Data Processing Addendum
Nexture AI LLC
Effective Date: October 8, 2026
This is the standard form of the Data Processing Addendum that supplements the Terms of Service. Bracketed fields in the parties block and the signature table are completed for each customer.
This Data Processing Addendum (the "DPA") is entered into between:
Nexture AI LLC, a Wyoming limited liability company doing business as MiaSure, with its principal mailing address at 1521 Alton Rd. PMB 106, Miami Beach, FL 33139, United States ("Nexture"); and
[CUSTOMER LEGAL NAME], a [STATE] [ENTITY TYPE], with its principal place of business at [ADDRESS] ("Customer").
Nexture and Customer are each a "party" and together the "parties".
This DPA supplements the MiaSure Terms of Service (effective October 8, 2026, or the version Customer has most recently accepted) and any order form, statement of work or other written agreement between the parties for the Service (together, the "Agreement"). It sets out the parties' obligations for the Processing of Customer Personal Information in connection with the Service.
1. Definitions
1.1. Capitalized terms used but not defined in this DPA have the meanings given in the Terms of Service. In this DPA:
(a) "Account Data" means information about Authorized Users that Nexture needs to operate Customer's account: names, business email addresses, firm and role, sign-in credentials and multi-factor authentication settings, account settings, and records of use of the Service.
(b) "Aggregated De-identified Data" means statistics that Nexture derives from Customer Data together with data of other customers, that contain no name, policy number, account identifier or other identifier of Customer, an Authorized User or a Data Subject, that are not produced for any group of fewer than five (5) policies, and that meet the definition of "deidentified" in California Civil Code § 1798.140(m).
(c) "Authorized User" means an individual whom Customer permits to use the Service under Customer's account, including Customer's employees and contractors.
(d) "CCPA" means the California Consumer Privacy Act of 1998, as amended by the California Privacy Rights Act of 2020, and its implementing regulations (Cal. Code Regs. tit. 11, § 7000 et seq.).
(e) "Customer Data" means the User Content that Customer and its Authorized Users upload to or create in the Service (including insurance policies, binders, quotes, endorsements, certificates, applications, loss runs and other documents), and all data the Service derives from it for Customer, including extracted policy data, deliverables, conversations with Mia, notes and messages.
(f) "Customer Personal Information" means any Personal Information contained in Customer Data or Account Data that Nexture Processes on behalf of Customer under the Agreement.
(g) "Data Protection Laws" means all United States federal and state laws and regulations that apply to a party's Processing of Customer Personal Information under the Agreement, including, as applicable, the Gramm-Leach-Bliley Act and its implementing rules (including the FTC Standards for Safeguarding Customer Information, 16 C.F.R. Part 314, and Regulation P), the CCPA, other comprehensive state consumer privacy laws, state data-breach notification laws, state insurance data security laws based on the NAIC Insurance Data Security Model Law (#668), and 23 NYCRR Part 500.
(h) "Data Subject" means an identified or identifiable natural person to whom Customer Personal Information relates, including a "consumer" under the CCPA. Data Subjects are typically Customer's clients and prospective clients ("Insureds") and the individuals named in their documents.
(i) "Determination" means the point at which Nexture concludes, on the evidence then available, that a Security Incident has occurred or is reasonably likely to have occurred. A credible report of unauthorized access to Customer Data that Nexture has not refuted within twenty-four (24) hours after receiving it is treated as a Determination.
(j) "Evaluation Records" means corrections that Authorized Users make to values the Service extracted, retained together with the policy to which they belong, and used as described in Section 5.2.
(k) "Nonpublic Personal Information" or "NPI" has the meaning given in the Gramm-Leach-Bliley Act and, where applicable, "nonpublic information" under a state law based on NAIC Model #668 or 23 NYCRR § 500.1.
(l) "Personal Information" means information that identifies, relates to, describes, or is reasonably capable of being associated with a particular natural person or household, and includes "personal information", "personal data" and NPI as those terms are defined in Data Protection Laws.
(m) "Process" and "Processing" mean any operation performed on Customer Personal Information, including collection, storage, retrieval, use, analysis, transmission, disclosure and deletion.
(n) "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, Customer Data while it is in the possession, custody or control of Nexture or a Sub-processor. It does not include unsuccessful attempts or activities that do not compromise the security of Customer Data, such as blocked log-in attempts, pings, port scans or denial-of-service attacks that do not result in access to Customer Data.
(o) "Service" means the MiaSure platform and related services provided by Nexture under the Agreement.
(p) "Sub-processor" means a third party that Nexture engages to Process Customer Personal Information on Nexture's behalf in providing the Service.
(q) "Sub-processors Page" means the page published at https://miasure.com/legal/sub-processors (or a successor address that Nexture notifies to Customer).
(r) "Terms of Service" means the MiaSure Terms of Service published by Nexture, as accepted by Customer.
1.2. The words "including" and "for example" mean "including without limitation". Section headings are for convenience only.
2. Scope and Roles
2.1. Scope. This DPA applies to Nexture's Processing of Customer Personal Information in providing the Service to Customer. Annex A describes the Processing.
2.2. Customer's role. With respect to Customer Personal Information, Customer is the "business" under the CCPA, the "controller" under other comprehensive state privacy laws, the "financial institution" under the Gramm-Leach-Bliley Act, and the "licensee" or "covered entity" under state insurance data security laws and 23 NYCRR Part 500, as applicable. Where Customer itself Processes an Insured's information on behalf of another person, Customer is responsible for ensuring that its instructions to Nexture are consistent with its own obligations to that person.
2.3. Nexture's role. Nexture Processes Customer Personal Information as Customer's "service provider" and "contractor" under the CCPA, "processor" under other comprehensive state privacy laws, "service provider" under the Gramm-Leach-Bliley Act, and "third-party service provider" under state laws based on NAIC Model #668 and under 23 NYCRR § 500.11.
2.4. Nexture's own records. Nexture Processes a limited set of records for its own legal and operational obligations: billing and payment records, the account-closure record described in Section 12.4, security and access audit logs, and records needed to detect and prevent fraud and abuse. Nexture Processes these only for those purposes, as described in the Privacy Policy, and does not use them for any purpose prohibited by Section 4.
2.5. Client portals and shared documents. Where Customer makes the Service available to its Insureds through a client portal presented under Customer's name or brand, or shares a document with a person through the Service, Nexture Processes the recipient's information on Customer's behalf under this DPA. A copy that a recipient accepts into the recipient's own MiaSure account is held in that account under the recipient's own agreement with Nexture from the time of acceptance, and is not Customer Data after that time.
2.6. Third-party AI assistants. If Customer or an Authorized User connects the Service to a third-party AI assistant or application (for example, Claude or ChatGPT), Nexture discloses information to that assistant at Customer's direction under Section 3.7 of the Terms of Service. The provider of that assistant is not Nexture's Sub-processor, and its use of the information is governed by Customer's agreement with it.
3. Processing Instructions
3.1. Documented instructions. Nexture will Process Customer Personal Information only (a) to provide the Service in accordance with the Agreement and this DPA, (b) as initiated by Customer and its Authorized Users through their use of the Service, including the settings they select, (c) as further documented in written instructions from Customer that Nexture accepts in writing, and (d) as required by applicable law, subject to Section 19. The Agreement, this DPA and Customer's use of the Service are Customer's complete instructions as of the date of this DPA.
