some browsers can send “Do Not Track” signals. We do not currently respond to “Do Not Track” signals, but we do honor Global Privacy Control (“GPC”) signals as described in Section 10.
5. Our Role in Processing Customer Data
For personal information contained in Customer Data, Open Insurance acts as a service provider (or, for purposes of European law, a “processor”) on behalf of our customer, which determines the purposes and means of that processing. Our processing of Customer Data is governed by our agreement with the customer, and this Privacy Policy does not supersede that agreement. Individuals whose personal information appears in Customer Data should direct privacy questions and rights requests to the relevant customer. We will reasonably assist our customers in honoring such requests as required by our agreements and applicable law.
6. Data Protection and Security
We maintain a security program with technical, organizational, and physical safeguards designed to protect the personal information and Customer Data we process, appropriate to the nature and sensitivity of that information. Our safeguards include:
- Independent audit. We undergo SOC 2 Type II examinations, in which an independent auditor examines our controls over a defined review period.
- Encryption. Data is encrypted at rest and in transit using 256-bit AES encryption and modern transport-layer security.
- Access controls and isolation. Customer environments are logically isolated, and access to personal information is restricted to personnel who need it to perform their roles, under confidentiality obligations.
- Audit trails. We maintain audit logs of activity within the Platform.
- Vendor management. We assess the security practices of service providers that process personal information on our behalf and bind them to contractual data protection obligations.
If we become aware of a breach of security affecting your personal information, we will notify you and applicable regulators as required by law.
No method of transmission over the internet or method of electronic storage is completely secure. While we work to protect your personal information, we cannot guarantee its absolute security. You are responsible for keeping your account credentials confidential and for notifying us promptly at legal@openinsured.com if you suspect unauthorized access to your account.
7. Retention
We retain personal information for as long as necessary to fulfill the purposes for which we collected it, including satisfying legal, accounting, or reporting requirements, establishing or defending legal claims, and fraud prevention. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process it and whether those purposes can be achieved through other means, and applicable legal requirements. When we no longer require personal information, we delete it, anonymize it, or, where that is not practicable (for example, in backup archives), securely store it and isolate it from further processing until deletion is possible. Customer Data is retained and deleted in accordance with our agreements with the relevant customer.
8. Your Choices
- Access or update your information. If you have an account on the Platform, you may review and update certain account information by logging into your account, or by contacting us at legal@openinsured.com.
- Opt out of marketing communications. You may opt out of marketing emails by following the unsubscribe instructions in the email or by contacting us at legal@openinsured.com. If you opt out, you may continue to receive service-related and other non-marketing communications.
- Opt out of visitor identification-based outreach. If you do not wish to receive outreach informed by our visitor identification practices, or wish to opt out of any processing that applicable state law may treat as a “sale” of personal information, contact us at legal@openinsured.com or see Section 10.
- Cookies. For choices regarding cookies and similar technologies, see our Cookie Policy.
- Declining to provide information. We need certain personal information to provide the Service. If you do not provide information we identify as required, we may not be able to provide the Service or respond to your request.
9. Other Sites and Services
The Service may contain links to websites and services operated by third parties. These links are not an endorsement of, or representation that we are affiliated with, any third party. We do not control third-party websites or services and are not responsible for their privacy practices. We encourage you to read the privacy policies of the other websites and services you use.
10. State Privacy Rights Notice
This section applies to residents of U.S. states with comprehensive privacy laws applicable to us that grant their residents the rights described below (collectively, the “State Privacy Laws”), including, as applicable, California, Colorado, Connecticut, Delaware, New Jersey, Oregon, Texas, Virginia, and other states with similar laws. For purposes of this section, “Personal Information” has the meaning given to “personal data,” “personal information,” or similar terms under the State Privacy Laws. Note that California’s law applies to personal information collected in a business-to-business context, while several other states exempt personal information about individuals acting in a commercial or employment context; the State Privacy Laws also generally treat information we process as a service provider or processor on behalf of our customers differently. Where an exemption applies, the rights below may not be available.
Depending on your state of residence, you may have the right to:
- Know/Access. Request confirmation of whether we process your Personal Information and request a copy of the Personal Information we have collected about you, including the categories collected, the sources, the purposes, and the categories of third parties to which we disclose it.
- Correct. Request that we correct inaccurate Personal Information.
- Delete. Request that we delete Personal Information we have collected from you.
- Portability. Obtain a copy of your Personal Information in a portable and readily usable format.
