Data Processing Addendum
Effective date: 2026-04-29 · Version 1.0 · This DPA forms part of the Terms of Service when entered between RateFileAI ("Processor") and Customer ("Controller").
Honest framing. This is the template enterprise customers receive at procurement. RateFileAI is a small operator; we do not yet hold SOC 2 Type I or Type II certification. Pre-SOC-2 customers (Lighthouse tier and pre-M6 enterprise) sign with explicit acknowledgment of pre-certification posture, paired with cyber-insurance coverage and the security controls described in Schedule C. Post-M6 customers receive Type I evidence; post-M12 receive Type II.
1. Definitions
Capitalized terms not defined here have the meaning given in the Terms of Service.
- Personal Data — any information relating to an identified or identifiable natural person, processed by Processor on behalf of Controller in connection with the Service.
- Controller — Customer (the entity that determines the purposes and means of processing Personal Data).
- Processor — RateFileAI (the entity processing Personal Data on behalf of the Controller).
- Sub-processor — any third party engaged by Processor to process Personal Data, as listed in Schedule B.
- Data Subject — the natural person to whom the Personal Data relates.
- Data Protection Laws — all applicable laws and regulations relating to data protection and privacy, including (where applicable) the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) and CPRA, and US state privacy laws.
- Security Incident — any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
2. Subject Matter, Duration, Nature, and Purpose
The subject matter of the processing is the Personal Data described in Schedule A. The duration of the processing is the term of the Agreement plus the retention periods specified in Schedule A. The nature of the processing is the storage, search, joining, ranking, and analytical aggregation of insurance rate-filing data and customer-supplied book-of-business data. The purpose is to provide the Service as described in the Terms of Service.
3. Processor Obligations
Processor shall:
- Process Personal Data only on documented instructions from Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by Union or Member State law (in which case Processor shall inform Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest).
- Ensure that personnel authorized to process Personal Data have committed themselves to confidentiality.
- Take all measures required pursuant to Article 32 GDPR (security of processing), as detailed in Schedule C.
- Respect the conditions for engaging Sub-processors as set out in Section 5.
- Assist Controller, by appropriate technical and organizational measures, insofar as possible, for the fulfillment of Controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III of the GDPR.
- Assist Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments).
- At Controller's choice, delete or return all Personal Data after the end of the provision of services relating to processing, and delete existing copies (subject to applicable legal retention requirements).
- Make available to Controller all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by Controller or another auditor mandated by Controller.
4. Controller Obligations
Controller represents and warrants that it has obtained all necessary consents and provided all necessary notices to Data Subjects required by Data Protection Laws to enable Processor to provide the Service. Controller is solely responsible for the accuracy, quality, and legality of Personal Data and the means by which Controller acquired Personal Data.
5. Sub-processors
Controller authorizes Processor to engage the Sub-processors listed in Schedule B. Processor shall:
- Maintain a current list of Sub-processors and provide at least 14 days' written notice (via the contact email on file) before engaging any new Sub-processor or replacing an existing one.
- Impose, by contract, data protection obligations on each Sub-processor that are no less protective than those in this DPA.
- Remain fully liable to Controller for the performance of each Sub-processor's obligations.
Controller may object to a new Sub-processor in writing within 14 days of notice. If the parties cannot resolve the objection in good faith, Controller may terminate the Agreement with prorated refund for the unused term.
6. Data Subject Rights
Processor shall, taking into account the nature of the processing, assist Controller by appropriate technical and organizational measures, insofar as possible, for the fulfillment of Controller's obligation to respond to requests for exercising data subject rights, including:
- Right of access (Art. 15 GDPR / CCPA "right to know")
- Right to rectification (Art. 16 GDPR)
- Right to erasure / "right to be forgotten" (Art. 17 GDPR / CCPA "right to delete")
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR / CCPA)
- Right to object (Art. 21 GDPR)
- Right to opt out of "sale" or "sharing" of personal information (CCPA/CPRA)
If Processor receives a Data Subject request directed at Personal Data processed on behalf of Controller, Processor will, without undue delay, forward the request to Controller and shall not respond to the Data Subject directly unless legally obligated.
7. Security Incident Notification
Processor shall notify Controller without undue delay, and in any case within 72 hours after becoming aware of a Security Incident affecting Personal Data. The notification shall include:
- The nature of the Security Incident, including the categories and approximate number of Data Subjects and records concerned.
- The likely consequences of the Security Incident.
- The measures taken or proposed to address the Security Incident, including measures to mitigate its possible adverse effects.
- The contact information for the person at Processor responsible for incident response.
Notifications shall be sent to the email on file for Controller's data protection contact, with a copy to info@ratefileai.com.
8. International Data Transfers
Processor's primary infrastructure is hosted with Hetzner Online GmbH (Germany / Finland data centers) and Hetzner Object Storage. Where Personal Data of EEA, UK, or Swiss Data Subjects is transferred to a country outside the EEA/UK/Switzerland not deemed adequate by the relevant authority, the parties agree that the European Commission's Standard Contractual Clauses (SCCs, 2021/914) shall apply, with Processor as the data importer (Module 2: Controller-to-Processor). UK Addendum (ICO Form S) and Swiss Addendum apply where relevant.
9. Audit Rights
Once per calendar year, Controller (or an independent auditor mandated by Controller) may, on at least 30 days' written notice, audit Processor's compliance with this DPA. Audits shall be conducted during normal business hours, in a manner that does not materially disrupt Processor's operations. Costs of the audit shall be borne by Controller, except where the audit reveals material non-compliance, in which case Processor shall reimburse reasonable audit costs. Where Processor maintains a current SOC 2 Type II report (target: M12 after service rollout), Controller agrees to accept that report in lieu of an on-site audit.
