Last Updated: May 20, 2026
Introduction
ClearMark LLC (“ClearMark,” “we,” “us,” or “our”) is committed to protecting personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information in connection with our websites, software platform, application programming interfaces, dashboards, and related services (collectively, the “Services”).
Business-to-business use. The Services are designed for use by insurance agencies, insurance agents, insurance carriers, and other business entities. This Privacy Policy describes our practices in two distinct roles: (a) when we act as a service provider under the California Consumer Privacy Act (as amended by the California Privacy Rights Act, collectively the “CCPA”) and a processor under the European Union General Data Protection Regulation (the “GDPR”) on behalf of our business customers (each, a “Customer”); and (b) when we act as a business or controller with respect to information collected about visitors to our websites and individuals who interact with us directly.
What This Policy Covers
- Scope and our different roles (Section 1)
- Customer Personal Data: our role as service provider and processor (Sections 2 and 3)
- Information we collect when acting as a business or controller (Sections 4 through 7)
- How we use, share, and transfer information (Sections 5 through 8)
- Use of artificial intelligence and machine learning (Section 9)
- Cookies, retention, and security (Sections 10 through 12)
- Your privacy rights and how to exercise them (Sections 13 and 14)
- Children, third-party sites, changes, and contact (Sections 15 through 19)
1. SCOPE OF THIS POLICY
1.1 Customer Personal Data. When ClearMark processes personal information that is contained in data the Customer or its authorized users submit to, upload to, or generate through the Services, including data extracted on the Customer’s behalf from agency management systems and customer relationship management systems (“Customer Personal Data”), ClearMark acts as a service provider under the CCPA and a processor under the GDPR. The applicable Customer is the business or controller responsible for that data and for responding to requests from the individuals to whom the data relates. ClearMark processes Customer Personal Data only on the documented instructions of the applicable Customer and in accordance with the Terms of Use, the applicable Order Form, and any executed Data Processing Addendum.
1.2 ClearMark-Controlled Data. Sections 4 through 8 of this Policy describe how ClearMark collects, uses, and shares information in its capacity as a business or controller, such as information collected from visitors to our websites, individuals who request a demo, prospective and current account administrators, and personnel of our Customers who interact with us in connection with their account.
2. WHOSE INFORMATION THIS POLICY COVERS
This Policy covers information about: (a) visitors to our public websites; (b) prospective customers and individuals who request information about the Services; (c) account administrators and other personnel of our Customers; (d) attendees of our events and recipients of our marketing communications; and (e) individuals whose personal information is contained in Customer Personal Data, to the extent described in Section 3.
3. CUSTOMER PERSONAL DATA (SERVICE PROVIDER/PROCESSOR ROLE)
3.1 Our Role. ClearMark processes Customer Personal Data solely on behalf of and on the documented instructions of the applicable Customer. The Customer determines the purposes and means of processing. ClearMark does not sell or share Customer Personal Data within the meaning of the CCPA, and does not use Customer Personal Data for cross-context behavioral advertising.
3.2 Permitted Purposes. ClearMark processes Customer Personal Data only for the following permitted business purposes: (a) providing, maintaining, and improving the Services as instructed by the Customer; (b) preventing, detecting, and responding to security incidents and fraud; (c) debugging to identify and repair errors that impair existing intended functionality; (d) complying with legal obligations and responding to legal process; and (e) performing services on behalf of the Customer, including processing data extracted from agency management systems and customer relationship management systems to generate notifications and insights for the Customer.
3.3 Restrictions. ClearMark does not: (a) retain, use, or disclose Customer Personal Data outside the direct business relationship with the Customer; (b) combine Customer Personal Data with personal information from any other source for any purpose other than performing services on behalf of the Customer or as otherwise permitted by the CCPA; or (c) use Customer Personal Data to train, fine-tune, evaluate, or improve any third-party artificial intelligence model, machine learning model, large language model, foundation model, or generative AI system that operates outside the Services. ClearMark’s use of Customer Personal Data within the Services is further described in Section 9.
3.4 Aggregated and De-Identified Data. ClearMark may generate aggregated and de-identified data from Customer Personal Data for benchmarking, analytics, product improvement, and the training and improvement of ClearMark’s own machine learning models operating within the Services. Such data does not identify, and cannot reasonably be linked to, any individual, and ClearMark will not attempt to re-identify it.
3.5 Individual Requests. If you are an individual whose personal information is contained in Customer Personal Data and you wish to exercise a privacy right with respect to that data, please contact the applicable Customer. ClearMark will reasonably assist Customers in responding to such requests as described in the applicable Data Processing Addendum.