- Opt out. Opt out of “sales” of Personal Information, “sharing” or processing of Personal Information for targeted advertising, and certain profiling.
- Appeal. Appeal our denial of a request, where provided by law.
- Nondiscrimination. Exercise these rights free from unlawful discrimination.
Categories of personal information. The following summarizes the categories of personal information we collect (described in Section 1), by reference to the statutory categories in the California Consumer Privacy Act, our purposes, and the parties to which we disclose them. This describes our practices currently and during the 12 months preceding the effective date of this Privacy Policy.
| Personal Information We Collect | CCPA Statutory Category | Purposes (see Section 2) | Disclosed for a Business Purpose To | “Sold” or “Shared” To |
|---|---|---|---|---|
| Contact data, account data | Identifiers; professional or employment-related information | Service delivery; marketing; events; compliance | Service providers; affiliates; the customer that controls your workspace; professional advisors; authorities; business transferees | None |
| Communications, marketing, and event data | Identifiers; commercial information | Service delivery; marketing; events; compliance | Service providers; affiliates; professional advisors; authorities; business transferees | None |
| Device data and online activity data | Identifiers; internet or other electronic network activity information; general (non-precise) geolocation | Service delivery; analytics and improvement; marketing (including visitor identification); security; compliance | Service providers; affiliates; authorities; business transferees | Visitor identification providers (IP address and device data), to the extent applicable law treats that disclosure as a “sale”; not “shared” for cross-context behavioral advertising |
| Personal information contained in Customer Data | Varies by document | Processed on behalf of the customer to provide the Service | Service providers (e.g., hosting and AI processing); the relevant customer | None |
Retention for each category is determined by the criteria described in Section 7.
Sales, sharing, and targeted advertising. We do not sell Personal Information for money, and we do not use or disclose Personal Information for targeted or cross-context behavioral advertising. However, some State Privacy Laws define “sale” broadly to include certain exchanges of Personal Information for non-monetary benefit. Our use of third-party visitor identification services (described in Section 1) involves the disclosure of identifiers such as IP addresses to those providers in exchange for identification and enrichment services, which may be characterized as a “sale” under some State Privacy Laws. You may opt out of this processing by: (1) broadcasting a Global Privacy Control (GPC) signal from your browser — we treat a GPC signal as a valid request to opt out of the “sale” or “sharing” of Personal Information for that browser; (2) using the “Cookies Settings” control on our websites; or (3) emailing legal@openinsured.com with the subject line “Opt-Out Request.”
Sensitive Personal Information. We do not intentionally collect or process sensitive Personal Information through our websites, and we do not process sensitive Personal Information for the purpose of inferring characteristics about consumers.
Profiling and automated decision-making. We do not use Personal Information for profiling or automated decision-making that produces legal or similarly significant effects concerning consumers.
Minors. We do not have actual knowledge that we sell or share the Personal Information of consumers under 16 years of age (or, for New Jersey residents, that we sell, or process for targeted advertising or certain profiling, the Personal Information of consumers 13 to 16 years of age).
Exercising your rights. You may submit requests by emailing legal@openinsured.com. We will respond within the time period required by applicable law (generally 45 days, extendable once where permitted). We may need to verify your identity before processing your request, and we reserve the right to confirm your state of residence. To verify your identity, we may request information sufficient to match you to our records, such as your name, email address, and company. Where permitted by law, you may use an authorized agent to submit a request on your behalf; we may require proof of the agent’s authority and verification of your identity.
Appeals. If we deny your request, you may appeal by replying to our denial or by emailing legal@openinsured.com with the subject line “Privacy Appeal” within a reasonable period after our decision. We will respond in writing within the period required by your state’s law (generally 45 to 60 days) explaining our decision and the reasons for it. If your appeal is denied, you may contact your state Attorney General; New Jersey residents may contact the New Jersey Division of Consumer Affairs.
Retention. We retain Personal Information as described in Section 7.
California Shine the Light. California residents may request information about disclosures of certain personal information to third parties for those parties’ own direct marketing purposes. Other than as described in this Privacy Policy with respect to visitor identification services, we do not disclose personal information to third parties for their own direct marketing purposes. California residents may submit requests to legal@openinsured.com with the statement “Shine the Light Request.”
Nevada. Nevada residents may opt out of the sale of certain covered information for monetary consideration. We do not engage in such sales, but Nevada residents may submit opt-out requests to legal@openinsured.com.