3.2. Unlawful instructions. Nexture will inform Customer if, in Nexture's reasonable opinion, an instruction infringes Data Protection Laws. Nexture may suspend performance of that instruction until Customer confirms or modifies it. Nexture is not obliged to perform a legal review of Customer's instructions.
3.3. Settings are instructions. The settings available in the Service are part of Customer's instructions. They include: which AI providers may process Customer's data (where the Service offers that choice), data enrichment on or off, semantic-search indexing on or off, the platform-improvement setting described in Section 5.4, support access on or off, and connected cloud and email accounts. Customer acknowledges that several of these settings are on by default, as described in the Privacy Policy and on the Sub-processors Page, and that some are set for each Authorized User rather than for the firm as a whole (Section 5.4).
4. Service Provider Restrictions
4.1. Restrictions. Except as expressly permitted by Section 5, Nexture will not:
(a) sell or share Customer Personal Information, as "sell" and "share" are defined in the CCPA;
(b) retain, use or disclose Customer Personal Information for any purpose other than the business purposes specified in this DPA and the Agreement, including for any commercial purpose other than providing the Service;
(c) retain, use or disclose Customer Personal Information outside the direct business relationship between Nexture and Customer;
(d) combine Customer Personal Information with Personal Information that Nexture receives from or on behalf of another person, or that Nexture collects from its own interaction with a consumer, except as permitted by the CCPA and its regulations for the business purposes described in this DPA;
(e) use Customer Personal Information for cross-context behavioral advertising, or to build or augment a profile of a Data Subject for use in providing services to another business; or
(f) attempt to re-identify Aggregated De-identified Data.
4.2. Compliance and same level of protection. Nexture will comply with the obligations that Data Protection Laws impose on it as a service provider, contractor or processor, and will provide Customer Personal Information the same level of privacy protection that the CCPA requires of businesses.
4.3. Customer's rights to ensure compliance. Customer may take reasonable and appropriate steps to ensure that Nexture uses Customer Personal Information consistently with Customer's obligations under Data Protection Laws, including by exercising its rights under Section 13. On written notice, Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Information.
4.4. Notice of inability to comply. Nexture will notify Customer in writing without undue delay if it determines that it can no longer meet its obligations under Data Protection Laws or this DPA.
4.5. Certification. Nexture certifies that it understands the restrictions in this Section 4 and will comply with them.
5. Permitted Purposes and Platform Improvement
5.1. Business purposes. Nexture may use Customer Personal Information to: provide, maintain and support the Service for Customer; secure the Service and detect, prevent and investigate security incidents, fraud and abuse; debug and repair errors; perform the internal quality checks on Customer's own results that are part of delivering the Service to Customer; comply with law; and for the purposes in Sections 5.2 and 5.3, subject to Section 5.4.
5.2. Evaluation Records. Nexture may retain Evaluation Records and use them, within Nexture and through Sub-processors acting on its behalf, to measure the accuracy of the Service and to test changes to the Service before release. Evaluation Records are not anonymized. They remain linked to the policy and account they came from, are encrypted at rest under Customer's account keys as described in Annex B, and are deleted when the related policy is permanently deleted or the account is closed.
5.3. Aggregated De-identified Data. Nexture may create Aggregated De-identified Data from Customer Data (for example, typical premium ranges for a line of coverage within an industry group and period). Nexture will (a) take reasonable measures to ensure the data cannot be associated with Customer, an Authorized User or a Data Subject, (b) publicly commit to maintain and use it only in de-identified form and not attempt to re-identify it, and (c) contractually require any recipient of it to comply with (a) and (b). Aggregated De-identified Data is not Customer Personal Information and is not deleted under Section 12, because it contains no information that identifies Customer or any individual.
5.4. Opt-out. The uses in Sections 5.2 and 5.3 are controlled by the "Help improve MiaSure" setting in the Service. When an Authorized User turns that setting off: (a) that user's corrections are no longer retained as Evaluation Records; and (b) policies owned by that user are excluded from future Aggregated De-identified Data. If the Service cannot confirm the setting for a user, Nexture treats that user as opted out. An opt-out applies from the time it is made. Evaluation Records made before the opt-out remain subject to Section 5.2 and are deleted as described there, or earlier on Customer's written request to [email protected]. Aggregated De-identified Data computed before the opt-out cannot be separated into its inputs. As of the date of this DPA the setting is held for each Authorized User individually. A firm that wishes to opt out entirely must have each Authorized User turn the setting off, or may request in writing that Nexture apply the opt-out to every Authorized User on Customer's account, which Nexture will do within ten (10) business days.
5.5. Generic contributions. Two further settings, "Contribute to the shared forms library" and "Help us fix the platform's own mistakes", control contributions that contain no Customer Personal Information: generic descriptions of standard insurance forms, and generic descriptions of defects in Nexture's own software. Each contribution must pass a check enforced in Nexture's code before it leaves Customer's account, and a contribution that cannot be made generic is discarded. These settings are on by default and can be turned off under Settings, Mia.
5.6. No model training. Nexture does not use Customer Data to train or fine-tune any artificial intelligence or machine-learning model, whether Nexture's own or a third party's. Nexture does not authorize any Sub-processor to use Customer Data to train or improve its own models, and engages AI providers only under terms that, as stated for each provider on the Sub-processors Page, exclude Customer Data from model training. Requests Nexture sends to OpenAI's API are sent with the setting that disables storage of the request by OpenAI (store: false). Using Evaluation Records to measure accuracy and to test changes to prompts, rules and configuration under Section 5.2 is not training for the purpose of this Section 5.6. If a Sub-processor's terms change so that they permit training on Customer Data, Nexture will stop sending Customer Data to that Sub-processor or obtain terms that restore this commitment.
5.7. No zero-retention claim. Customer acknowledges that some AI Sub-processors may retain inputs and outputs for a limited period for abuse monitoring or trust-and-safety review under their own terms, as stated on the Sub-processors Page. Nexture does not represent that any AI provider retains no data.
6. Customer Obligations
6.1. Customer is responsible for:
(a) having a lawful basis, and giving every notice and obtaining every consent or authorization required by Data Protection Laws and by its professional obligations, for uploading Customer Personal Information to the Service and for instructing Nexture to Process it, including the privacy notices Customer must give its clients under Regulation P and state insurance privacy laws;
(b) the accuracy and quality of Customer Data and the lawfulness of the means by which Customer acquired it;
(c) not uploading Social Security numbers except as strictly necessary within standard insurance documentation, in accordance with Section 3.3 of the Terms of Service, and not uploading Protected Health Information except as permitted by Section 17;
(d) managing its Authorized Users, including their access rights, promptly removing access for individuals who no longer require it, and requiring its Authorized Users to enable the multi-factor authentication that the Service offers;
(e) its own record-keeping obligations, which deleting data from the Service does not satisfy (Section 3.4 of the Terms of Service);
(f) reviewing AI outputs as described in Section 14; and
(g) the notice and consent obligations described in Section 14.5 whenever it uses a feature that records or transcribes a conversation.
6.2. Customer represents that its instructions to Nexture comply with Data Protection Laws.
7. Personnel
7.1. Confidentiality. Nexture will ensure that every person it authorizes to Process Customer Personal Information is bound by a written duty of confidentiality, or an appropriate statutory duty, that survives the end of that person's engagement.
