Doux is software used by licensed insurance agencies to operate their own business. Almost all of the data we handle belongs to the agency and to the agency's clients — not to us. This policy explains what we do with it, and the short version is: we process it to provide the service, and nothing else.
Doux ("Doux", "we", "us") provides agency automation software to commercial property and casualty insurance agencies in the United States. Contact: privacy@getdoux.com.
For the data inside an agency's account, the agency is the controller and Doux is a processor (a "service provider" under the CCPA/CPRA). We act on the agency's documented instructions. We do not decide what data an agency collects about its clients, and we do not use that data for our own purposes.
Credentials for an agency's connected systems are encrypted with a key unique to that agency and are used only to perform actions the agency has authorised. They are never shared between agencies, never exposed to our staff in plain text, and never sent to a third-party model provider.
Doux uses large language models to classify, extract and propose. Three commitments govern that use:
To provide the service the agency has contracted for; to secure it and prevent abuse; to meet legal obligations; and, using aggregated, de-identified information only, to improve the product. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
We use a small number of vendors for hosting, storage, authentication, model inference, error monitoring and payments. A current list, with each vendor's role and location, is available at privacy@getdoux.com and is provided to every customer before onboarding. Customers are notified before a new subprocessor is added.
We retain data for as long as the agency's account is active, and then for the period stated in the agency's agreement. On request or on termination we delete or return the agency's data, and we destroy the encryption keys protecting it. Records we are legally required to keep are retained for that period and no longer. An agency's own regulatory record-keeping obligations remain the agency's.
All customer data is stored and processed in the United States.
Encryption in transit and at rest, per-agency key separation, least-privilege access, an append-only audit record, and independent security testing. Details are on our security page. Report a vulnerability to security@getdoux.com.
If you are an insured or a contact of an agency using Doux, your relationship is with that agency — please direct requests to access, correct or delete your information to them, and we will assist them in responding. If you are a user at a Doux customer, contact us directly. California residents have rights under the CCPA/CPRA including access, deletion, correction and non-discrimination; we do not sell or share personal information as those terms are defined.
Doux is a business product and is not directed to anyone under 18.
We will post any change here and update the date above. Material changes affecting customers are notified in advance under the customer agreement.