Cookie Preferences

We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. You can accept or reject non-essential cookies, and you can change your preferences at any time using the Cookie Preferences link in the footer. Learn more in our Privacy Policy and Cookie Policy.

Cookie Preferences

Manage your cookie preferences. You can enable or disable different types of cookies below.

Essential Cookies

Required for the website to function properly. These cannot be disabled.

Analytics Cookies

Help us understand how visitors interact with our website by collecting anonymous information.

Marketing Cookies

Used to track visitors across websites for marketing purposes and to deliver personalized ads.

Risk FabrIQ logo
About Solutions Work With Us
Sign In Get Started
About Solutions Work With Us Sign In Get Started

Privacy Policy

Last Updated: July 7, 2026

Version: 1.1

Important Notice

This Privacy Policy applies to users worldwide. Specific rights and obligations may vary by jurisdiction. We are committed to complying with applicable data protection laws in all jurisdictions where we operate, including but not limited to GDPR (EU/EEA/UK), PIPL (China), LGPD (Brazil), POPIA (South Africa), CCPA/CPRA (California), PIPEDA (Canada), and country-specific data protection laws in over 190 countries.

1. Introduction and Scope

Risk FabrIQ ("we," "our," "us," or "the Company") operates a global insurance placement platform serving users in over 190 countries and jurisdictions. This Privacy Policy explains how we collect, use, process, disclose, transfer, and safeguard your personal information when you access or use our website, software, services, and related applications (collectively, the "Services").

Data Controller: For users in the European Economic Area (EEA), United Kingdom, and Switzerland, Risk FabrIQ acts as the data controller. For users in other jurisdictions, the applicable data controller may vary based on local entity structure and applicable law.

Geographic Scope: This policy applies globally. However, certain provisions may be modified or supplemented by jurisdiction-specific addenda to comply with local data protection laws, including but not limited to:

  • European Union/EEA/UK: General Data Protection Regulation (GDPR) and UK GDPR
  • China: Personal Information Protection Law (PIPL) and Cybersecurity Law
  • Brazil: Lei Geral de Proteção de Dados (LGPD)
  • South Africa: Protection of Personal Information Act (POPIA)
  • United States: California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), and other applicable state privacy laws
  • Canada: Personal Information Protection and Electronic Documents Act (PIPEDA) and provincial privacy laws
  • Australia: Privacy Act 1988
  • Japan: Act on the Protection of Personal Information (APPI)
  • Singapore: Personal Data Protection Act (PDPA)
  • India: Digital Personal Data Protection Act (DPDPA)
  • Other Jurisdictions: Applicable local data protection and privacy laws

2. Information We Collect

We collect information that identifies, relates to, describes, references, or could reasonably be linked, directly or indirectly, with you or your device ("Personal Information"). The categories of Personal Information we collect depend on how you interact with our Services and may include:

2.1 Information You Provide Directly

  • Account Information: Name, email address, phone number, company name, job title, business address, and other professional information
  • Insurance-Related Data: Information related to insurance quotes, policies, claims, risk assessments, and insurance transactions
  • Financial Information: Payment card information (processed securely through third-party payment processors), billing addresses, and transaction history
  • Communication Data: Correspondence, inquiries, support requests, and feedback
  • Authentication Data: Usernames, passwords (hashed), and security questions
  • Profile Information: Preferences, settings, and customizations

2.2 Information Collected Automatically

  • Device Information: IP address, device type, operating system, browser type and version, device identifiers, and mobile network information
  • Usage Data: Pages visited, time spent, clickstream data, search queries, features used, and interaction patterns
  • Location Data: General geographic location derived from IP address (country/region level), and precise location if you grant permission
  • Technical Data: Log files, error reports, performance data, and system configuration
  • Cookies and Tracking Technologies: See Section 9 for detailed information

2.3 Information from Third Parties

  • Business Partners: Information from insurers, brokers, and other business partners
  • Service Providers: Information from analytics providers, payment processors, and other vendors
  • Public Sources: Information from publicly available sources, subject to applicable law
  • Regulatory Databases: Information from insurance regulatory authorities and compliance databases

