Privacy Policy
Premwise Privacy Policy
Effective date: August 26, 2026
Last updated: August 26, 2026
Status: Published edition, authorized 2026-08-30.
This Privacy Policy explains how Premwise LLC (“Premwise,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects information in connection with our websites, business communications, software, and services (collectively, the “Services”).
1. Scope and roles
This Policy applies to information we process as a business or controller, such as website, account, business-contact, marketing, and customer-relationship information.
When we process personal information contained in documents or data provided by or for a customer—such as employee, payroll, policy, claim, or loss-run information—we generally act as the customer’s processor, service provider, or contractor. The customer controls that information, and Section 8.2 of our Master Services Agreement governs our processing as a processor, service provider, or contractor. (Corrected 2026-08-21: this named a Data Processing Addendum. There is no DPA and there will not be one — founder decision 2026-08-20, executed as FVA-005; the MSA carries the processing terms directly and the Processor List identifies our subprocessors.) An individual seeking to exercise rights concerning customer-controlled information should ordinarily contact the employer or other customer that supplied or authorized the data.
This Policy does not apply to independent websites, carriers, rating bureaus, brokers, payment processors, or other third parties that determine their own purposes and means of processing.
2. Information we collect
2.1 Account and business-contact information
We may collect:
- name, business email, phone number, title, employer, and business address;
- account credentials and authentication information;
- authorized-user, team, role, and permission information;
- customer-service, sales, and support communications; and
- preferences, consents, acknowledgments, and contract acceptance records.
2.2 Authorization and identity records
To obtain or process workers’ compensation information, we may collect:
- customer legal entity and trade names;
- signer name, title, capacity, and contact information;
- typed or electronic signatures;
- authorization text and version;
- date, time, device, and audit-trail information;
- policy, bureau, carrier, broker, and account identifiers; and
- revocation requests and effective dates.
We collect only the identity evidence reasonably needed for the applicable source and service.
2.3 Policy, rating, payroll, and premium information
Customer Content may include:
- policy declarations, endorsements, schedules, classifications, rates, premiums, deductibles, credits, debits, and policy periods;
- experience-rating worksheets, experience modifications, expected and actual loss data, rating values, and bureau records;
- payroll and remuneration by employee, class, state, project, or period;
- premium-audit records, auditor worksheets, invoices, notices, and account statements;
- certificates of insurance and subcontractor records; and
- generated findings, recomputations, scenarios, reports, and customer documents.
2.4 Claim and loss-run information
Customer Content may include:
- claim number, date, status, type, jurisdiction, and financial values;
- paid, reserved, incurred, recovery, and subrogation amounts;
- employee or claimant name and identifier;
- injury category and limited medical-related information contained in loss runs; and
- claim notes or supporting records supplied by the customer.
Premwise does not need full medical records for ordinary rating analysis. Customers should not upload detailed medical narratives, diagnoses, treatment records, Social Security numbers, or other highly sensitive data unless a specific approved workflow requires them.
2.5 Billing information
We may collect:
- billing contacts and addresses;
- subscription, Order Form, invoice, payment-status, tax, refund, and credit information;
- limited payment-method metadata supplied by our payment processor; and
- evidence of a cash refund, posted premium credit, finality, allocation, or reversal when a lawful recovery-based fee applies.
Complete payment-card numbers are intended to be collected and processed by our payment processor, not stored by Premwise.
2.6 Website, device, and usage information
We may collect:
- IP address, browser, device, operating system, and language;
- login, session, security, error, and audit logs;
- pages, features, buttons, searches, and workflow events;
- referring source and campaign information;
- approximate location inferred from IP address; and
- cookie, local-storage, and similar technology data.
We will describe nonessential analytics or advertising technologies in a cookie notice and provide choices required by law. We do not use Customer Content for cross-context behavioral advertising.