7.2. Need to know. Nexture will limit access to Customer Personal Information to personnel who need it to provide, secure or support the Service.
7.3. Support access. Access by Nexture personnel to an individual account through the Service's support tools, including a read-only session in which personnel view the Service as the account holder, is off by default, is available only when the account holder has turned it on in account settings, is time-limited and restricted to authorized personnel, and is recorded in an audit log. The account holder may turn it off at any time.
7.4. Operational access. Customer acknowledges that the Service must Process Customer Data in readable form to perform extraction, answer questions and generate deliverables, and that Nexture personnel with production deployment access therefore have the technical ability to access Customer Data while it is being Processed. Nexture controls that ability through the measures in Annex B and this Section 7. Nexture does not represent that its personnel are technically unable to read Customer Data.
7.5. Training. Nexture will provide security and privacy training to personnel with access to Customer Personal Information at onboarding and at least annually.
8. Security
8.1. Security program. Nexture will implement and maintain a written information security program with administrative, technical and physical safeguards appropriate to the nature of Customer Personal Information and designed to (a) protect its security and confidentiality, (b) protect against anticipated threats or hazards to its security or integrity, and (c) protect against unauthorized access to or use of it that could result in substantial harm or inconvenience to a Data Subject. The program includes, at a minimum, the measures described as in place in Annex B.
8.2. Qualified individual. Nexture has designated a qualified individual responsible for overseeing and enforcing its information security program, as required by 16 C.F.R. § 314.4(a).
8.3. Changes. Nexture may update the measures in Annex B, provided that an update does not materially reduce the overall protection of Customer Personal Information.
8.4. Items marked Target. Items marked [Target] in Annex B describe measures Nexture intends to implement. They are not representations that the measure is in place.
8.5. Customer's responsibilities. Customer is responsible for the security of its own systems, devices and credentials, for its Authorized Users' use of the Service, and for any Customer Data that Customer exports from the Service or sends to third parties through it.
9. Sub-processors
9.1. General authorization. Customer authorizes Nexture to engage the Sub-processors listed on the Sub-processors Page as of the date of this DPA. Annex C reproduces that list as of the date of this DPA for reference; the Sub-processors Page is the current list.
9.2. Conditional Sub-processors. Some Sub-processors are engaged only when a feature is in use, as the Sub-processors Page explains: cloud and email connectors (engaged only after an Authorized User grants OAuth consent), web research (engaged only where that feature is enabled for the deployment), and data enrichment (on by default and able to be switched off for the account or for an individual policy). Customer authorizes these Sub-processors for the features it or its Authorized Users use.
9.3. Notice of new Sub-processors. Before a new Sub-processor receives Customer Personal Information, Nexture will (a) update the Sub-processors Page with its role, data class, processing region and contractual basis, and (b) give Customer at least thirty (30) days' notice by email to the account holder and by a notice in the Service. The meeting assistant provider listed on the Sub-processors Page as not yet used in production, and the providers listed there as dormant, are subject to this notice before any Customer Personal Information is sent to them.
9.4. Objection. Customer may object to a new Sub-processor on reasonable data-protection grounds by writing to [email protected] during the notice period. The parties will discuss the objection in good faith. Nexture may offer to provide the Service without the feature that depends on the Sub-processor. If Nexture cannot reasonably accommodate the objection, Customer may terminate the affected part of the Service on written notice, and Nexture will refund any prepaid fees and unused Credits attributable to the terminated part, as provided in Section 17 of the Terms of Service.
9.5. Flow-down. Nexture will engage each Sub-processor under a written agreement that (a) restricts the Sub-processor's Processing of Customer Personal Information to the services it provides to Nexture, (b) requires the Sub-processor to protect the confidentiality and security of Customer Personal Information, and (c) for AI providers, excludes Customer Data from model training. Nexture will seek terms from each Sub-processor that are no less protective of Customer Personal Information than this DPA, to the extent applicable to the service that Sub-processor provides. Where a Sub-processor is engaged only on its standard published terms, the Sub-processors Page says so.
9.6. Responsibility. Nexture remains responsible to Customer for the performance of its Sub-processors' obligations with respect to Customer Personal Information, subject to Section 20.
9.7. Emergency replacement. If Nexture must replace a Sub-processor urgently to maintain the security or availability of the Service, Nexture may do so and will give the notice in Section 9.3 as soon as reasonably practicable, with the objection right in Section 9.4 running from that notice.
10. Security Incidents
10.1. Notice to Customer. Nexture will notify Customer of a Security Incident affecting Customer Data without undue delay and in any event within forty-eight (48) hours after Determination, and will use reasonable efforts to notify Customer within twenty-four (24) hours after Determination. Nexture will not delay notice to complete its investigation or to establish the full scope of the Security Incident.
10.2. Method. Nexture will notify the account holder and any security contact that Customer has designated in writing, by email and, where practicable, by telephone. Customer is responsible for keeping those contact details current.
10.3. Content. The notice will describe, to the extent then known: (a) the nature of the Security Incident and the time of Determination; (b) the categories of Customer Data involved and the approximate number of policies, Insureds and records affected, identifying where known whether the identifiers that trigger state breach-notification laws (such as driver's license numbers, financial account numbers, medical or health insurance information, or account credentials) are involved and the states of residence of affected individuals; (c) whether the affected data was encrypted and whether the means of decrypting it may also have been compromised; (d) containment status and the date on which the exposure ended; (e) the measures Nexture has taken and proposes to take; (f) the likely consequences; and (g) a named Nexture contact. Where information is not yet available, the notice will say so and Nexture will provide it in updates as it becomes available, at intervals agreed with Customer or, absent agreement, at least every forty-eight (48) hours until the investigation is complete.
10.4. Customer's regulatory clocks. Nexture acknowledges that Customer may be required to notify its insurance regulator within seventy-two (72) hours after Customer determines that a cybersecurity event has occurred, including an event at a third-party service provider, under a state law based on NAIC Model #668 or under 23 NYCRR § 500.17. Nexture will provide the information Customer reasonably requests to make those notices, and any notices to Data Subjects, attorneys general, consumer reporting agencies and other regulators that Data Protection Laws require of Customer.
10.5. Cooperation. Nexture will (a) take reasonable steps to contain, investigate and remediate the Security Incident, (b) preserve relevant logs and evidence, including by suspending automated deletion of relevant records for the duration of the investigation, (c) cooperate with Customer's investigation and with any inquiry by a regulator with authority over Customer, and (d) provide a written summary of root cause and remediation after the investigation is complete.
10.6. Notices to third parties. Customer, as the owner or licensee of Customer Personal Information, is responsible for notices to Data Subjects and regulators, except where Data Protection Laws require Nexture to give notice itself or the parties agree in writing that Nexture will give notice on Customer's behalf. Nexture will not notify Customer's clients or Customer's regulators of a Security Incident that affects only Customer Data without first consulting Customer, unless required by law.
10.7. Costs. Each party bears its own costs of responding to a Security Incident, and Nexture's liability for a Security Incident is subject to Section 20.
10.8. No admission. Nexture's notice of or response to a Security Incident is not an acknowledgement of fault or liability.