2.4 Special Categories of Personal Data

In certain jurisdictions and contexts, we may process special categories of personal data (sensitive personal information), such as health information related to insurance underwriting, financial information, or information revealing racial or ethnic origin. We only process such data when:

  • You have provided explicit consent
  • Processing is necessary for insurance purposes and permitted by applicable law
  • Processing is required to comply with legal obligations
  • Processing is necessary for the establishment, exercise, or defense of legal claims

3. Legal Basis for Processing (GDPR/UK GDPR)

For users in the EEA, UK, and other GDPR-applicable jurisdictions, we process your Personal Information based on the following legal bases:

  • Consent: When you have given clear consent for specific processing activities
  • Contract Performance: To perform our contract with you or take steps at your request before entering into a contract
  • Legal Obligation: To comply with legal obligations, including insurance regulatory requirements, tax laws, and anti-money laundering regulations
  • Legitimate Interests: For our legitimate business interests, such as improving our Services, fraud prevention, and network security, where such interests are not overridden by your rights
  • Vital Interests: To protect your vital interests or those of another person
  • Public Task: When processing is necessary for the performance of a task carried out in the public interest

For users in other jurisdictions, we process Personal Information in accordance with applicable local laws, which may include consent, contractual necessity, legitimate interests, or other legal bases recognized under local law.

4. How We Use Your Information

We use Personal Information for the following purposes:

4.1 Service Delivery

  • Provide, operate, maintain, and improve our Services
  • Process insurance quotes, applications, and policy transactions
  • Facilitate communication between users, insurers, and brokers
  • Manage user accounts, authentication, and access control
  • Process payments and manage billing

4.2 Compliance and Regulatory

  • Comply with insurance regulatory requirements across multiple jurisdictions
  • Meet data protection and privacy law obligations
  • Respond to regulatory inquiries and audits
  • Maintain records as required by law
  • Conduct compliance monitoring and reporting

4.3 Business Operations

  • Analyze usage patterns and improve user experience
  • Conduct research and analytics
  • Develop new features and services
  • Prevent fraud, abuse, and security threats
  • Enforce our Terms of Service and policies

4.4 Communication

  • Send service-related communications (transactional, administrative)
  • Respond to inquiries and provide customer support
  • Send marketing communications (with your consent, where required)
  • Notify you of important changes to our Services or policies

4.5 Legal and Safety

  • Protect our rights, property, and safety, and that of our users
  • Comply with court orders, subpoenas, and legal processes
  • Investigate potential violations of our Terms of Service
  • Defend against legal claims

5. Data Sharing and Disclosure

We do not sell your Personal Information. We may share your Personal Information in the following circumstances:

5.1 Service Providers and Business Partners

We share information with third-party service providers who perform services on our behalf, including:

  • Cloud Infrastructure Providers: For hosting, storage, and computing services
  • Payment Processors: For secure payment processing (e.g., Stripe)
  • Analytics Providers: For usage analytics and performance monitoring
  • Communication Services: For email, messaging, and notification services
  • Insurance Partners: Insurers, brokers, and other insurance industry participants as necessary to provide insurance services
  • Compliance and Regulatory Services: For regulatory reporting and compliance monitoring

All service providers are contractually obligated to protect your Personal Information and use it only for specified purposes in accordance with applicable data protection laws.

5.2 Legal and Regulatory Disclosures

We may disclose Personal Information when required by law, regulation, or legal process, including:

  • Compliance with insurance regulatory requirements
  • Response to court orders, subpoenas, or government requests
  • Cooperation with law enforcement investigations
  • Protection of rights, property, or safety
  • Compliance with anti-money laundering and sanctions regulations

5.3 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your Personal Information may be transferred to the acquiring entity, subject to the same privacy protections.

5.4 With Your Consent

We may share your Personal Information with third parties when you have provided explicit consent for such sharing.

6. International Data Transfers

As a global platform, your Personal Information may be transferred to, stored in, and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your jurisdiction.