2.7 Information from third parties
With customer authorization or as otherwise lawful, we may receive information from:
- rating bureaus;
- insurance carriers;
- brokers or agents;
- claims administrators;
- payroll, accounting, or HR providers;
- payment processors;
- identity, fraud, security, and business-information providers;
- public regulatory filings and government sources; and
- a customer’s authorized users or advisors.
3. How we use information
We use information to:
- create, authenticate, administer, and secure accounts;
- verify authority and retain authorization evidence;
- provide the Services requested by the customer;
- ingest, extract, normalize, recompute, compare, and cite customer-authorized data;
- generate findings, reports, scenarios, and customer-controlled documents;
- perform licensed review where required;
- apply jurisdiction, license, entity, and feature controls;
- support customers and respond to communications;
- bill, collect, reconcile, refund, and audit fees;
- detect fraud, abuse, security incidents, and violations;
- debug, maintain, test, and improve reliability and user experience;
- maintain records and comply with legal, regulatory, license, insurance, tax, and accounting duties;
- establish, exercise, or defend legal rights; and
- send service messages and, subject to law and preferences, business marketing.
4. Machine learning and product improvement
4.1 No generalized or shared model training with Customer Content
We do not use Customer Content—including policy, payroll, employee, claim, loss-run, or customer document data—to train or improve generalized or shared machine-learning models. We contractually require subprocessors that receive Customer Content to use it only to provide the contracted services and not for their own model training, except where the customer gives separate written authorization.
4.2 Automated and assisted processing
We may use deterministic software, OCR, extraction models, and other automated or assisted tools to process Customer Content for the customer’s requested service. For the self-serve employer-direct service, Premwise does not review your findings: no Premwise person approves, edits, or signs off on them. Findings are presented to you, and you review and approve them before anything is prepared for your submission. Where the platform cannot verify a result to its own standard, it declines to release it or holds it and tells you so, rather than routing it to a Premwise reviewer. Where your broker uses the platform on your behalf, your broker reviews the findings; Premwise still does not.
4.3 Deidentified and aggregated information
We may create and use information that has been aggregated or deidentified so it cannot reasonably be linked to a customer or individual. We do not describe information as deidentified if we retain a reasonably usable means of linking it back.
(Conforming addition, 2026-08-08, adopted with the Master Services Agreement — this paragraph is the public commitment MSA §9.6(b) refers to. It is stated here, in the public document, because a commitment made only inside a signed contract is not a public one.)
Our public commitment. We commit to maintain and use aggregated and deidentified information solely in deidentified form, and not to attempt to reidentify it, except solely to test whether our deidentification is effective. Where we provide such information to an identified recipient, we contractually require that recipient to make the same commitments, including this pass-down obligation, and we monitor compliance and act on breaches. Where we publish such information generally, we apply the suppression and minimum-group rules of our documented deidentification methodology, so that the published output itself cannot reasonably be used to identify any business or individual.
We do not publish row-level data. We will not publish, license, distribute, or otherwise disclose outside Premwise any claim-level or injury-attribute row data in any form. What we publish or license is limited to aggregated statistics and derived measures.
We do not name customers. We will not identify a customer or a business whose information was submitted to us, by name, in any published material without prior written consent.
These commitments bind our successors and assigns, including any acquirer of our assets.
4.4 Separate authorization
We will not use identifiable Customer Content to develop a generalized model, benchmark, dataset, or commercial training corpus unless the customer provides separate, specific, written authorization that is not bundled with access to the ordinary Services.
5. How we disclose information
We may disclose information as follows.
5.1 Service providers and subprocessors
We may use providers for hosting, storage, security, authentication, OCR, AI-assisted extraction, communications, support, analytics, payment processing, document generation, and professional services. They may process information only for the contracted purpose and under confidentiality, security, use-restriction, deletion, and subprocessor terms appropriate to the information.
A current subprocessor list is maintained as the Premwise Processor List, published at https://premwise.ai/legal/processors and incorporated into the Master Services Agreement at §1.1(6) and §8.2(e).
