Legal

Data Processing Agreement

The terms under which RM Assistant processes personal data contained in submissions on a customer's behalf. Forms part of the customer agreement.

Last updated: 16 August 2026

This agreement (the “DPA”) applies where RM Assistant(“Processor”) processes personal data on behalf of a customer (“Controller”) under a services agreement. It is incorporated into that agreement by reference. A counter-signed copy is available on request from [email protected].

1. Roles

The Controller determines the purposes and means of processing personal data contained in insurance submissions. The Processor processes that data only on the Controller's documented instructions, which include the instruction to provide the service as described in the services agreement and this DPA.

2. Subject matter, duration and nature of processing

  • Subject matter:automated ingestion, classification and extraction of data from insurance submission documents, and delivery of structured records to the Controller's system of record.
  • Duration: the term of the services agreement, plus the deletion period in section 9.
  • Categories of data subject:insureds and prospective insureds, named drivers and operators, claimants referenced in loss runs, and the Controller's own personnel who use the platform.
  • Categories of personal data: identifying and contact details, business and vehicle information, driver licensing and motor vehicle record data, loss and claims history, and any other personal data the Controller chooses to submit.

3. Processor obligations

The Processor shall:

  • process personal data only on documented instructions from the Controller;
  • not use personal data for its own purposes, and specifically not use Controller data to train shared or general-purpose AI models, nor pool it with any other customer's data;
  • ensure personnel authorised to process personal data are bound by confidentiality obligations;
  • implement the technical and organisational measures set out in section 5;
  • assist the Controller, taking into account the nature of processing, in responding to data subject requests and in meeting its security, breach notification and impact assessment obligations;
  • make available information necessary to demonstrate compliance and allow for audits as set out in section 8.

4. Controller obligations

The Controller warrants that it has a lawful basis for the personal data it submits, that it has provided any required notices to data subjects, and that its instructions comply with applicable data protection law.

5. Security measures

  • Encryption of personal data in transit and at rest.
  • Logical isolation of each customer's data in a dedicated tenant environment, with no shared data pool between customers.
  • Encrypted storage of credentials for third-party systems, scoped per tenant.
  • Role-based access control, with access to production data limited to personnel who require it for support and operations.
  • Field-level provenance: every extracted value retains a reference to the source document and page, and human review actions are attributable, producing an auditable record of how a value was derived.
  • A human approval step before extracted data is written to any downstream system, so that no record enters the Controller's system of record without human confirmation.
  • Regular backups, with restoration procedures tested periodically.

6. Sub-processors

The Controller grants general authorisation for the Processor to engage sub-processors. The current list is maintained at rmassistant.com/subprocessors. The Processor will give the Controller notice before a new sub-processor begins processing its personal data, and the Controller may object on reasonable data protection grounds; if the objection cannot be resolved, the Controller may terminate the affected service.

The Processor remains liable for the acts and omissions of its sub-processors, and imposes on each obligations no less protective than those in this DPA.

7. Personal data breach

The Processor will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Controller's data. The notification will describe the nature of the breach, the categories and approximate volume of data concerned, the likely consequences, and the measures taken or proposed. The Processor will cooperate with and assist the Controller in its own notification obligations.

8. Audit

On reasonable written notice and no more than once in any 12-month period (unless required by a supervisory authority or following a breach), the Processor will provide the Controller with information reasonably necessary to demonstrate compliance with this DPA, and will make appropriate personnel available to answer questions. Audits must not unreasonably disrupt operations or compromise the confidentiality of other customers.

9. Return and deletion

On termination of the services agreement, the Processor will, at the Controller's election, return or delete personal data processed on its behalf within 30 days, save where retention is required by applicable law. Backup copies are deleted in line with the backup rotation schedule.

10. International transfers

Processing takes place in the United States. Where personal data is transferred from a jurisdiction that restricts such transfers, the parties will rely on an appropriate transfer mechanism, including the applicable standard contractual clauses, which are incorporated by reference where required.

11. Order of precedence

In the event of conflict, this DPA prevails over the services agreement in respect of the processing of personal data. Where standard contractual clauses apply, they prevail over this DPA to the extent of any conflict.

12. Contact

Data protection and DPA questions: [email protected]
Security and audit requests: [email protected]