ForsuredForsured

Forsured, Inc. — Privacy Policy

Effective Date: April 28, 2026 | Last Updated: April 28, 2026 | Version 1.2

This Privacy Policy explains how Forsured, Inc. (“Forsured,” “we,” “us,” or “our”) collects, uses, shares, and protects information in connection with the Forsured platform, websites, mobile applications, APIs, and related services (collectively, the “Platform”). This Policy is incorporated by reference into the Forsured Terms and Conditions of Service.

Forsured is committed to handling personal information responsibly, transparently, and in compliance with applicable privacy and AI governance laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), the Colorado Privacy Act and the Colorado Artificial Intelligence Act (SB24-205), the Texas Data Privacy and Security Act and the Texas Responsible Artificial Intelligence Governance Act (“TRAIGA”), the Virginia Consumer Data Protection Act (“VCDPA”), and similar state laws.

1. Quick Summary

We have written this Policy in plain language wherever possible. The following summary is provided for convenience and is not a substitute for the full Policy below.

  • We collect information you provide (such as account details and uploaded insurance documents), information generated through your use of the Platform, and limited information from third parties (such as carrier ratings and other integrations).
  • We use this information to operate the Platform, generate compliance assessments, communicate with you, comply with law, and improve our services and AI models.
  • We do not sell your personal information for third-party advertising without your explicit consent. We do not share your personal contact information with third parties for their marketing purposes without your explicit consent.
  • We may use de-identified, aggregated data for industry research, benchmarking, and limited commercial purposes. You may opt out of inclusion in such data sets.
  • You have rights to access, correct, delete, and port your information, and to object to certain automated processing. You may also request human review of consequential AI decisions.

2. Scope of This Policy

This Policy applies to information collected through the Platform. It does not apply to:

  • Information collected by third-party services you connect to the Platform (such as Procore, Sage, QuickBooks, Textura, your insurance broker, etc.), which is governed by those services’ own privacy policies.
  • Information you exchange directly with other Platform users in messages, comments, or shared documents (you remain responsible for what you choose to share).
  • Public-facing marketing pages or recruitment activities, which may be governed by separate privacy notices linked from those pages.

3. Information We Collect

3.1 Information You Provide

  • Account information: name, business email, phone number, business address, job title, role (General Contractor, Subcontractor, Insurance Broker, Administrator), and account credentials. References in this Policy to a “Broker” mean a licensed insurance broker, agent, or producer.
  • Business and entity information: company name, DBA, EIN or tax ID where required, contractor license numbers, NAICS or trade codes, project specifications, and entity hierarchy.
  • Insurance documentation: Certificates of Insurance, policy declarations, endorsements, schedules, bonds, loss runs, broker letters, and related materials uploaded to the Platform.
  • Payment information: billing contact, billing address, and payment method details processed by our payment processor (we do not store full card numbers on our servers).
  • Communications: messages, comments, support tickets, survey responses, and other content you submit to or through the Platform.

3.2 Information Generated by Use of the Platform

  • Document metadata: data extracted from uploaded documents by AI and OCR systems, including carrier names, policy numbers, limits, effective and expiration dates, named insureds, and detected endorsements.
  • Activity data: pages viewed, features used, documents uploaded, validations performed, sign-offs recorded, and AI interactions.
  • Device and technical data: IP address, browser type, operating system, device identifiers, log files, and approximate location derived from IP address.
  • Cookies and similar technologies: see Section 9 for details.

3.3 Information from Third Parties

  • Carrier and licensing data: financial strength ratings (such as AM Best), carrier admittance status, and licensing information from public databases and licensed data providers.
  • Identity and fraud-prevention data: limited verification information from authorized verification services, where used.
  • Integration data: information you authorize us to retrieve from connected third-party services (such as Procore project data).

3.4 Sensitive Categories

We do not intentionally collect sensitive personal information as defined under CCPA/CPRA (such as Social Security numbers, government-issued ID numbers beyond contractor license numbers, precise geolocation, racial or ethnic origin, or biometric data) through normal Platform use. If you submit such information voluntarily through uploaded documents or communications, we will treat it in accordance with applicable law and this Policy.

4. How We Use Information

We use the information we collect for the following purposes:

  • To provide, operate, secure, and maintain the Platform.
  • To process documents, generate compliance assessments, and deliver Platform outputs.
  • To facilitate authorized communication and document sharing between users you have invited or who have invited you.
  • To process payments, manage subscriptions, and prevent fraud.
  • To respond to support requests and communicate about your account or the Platform.
  • To improve the Platform, develop new features, and conduct internal research and analytics.
  • To train, fine-tune, and evaluate AI and machine learning models, subject to the limits in Section 5.
  • To send transactional communications (which you cannot opt out of while maintaining an account) and, with consent where required, marketing communications.
  • To comply with legal obligations, respond to lawful requests from public authorities, enforce our Terms, and protect the rights, property, or safety of Forsured, our users, or others.

5. Artificial Intelligence and Model Training

5.1 Use of AI Systems

The Platform uses AI Systems (but not limited to) to extract data from uploaded documents, classify endorsements, compare extracted data against requirements, and generate compliance scores and informational outputs. These outputs are decision-support tools and are subject to the disclaimers and human-review provisions in our Terms.