11. Assistance
11.1. Consumer rights requests. Taking into account the nature of the Processing, Nexture will provide reasonable assistance to enable Customer to respond to requests from Data Subjects to exercise their rights under Data Protection Laws (including to know, access, correct, delete and receive a portable copy of Personal Information). The Service provides the following tools for this purpose:
(a) correction of extracted values and deliverables within the Service;
(b) permanent deletion of individual policies ("Delete forever") and of individual deliverables;
(c) an in-product download for each Authorized User account of a copy of the account's documents, saved deliverables and extracted policy data in machine-readable (JSON) form, with a manifest; and
(d) account closure as described in Section 12.
Where these tools do not meet a request, Nexture will, on Customer's written request, provide a data inventory or perform the action within a time that allows Customer to meet its statutory deadline, and in any event within fifteen (15) business days.
11.2. Requests made to Nexture. If Nexture receives a request from a Data Subject that relates to Customer Personal Information, Nexture will direct the Data Subject to Customer and will forward the request to Customer within five (5) business days, unless the law requires otherwise. Nexture will not otherwise respond to the request except to confirm that it has been forwarded.
11.3. Regulator and auditor inquiries. Nexture will provide reasonable cooperation, at Customer's request, in responding to an inquiry, examination or investigation of Customer by a regulator with authority over Customer (including a state insurance department or the New York Department of Financial Services) that concerns Nexture's Processing of Customer Personal Information. If a regulator contacts Nexture directly about Customer, Nexture will notify Customer unless prohibited by law.
11.4. Risk assessments. Nexture will provide information reasonably necessary for Customer to carry out a data protection or risk assessment that Data Protection Laws require of Customer in relation to the Service, including the information in docs/AI_GOVERNANCE.md (made available to Customer on request).
11.5. Costs of assistance. Assistance under this Section 11 is provided at no additional charge unless the requests are manifestly excessive or repetitive, in which case Nexture may charge a reasonable fee on prior written notice.
12. Return and Deletion
12.1. During the term. Customer may export and delete Customer Data at any time using the tools described in Section 11.1. When an Authorized User permanently deletes a policy, the Service removes the policy and the records made from it from Nexture's active systems, normally within minutes, and records the outcome of the deletion. Deliverables that were published or sent are kept as Customer's business records until they are permanently deleted individually or the account is closed.
12.2. On termination. On expiry or termination of the Agreement:
(a) Customer may, for thirty (30) days after the effective date of termination (the "Export Window"), export Customer Data using the Service's tools or request a firm-wide export in writing, which Nexture will provide in a machine-readable format within that period. If Customer closes its account itself using the in-product account-deletion option, deletion begins immediately on confirmation and there is no Export Window; Customer should export first.
(b) Within thirty (30) days after the end of the Export Window, or earlier on Customer's written request, Nexture will delete Customer Data and Customer Personal Information from its active systems, except as permitted by Section 12.4.
(c) Copies of deleted data in backups are not restored to active use and are removed as the backups expire on their rotation cycle, within ninety (90) days after deletion from active systems. Until then they remain protected by this DPA.
12.3. Firm and administrator accounts. Accounts that belong to a firm, the accounts of its owners and administrators, and accounts with a recurring billing plan or an unsettled balance cannot be closed from inside the Service and are closed on written request to [email protected]. Nexture will verify the request and complete deletion within the periods in Section 12.2.
12.4. Retained records. Nexture may retain the following after deletion, only for the stated purpose and period, and will continue to protect them under this DPA:
(a) payment and billing records, for as long as required for tax, accounting and regulatory purposes (generally at least seven (7) years), with their link to Customer's policies removed on account closure;
(b) an account-closure record containing the account email address (stored encrypted where the account is closed through the Service) and the dates the account was opened and closed, for up to three (3) years;
(c) document access records (which document was opened, when, and by whom or, for a recipient without an account, from which network), for seven (7) years from the access, or longer while a legal hold is in place, because they are the record of who was shown what;
(d) security audit logs and records of processing jobs and AI usage, which contain identifiers, timings and costs but not document content, for security, fraud-prevention and billing purposes;
(e) Aggregated De-identified Data;
(f) copies of Customer Data that recipients accepted into their own accounts before deletion (Section 2.5); and
(g) Customer Data that Nexture is required by law or by a legal hold to retain, for the period required, in which case Nexture will notify Customer unless prohibited by law.
12.5. Certificate. On Customer's written request, Nexture will provide a written certification, signed by an officer, that deletion under Section 12.2 has been completed, identifying any data retained under Section 12.4.
13. Audits and Information
13.1. Security questionnaire and summary. Once in any twelve (12) month period, and additionally after a Security Incident, Nexture will on request (a) complete a reasonable security questionnaire and (b) provide a written summary of the controls in its information security program, including the current status of the items in Annex B.
13.2. SOC 2. Nexture's SOC 2 program is in progress. Nexture has not received a SOC 2 report and does not hold any security certification. When Nexture receives a SOC 2 report, it will provide the most recent report to Customer on request, subject to confidentiality obligations. Until then, Nexture will provide the summary in Section 13.1 and, where available, a summary of its most recent penetration test.
13.3. Customer audit. If the information in Sections 13.1 and 13.2 is not reasonably sufficient to demonstrate Nexture's compliance with this DPA, or if a regulator with authority over Customer requires it, Customer (or an independent auditor bound by confidentiality who is not a competitor of Nexture) may audit Nexture's compliance with this DPA, on the following terms:
(a) no more than once in any twelve (12) month period, except following a Security Incident affecting Customer Data or where required by a regulator;
(b) on at least thirty (30) days' written notice, except following a Security Incident, when the notice period is ten (10) business days, or as a regulator requires;
(c) remotely by default, or on-site at Nexture's premises during business hours where a remote audit is not reasonably sufficient;
(d) at Customer's cost, except where the audit follows a Security Incident caused by Nexture's breach of this DPA or reveals a material breach of this DPA, in which case Nexture bears its own costs and reimburses Customer's reasonable audit costs [subject to Section 20];
(e) under a scope and plan agreed in advance, in a way that does not unreasonably disrupt Nexture's operations, does not give access to other customers' data, and does not require Nexture to disclose information that would compromise the security of the Service or breach its obligations to others; and
(f) subject to confidentiality obligations, with Customer providing Nexture a copy of the findings.
13.4. Regulators. Nexture will make information available to a regulator with authority over Customer as required by law.
14. Artificial Intelligence Terms
14.1. Human review. Outputs of the Service, including extracted data, Summaries of Insurance, comparisons, reviews, letters and answers from Mia, are generated with the assistance of artificial intelligence and may contain errors or omissions. The insurance policy documents as issued control. Customer must verify any output against the underlying documents before relying on it or sharing it, as set out in Sections 2.6 and 6 of the Terms of Service. Customer's licensed personnel remain the decision-makers and the authors of record for anything sent to Customer's clients.
14.2. Not insurance advice. Nexture is not a licensed insurance producer, and the Service does not provide insurance, legal, tax or financial advice, underwrite, rate, bind coverage, or make coverage or claims determinations (Section 2.5 of the Terms of Service). The Service does not make decisions that produce legal or similarly significant effects on Data Subjects.