3.6 Subprocessors. ClearMark engages a limited number of trusted subprocessors to assist in providing the Services, including cloud hosting providers, infrastructure and storage providers, security and monitoring providers, and customer support providers. ClearMark imposes contractual obligations on each subprocessor that are no less protective than those in this Policy and the applicable Data Processing Addendum. A current list of subprocessors is available on request.
4. INFORMATION WE COLLECT AS A BUSINESS/CONTROLLER
This Section 4 describes the categories of personal information that ClearMark collects when acting as a business under the CCPA or a controller under the GDPR. The categories below correspond to the categories enumerated in the CCPA.
Information You Provide Directly
- Identifiers, such as name, email address, telephone number, employer, job title, and business mailing address, when you create an account, request a demo, attend an event, or contact us;
- Commercial information, such as billing contact details, services purchased, and order history;
- Professional information, such as the agency, brokerage, or carrier you are affiliated with and your role;
- Communications, such as the content of emails, support tickets, and other correspondence you send to us; and
- User research and survey responses, including any demographic information you choose to share with us.
Information Collected Automatically
- Internet and electronic network activity information, including IP address, browser type, device identifiers, operating system, referring and exit URLs, pages visited, log-in history, navigation paths, and dates and times of access;
- Approximate location information inferred from your IP address (for example, city or region). We do not collect precise GPS-based location;
- Usage information about your interaction with our websites and the Services, including features used, configurations selected, search queries, time spent on pages, and aggregate usage patterns; and
- Cookies and similar technologies as described in Section 10 below.
Information from Other Sources
- Information from public sources, business contact databases, and analytics or marketing providers, used to identify prospective customers and to improve our outreach; and
- Information from third-party services used to authenticate users, route traffic, prevent fraud, or process payments.
Sensitive personal information. ClearMark does not intentionally collect sensitive personal information as defined under the CCPA (for example, government identifiers, precise geolocation, racial or ethnic origin, religious beliefs, or health data) about visitors to our websites or individuals who interact with us directly. ClearMark does not use the Services to collect, process, or transmit Protected Health Information under the Health Insurance Portability and Accountability Act except as expressly authorized in a separate written agreement and executed Business Associate Agreement.
Please do not send us sensitive information. We ask that you not send us, and you not disclose, any sensitive information (for example, Social Security numbers, social insurance numbers, passports, driver’s license numbers, financial account numbers, or information related to racial or ethnic origin, religion, or health) on or through the Services or otherwise to us unless we specifically request that information. If you provide sensitive information to us anyway, you do so at your own risk, and we may delete it.
5. HOW WE USE INFORMATION
ClearMark uses the categories of personal information described in Section 4 for the following business and commercial purposes:
- To provide, operate, maintain, secure, and improve the Services and our websites;
- To create and administer accounts, authenticate users, and process payments;
- To communicate with you about the Services, including account notifications, security alerts, and changes to our terms or policies;
- To respond to inquiries, provide customer support, and resolve disputes;
- To send marketing communications about our products and services, subject to your right to opt out at any time;
- To prevent, detect, and respond to fraud, security incidents, and unlawful or harmful activity;
- To enforce our agreements and comply with legal obligations, including responding to lawful requests from public authorities;
- To conduct analytics, research, and product development, and to derive aggregated and de-identified data for business purposes; and
- To train, evaluate, and improve ClearMark’s own machine learning and analytics models operating within the Services, as further described in Section 9.
6. LEGAL BASES FOR PROCESSING (GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, ClearMark relies on the following legal bases under the GDPR to process personal information:
- Performance of a contract: to provide the Services to you or to your employer, to enter into a contract with you, or to take pre-contractual steps at your request;
- Legitimate interests: to operate and improve the Services, secure our systems, prevent fraud, conduct business-to-business marketing to business contacts, and exercise or defend legal claims, where such interests are not overridden by your rights and freedoms;
- Legal obligation: to comply with applicable laws, including tax, accounting, and regulatory requirements; and
- Consent: where you have given consent, such as for certain marketing communications or non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
7. HOW WE SHARE INFORMATION
ClearMark does not sell personal information for monetary consideration. ClearMark may share personal information in the following limited circumstances:
- Service providers and subprocessors: with third parties that provide services on our behalf, such as cloud hosting, infrastructure, security, payment processing, analytics, customer support, and email delivery, subject to contractual obligations that restrict their use of personal information to the services they provide to us;
- Affiliates: with our corporate affiliates for the purposes described in this Policy;
- Professional advisors: to our lawyers, accountants, auditors, insurers, and other professional advisors, where necessary in the course of the professional services they render to us;
- Business transfers: in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, in which case personal information may be transferred to the acquiring entity, subject to obligations consistent with this Policy;
- Legal compliance and protection: to comply with applicable law, regulation, legal process, or governmental request; to enforce our Terms of Use and other agreements; and to protect the rights, property, or safety of ClearMark, our customers, our employees, or others; and
- With consent or at direction: with your consent or at your direction, including in connection with a Customer’s instructions regarding Customer Personal Data.
