Privacy Policy
How RM Assistant handles personal information — both the data you give us directly and the data contained in submission documents we process for our customers.
Last updated: 16 August 2026
1. Two very different kinds of data
This distinction determines almost everything else in this policy, so it comes first.
Data we control. Information you give us directly — for example when you request a demo, email us, or visit this website. We decide how it is used, and we are the controller of it.
Data we process for customers.The contents of insurance submissions our customers send through the platform: applications, loss runs, vehicle schedules, driver records and similar documents. These may contain personal information about insureds, drivers and claimants. We process this strictly on our customer's instructions. The customer is the controller; we are the processor. If your personal information appears in a submission, the insurance business that holds your relationship is the right first point of contact, and we will support them in responding.
2. Information we collect directly
- Contact and enquiry details — name, work email, company, phone, role, and anything you write in a message when you submit the demo form or email us.
- Account information — for users of the platform, the credentials and profile details needed to authenticate and to attribute review actions.
- Website usage data — pages viewed, referring source, approximate location derived from IP, device and browser type, and interaction events such as which call to action was clicked. Collected through Google Analytics and Microsoft Clarity, which uses session replay to record on-page interactions.
- Security and anti-abuse data — IP address and request metadata used for rate limiting and bot detection, including through Cloudflare Turnstile.
3. How we use it
- To respond to enquiries and arrange demonstrations.
- To provide, operate, secure and support the platform.
- To improve the website and understand which content is useful.
- To detect and prevent abuse, fraud and security incidents.
- To meet legal, tax and regulatory obligations.
We do not sell personal information. We do not share it with third parties for their own marketing. We do not use customer submission data to train shared or general-purpose AI models, and it is not pooled across customers.
4. Artificial intelligence processing
Submission documents are processed using third-party AI models to classify documents and extract structured data. That processing is carried out under commercial API terms which do not permit the provider to use the content to train its models. Documents are sent for processing, a structured result is returned, and the result is stored in your customer's isolated tenant environment.
Extracted data is presented to a human for review before it is written to any policy administration system. No automated decision producing a legal or similarly significant effect is made without human involvement.
5. Sharing and sub-processors
We share data with the service providers necessary to run the platform — hosting, AI processing, email delivery, carrier-data lookup and CRM. Each is bound by contract to process data only on our instructions. The current list, including what each one receives, is published at rmassistant.com/subprocessors.
We may also disclose information where required by law, to enforce our agreements, or in connection with a merger or acquisition — in which case this policy continues to apply to the transferred information.
6. Retention
Customer submission data is retained for as long as the customer's agreement requires, and is deleted or returned on termination in line with the data processing agreement. Enquiry and marketing contact data is retained while there is a live business relationship and for a reasonable period afterwards. Website analytics data is retained according to the retention settings of the analytics services described above.
7. Security
Data is encrypted in transit and at rest. Each customer's data is isolated in its own tenant environment. Access is restricted to personnel who need it, third-party credentials are stored encrypted, and every extracted field retains a link to its source document so records remain auditable. See our data processing agreement for the contractual security commitments.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, port or restrict the processing of your personal information, and to object to certain processing. California residents have rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them; we do not sell or share personal information as those terms are defined there.
To exercise a right in respect of data we control, email [email protected]. If your request concerns data inside a customer's submissions, contact that insurance business directly — we will assist them, but we cannot act on their data without instruction.
9. Cookies and tracking
This website uses cookies and similar technologies for analytics and security. You can block or delete cookies in your browser; essential security functionality may not work correctly if you do. We do not use advertising cookies or third-party ad pixels.
10. International transfers
We are based in and operate the platform from the United States, and personal information is processed there. Where data is transferred from another jurisdiction, we rely on appropriate safeguards, including standard contractual clauses where applicable.
11. Children
The platform is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16 through this website.
12. Changes
We will update this policy as the platform changes and will revise the date at the top. Material changes affecting customers will be notified under the terms of their agreement.
13. Contact
Privacy questions and requests: [email protected]
Security matters: [email protected]
Anything else: [email protected]