6.1 Transfer Mechanisms

We implement appropriate safeguards for international data transfers, including:

  • Standard Contractual Clauses (SCCs): For transfers from the EEA/UK to third countries, we use European Commission-approved Standard Contractual Clauses
  • Adequacy Decisions: We rely on adequacy decisions where applicable (e.g., transfers to countries with adequacy decisions under GDPR)
  • Binding Corporate Rules: Where applicable, we implement binding corporate rules for intra-group transfers
  • Other Legal Mechanisms: We use other legally recognized transfer mechanisms as required by applicable law (e.g., PIPL-compliant mechanisms for China)

6.2 Data Localization Requirements

Certain jurisdictions require that Personal Information be stored within their borders. We comply with applicable data localization requirements, including:

  • China: Personal Information Protection Law (PIPL) requires data localization for certain categories of data. We maintain data storage infrastructure in China where required.
  • Other Jurisdictions: We comply with data localization requirements in other jurisdictions as applicable.

For more information about data hosting in specific countries, please refer to our Country Compliance Documentation.

6.3 Your Rights Regarding Transfers

You have the right to obtain information about the safeguards we use for international transfers. Contact us using the information in Section 13 to request this information.

7. Your Data Protection Rights

Depending on your jurisdiction, you may have certain rights regarding your Personal Information. We are committed to honoring these rights in accordance with applicable law.

7.1 Rights Under GDPR/UK GDPR (EU/EEA/UK Users)

If you are located in the EEA, UK, or Switzerland, you have the following rights:

  • Right of Access: Request a copy of your Personal Information and information about how it is processed
  • Right to Rectification: Request correction of inaccurate or incomplete Personal Information
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your Personal Information in certain circumstances
  • Right to Restrict Processing: Request limitation of processing in certain circumstances
  • Right to Data Portability: Receive your Personal Information in a structured, commonly used, and machine-readable format
  • Right to Object: Object to processing based on legitimate interests or for direct marketing purposes
  • Right to Withdraw Consent: Withdraw consent where processing is based on consent
  • Right to Lodge a Complaint: File a complaint with your local data protection authority

7.2 Rights Under CCPA/CPRA (California Users)

If you are a California resident, you have the following rights:

  • Right to Know: Request disclosure of categories and specific pieces of Personal Information collected, used, disclosed, or sold
  • Right to Delete: Request deletion of Personal Information, subject to certain exceptions
  • Right to Correct: Request correction of inaccurate Personal Information
  • Right to Opt-Out: Opt-out of the sale or sharing of Personal Information (we do not sell Personal Information)
  • Right to Non-Discrimination: Not be discriminated against for exercising your privacy rights
  • Right to Limit Use of Sensitive Personal Information: Limit the use of sensitive personal information to specified purposes

7.2.1 Insurance-Specific CCPA/GLBA Considerations

GLBA and CCPA Overlap: As an insurance platform, we are subject to both the Gramm-Leach-Bliley Act (GLBA) and the California Consumer Privacy Act (CCPA). The following applies:

  • Consumer Insurance Policies: Personal, family, or household insurance policies are subject to GLBA privacy requirements. Nonpublic personal information (NPI) collected for consumer insurance policies may be exempt from certain CCPA requirements, including the right to opt-out of sale/sharing, as GLBA governs this information.
  • Commercial Insurance Policies: Commercial/business insurance policies are not covered by GLBA and are fully subject to CCPA requirements, including the right to opt-out of sale/sharing of personal information.
  • Data Retention: Insurance regulations require us to retain policy and financial records for 7-10 years. If you request deletion of your data, we may need to retain certain information to comply with these legal obligations. We will inform you if any data must be retained and when it can be deleted.
  • Opt-Out Impact: If you opt-out of the sale/sharing of your personal information, this affects marketing and analytics sharing, but does not affect necessary sharing with service providers (e.g., payment processors, claims adjusters) or regulatory bodies, which are required for insurance services and legal compliance.

7.2.2 Sensitive Personal Information (CPRA)

Insurance services may involve sensitive personal information, including:

  • Health Information: For health insurance policies or medical underwriting
  • Financial Account Information: For premium payments and claims processing
  • Precise Geolocation: For property insurance risk assessment

We use sensitive personal information only as necessary to provide insurance services (underwriting, claims processing, policy administration). You have the right to limit the use of sensitive personal information for non-essential purposes, such as marketing. However, we may continue to use sensitive information as necessary for insurance services.

7.3 Rights Under Other Jurisdictions

Users in other jurisdictions may have similar or additional rights under local data protection laws, including:

  • China (PIPL): Rights to access, correction, deletion, portability, and withdrawal of consent
  • Brazil (LGPD): Rights to confirmation, access, correction, anonymization, portability, deletion, information about sharing, revocation of consent, and review of automated decisions
  • South Africa (POPIA): Rights to access, correction, deletion, and objection
  • Canada (PIPEDA): Rights to access and correction
  • Other Jurisdictions: Rights as provided under applicable local data protection laws

7.4 How to Exercise Your Rights

To exercise your rights, please contact us using the information provided in Section 13. We will respond to your request within the timeframes required by applicable law (typically 30 days for GDPR, or 45 days for CCPA/CPRA). We may need to verify your identity before processing your request.

CCPA/CPRA Opt-Out: California residents can opt-out of the sale or sharing of their personal information by visiting our Do Not Sell My Personal Information page or by contacting us directly. We do not sell your personal information, but you can still exercise your right to opt-out to ensure we do not share your information for purposes that may be considered a "sale" under CCPA.

Note: Some rights may be limited or unavailable in certain circumstances, such as when we are required to retain information for legal or regulatory purposes, or when deletion would prevent us from providing services you have requested.

8. Data Security

We implement technical, administrative, and physical security measures designed to protect your Personal Information against unauthorized access, alteration, disclosure, or destruction. Our security measures include:

  • Encryption: TLS 1.3 encryption for data in transit; AES-256 encryption for data at rest
  • Access Controls: Role-based access control (RBAC), multi-factor authentication (MFA), and regular access reviews
  • Security Standards: Compliance with ISO 27001:2022 and SOC 2 Type II security standards
  • Network Security: Firewalls, intrusion detection systems, and regular security assessments
  • Employee Training: Regular security awareness training for personnel
  • Incident Response: Procedures for detecting, responding to, and recovering from security incidents
  • Vendor Management: Security assessments and contractual requirements for third-party service providers

Important: While we implement industry-standard security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your Personal Information. You should also take steps to protect your information, such as using strong passwords and not sharing your account credentials.

9. Cookies and Tracking Technologies

We use cookies, web beacons, pixels, and similar tracking technologies ("Cookies") to collect and store information about your interactions with our Services. For detailed information about our use of Cookies, including types of Cookies, purposes, and how to manage preferences, please see our Cookie Policy.

Cookie Consent: Where required by applicable law (e.g., GDPR, ePrivacy Directive), we obtain your consent before placing non-essential Cookies. You can manage your Cookie preferences through our Cookie consent banner or your browser settings.

10. Data Retention

We retain your Personal Information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Retention periods vary based on:

  • Insurance Records: 7-10 years after policy expiry (as required by insurance regulations)
  • Financial Records: 7 years (as required by tax and financial regulations)
  • Quote Data: 7 years after quote completion or cancellation
  • Marketing Data: Until consent is withdrawn or legal basis expires
  • Contract Data: Duration of contract plus legal retention period

Insurance-Specific Retention: Due to insurance regulatory requirements, we must retain policy and financial records for extended periods. If you request deletion of your data under CCPA or other privacy laws, we will:

  • Delete marketing and analytics data immediately (if no retention requirement)
  • Delete policy and financial data after the retention period expires (typically 7 years after policy expiry)
  • Inform you of any data that must be retained and provide a deferred deletion date
  • Anonymize data where possible while retaining necessary information for legal compliance

Retention periods vary based on:

  • Purpose of Processing: We retain data for the duration necessary to provide services and fulfill contractual obligations
  • Legal Requirements: We retain data as required by applicable laws, including insurance regulatory requirements, tax laws, and anti-money laundering regulations
  • Statute of Limitations: We retain data for periods necessary to defend against potential legal claims
  • Legitimate Business Interests: We may retain certain data for legitimate business purposes, such as fraud prevention and service improvement

When Personal Information is no longer needed, we securely delete or anonymize it in accordance with our data retention policies and applicable law.

11. Children's Privacy

Our Services are not directed to individuals under the age of 18 (or the age of majority in your jurisdiction, if higher). We do not knowingly collect Personal Information from children. If you are a parent or guardian and believe your child has provided us with Personal Information, please contact us immediately. If we become aware that we have collected Personal Information from a child without parental consent, we will take steps to delete such information.

12. Insurance Industry-Specific Considerations

As an insurance technology platform, we process information in the context of insurance operations, which may involve:

  • Regulatory Compliance: Processing required to comply with insurance regulatory requirements across multiple jurisdictions
  • Underwriting Data: Information necessary for risk assessment and insurance underwriting
  • Claims Processing: Information related to insurance claims and loss events
  • Regulatory Reporting: Data required for reporting to insurance regulatory authorities
  • Data Sharing with Insurers: Sharing information with insurance carriers and brokers as necessary to provide insurance services

These processing activities are necessary for the provision of insurance services and compliance with insurance regulations. In some jurisdictions, insurance-related data processing may be subject to specific exemptions or requirements under data protection laws.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

  • Posting the updated Privacy Policy on this page with an updated "Last Updated" date
  • Sending an email notification to registered users (for material changes)
  • Displaying a prominent notice on our website (for significant changes)

Your continued use of our Services after such changes constitutes acceptance of the updated Privacy Policy. We encourage you to review this Privacy Policy periodically.

14. Contact Information and Data Protection Officer

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, or if you wish to exercise your data protection rights, please contact us:

General Inquiries

Email: support@riskfabriq.com
Subject Line: "Privacy Inquiry" or "Data Protection Request"

Data Protection Officer (GDPR/UK GDPR)

For users in the EEA, UK, and Switzerland, you may contact our Data Protection Officer directly:

Email: dpo@riskfabriq.com
Subject Line: "Data Protection Officer Inquiry"

California Privacy Rights (CCPA/CPRA)

California residents may exercise their rights under CCPA/CPRA by:

Email: privacy@riskfabriq.com
Subject Line: "California Privacy Rights Request"

Supervisory Authority Complaints (GDPR)

If you are located in the EEA or UK, you have the right to lodge a complaint with your local data protection authority if you believe we have not addressed your concerns. A list of data protection authorities can be found at:

  • EU: European Data Protection Board
  • UK: Information Commissioner's Office (ICO)

Response Times

We will respond to your requests within the timeframes required by applicable law:

  • GDPR/UK GDPR: Within one month (may be extended by two months for complex requests)
  • CCPA/CPRA: Within 45 days (may be extended by 45 days with notice)
  • Other Jurisdictions: As required by applicable local law

15. Jurisdiction-Specific Addenda

Certain jurisdictions may require additional disclosures or provide additional rights. Where applicable, jurisdiction-specific addenda to this Privacy Policy may be provided. Such addenda will be incorporated by reference and form part of this Privacy Policy.

European Union/EEA/UK: This Privacy Policy complies with GDPR and UK GDPR requirements. For additional information about our GDPR compliance practices, please contact our Data Protection Officer.

China: For users in China, our processing of Personal Information complies with PIPL requirements. Data localization requirements are addressed in Section 6.2.

Brazil: For users in Brazil, our processing complies with LGPD requirements. Additional LGPD-specific information is available upon request.

Solutions

  • Multinational

Help & Resources

  • Partner onboarding
  • Contact us

Company

  • About
  • Privacy
  • Terms
  • Cookie Policy

Compliance

  • Overview
  • Do Not Sell
  • Submit Notification/Request

Disclaimer: The information on this website is provided for general informational purposes only. While we strive to keep the information up to date and accurate, we make no representations or warranties of any kind, express or implied, about the completeness, accuracy, reliability, suitability, or availability of the information, products, services, or related graphics contained on this website. Any reliance you place on such information is strictly at your own risk.

Performance metrics and results may vary based on individual use cases, configurations, and circumstances. Compliance features are designed to support regulatory requirements. You are responsible for ensuring your use of the platform complies with all applicable laws and regulations in your jurisdiction.

© 2026 Risk FabrIQ. All rights reserved.