InsurWing respects your privacy and is committed to protecting personal data processed in connection with our website, platform and related services.
This Privacy Policy explains how InsurWing (“InsurWing”, “we”, “us” or “our”) collects, uses, shares and protects personal data. It should be read together with our Terms of Use and Disclaimer and, where applicable, the agreement governing your or your organisation’s use of InsurWing.
1Who We Are and When This Policy Applies
InsurWing is a business-to-business technology platform providing insurance brokers and other insurance professionals with intelligence, analytics, document-processing, workflow and decision-support capabilities.
Where we determine the purposes and means of processing personal data, Lognormal Analytics Private Limited acts as the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and, where applicable, as the Controller under the EU General Data Protection Regulation (“GDPR”).
This Policy applies to website visitors, individual brokers and professionals, employees and authorised users of broker firms, prospective customers and other individuals who interact directly with InsurWing.
Customer Data. Where a broker, broker firm or other customer provides personal data relating to its clients, prospects, employees or other individuals for processing through InsurWing, the customer generally acts as the Data Fiduciary/Controller and InsurWing acts as its Data Processor/Processor, subject to the applicable customer agreement and data processing agreement. Individuals seeking to exercise rights in relation to such data should ordinarily contact the relevant customer.
2Personal Data We Collect
Depending on how you interact with us, we may collect:
- Contact and account information: name, business email, telephone number, organisation, job title, account/login and subscription information;
- Communications: demo requests, enquiries, feedback and support communications;
- Technical and usage information: IP address, device/browser information, login activity, usage, security, diagnostic and error logs;
- Business information: professional and business contact information obtained from publicly available or authorised third-party sources; and
- Customer-provided information: information contained in policies, quotations, proposals, RFQs, endorsements, client/prospect records and other documents customers choose to process through InsurWing.
Customers are responsible for ensuring that they have an appropriate lawful basis or authority to provide personal data to InsurWing.
3How and Why We Use Personal Data
Where we act as Data Fiduciary/Controller, we may process personal data to:
- provide, administer and secure InsurWing and user accounts;
- manage subscriptions and provide support;
- respond to enquiries, arrange demonstrations and maintain business relationships;
- send service and, where permitted, marketing communications;
- monitor, troubleshoot and improve our services;
- prevent fraud, misuse and security incidents; and
- comply with legal obligations and establish, exercise or defend legal claims.
Under the GDPR, our legal bases may include performance of a contract, legitimate interests, consent and compliance with legal obligations, as applicable.
Under the DPDP Act, we process personal data for lawful purposes on the basis of consent or other uses permitted by applicable law. Where processing is based on consent, consent may be withdrawn in accordance with applicable law.
4AI and Customer-Provided Data
Certain InsurWing features may use artificial intelligence, machine learning or other automated technologies. Users should apply appropriate professional judgment and independently verify material AI-generated or automated outputs, as further explained in our Disclaimer.
Where InsurWing processes personal data contained in insurance documents or other customer-provided information on behalf of a customer, we process that data in accordance with the customer's instructions, applicable agreement and data-protection requirements.
Where applicable law imposes requirements concerning solely automated decision-making producing legal or similarly significant effects, we will comply with those requirements. We do not use personal data contained in customer-provided documents to train public or foundational artificial intelligence models.
5How We Share and Transfer Personal Data
We do not sell personal data.
We may share personal data, where necessary and permitted by law, with:
- service providers supporting hosting, infrastructure, communications, security, analytics, support and payments;
- authorised users within the relevant customer organisation;
- professional advisers;
- competent governmental, regulatory or legal authorities; and
- parties involved in a merger, acquisition, restructuring or similar corporate transaction.
Service providers processing personal data on our behalf are subject to appropriate contractual and security obligations.
Personal data may be processed outside the country in which it was collected. Where the GDPR applies, transfers outside the EEA will be made using an applicable adequacy decision or appropriate safeguard, including Standard Contractual Clauses where required. Transfers subject to the DPDP Act will be made in accordance with applicable statutory restrictions.
6Retention and Security
We retain personal data only for as long as reasonably necessary for the relevant purpose and to meet applicable contractual, legal, regulatory, security and dispute-resolution requirements.
Where we process customer-controlled personal data as a Processor, retention and deletion are governed by the applicable customer agreement, customer instructions and law.
We maintain appropriate technical and organisational safeguards designed to protect personal data, including appropriate access controls, authentication, encryption, logging, monitoring and security management measures. No system can guarantee absolute security.
7Your Privacy Rights
Depending on applicable law, you may have rights relating to your personal data.
Under the DPDP Act, these may include rights to access prescribed information about processing, correction, completion, updating and erasure, withdrawal of consent, grievance redressal and nomination.
Under the GDPR, these may include rights of access, rectification, erasure, restriction, objection, data portability, withdrawal of consent and rights relating to certain automated decision-making. You may also lodge a complaint with the competent supervisory authority.
To exercise an applicable right or raise a privacy concern, contact [email protected]. Where we process personal data solely on behalf of a customer, we may refer or coordinate the request with that customer as the relevant Data Fiduciary/Controller.
8Cookies, Marketing and Other Websites
We may use cookies and similar technologies for the operation and security of our website and Platform and to understand website usage and performance. Where required by applicable law, non-essential cookies, including analytics cookies, will be used only with your consent. You may withdraw or change your cookie preferences through the cookie settings available on our website.
Where permitted by law, we may send communications about InsurWing. You may opt out of marketing communications at any time without affecting necessary service, security or transactional communications.
InsurWing is intended for insurance brokers and other professionals and is not directed to children. We do not knowingly seek to collect children's personal data through the website or Platform for their own use of InsurWing.
Our website may link to third-party services. We are not responsible for the independent privacy practices of those third parties.
9Updates, Contractual Terms and Contact
We may update this Privacy Policy to reflect changes in our services, technology, processing practices or applicable law. The latest version will be published here with an updated date and, where required, additional notice or consent will be provided.
Where use of InsurWing is governed by a separate customer agreement or data processing agreement, that agreement governs the parties' contractual rights and obligations. In the event of an inconsistency concerning customer-controlled personal data processed by InsurWing on the customer's behalf, the applicable customer agreement or data processing agreement will prevail to the extent of the inconsistency.
For privacy questions, requests or grievances, please contact: