Effective Date: April 28, 2026 | Last Updated: April 28, 2026 | Version 1.2
This Privacy Policy explains how Forsured, Inc. (“Forsured,” “we,” “us,” or “our”) collects, uses, shares, and protects information in connection with the Forsured platform, websites, mobile applications, APIs, and related services (collectively, the “Platform”). This Policy is incorporated by reference into the Forsured Terms and Conditions of Service.
Forsured is committed to handling personal information responsibly, transparently, and in compliance with applicable privacy and AI governance laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), the Colorado Privacy Act and the Colorado Artificial Intelligence Act (SB24-205), the Texas Data Privacy and Security Act and the Texas Responsible Artificial Intelligence Governance Act (“TRAIGA”), the Virginia Consumer Data Protection Act (“VCDPA”), and similar state laws.
We have written this Policy in plain language wherever possible. The following summary is provided for convenience and is not a substitute for the full Policy below.
This Policy applies to information collected through the Platform. It does not apply to:
We do not intentionally collect sensitive personal information as defined under CCPA/CPRA (such as Social Security numbers, government-issued ID numbers beyond contractor license numbers, precise geolocation, racial or ethnic origin, or biometric data) through normal Platform use. If you submit such information voluntarily through uploaded documents or communications, we will treat it in accordance with applicable law and this Policy.
We use the information we collect for the following purposes:
The Platform uses AI Systems (but not limited to) to extract data from uploaded documents, classify endorsements, compare extracted data against requirements, and generate compliance scores and informational outputs. These outputs are decision-support tools and are subject to the disclaimers and human-review provisions in our Terms.
To improve the accuracy and reliability of our AI Systems, we may use (but not limited to):
You may opt out of having your data (including de-identified extracts from your documents) used to train or improve our AI Systems by contacting privacy@forsured.com. Exercising this opt-out will not affect your access to core compliance features but may limit certain personalized improvements over time.
Where a Platform output (such as a “Non-Compliant” status) materially affects a legally protected interest — including bid eligibility, contract eligibility, or insurance procurement obligations — and is generated through fully automated processing without meaningful human involvement, you may request human review of that output. To request human review, contact privacy@forsured.com or use the in-Platform “Request Human Review” function on the affected record. We will respond within the timeframes required by applicable law.
Where required by applicable law (including Colorado SB24-205 and Texas TRAIGA), we provide notice that you are interacting with an AI System, disclose the general categories of decisions the AI System informs, and describe the data sources used to generate outputs. Additional information regarding our use of AI may be made available from time to time within the Platform or upon request to privacy@forsured.com.
We share information only as described below.
When you invite a party to a project or accept an invitation, you authorize Forsured to share with that party the documents, compliance status, and contact information necessary for the project. You control which parties are invited and which documents are shared.
We share information with vendors who perform services on our behalf, including cloud hosting (Supabase, AWS, etc.), document processing (AWS Textract and similar OCR providers), AI inference providers, payment processors, customer support tools, email delivery, analytics, and security monitoring. These vendors are contractually required to use information only as necessary to provide services to Forsured and to protect it appropriately.
When you connect a third-party service (such as Procore, Sage, Textura, QuickBooks, etc.), we share information with that service as you direct. The third-party service’s use of your information is governed by its own terms and privacy policy.
We may disclose information when we believe in good faith that disclosure is necessary to: comply with law or legal process; respond to lawful requests from government authorities; enforce our Terms; protect the rights, property, or safety of Forsured, our users, or others; or detect, prevent, or address fraud or security issues.
If Forsured is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction. We will notify users of any such transfer and any material change to this Policy.
We may create de-identified or aggregated data sets derived from Platform activity (“De-Identified Data”). De-Identified Data is processed in a manner intended to prevent the identification of any individual or specific business entity, and may include statistical patterns such as average compliance scores by trade, common gap categories, regional renewal trends, and similar information.
When de-identifying data, we apply technical and procedural safeguards consistent with the HIPAA Safe Harbor de-identification standard (as guidance, not as a regulated obligation), the NIST Privacy Framework, and emerging state-level guidance under CCPA/CPRA. We commit to: (a) not attempting to re-identify de-identified data, (b) not permitting downstream recipients to re-identify it, and (c) including contractual prohibitions on re-identification in any sharing agreements.
You may opt out of having your data contribute to De-Identified Data sets used for purposes beyond core Platform improvement (such as third-party industry research) by contacting privacy@forsured.com. Enterprise customers may negotiate stricter terms in their Commercial Schedule.
De-Identified Data is not personal information. The use of De-Identified Data as described in this Section 7 does not constitute a “sale” or “share” of personal information under CCPA/CPRA.
We retain personal information only as long as necessary for the purposes described in this Policy, to comply with legal obligations, to resolve disputes, and to enforce our agreements.
| Category | Retention Period |
|---|---|
| Active account data | For the duration of the account, plus archive period below |
| Uploaded insurance documents | 7 years after expiration or termination, to support audit, dispute, and statute-of-limitations needs |
| Communications and chat history | 1 years from the date of the communication, unless retention is extended for legal or audit reasons |
| Activity logs and security logs | 12 months |
| Payment records | 7 years (for tax and accounting purposes) |
| Marketing data | Until you unsubscribe, plus a reasonable period for suppression list management |
| De-Identified Data | Indefinitely (no longer personal information) |
Following the applicable retention period, we will delete or further de-identify personal information, except where retention is required by law or where data has been incorporated into De-Identified Data sets.
We use cookies, pixel tags, local storage, and similar technologies to operate the Platform, remember your preferences, secure your session, and understand usage. We use:
We do not use third-party advertising cookies by default on the Platform without your consent. You may manage cookie preferences through your browser settings or, where presented, through our in-Platform cookie controls. Note that disabling strictly necessary cookies will prevent the Platform from functioning.
Subject to verification of your identity and to applicable legal exceptions, you may:
California residents have additional rights, including the right to:
You may also designate an authorized agent to act on your behalf.
Residents of states with comprehensive privacy laws have rights similar to those described above, including rights to access, correct, delete, port, and opt out of certain processing. You may also have the right to appeal a denial of a privacy request. To exercise these rights, contact privacy@forsured.com. If we deny your request, we will explain why and provide instructions for appeal.
To exercise any of these rights, contact us at privacy@forsured.com or use the in-Platform privacy controls in your account settings. We will respond within the timeframes required by applicable law (generally 45 days, with one possible 45-day extension).
We use technical, administrative, and physical safeguards designed to protect personal information from unauthorized access, use, alteration, and destruction. These safeguards include:
No system is 100% secure. You are responsible for maintaining the confidentiality of your account credentials and for promptly notifying us of any suspected unauthorized access at security@forsured.com.
In the event of a security incident affecting personal information, we will notify affected users and applicable regulators in accordance with applicable law.
The Platform is intended solely for business users 18 years of age or older. We do not knowingly collect personal information from individuals under 18. If we learn that we have collected personal information from a minor, we will delete it. If you believe a minor has provided information to us, contact privacy@forsured.com.
Forsured is a U.S.-based company, and personal information collected through the Platform is stored and processed in the United States. The Platform is intended for users in the United States. If you access the Platform from outside the United States, you understand that your information will be transferred to, processed in, and stored in the United States, where data protection laws may differ from those in your country.
The Platform may contain links to third-party websites and services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any information.
We may update this Privacy Policy from time to time. When we do, we will revise the “Last Updated” date at the top of the Policy. If changes are material, we will provide additional notice (such as by email or prominent in-Platform notification) at least 30 days before the changes take effect. Your continued use of the Platform after the effective date constitutes acceptance of the updated Policy.
Prior versions of this Policy are available upon request to privacy@forsured.com.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact:
Forsured, Inc.
Attn: Privacy Office
Email: privacy@forsured.com
Security incidents: security@forsured.com
California Privacy Rights: privacy@forsured.com (subject line: “California Privacy Request”)
Our Privacy Officer can be reached at privacy@forsured.com. We aim to respond to all privacy inquiries within 15 business days, and to formal rights requests within the timeframes required by applicable law.