Published data unavailable. RateFileAI could not verify current source and as-of metadata. No unverified factual claim is being shown.

Legal

Data Processing Addendum

Effective date: 2026-04-29 · Version 1.0 · This DPA forms part of the Terms of Service when entered between RateFileAI ("Processor") and Customer ("Controller").

Template Enterprise procurement No SOC 2 yet

Honest framing. This is the template enterprise customers receive at procurement. RateFileAI is a small operator; we do not yet hold SOC 2 Type I or Type II certification. Pre-SOC-2 customers (Lighthouse tier and pre-M6 enterprise) sign with explicit acknowledgment of pre-certification posture, paired with cyber-insurance coverage and the security controls described in Schedule C. Post-M6 customers receive Type I evidence; post-M12 receive Type II.

1. Definitions

Capitalized terms not defined here have the meaning given in the Terms of Service.

2. Subject Matter, Duration, Nature, and Purpose

The subject matter of the processing is the Personal Data described in Schedule A. The duration of the processing is the term of the Agreement plus the retention periods specified in Schedule A. The nature of the processing is the storage, search, joining, ranking, and analytical aggregation of insurance rate-filing data and customer-supplied book-of-business data. The purpose is to provide the Service as described in the Terms of Service.

3. Processor Obligations

Processor shall:

  1. Process Personal Data only on documented instructions from Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by Union or Member State law (in which case Processor shall inform Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest).
  2. Ensure that personnel authorized to process Personal Data have committed themselves to confidentiality.
  3. Take all measures required pursuant to Article 32 GDPR (security of processing), as detailed in Schedule C.
  4. Respect the conditions for engaging Sub-processors as set out in Section 5.
  5. Assist Controller, by appropriate technical and organizational measures, insofar as possible, for the fulfillment of Controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III of the GDPR.
  6. Assist Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments).
  7. At Controller's choice, delete or return all Personal Data after the end of the provision of services relating to processing, and delete existing copies (subject to applicable legal retention requirements).
  8. Make available to Controller all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by Controller or another auditor mandated by Controller.

4. Controller Obligations

Controller represents and warrants that it has obtained all necessary consents and provided all necessary notices to Data Subjects required by Data Protection Laws to enable Processor to provide the Service. Controller is solely responsible for the accuracy, quality, and legality of Personal Data and the means by which Controller acquired Personal Data.

5. Sub-processors

Controller authorizes Processor to engage the Sub-processors listed in Schedule B. Processor shall:

Controller may object to a new Sub-processor in writing within 14 days of notice. If the parties cannot resolve the objection in good faith, Controller may terminate the Agreement with prorated refund for the unused term.

6. Data Subject Rights

Processor shall, taking into account the nature of the processing, assist Controller by appropriate technical and organizational measures, insofar as possible, for the fulfillment of Controller's obligation to respond to requests for exercising data subject rights, including:

If Processor receives a Data Subject request directed at Personal Data processed on behalf of Controller, Processor will, without undue delay, forward the request to Controller and shall not respond to the Data Subject directly unless legally obligated.

7. Security Incident Notification

Processor shall notify Controller without undue delay, and in any case within 72 hours after becoming aware of a Security Incident affecting Personal Data. The notification shall include:

Notifications shall be sent to the email on file for Controller's data protection contact, with a copy to info@ratefileai.com.

8. International Data Transfers

Processor's primary infrastructure is hosted with Hetzner Online GmbH (Germany / Finland data centers) and Hetzner Object Storage. Where Personal Data of EEA, UK, or Swiss Data Subjects is transferred to a country outside the EEA/UK/Switzerland not deemed adequate by the relevant authority, the parties agree that the European Commission's Standard Contractual Clauses (SCCs, 2021/914) shall apply, with Processor as the data importer (Module 2: Controller-to-Processor). UK Addendum (ICO Form S) and Swiss Addendum apply where relevant.

9. Audit Rights

Once per calendar year, Controller (or an independent auditor mandated by Controller) may, on at least 30 days' written notice, audit Processor's compliance with this DPA. Audits shall be conducted during normal business hours, in a manner that does not materially disrupt Processor's operations. Costs of the audit shall be borne by Controller, except where the audit reveals material non-compliance, in which case Processor shall reimburse reasonable audit costs. Where Processor maintains a current SOC 2 Type II report (target: M12 after service rollout), Controller agrees to accept that report in lieu of an on-site audit.

10. Term and Termination

This DPA remains in effect for the term of the underlying Agreement plus any retention periods specified in Schedule A. Upon termination, Processor shall, at Controller's written choice, delete or return all Personal Data within 30 days, except for any data Processor is required to retain by applicable law (in which case Processor shall continue to protect such data in accordance with this DPA).

11. Liability

The liability of each party arising out of or related to this DPA shall be subject to the limitations of liability set forth in the underlying Agreement (Section 8 of the Terms of Service).

12. Governing Law

This DPA is governed by the law specified in the underlying Agreement. For Controllers located in the EEA, UK, or Switzerland, the SCCs and applicable national data protection laws apply concurrently to the extent required.


Schedule A — Description of Processing

Categories of Data Subjects

Categories of Personal Data

CategorySourcePurpose
Account credentials, name, email, roleCustomer signup via ClerkAuthentication, audit logs
IP address, device, session metadataCaptured at sessionSecurity, abuse detection
Saved alert scopes (carrier / state / LOB)Customer enters in appPersonalized alerts
Book of business uploads (customer identifier, carrier, state, lob, premium, renewal_date)Customer uploads CSV via Renewal DefenseRanking against rate filings and generation of renewal-risk scores and talking points. When the Customer saves a book in-app, these rows are persisted server-side for the Customer's own use until the Customer deletes the book or account; processed per-Customer only and never aggregated into any output shown to other Customers
Billing and invoicing dataStripeSubscription management

Processing Operations

Storage, retrieval, search, indexing, ranking, joining (against public-record rate-filing data), aggregation (per-Customer only, not cross-Customer), export to Customer (CSV / API).

Retention

Schedule B — List of Sub-processors

Current as of 2026-05-12. Processor will provide 14 days' written notice via the contact on file before adding or replacing any Sub-processor.

Sub-processorPurposeLocation
Hetzner Online GmbHApplication + database hosting; object storage for filing PDFsGermany / Finland
Clerk Inc.Authentication and user identityUnited States
Stripe, Inc.Subscription billing and payment processingUnited States
ResendTransactional email (alerts, digests, account notifications)United States
Anthropic PBCLLM-generated narrative summaries (AI brief, monthly reports). Zero-retention configuration; prompt and output are not used for training.United States
Cloudflare, Inc.DNS, edge caching of static assetsGlobal edge

Not Sub-processors: Certain infrastructure vendors are used by RateFileAI for our own automated collection from public state and NAIC regulatory filing repositories; they do not process Customer Personal Data and are therefore not Sub-processors under this DPA.

Schedule C — Technical and Organizational Security Measures

Network and Infrastructure

Application

Operational

Compliance roadmap

SOC 2 Type I report target: 2026 Q3. SOC 2 Type II report target: 2027 Q1. Pre-certification customers receive cyber-insurance certificate, vendor security questionnaire, and quarterly attestation of the controls listed above.

13. Contact

Data protection contact: info@ratefileai.com. Mailing address provided on request.