8. INTERNATIONAL DATA TRANSFERS
ClearMark is based in the United States. Personal information that we collect may be transferred to, stored in, or processed in the United States or other countries that may have data protection laws different from those in your country, and may be subject to access requests from governments, courts, regulatory agencies, or law enforcement in those jurisdictions. For transfers from the European Economic Area, the United Kingdom, or Switzerland to countries that have not been recognized as providing an adequate level of protection, ClearMark relies on appropriate safeguards such as the Standard Contractual Clauses adopted by the European Commission, the UK International Data Transfer Addendum, and the Swiss adaptations of those clauses. A copy of the relevant transfer mechanism is available on request.
9. ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING
9.1 How We Use AI in the Services. The Services include machine learning models, statistical models, and other artificial intelligence components that operate on Customer Personal Data and other data to identify patterns, generate notifications, and produce insights. These models are operated by ClearMark and run within the Services.
9.2 Our Commitments. ClearMark commits that:
- We do not use Customer Personal Data to train, fine-tune, evaluate, or improve any third-party artificial intelligence model, machine learning model, large language model, foundation model, or generative AI system that operates outside the Services;
- We do not provide Customer Personal Data to any third-party provider of generative AI services for the purpose of training that third party’s models;
- We do not use Customer Personal Data for cross-context behavioral advertising or any form of profiling that produces legal or similarly significant effects on individuals without an applicable lawful basis;
- We use aggregated and de-identified data, rather than identifiable Customer Personal Data, to train and improve ClearMark’s own models wherever practicable; and
- We design our AI components to be assistive tools. Notifications and insights generated by the Services do not constitute insurance, financial, legal, or other professional advice, and our Customers and their personnel are expected to apply professional judgment before acting on Service output.
9.3 Third-Party AI Components. Where ClearMark uses third-party AI components or models within the Services, we contractually require those providers not to use Customer Personal Data to train, retrain, or improve their own or any other party’s models, and not to retain Customer Personal Data beyond what is necessary to provide the relevant service to ClearMark.
9.4 Restrictions on User-Side Use of AI. The ClearMark Terms of Use prohibit you from feeding the Services or any output of the Services into any third-party AI system, including any chatbot, copilot, or generative AI interface, or from using the Services or any output to train, develop, or improve any AI system. Please review the Terms of Use for the full restrictions.
10. COOKIES AND SIMILAR TECHNOLOGIES
ClearMark and our service providers use cookies, pixels, web beacons, local storage, and similar technologies on our websites for purposes that include authenticating users, remembering preferences, measuring website performance, securing the Services, and analyzing traffic. We use the following categories:
- Strictly necessary: required for the operation of the Services, such as authentication and security;
- Performance and analytics: help us understand how visitors interact with our websites so that we can improve them;
- Functional: remember your preferences and provide enhanced features; and
- Marketing: used to measure the effectiveness of business-to-business marketing campaigns. We do not use cookies for cross-context behavioral advertising
Your Cookie Choices
You can manage cookies in several ways:
- Cookie preferences tool. Where available on our website, you can change your cookie preferences through the cookie preferences link in the webpage footer.
- Browser settings. Most browsers let you remove or reject cookies. Follow the instructions in your browser settings. Many browsers accept cookies by default until you change your settings.
- Privacy plug-ins and browsers. You can block sites from setting cookies for analytics or advertising by using a browser with privacy features or installing plugins that block third-party cookies and trackers.
- Advertising industry opt-out tools. You can use industry opt-out options to limit use of your information for interest-based advertising by participating companies, including the Network Advertising Initiative (NAI), the Digital Advertising Alliance (DAA) for web and mobile, and the European Interactive Digital Advertising Alliance (EDAA) for users in the United Kingdom and Europe.
Do Not Track and Global Privacy Control. At this time, we do not respond to browser Do Not Track signals because no common industry standard for those signals has been finalized. ClearMark honors Global Privacy Control (GPC) signals as a valid opt-out request to the extent required by applicable law.
11. DATA RETENTION
ClearMark retains personal information for as long as necessary to fulfill the purposes for which it was collected, including to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary based on the type of information, the purpose of processing, and applicable legal requirements. Customer Personal Data is retained in accordance with the applicable Customer’s instructions and the Terms of Use. When we no longer have an ongoing legitimate business need to process personal information, we will either delete or anonymize it, or, if that is not possible (for example, because the information is stored in backup archives), we will securely store the information and isolate it from further processing until deletion is possible.