11. International Data Transfers
We are headquartered in the United States and use service providers that operate in the United States and other countries. Your personal information may be transferred to, stored in, and processed in the United States or other locations where privacy laws may not be as protective as those in your state, province, or country. Individuals in Europe should read Section 14 for important information about transfers of personal information outside of Europe.
12. Children
The Service is intended for business users and is not directed to anyone under 18 years of age. We do not knowingly collect personal information from children. If you are a parent or guardian and believe we have collected personal information from a child in a manner prohibited by law, please contact us at legal@openinsured.com and we will delete the information as required by applicable law.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you before the changes take effect by email (where we have your email address), by a prominent notice on the Service, or by other appropriate means, and we will update the effective date of this Privacy Policy. We will not apply materially new uses to personal information collected under an earlier version of this Privacy Policy without your consent where consent is required by law. Your use of the Service after the effective date of a modified Privacy Policy constitutes your acknowledgment that the modified Privacy Policy applies to your interactions with the Service.
14. Notice to European Users
General
The information in this section applies only to individuals located in the European Economic Area or the United Kingdom (collectively, “Europe”). References to “personal information” in this Privacy Policy are equivalent to “personal data” as defined under the EU General Data Protection Regulation and the UK GDPR (collectively, the “GDPR”).
Controller. Open Insurance Inc. is the controller of your personal information covered by this Privacy Policy for purposes of the GDPR, except for personal information contained in Customer Data, for which we act as a processor on behalf of the relevant customer (see Section 5). Our contact details are in Section 15.
Legal Bases for Processing
The GDPR requires a legal basis for each use of your personal information. Our legal bases are:
| Purpose | Legal Basis |
|---|---|
| Service delivery and operations | Contractual necessity (where we have a contract with you); otherwise, our legitimate interests in providing and operating the Service |
| Service improvement and analytics | Legitimate interests in understanding and improving the Service; consent, in respect of any non-essential cookies used for this purpose |
| Direct marketing and business outreach (including visitor identification) | Legitimate interests in promoting our business to relevant professional audiences; consent, where required by applicable law (including for any non-essential cookies and for electronic marketing where consent is required) |
| Events and promotions | Contractual necessity to administer the event or promotion; legitimate interests in promoting our business |
| Compliance and protection | Compliance with European laws to which we are subject (legal obligation); otherwise, our legitimate interests in complying with non-European legal obligations, protecting rights, safety, and property, and cooperating with legal process and authorities |
| Aggregated, de-identified, or anonymized data | Legitimate interests in analyzing and improving the Service |
Where we rely on consent, you may withdraw it at any time; withdrawal does not affect the lawfulness of processing before withdrawal.
Your Rights
If you are located in Europe, you may ask us to take the following actions with respect to personal information we hold about you as a controller: access it and receive information about our processing; correct inaccuracies; delete it; transfer a machine-readable copy of it to you or a third party of your choice; restrict its processing; object to processing based on legitimate interests, including for direct marketing (an objection to direct marketing is absolute); or withdraw any consent you have given, at any time. You may submit requests by email to legal@openinsured.com. We may request information to confirm your identity and process your request. If we decline a request in whole or in part, we will explain our grounds, subject to legal restrictions.
Complaints. If you are not satisfied with our response, you may lodge a complaint with the data protection supervisory authority in your habitual place of residence. For UK users, this is the Information Commissioner’s Office (ico.org.uk).
Data Processing Outside Europe
We are a U.S.-based company, and many of our service providers are also based in the United States. If you use the Service from Europe, your personal information will be processed in the United States and may be provided to recipients in other countries outside Europe. The United States is not the subject of a general adequacy decision under the GDPR. Where we transfer personal information out of Europe, we seek to ensure a similar degree of protection by implementing appropriate safeguards, such as the European Commission’s or UK’s approved standard contractual clauses with recipients, transfers to territories with an adequacy decision, or, in limited circumstances, reliance on a legal derogation such as your explicit consent. You may contact us at legal@openinsured.com for more information about the specific mechanism used for a transfer, or to request a copy of the relevant safeguards.
Other Information
Sensitive data. Other than personal information contained in Customer Data that we process as a processor on a customer’s behalf, please do not provide sensitive personal information (such as government identification numbers, racial or ethnic origin, political opinions, religion, health data, biometric or genetic data, criminal background, or trade union membership) through the Service.
Automated decision-making. We do not engage in automated decision-making or profiling that produces legal or similarly significant effects.
15. How to Contact Us
If you have questions about this Privacy Policy or our practices, or wish to exercise any privacy right available to you, please contact us at:
Email: legal@openinsured.com
Open Insurance Inc.