14.3. Controls on AI actions. Mia does not send a message to a third party, share a document, schedule a meeting or create a deliverable without an Authorized User's confirmation; such actions are staged for the Authorized User to confirm or cancel. Deliverables are created as drafts and must be published by an Authorized User before they are shared outside the Service. Structured Review of a policy is started only by an Authorized User.
14.4. Transparency. Mia is identified in the Service as an AI assistant. Deliverables generated with AI assistance carry a visible statement to that effect, and exported PDF, Word, Excel and PowerPoint files and generated images carry machine-readable information identifying them as AI-assisted. Customer will not remove or obscure those statements in a way that would mislead a recipient about the involvement of AI.
14.5. Voice and meetings. When an Authorized User talks to Mia by voice, the audio is streamed to the voice and speech providers listed on the Sub-processors Page; Nexture does not store the audio, and the transcript is saved to the account. The meeting assistant (in which Mia joins a third-party meeting as an AI notetaker) and AI voice interviews of invited persons are not available in the production Service as of the date of this DPA. Nexture will not make either available to Customer without the notice in Section 9.3. If either is later made available, Customer is responsible, before any conversation is recorded or transcribed, for giving every participant notice that an AI assistant will record or transcribe it, for obtaining every consent required by law (including in states that require the consent of all parties), and for stopping the recording or transcription if a participant objects, as provided in Section 3.5 of the Terms of Service.
14.6. Provider choice. Where the Service offers Customer a choice of AI providers, Nexture will send Customer Data only to the providers that the choice permits.
14.7. Governance information. Nexture maintains an inventory of the AI models and providers it uses, a description of human oversight, its accuracy-testing program and its AI change-management process, and will provide that information to Customer on request to support Customer's obligations under state adoptions of the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, to the extent applicable to Customer.
15. Insurance Regulatory Terms
15.1. Annex D sets out the terms that apply where Customer is a licensee subject to a state law based on NAIC Model #668 or a covered entity subject to 23 NYCRR Part 500. Annex D forms part of this DPA.
16. Gramm-Leach-Bliley Act
16.1. Nexture will not disclose or use NPI that it receives from Customer other than to carry out the purposes for which Customer disclosed it, as permitted by 16 C.F.R. § 313.11(a) and Regulation P (12 C.F.R. § 1016.11(a)), including the exceptions in 16 C.F.R. §§ 313.14 and 313.15 as they apply to Nexture's performance of the Service.
16.2. Nexture will implement and maintain appropriate safeguards for NPI consistent with 16 C.F.R. Part 314, as described in Section 8 and Annex B.
17. Health Information
17.1. The Service is designed for property and casualty and related commercial insurance documents. Some documents (for example, workers' compensation loss runs, accident and health or employee benefits documents, and driver schedules) may incidentally contain health information, driver's license numbers or dates of birth. Nexture Processes that information only to provide the Service to Customer and protects it as Customer Personal Information under this DPA.
17.2. Nexture is not a covered entity under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and is not Customer's business associate unless the parties have signed a separate business associate agreement. Unless such an agreement is in force, Customer will not use the Service to store or process Protected Health Information on behalf of a HIPAA covered entity or business associate. Nexture may decline to Process, and may remove, documents that Customer uploads in breach of this Section 17.2.
18. Data Location; Non-US Personal Data
18.1. Location. Nexture stores Customer Data in the United States (AWS us-east-1 and MongoDB Atlas on AWS us-east-1). Some Sub-processors may Process Customer Data in other regions in providing their services, as stated for each on the Sub-processors Page. In particular, Mistral AI, which is used for OCR and some extraction steps, is based in France and may Process Customer Data in the European Union, and Cloudflare handles traffic on its global network nearest to the requester.
18.2. US only. The Service is offered only to businesses and individuals located in the United States and its territories. Nexture restricts account creation and sign-in in production to those locations. The Service is not offered for the Processing of personal data subject to the EU General Data Protection Regulation, the UK GDPR or the Swiss Federal Act on Data Protection, and this DPA does not include standard contractual clauses or other transfer mechanisms under those laws. Customer will not use the Service to Process such personal data except where it is incidental to the insurance documents of Customer's US clients.
19. Legal Requests
19.1. If Nexture receives a subpoena, court order, warrant or other legal demand from a third party or a government authority for Customer Personal Information, Nexture will (a) attempt to redirect the requesting party to Customer, (b) notify Customer promptly so that Customer may seek a protective order or other remedy, unless the law prohibits notice, and (c) disclose only the Customer Personal Information that it is legally required to disclose. Nexture will not voluntarily disclose Customer Personal Information to a government authority except where Nexture reasonably believes disclosure is necessary to prevent imminent risk of death or serious bodily harm.
20. Liability
20.1. Each party's liability arising out of or related to this DPA, whether in contract, tort or otherwise, is subject to the exclusions and limitations of liability in Section 11 of the Terms of Service, and a reference in those Sections to liability under the Terms includes liability under this DPA.
20.2. Nothing in this DPA limits Customer's indemnity obligations under Section 12 of the Terms of Service.
21. Term and Termination
21.1. This DPA takes effect on the date of the last signature below and continues for as long as the Agreement is in effect. Sections 7.1, 10, 12, 13 (for twelve (12) months), 19 and 20 survive for as long as Nexture retains any Customer Personal Information, and until the obligations in them are complete.
21.2. Either party may terminate this DPA and the Agreement for the other party's material breach of this DPA if the breach is not cured within thirty (30) days after written notice describing it. Termination of this DPA without termination of the Agreement is not permitted, because Nexture cannot Process Customer Personal Information in providing the Service except under this DPA.
22. Order of Precedence; Changes
22.1. Precedence. If there is a conflict concerning the Processing or protection of Customer Personal Information, the documents apply in the following order: (a) this DPA, including its Annexes; (b) any order form or other written agreement signed by both parties; (c) the Terms of Service; (d) the Privacy Policy and Security Statement. For all other matters, the Agreement controls. During a beta test, the Beta Test Agreement does not reduce Customer's rights under this DPA.
22.2. Changes. Nexture may update this DPA on at least thirty (30) days' written notice where the update is required by law or does not materially reduce the protection of Customer Personal Information. Any other change requires a written amendment signed by both parties. If Customer reasonably objects to an update made under the first sentence, Customer may terminate the Agreement by written notice before the update takes effect and receive the refund provided in Section 17 of the Terms of Service.
23. Governing Law and Disputes
23.1. This DPA is governed by the law that governs the Terms of Service (Section 15 of the Terms of Service), except where Data Protection Laws require otherwise.
23.2. Any dispute arising out of or relating to this DPA is resolved under Section 14 (Dispute Resolution) of the Terms of Service, including its informal dispute-resolution step, which is incorporated by reference, except that either party may seek injunctive or other equitable relief in a court of competent jurisdiction to prevent or stop the unauthorized use or disclosure of Customer Personal Information.
24. General
24.1. Notices. Notices under this DPA to Nexture must be sent to [email protected] (and, for Security Incident matters, [email protected]), with a copy by mail to the address at the top of this DPA. Notices to Customer will be sent to the contacts in the signature block below or as Customer later designates in writing.
24.2. Severability. If any provision of this DPA is held invalid or unenforceable, the remainder continues in effect, and the provision is modified to the minimum extent necessary to make it enforceable consistent with the parties' intent and Data Protection Laws.