5.2 Customer and authorized users
We disclose Customer Content and results to the customer, its authorized users, and persons the customer directs us to include, subject to account permissions.
5.3 Licensed professionals and advisors
We may disclose information to licensed insurance professionals or attorneys assigned to provide or review a service, subject to their professional and contractual duties. No attorney-client relationship is created unless a separate legal engagement expressly creates one.
5.4 Carriers, rating bureaus, and other sources
We may transmit an authorization or access request to a carrier, bureau, or other source when the customer has expressly authorized that access and the applicable source permits it.
Unless a separate, lawful Order Form expressly enables a communication feature, we do not submit a correction, dispute, demand, or substantive position to a carrier or rating bureau on the customer’s behalf.
5.5 Business transfers
We may disclose information in connection with a proposed or completed financing, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and continued legal restrictions.
5.6 Legal, safety, and compliance
We may disclose information when reasonably necessary to:
- comply with law, legal process, regulator request, license duty, or court order;
- protect rights, safety, systems, customers, or the public;
- investigate fraud, security incidents, or violations; or
- establish, exercise, or defend legal claims.
Where lawful and appropriate, we will notify the customer and seek to limit the disclosure.
5.7 With consent or direction
We may disclose information with the customer’s or individual’s direction or consent.
6. What we do not do
- We do not sell personal information for money.
- We do not share personal information for cross-context behavioral advertising.
- We do not use Customer Content for generalized or shared model training as described above.
- We do not intentionally collect full payment-card numbers into Premwise systems.
- We do not publish customer recoveries, logos, or case details without written permission.
- We do not disclose Customer Content to a carrier or bureau to pursue a correction unless a separately authorized and lawful feature permits it.
If our practices change in a way that legally constitutes a sale or sharing, we will provide required notice and choice before the change applies.
7. Legal bases for processing
Where a law requires a legal basis, we process information as necessary to:
- perform a contract or take requested pre-contract steps;
- comply with legal and regulatory obligations;
- pursue legitimate interests such as providing, securing, supporting, and improving the Services, where those interests are not overridden by individual rights; or
- act with consent, which may be withdrawn subject to prior lawful processing.
For Customer Content processed on a customer’s behalf, the customer determines the legal basis and is responsible for required notices and permissions.
8. Data retention
We retain information only as long as reasonably necessary for the purposes described, including contractual, source-access, security, backup, dispute, tax, and legal requirements. Our retention periods are:
| Category | Retention |
|---|---|
| Account and contract records | Term of the agreement, then 7 years |
| Authorization evidence | Term, then 7 years |
| Source documents and extracted data | Term, then 30 days |
| Claim and loss-run data | Term, then 30 days |
| Generated findings and reports | Term, then 30 days |
| Billing records | 7 years |
| Support communications | 2 years |
| Audit and security logs | 12 months |
| Website, device, and usage information (analytics) | 12 months |
| Information received from third parties | The retention period of the category it supplements |
| Database backups (held by our infrastructure provider) | 7 days |
| Encrypted document copies (separate storage provider) | 90 days maximum |
Backups. We use Supabase as our database and file-storage provider. Supabase takes automated daily backups of our database, which they retain for seven days; those backups are held by Supabase and are not separately downloaded or stored by us. Documents you upload are additionally copied, in encrypted form, to a separate storage provider (Cloudflare R2) so that a failure at one provider does not destroy your files; those copies are retained for no more than ninety days.
Customer Content is deleted within 30 days of a request made within thirty (30) days after termination, and purged from backups within 90 additional days. A customer may request earlier deletion, subject to legal hold and dispute preservation.
Copies may persist in the backups described above until those backups expire on the schedules stated — no more than seven days for database backups and ninety days for encrypted document copies. In no case will Customer Content persist more than one hundred fifty (150) days after termination: up to thirty (30) days for you to make a deletion request, up to thirty (30) days for us to delete it from our live systems, and up to ninety (90) further days for the backup copies described above to expire.