10. Term and Termination
This DPA remains in effect for the term of the underlying Agreement plus any retention periods specified in Schedule A. Upon termination, Processor shall, at Controller's written choice, delete or return all Personal Data within 30 days, except for any data Processor is required to retain by applicable law (in which case Processor shall continue to protect such data in accordance with this DPA).
11. Liability
The liability of each party arising out of or related to this DPA shall be subject to the limitations of liability set forth in the underlying Agreement (Section 8 of the Terms of Service).
12. Governing Law
This DPA is governed by the law specified in the underlying Agreement. For Controllers located in the EEA, UK, or Switzerland, the SCCs and applicable national data protection laws apply concurrently to the extent required.
Schedule A — Description of Processing
Categories of Data Subjects
- Authorized users of Customer (agency principals, producers, operations staff, analysts) — limited to login credentials, work email, IP address, session metadata.
- Customer's policyholders (where Customer uploads book of business data via the Renewal Defense feature) — limited to the data fields Customer chooses to upload (typically: customer identifier, current carrier, state, line of business, premium, renewal date). RateFileAI does not require directly-identifying personal information (full name, SSN, DOB, address) for the Renewal Defense feature to function, and recommends that Customer's uploaded data use opaque customer identifiers.
Categories of Personal Data
| Category | Source | Purpose |
|---|---|---|
| Account credentials, name, email, role | Customer signup via Clerk | Authentication, audit logs |
| IP address, device, session metadata | Captured at session | Security, abuse detection |
| Saved alert scopes (carrier / state / LOB) | Customer enters in app | Personalized alerts |
| Book of business uploads (customer identifier, carrier, state, lob, premium, renewal_date) | Customer uploads CSV via Renewal Defense | Ranking against rate filings and generation of renewal-risk scores and talking points. When the Customer saves a book in-app, these rows are persisted server-side for the Customer's own use until the Customer deletes the book or account; processed per-Customer only and never aggregated into any output shown to other Customers |
| Billing and invoicing data | Stripe | Subscription management |
Processing Operations
Storage, retrieval, search, indexing, ranking, joining (against public-record rate-filing data), aggregation (per-Customer only, not cross-Customer), export to Customer (CSV / API).
Retention
- Account data: retained for the term of the Agreement; deleted within 30 days of termination at Controller's request (subject to legal retention).
- Saved alert scopes: retained for the term; deleted on Controller request or termination.
- Book of business uploads: the public in-browser demo is parsed on the Customer's device, and only already-public carrier/state/line-of-business lookup tuples are sent server-side — no insured personal data is written. When the Customer saves a book in the app, the uploaded rows, scores, and talking points are persisted server-side (encrypted at rest) for the Customer's own use and retained until the Customer deletes the book or terminates, then deleted within 30 days of a deletion request (subject to legal retention). Processed per-Customer only; never aggregated into output shown to other Customers.
- Audit logs: 12 months.
- Billing records: as required by tax law (typically 7 years).
Schedule B — List of Sub-processors
Current as of 2026-05-12. Processor will provide 14 days' written notice via the contact on file before adding or replacing any Sub-processor.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application + database hosting; object storage for filing PDFs | Germany / Finland |
| Clerk Inc. | Authentication and user identity | United States |
| Stripe, Inc. | Subscription billing and payment processing | United States |
| Resend | Transactional email (alerts, digests, account notifications) | United States |
| Anthropic PBC | LLM-generated narrative summaries (AI brief, monthly reports). Zero-retention configuration; prompt and output are not used for training. | United States |
| Cloudflare, Inc. | DNS, edge caching of static assets | Global edge |
Not Sub-processors: Certain infrastructure vendors are used by RateFileAI for our own automated collection from public state and NAIC regulatory filing repositories; they do not process Customer Personal Data and are therefore not Sub-processors under this DPA.
Schedule C — Technical and Organizational Security Measures
Network and Infrastructure
- HTTPS/TLS 1.2+ enforced on all endpoints (HSTS).
- Strict-Transport-Security, X-Frame-Options DENY, X-Content-Type-Options nosniff, Referrer-Policy strict-origin-when-cross-origin, Permissions-Policy disabling camera/mic/geolocation.
- Subresource Integrity (SRI) on third-party CDN assets.
- Closed-beta gate (LAUNCH_LOCKDOWN) requiring authenticated session or service token for all data endpoints.
- Database not exposed to the public internet (loopback only); access via authenticated application backend.
- Secrets stored in environment variables with restricted file permissions; never committed to source control.
- Caddy deny rules block public access to
/app.jsx,/build.sh,/package.json,/node_modules/*,/backups/*,/.env*,/scripts/*.
Application
- Authenticated session required for all customer-data endpoints (Clerk JWT bearer tokens).
- SQL parameterization (no string concatenation in queries); parameterized via SQLAlchemy.
- Rate-limiting on authentication endpoints.
- Audit logging on data-export and book-upload events.
- Object storage signed-URL proxy: PDFs are served via 120-second signed URLs, never public-read.
Operational
- Production access limited to founder; SSH key-based, password authentication disabled.
- Daily encrypted database backups; quarterly restore drills.
- Cyber-insurance policy in force (general aggregate + privacy/security liability).
- Vendor security-questionnaire program for new Sub-processors.
Compliance roadmap
SOC 2 Type I report target: 2026 Q3. SOC 2 Type II report target: 2027 Q1. Pre-certification customers receive cyber-insurance certificate, vendor security questionnaire, and quarterly attestation of the controls listed above.
13. Contact
Data protection contact: info@ratefileai.com. Mailing address provided on request.