24.3. Counterparts. This DPA may be signed in counterparts and by electronic signature, each of which is an original and all of which together are one instrument.
24.4. No third-party beneficiaries. Nothing in this DPA confers rights on any third party, including any Data Subject, except as required by Data Protection Laws.
Signatures
| Nexture AI LLC (d/b/a MiaSure) | [CUSTOMER LEGAL NAME] | |
|---|---|---|
| Signature | ||
| Name | ||
| Title | ||
| Date | ||
| Notice email | [email protected] | |
| Security contact (Section 10.2) | [email protected] |
Annex A — Details of Processing
| Item | Description |
|---|---|
| Subject matter | Provision of the MiaSure insurance-document platform to Customer under the Agreement. |
| Duration | The term of the Agreement, plus the Export Window and deletion periods in Section 12, plus the retention periods in Section 12.4 for retained records. |
| Nature of Processing | Receipt, storage and retrieval of uploaded documents; conversion of documents to text (OCR); AI-assisted extraction of structured policy data; verification of extracted values; generation of deliverables at Customer's request; semantic-search indexing of Customer's own documents; answering Authorized Users' questions through Mia by chat and voice, including Mia's memory of an Authorized User's preferences and work; data enrichment with public and licensed reference data (on by default, can be switched off); sharing and client-portal delivery at Customer's direction; outbound email that Customer sends through the Service; connectors to Customer's cloud storage and email accounts where an Authorized User connects them; audit and access logging; backup and recovery; support; deletion; and the permitted uses in Section 5. |
| Purpose | To provide, secure and support the Service for Customer, and the permitted purposes in Section 5. |
| Categories of Data Subjects | (a) Customer's clients and prospective clients (Insureds) that are individuals, and the owners, officers, employees and contacts of Insureds that are businesses; (b) drivers, employees, claimants, injured workers, beneficiaries, additional insureds, loss payees, mortgagees and other individuals named in insurance documents; (c) producers, underwriters and other insurance-industry contacts named in documents; (d) recipients of documents Customer shares and users of Customer's client portal; (e) Authorized Users. |
| Categories of Personal Information | Identifiers (names, postal addresses, email addresses, telephone numbers, account identifiers, IP address or, for link and portal recipients, the network a request came from); insurance and customer-record information (named insureds, policy numbers, coverage, limits, deductibles, premiums, insured property addresses, vehicle identification numbers, loss history and claims information); commercial information (the Service's billing records); professional information (firm, title); internet and electronic network activity (use of the Service, document access records); approximate location (country, derived from IP address, used to restrict access to the United States); audio and electronic information (voice streamed to providers while an Authorized User talks to Mia, and transcripts); inferences (Mia's memory of an Authorized User's preferences, role and focus areas). |
| Sensitive Personal Information | Driver's license numbers and dates of birth (for example, in auto policy driver schedules); health information incidentally contained in documents (for example, injury descriptions in workers' compensation loss runs); account log-in credentials (held by the authentication Sub-processor, not in Nexture's database). Social Security numbers are prohibited by Section 3.3 of the Terms of Service and are not intentionally collected. Protected Health Information is excluded by Section 17. Nexture does not use Sensitive Personal Information to infer characteristics about Data Subjects. |
| Frequency | Continuous, for the duration of the Agreement. |
| Retention | As set out in Section 7 of the Privacy Policy and Section 12 of this DPA. In summary: documents and extracted data until permanently deleted or the account is closed (items in Trash do not expire); published or sent deliverables until deleted individually or the account is closed; Mia chat history and Mia's memory until deleted or the account is closed; transcripts of voice conversations with Mia as part of Mia chat history, until deleted or the account is closed; meeting transcripts and summaries twelve (12) months; Evaluation Records with their policy; usage and analytics data up to ninety (90) days; in-app notifications up to ninety (90) days; most operational logs between seven (7) and ninety (90) days; document access records seven (7) years; billing records generally at least seven (7) years; account-closure record up to three (3) years; backups within ninety (90) days after deletion from active systems. |
| Sub-processors | Annex C and the Sub-processors Page. |
Annex B — Technical and Organizational Measures
Status key: In place = operating in production as of the date of this DPA. [Target] = not yet in place; not a representation. This Annex describes the Service as operated by Nexture; it does not describe the measures of Sub-processors, which operate under their own terms.
B.1 Encryption
| Measure | Status |
|---|---|
| Uploaded documents (PDFs) and OCR transcripts are encrypted by the application with AES-256-GCM before they are stored in AWS S3; S3 server-side encryption is applied in addition. | In place |
| Personal Information in policy records is encrypted at the field level by the application with AES-256-GCM under a key specific to the owning account. This covers named insured, carrier name, policy number and document filename; the structured extraction payload (coverage, limits, deductibles, premiums, schedules, endorsements); clients' names and contact details; agent reasoning, validation findings and the field-edit audit trail; deliverable content; chat, email and meeting-note bodies and quoted text; and cross-tenant audit-log payloads. | In place |
| Authorized Users' email address, name and company are encrypted under a separate server-held key, with a keyed one-way index for sign-in by email. | In place |
| Per-account keys are stored only in wrapped form. For individual accounts, the wrapping secret is itself sealed under a customer master key in AWS KMS and recovered by a KMS decrypt call, which AWS CloudTrail records. Firm (brokerage) keys additionally require an administrator secret that is not stored. | In place |
| Migration of the remaining legacy key-wrapping path (firm keys and the session key cache) to the KMS-sealed secret. | [Target] |
| KMS key automatic rotation, deletion protection, and an alert on any attempt to schedule deletion or disable the key. | In place |
| The following are not encrypted by the application and are protected by the database provider's storage encryption, per-account access scoping, TLS and access controls: firm business name; internal identifiers, timestamps, status values and categories used to route and scope records; embeddings (numerical search representations) derived from document text; and the platform-wide library of standard insurance forms, which contains no customer identifiers. | Disclosed limitation |
| Database storage encryption at rest (MongoDB Atlas encrypted storage). | In place |
| Encryption in transit: HTTPS/TLS between browsers and the Service, and authenticated, encrypted connections to the database and cache (TLS 1.2 minimum on the cache connection). | In place |
| TLS 1.2 minimum enforced at the edge for all public hostnames. | [Target — to be verified in the edge configuration] |
| Customer-controlled key revocation (cryptographic destruction on demand, including of backups). | [Target — roadmap] |
B.2 Access control and tenant isolation
| Measure | Status |
|---|---|