12. SECURITY
ClearMark maintains administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These safeguards include encryption in transit and at rest, access controls based on the principle of least privilege, security monitoring and logging, vendor risk management, and regular security testing. ClearMark aligns its information security program with industry-recognized frameworks. However, no security program can guarantee absolute security, and no method of transmitting or storing information can be one hundred percent secure. Individuals provide personal information to ClearMark at their own risk.
13. YOUR U.S. STATE PRIVACY RIGHTS
Depending on where you reside, you may have the following rights with respect to personal information that ClearMark processes as a business or controller. These rights are subject to verification of your identity and to legal exceptions.
California (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what categories and specific pieces of personal information we have collected about you, the sources of that information, the business and commercial purposes for collecting it, and the categories of third parties with whom we share it;
- Request deletion of personal information we have collected from you;
- Correct inaccurate personal information we maintain about you;
- Request a portable copy of the personal information you have provided to us;
- Opt out of the sale or sharing of personal information. ClearMark does not sell or share personal information within the meaning of the CCPA;
- Limit our use and disclosure of sensitive personal information. ClearMark does not use sensitive personal information for purposes that would trigger this right; and
- Be free from retaliation or discrimination for exercising your privacy rights.
Virginia, Colorado, Connecticut, Utah, Texas, and Other States
If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, New Hampshire, New Jersey, Minnesota, Tennessee, Indiana, Iowa, Kentucky, Maryland, Rhode Island, or another state with a comprehensive consumer privacy law, you may have rights similar to those described above for California residents, including the rights to access, correct, delete, and obtain a portable copy of your personal information, and to opt out of targeted advertising, the sale of personal information, and certain profiling. ClearMark does not engage in targeted advertising or profiling that produces legal or similarly significant effects based on personal information processed in its capacity as a business or controller.
How to Exercise Your Rights and How to Appeal
To exercise any of these rights, contact ClearMark using the information in Section 19. We may need to verify your identity before fulfilling your request and may decline requests as permitted by law. You may designate an authorized agent to submit a request on your behalf, subject to verification, including a valid power of attorney and government-issued identification of the requester and the authorized agent. If we decline a request, we will inform you of the reasons (subject to legal restrictions), and, in states that provide an appeal right, you may appeal our decision by contacting us using the information in Section 19. You should not transmit government-issued identification or other sensitive information by email; please contact us first for secure transmission instructions.
14. YOUR GDPR RIGHTS
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights, subject to applicable exceptions: the right of access; the right to rectification; the right to erasure; the right to restriction of processing; the right to data portability; the right to object to processing based on legitimate interests; the right to withdraw consent; and the right to lodge a complaint with a supervisory authority. To exercise these rights, contact ClearMark using the information in Section 19. If ClearMark processes your personal information as a processor on behalf of a Customer, please contact the applicable Customer directly.
Controller. ClearMark is the controller of personal information collected when we act in a controller capacity under this Policy. Where we have appointed local representatives in the United Kingdom or the European Economic Area as required by applicable law, the contact details for those representatives are available on request.
15. CHILDREN
The Services are not directed to, and ClearMark does not knowingly collect personal information from, individuals under the age of sixteen (16). If you believe that we have collected personal information from a child without appropriate consent, please contact us so that we can delete the information.
16. THIRD-PARTY WEBSITES AND SERVICES
Our websites and the Services may contain links to, or interoperate with, third-party websites, applications, and services, including agency management systems, customer relationship management systems, anti-spam services such as reCAPTCHA, and analytics providers. ClearMark is not responsible for the privacy practices of those third parties. We encourage you to review the privacy notices of any third party before providing personal information to it.
17. TRANSLATIONS
Where ClearMark provides this Privacy Policy in a language other than English, the English version controls in the event of any inconsistency or conflict between versions.
18. CHANGES TO THIS POLICY
ClearMark may update this Privacy Policy from time to time. When we make material changes, we will revise the “Last Updated” date at the top of this Policy and, where appropriate, provide additional notice (such as by email or through the Services). Your continued use of the Services after the effective date of a revised Policy constitutes acceptance of the revised Policy.
19. HOW TO CONTACT US
If you have questions about this Privacy Policy or wish to exercise a privacy right, contact us at:
ClearMark LLC
Attn: Privacy
Email: privacy@clearmark.ai
Website: www.clearmark.ai
If you are located in the European Economic Area, the United Kingdom, or Switzerland and wish to contact our local representative or a supervisory authority, please reach out to us using the information above and we will provide further instructions.