5.2 Data Used to Improve AI Systems

To improve the accuracy and reliability of our AI Systems, we may use (but not limited to):

  • De-identified content from uploaded documents (with personal identifiers removed).
  • User corrections and validations (which help us identify and fix model errors).
  • Aggregated patterns of use (which help us understand how compliance assessments succeed or fail across the Platform).

5.3 What We Do Not Do

  • We do not use the personal contact information of any user (such as name, email, or phone number) as training data.
  • We do not sell or share raw uploaded documents with third-party AI developers for the purpose of training their models.
  • We do not use customer data to train general-purpose foundation models offered by third parties; where third-party models are used to provide Platform features, we contractually prohibit those vendors from using your data to train their public models.

5.4 Opt-Out of AI Training

You may opt out of having your data (including de-identified extracts from your documents) used to train or improve our AI Systems by contacting privacy@forsured.com. Exercising this opt-out will not affect your access to core compliance features but may limit certain personalized improvements over time.

5.5 Automated Decision-Making and Right to Human Review

Where a Platform output (such as a “Non-Compliant” status) materially affects a legally protected interest — including bid eligibility, contract eligibility, or insurance procurement obligations — and is generated through fully automated processing without meaningful human involvement, you may request human review of that output. To request human review, contact privacy@forsured.com or use the in-Platform “Request Human Review” function on the affected record. We will respond within the timeframes required by applicable law.

5.6 AI Transparency

Where required by applicable law (including Colorado SB24-205 and Texas TRAIGA), we provide notice that you are interacting with an AI System, disclose the general categories of decisions the AI System informs, and describe the data sources used to generate outputs. Additional information regarding our use of AI may be made available from time to time within the Platform or upon request to privacy@forsured.com.

6. How We Share Information

We share information only as described below.

6.1 With Other Platform Users

When you invite a party to a project or accept an invitation, you authorize Forsured to share with that party the documents, compliance status, and contact information necessary for the project. You control which parties are invited and which documents are shared.

6.2 With Service Providers

We share information with vendors who perform services on our behalf, including cloud hosting (Supabase, AWS, etc.), document processing (AWS Textract and similar OCR providers), AI inference providers, payment processors, customer support tools, email delivery, analytics, and security monitoring. These vendors are contractually required to use information only as necessary to provide services to Forsured and to protect it appropriately.

6.3 With Authorized Integrations

When you connect a third-party service (such as Procore, Sage, Textura, QuickBooks, etc.), we share information with that service as you direct. The third-party service’s use of your information is governed by its own terms and privacy policy.

6.4 For Legal and Safety Reasons

We may disclose information when we believe in good faith that disclosure is necessary to: comply with law or legal process; respond to lawful requests from government authorities; enforce our Terms; protect the rights, property, or safety of Forsured, our users, or others; or detect, prevent, or address fraud or security issues.

6.5 In Connection with a Business Transfer

If Forsured is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction. We will notify users of any such transfer and any material change to this Policy.

6.6 What We Do Not Do

  • We do not sell personal information for third-party advertising without explicit consent.
  • We do not share personal contact information with third parties for their direct marketing purposes without your explicit consent.
  • We do not enable third-party advertising networks to target you with ads based on your activity within the Platform explicit consent.

7. De-Identified and Aggregated Data

7.1 What We Create

We may create de-identified or aggregated data sets derived from Platform activity (“De-Identified Data”). De-Identified Data is processed in a manner intended to prevent the identification of any individual or specific business entity, and may include statistical patterns such as average compliance scores by trade, common gap categories, regional renewal trends, and similar information.

7.2 Standard Used

When de-identifying data, we apply technical and procedural safeguards consistent with the HIPAA Safe Harbor de-identification standard (as guidance, not as a regulated obligation), the NIST Privacy Framework, and emerging state-level guidance under CCPA/CPRA. We commit to: (a) not attempting to re-identify de-identified data, (b) not permitting downstream recipients to re-identify it, and (c) including contractual prohibitions on re-identification in any sharing agreements.

7.3 How We Use De-Identified Data

  • To improve and benchmark the Platform.
  • To produce industry research, white papers, and aggregate market reports (which may be published or shared with third parties).
  • On a limited basis, to provide aggregate analytics to insurance industry participants (such as carriers, reinsurers, and actuarial firms) for the purpose of industry research and product development.

7.4 Opt-Out

You may opt out of having your data contribute to De-Identified Data sets used for purposes beyond core Platform improvement (such as third-party industry research) by contacting privacy@forsured.com. Enterprise customers may negotiate stricter terms in their Commercial Schedule.

7.5 No Sale of Personal Information

De-Identified Data is not personal information. The use of De-Identified Data as described in this Section 7 does not constitute a “sale” or “share” of personal information under CCPA/CPRA.

8. Data Retention

We retain personal information only as long as necessary for the purposes described in this Policy, to comply with legal obligations, to resolve disputes, and to enforce our agreements.