| Every database query for customer data is scoped to the authenticated account; the account identity is set only by the server-side trust boundary, never by the browser. Automated tests in CI check tenant-scoping, encryption write sites and related invariants on every change. | In place |
| Tenant-isolation re-verification on a quarterly cadence (last performed 2026-09-21). | In place |
| Multi-factor authentication (authenticator app, TOTP) available to every Authorized User. | In place |
| Administrator-enforced MFA for the producers and staff of a firm: a firm setting managed by Customer's administrator, required by default where Customer's recorded licensed states include New York (or, until licensed states are recorded, its recorded address is in New York); the second factor is an authenticator app or, where the administrator allows it, a one-time code emailed after the password; Nexture platform administrators must use an authenticator app. Access to Customer's data is refused until the Authorized User has enrolled. | In place |
| Multi-factor authentication required for Nexture personnel accessing production systems and administrative tools. | In place (per Security Statement §3.2) |
| Least-privilege access to production systems; quarterly review of privileged accounts (AWS, database, source control, secrets manager, edge, hosting, authentication, administrative roles). First review performed 2026-09-27. | In place |
| Support access to an individual account off by default, enabled only by the account holder, time-limited and audit-logged (Section 7.3). | In place |
| Account self-deletion requires re-authentication (password and, where enabled, MFA code); neither account deletion nor data export can be performed from a support session. | In place |
| Background checks for personnel with production data access. | [Target] |
B.3 Logging and monitoring
| Measure | Status |
|---|---|
| AWS API activity logged with AWS CloudTrail (log encryption under a dedicated KMS key). | In place |
| Application audit trail of security-relevant account events; document access records (Section 12.4(c)). | In place |
| Error monitoring (Sentry) with default personal-data collection disabled and a scrubber applied before transmission; no session recording or replay. | In place |
| Application logs redact credentials, email addresses, Social Security numbers, labelled driver's license numbers and labelled dates of birth. Redaction is pattern-based and does not reliably remove personal names from free text. | In place, with disclosed limitation |
| Pipeline-health monitoring and automated alerts routed to Nexture's on-call responder. | In place |
| No advertising pixels, third-party analytics or advertising cookies, session-replay tools or third-party chat widgets in the Service. | In place |
B.4 Data minimization and handling
| Measure | Status |
|---|---|
| Social Security numbers prohibited by the Terms of Service. | In place |
| Social Security numbers and labelled driver's license numbers stripped before text is embedded for semantic search. | In place |
| Extraction models receive document text unredacted, because driver schedules and similar content are policy content that extraction must read. | Disclosed limitation |
| Document text is treated as data, not instructions, and sanitized before it is included in prompts (prompt-injection defence). | In place |
| Outbound requests from the Service are restricted to prevent server-side request forgery. | In place |
| Web-research queries that mention a person or an Insured are not sent to the general web-search provider (Tavily). | In place |
B.5 Network and platform
| Measure | Status |
|---|---|
| Edge protection through Cloudflare: web application firewall, rate limiting, bot protection and challenge on sign-in and sign-up. | In place |
| Application-layer restriction of account creation and sign-in in production to the United States and its territories (US, PR, GU, VI, AS, MP, UM), which also excludes OFAC-sanctioned jurisdictions. | In place |
| Edge-layer (WAF) country rule for production hostnames matching the application-layer rule. | [Target — owner configuration step] |
| Refusal of account creation when the request's country cannot be determined (today the application-layer check allows the request and logs a critical event). | [Target] |
| Application rate limits; single trusted server boundary validating every request. | In place |
| Secrets held in a secrets manager (Doppler) and injected at deploy; no secrets committed to source control; rotation after exposure. | In place |
B.6 Secure development and vulnerability management
| Measure | Status |
|---|---|
| Source changes pass protected-branch pull requests with blocking automated checks (lint, type checks, and a guard suite of more than 1,600 tests covering security, tenant-isolation, encryption and accuracy invariants). | In place |
| Monthly dependency-vulnerability review across all application packages. | In place |
| Internal penetration test (performed 2026-06-20; annual cadence). | In place |
| Independent third-party penetration test. | [Target] |
| Vulnerability reports received at [email protected] and acknowledged within two (2) business days. | In place |
B.7 Availability, backup and recovery
| Measure | Status |
|---|---|
| Database backups: continuous point-in-time recovery for seven (7) days, snapshots every six (6) hours retained seven (7) days, daily snapshots retained thirty (30) days, weekly snapshots retained twelve (12) weeks; backups stored encrypted in AWS us-east-1. | In place |
| S3 object versioning on the document bucket. | In place |
| Expiry of non-current S3 object versions within ninety (90) days (lifecycle rule). | [Target — to be verified] |
| Quarterly restore test with decryption verified end to end (last performed 2026-06-29). | In place (next test due) |
| Backup and recovery of the KMS-sealed wrapping secret in two independent locations. | In place |
| Documented disaster-recovery procedure. | In place |
B.8 Deletion
| Measure | Status |
|---|---|
| Permanent deletion of a policy driven by a single data manifest covering every collection and stored file that holds policy data, followed by a verification re-scan and a recorded outcome; partial deletions are retried automatically. | In place |
| Account erasure covering the account profile, documents, extracted data, deliverables, Mia chat history and memory, and other account records, with billing records retained and unlinked from policies. | In place |
| Deletion of transcripts held by the voice service operated for Talk to Mia when the associated account or policy is deleted. | [Target] |
B.9 Organizational measures
| Measure | Status |
|---|---|
| Written information security program; sixteen (16) written policies approved and dated 2026-09-27; designated qualified individual. | In place |
| Documented incident response runbook with severity levels, a provisional-SEV-1 rule, breach-notification decision tree and the broker notice commitment in Section 10; tabletop exercise performed 2026-09-27. | In place |
| Annual risk assessment (performed 2026-09-27). | In place |
| Security and privacy awareness training for all personnel, dated. | [Target — first dated record not yet logged] |
| Annual vendor and Sub-processor review, including collection of Sub-processors' SOC 2 reports. | [Target — first review not yet performed] |
| Named backup incident responder and retained external breach counsel. | [Target — before general availability] |
| SOC 2 Type II examination. | [Target — in progress; observation window not yet started] |
Annex C — Sub-processors
The current list is the Sub-processors Page, https://miasure.com/legal/sub-processors, which states for each provider its role, data class, processing region, contractual basis and what its terms say about training on and retaining data. The table below is a snapshot of that page as of its effective date, September 28, 2026, provided for reference only. If the table and the Sub-processors Page differ, the Sub-processors Page controls.