We do not hold professional review or license review records, because we do not review findings — the platform is self-serve.
9. Security
We maintain administrative, technical, and organizational safeguards designed to protect information against unauthorized access, acquisition, destruction, loss, alteration, or disclosure. Depending on the system and data, safeguards may include:
- access controls and role-based permissions;
- encryption in transit and at rest;
- tenant isolation and database controls;
- logging and monitoring;
- secure development and change management;
- vulnerability management;
- vendor due diligence;
- incident response;
- backup of our database by our infrastructure provider, and encrypted copies of uploaded documents held with a second storage provider (described in Section 8); and
- human access to Customer Content limited to the operator, under the confidentiality obligations in our customer agreements; subprocessors process Customer Content only under the contractual controls described in Section 5.1.
No system is completely secure, and we cannot guarantee that an incident will never occur.
SOC 2 status
Premwise has not completed a SOC 2 Type II examination. We are implementing controls mapped to the AICPA Trust Services Criteria and preparing for an independent examination.
We will update this statement only when the actual engagement and report status changes. We do not describe Premwise as “SOC 2 certified.”
10. Workers’ compensation and medical-related information
Workers’ compensation records can contain sensitive employment and medical-related information. Premwise is not necessarily a HIPAA covered entity or business associate merely because a record contains health information. Customers and source organizations remain responsible for determining whether HIPAA or another medical, employment, disability, or workers’ compensation privacy rule applies.
We use a minimum-necessary approach. Customers should:
- provide only fields needed for the analysis;
- redact Social Security numbers and unnecessary medical narratives;
- avoid uploading full treatment records unless expressly required and approved;
- limit user access; and
- use approved secure upload methods rather than ordinary email.
11. Individual privacy rights
Depending on location and applicable law, an individual may have rights to:
- know or access personal information;
- correct inaccurate information;
- delete information;
- obtain a portable copy;
- opt out of certain sales, sharing, targeted advertising, or profiling;
- restrict or object to certain processing; and
- appeal a denial.
To submit a request concerning information Premwise controls, contact legal@premwise.ai. We may verify identity and authority and may deny or limit a request where law permits.
For information in a customer account or Customer Content, contact the employer or customer first. We will assist the customer as required by MSA §8.2(f).
We will not discriminate against an individual for exercising a privacy right.
12. California notice
Where the California Consumer Privacy Act applies:
- the categories collected are described in Section 2;
- purposes are described in Section 3;
- disclosure categories are described in Section 5;
- retention is described in Section 8;
- Premwise does not sell or share personal information for cross-context behavioral advertising as described in Section 6; and
- Premwise generally acts as a service provider or contractor for Customer Content under MSA §8.2.
We do not knowingly sell or share personal information of individuals under 16. We do not use or disclose sensitive personal information for purposes requiring a right to limit beyond those permitted by law or directed by the customer.
13. Cookies and communications
We use strictly necessary technologies for authentication, security, preferences, and core functions. We may use analytics technologies subject to applicable notice and choice.
Customers may opt out of nonessential marketing emails using the unsubscribe link or by contacting us. We may still send transactional, security, account, license, billing, and legal messages.
14. International processing
Premwise is intended initially for United States businesses. Information may be processed in the United States and other locations where approved subprocessors operate. Where required, we will use appropriate transfer mechanisms and disclosures.
15. Children
The Services are for businesses and are not directed to children. We do not knowingly collect personal information directly from children through account registration. Customer Content may concern employees or claimants; customers must have lawful authority to provide it.
16. Changes to this Policy
We may update this Policy to reflect changes in law, products, or practices. We will post the updated date and provide additional notice when required. We will not materially expand use of Customer Content for a new purpose without the notice, contract change, or consent required by law.
17. Contact
Premwise LLC
Privacy: legal@premwise.ai
Security incidents: legal@premwise.ai
Data protection contact: legal@premwise.ai