CategoryRetention Period
Active account dataFor the duration of the account, plus archive period below
Uploaded insurance documents7 years after expiration or termination, to support audit, dispute, and statute-of-limitations needs
Communications and chat history1 years from the date of the communication, unless retention is extended for legal or audit reasons
Activity logs and security logs12 months
Payment records7 years (for tax and accounting purposes)
Marketing dataUntil you unsubscribe, plus a reasonable period for suppression list management
De-Identified DataIndefinitely (no longer personal information)

Following the applicable retention period, we will delete or further de-identify personal information, except where retention is required by law or where data has been incorporated into De-Identified Data sets.

9. Cookies and Tracking Technologies

We use cookies, pixel tags, local storage, and similar technologies to operate the Platform, remember your preferences, secure your session, and understand usage. We use:

  • Strictly necessary cookies (required for the Platform to function and that you cannot opt out of).
  • Functional cookies (to remember your preferences).
  • Analytics cookies (to understand how the Platform is used and to improve it).

We do not use third-party advertising cookies by default on the Platform without your consent. You may manage cookie preferences through your browser settings or, where presented, through our in-Platform cookie controls. Note that disabling strictly necessary cookies will prevent the Platform from functioning.

10. Your Privacy Rights

10.1 Rights Available to All Users

Subject to verification of your identity and to applicable legal exceptions, you may:

  • Access the personal information we hold about you.
  • Correct inaccurate personal information.
  • Delete personal information, subject to retention obligations under Section 8.
  • Receive a portable copy of personal information you provided to us in a commonly used machine-readable format.
  • Object to or restrict certain processing.
  • Opt out of marketing communications.
  • Opt out of certain AI training and certain De-Identified Data uses (Sections 5.4 and 7.4).
  • Request human review of consequential automated decisions where lawfully rightful (Section 5.5).

10.2 California Residents (CCPA/CPRA)

California residents have additional rights, including the right to:

  • Know what categories of personal information we collect, the sources, the purposes, and the categories of recipients.
  • Delete personal information collected from you, subject to exceptions.
  • Correct inaccurate personal information.
  • Opt out of the “sale” or “sharing” of personal information (we do not sell or share personal information for cross-context behavioral advertising).
  • Limit the use of sensitive personal information (we do not use sensitive personal information for purposes beyond those permitted by CCPA/CPRA without consent).
  • Non-discrimination for exercising your rights.

You may also designate an authorized agent to act on your behalf.

10.3 Colorado, Connecticut, Virginia, and Other State Residents

Residents of states with comprehensive privacy laws have rights similar to those described above, including rights to access, correct, delete, port, and opt out of certain processing. You may also have the right to appeal a denial of a privacy request. To exercise these rights, contact privacy@forsured.com. If we deny your request, we will explain why and provide instructions for appeal.

10.4 How to Exercise Your Rights

To exercise any of these rights, contact us at privacy@forsured.com or use the in-Platform privacy controls in your account settings. We will respond within the timeframes required by applicable law (generally 45 days, with one possible 45-day extension).

11. Security

We use technical, administrative, and physical safeguards designed to protect personal information from unauthorized access, use, alteration, and destruction. These safeguards include:

  • Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
  • Role-based access controls and the principle of least privilege.
  • Multi-factor authentication for administrative access.
  • Regular security testing, vulnerability scanning, and third-party penetration testing.
  • Logging, monitoring, and incident response procedures.
  • Vendor due diligence and contractual data protection requirements.

No system is 100% secure. You are responsible for maintaining the confidentiality of your account credentials and for promptly notifying us of any suspected unauthorized access at security@forsured.com.

11.1 Breach Notification

In the event of a security incident affecting personal information, we will notify affected users and applicable regulators in accordance with applicable law.

12. Children

The Platform is intended solely for business users 18 years of age or older. We do not knowingly collect personal information from individuals under 18. If we learn that we have collected personal information from a minor, we will delete it. If you believe a minor has provided information to us, contact privacy@forsured.com.

13. International Users and Data Transfers

Forsured is a U.S.-based company, and personal information collected through the Platform is stored and processed in the United States. The Platform is intended for users in the United States. If you access the Platform from outside the United States, you understand that your information will be transferred to, processed in, and stored in the United States, where data protection laws may differ from those in your country.

14. Third-Party Links and Services

The Platform may contain links to third-party websites and services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any information.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last Updated” date at the top of the Policy. If changes are material, we will provide additional notice (such as by email or prominent in-Platform notification) at least 30 days before the changes take effect. Your continued use of the Platform after the effective date constitutes acceptance of the updated Policy.

15.1 Version History

Prior versions of this Policy are available upon request to privacy@forsured.com.

16. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact:

Forsured, Inc.
Attn: Privacy Office
Email: privacy@forsured.com
Security incidents: security@forsured.com
California Privacy Rights: privacy@forsured.com (subject line: “California Privacy Request”)

16.1 Designated Privacy Contact

Our Privacy Officer can be reached at privacy@forsured.com. We aim to respond to all privacy inquiries within 15 business days, and to formal rights requests within the timeframes required by applicable law.