C.1 Active for every customer
| Sub-processor | Purpose | Data | Location |
|---|---|---|---|
| Render | Application hosting (web servers, workers, runtime memory, application logs) | Customer Data in transit and in process memory; metadata; Account Data; telemetry | United States (us-east) |
| MongoDB Atlas | Primary database; semantic-search index | Customer Data (application-encrypted PII); metadata; Account Data | AWS us-east-1 |
| Redis Cloud | Job queue and transient cache | Metadata; transient Customer Data during job execution | AWS us-east-1 |
| Cloudflare | DNS, TLS termination, web application firewall, rate limiting, bot protection, geographic access restriction | Customer Data in transit; IP address, user agent, request metadata | Global network, nearest the requester |
| AWS S3 | Storage of documents, transcripts and deliverables | Customer Data (application-encrypted) | us-east-1 |
| AWS KMS | Key management | Key material only | us-east-1 |
| AWS SES | Outbound email | Sender and recipient addresses; message content | us-east-1 |
| AWS Cognito | Authentication, password hashing, MFA | Account Data | us-east-1 |
| AWS Secrets Manager | Platform secrets and integration credentials | Credential material only | us-east-1 |
| OpenAI | Language models for extraction and Mia; embeddings; web search during enrichment; alternative real-time voice model | Document text, questions, prompts; for enrichment, insured name or address in search queries | United States |
| Anthropic | Language models for Mia, extraction and validation | Document text, questions, prompts | United States |
| Google (Gemini API, Maps Platform) | Structural pass and other extraction and analysis steps; geocoding; static map images in some deliverables | Document text; property addresses or coordinates | United States |
| Mistral AI | OCR and some extraction steps | Document images and text | France; may process in the European Union |
| LLMWhisperer (Unstract, Inc.) | OCR and PDF-to-text conversion | Document bytes and extracted text | United States |
| Voice and meeting service (software licensed from AI Meetings LLC) | Real-time voice sessions for Talk to Mia | Audio in transit; transcripts | United States |
| xAI | Default real-time voice model for Talk to Mia | Voice and conversation | United States |
| Deepgram | Speech-to-text | Audio and transcript text | United States |
| Stripe | Payment processing | Billing details only; no policy or Insured information | United States and Stripe's global footprint |
| Sentry | Error and performance monitoring | Telemetry, scrubbed before transmission | United States |
| Plausible Analytics | Cookieless page-view counts on public pages only | Aggregate page views; no Customer Data | European Union |
C.2 Conditional
| Sub-processor | Purpose | Data | Location | Engaged when |
|---|---|---|---|---|
| Microsoft (Microsoft Graph) | Outlook calendar and email, OneDrive, SharePoint connectors | Microsoft 365 content read or written at the user's direction; OAuth tokens (stored encrypted) | Microsoft's footprint for the customer's tenant | An Authorized User grants OAuth consent |
| Box | Cloud-folder ingest | Box content the user authorizes | Box's footprint for the customer's account | An Authorized User grants OAuth consent |
| Tavily | Web search for market intelligence | Query terms only; never a query that mentions a person or an Insured | United States | Web research enabled for the deployment |
| Jina Reader | URL-to-text fallback in web research | Public URLs only | Provider's global footprint | Web research enabled |
| Firecrawl | Web-scraping fallback in web research | Public URLs only | United States | Web research enabled and configured |
| Google Geocoding | Address normalization for enrichment | Insured property address | United States | Enrichment on (default) |
| FEMA (OpenFEMA / NFHL) | Flood-zone lookup | Coordinates only | United States (federal service) | Enrichment on (default) |
| USGS | Seismic design data | Coordinates only | United States (federal service) | Enrichment on (default) |
| NAICS.com | Industry code descriptions | A NAICS code; no Customer Personal Information | United States | Enrichment on (default) |
| Parse.bot | Extraction from known carrier web pages | Public URL and carrier name; no Insured data | United States | Enrichment on and configured |
C.3 Not used in production
| Sub-processor | Purpose | Status |
|---|---|---|
| Recall.ai | Meeting bot for the meeting assistant | Not used in production until the meeting assistant launches; subject to Section 9.3 notice |
| AM Best, Dun & Bradstreet, Middesk, OpenCorporates, OFAC, NCCI, Realie | Planned reference-data integrations | Dormant: no code calls them and no Customer Data has been sent; subject to Section 9.3 notice |
MaxMind (licensed country database run on Nexture's own servers) and third-party AI assistants connected at Customer's direction are not Sub-processors (Sub-processors Page §4; Section 2.6).
Annex D — State Insurance Regulatory Addendum
D.1. Application. This Annex applies where Customer is (a) a "licensee" under a state law based on the NAIC Insurance Data Security Model Law (#668), or (b) a "covered entity" under 23 NYCRR Part 500. Nexture is Customer's "third-party service provider" under those laws. This Annex is intended to provide the terms that Customer's third-party service provider policies must require under Section 4(F) of Model #668 (as adopted in Customer's state) and 23 NYCRR § 500.11. If a law adopted in Customer's state requires a term not addressed here, the parties will agree on it in good faith.
D.2. Information security program. Nexture represents and warrants that it maintains the information security program described in Section 8 and Annex B, that the program includes administrative, technical and physical safeguards appropriate to the size and complexity of Nexture, the nature and scope of its activities and the sensitivity of the nonpublic information it holds, and that the measures described as in place in Annex B are in place. Nexture will notify Customer of any change that materially reduces the protection that program provides.
D.3. Access controls and multi-factor authentication (23 NYCRR §§ 500.11(b)(1), 500.12). Nexture (a) limits access to Customer's nonpublic information to personnel who need it; (b) requires multi-factor authentication for its personnel's access to production systems and administrative tools; (c) makes multi-factor authentication available to every Authorized User; (d) records support access to an account in an audit log; and (e) provides a firm-level setting, managed by Customer's administrator, that requires multi-factor authentication for every Authorized User of the firm who is a producer or staff member of the firm (not Customer's clients) and refuses access to Customer's data until that Authorized User has enrolled. Multi-factor authentication is required by default where Customer's recorded licensed states include New York, or, until Customer records its licensed states, where Customer's recorded address is in New York. The second factor is an authenticator app or, where Customer's administrator allows it, a one-time code sent by email after the password. Customer is responsible for keeping its licensed states accurate and the setting on where 23 NYCRR 500.12 applies to Customer.
D.4. Encryption (23 NYCRR §§ 500.11(b)(2), 500.15). Nexture encrypts Customer's nonpublic information in transit over external networks and at rest, as described in Annex B.1. Personal Information in policy records, documents and transcripts is encrypted by the application under per-account keys; the items listed in Annex B.1 as not encrypted by the application are encrypted at rest by the database provider's storage encryption.
D.5. Notice of cybersecurity events (Model #668 § 6; 23 NYCRR §§ 500.11(b)(3), 500.17). Nexture will notify Customer of any cybersecurity event that directly impacts Customer's information systems or Customer's nonpublic information held by Nexture, in accordance with Section 10, within forty-eight (48) hours after Determination and using reasonable efforts to do so within twenty-four (24) hours. Nexture will provide the information Customer needs to notify its domiciliary or home-state commissioner, the New York Superintendent of Financial Services, and any other regulator within the periods the law requires of Customer, including the seventy-two (72) hour periods under Model #668 § 6 and 23 NYCRR § 500.17(a). For this Annex, "cybersecurity event" has the meaning given in the law applicable to Customer.
D.6. Investigation. Nexture will investigate a cybersecurity event affecting Customer's nonpublic information, determine to the extent possible whether it occurred and its nature and scope, identify the nonpublic information involved, take reasonable measures to restore the security of affected systems, and maintain records of the event for at least five (5) years, and will share the results with Customer to the extent needed for Customer's own investigation obligations under Model #668 § 5.
D.7. Representations about cybersecurity policies (23 NYCRR § 500.11(b)(4)). Nexture represents and warrants that (a) it maintains written cybersecurity policies and procedures covering information security, access control, incident response, vendor management, data retention and disposal, and business continuity; (b) it will maintain them for the term of the Agreement; and (c) the statements in Annex B are accurate as of the date of this DPA and will be kept current under Section 13.1.
D.8. Disposal. Nexture will dispose of Customer's nonpublic information in accordance with Section 12 when it is no longer necessary for the provision of the Service, except where retention is required by law or permitted by Section 12.4.
D.9. Sub-processors. Nexture will require its Sub-processors that hold Customer's nonpublic information to protect it as described in Section 9.5.
D.10. Examinations. Nexture will cooperate with an examination of Customer by its insurance regulator to the extent it concerns the Service, as provided in Sections 11.3 and 13.4.
D.11. AI. Where Customer's regulator has adopted the NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers and it applies to Customer, Nexture will provide the information described in Section 14.7 to support Customer's oversight of the Service as a third-party AI system.