Privacy Policy
Last updated 8 August 2026
Doux is software used by licensed insurance agencies to operate their own business. Almost all of the data we handle belongs to the agency and to the agency's clients, not to us. This policy explains what we do with it, and the short version is: we process it to provide the service, and nothing else.
Who we are
Doux ("Doux", "we", "us") provides agency automation software to commercial property and casualty insurance agencies in the United States. Contact: privacy@getdoux.com.
Our role
For the data inside an agency's account, the agency is the controller and Doux is a processor (a "service provider" under the CCPA/CPRA). We act on the agency's documented instructions. We do not decide what data an agency collects about its clients, and we do not use that data for our own purposes.
What we process
- Account data — name, work email, role, and authentication identifiers for the people at the agency who use Doux.
- Connected system data — with the agency's authorisation, content from the agency's email, its management system, and the carrier, MGA and payment portals it is appointed with. This can include information about the agency's insureds: names, contact details, policy and coverage details, documents and correspondence.
- Operational records — what Doux proposed, what a person approved or rejected, when, and the evidence behind it. This audit record is a core part of the product.
- Service data — logs, traces, error reports and usage metrics used to operate and improve the service.
Credentials
Credentials for an agency's connected systems are encrypted with a key unique to that agency and are used only to perform actions the agency has authorised. They are never shared between agencies, never exposed to our staff in plain text, and never sent to a third-party model provider.
Artificial intelligence
Doux uses large language models to classify, extract and propose. Three commitments govern that use:
- Personal information is minimised and redacted before a model call wherever the task allows it.
- Our model providers are engaged under terms that prohibit training on customer data, and we are contracting for zero data retention. We will state the current position in writing on request.
- A model never executes an action. It produces a proposal; a deterministic system and a human decide.
Why we process it
To provide the service the agency has contracted for; to secure it and prevent abuse; to meet legal obligations; and, using aggregated, de-identified information only, to improve the product. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
Subprocessors
We use a small number of vendors for hosting, storage, authentication, model inference, error monitoring and payments. A current list, with each vendor's role and location, is available at privacy@getdoux.com and will be provided to every customer before onboarding. Customers are notified before a new subprocessor is added.
Retention and deletion
We retain data for as long as the agency's account is active, and then for the period stated in the agency's agreement. On request or on termination we delete or return the agency's data, and we destroy the encryption keys protecting it. Records we are legally required to keep are retained for that period and no longer. An agency's own regulatory record-keeping obligations remain the agency's.
Where data is held
All customer data is stored and processed in the United States.
Security
Encryption in transit and at rest, per-agency key separation, least-privilege access, and an append-only audit record. Our formal security programme, including its current stage, is set out on our security page. Report a vulnerability to security@getdoux.com.
Your rights
If you are an insured or a contact of an agency using Doux, your relationship is with that agency — please direct requests to access, correct or delete your information to them, and we will assist them in responding. If you are a user at a Doux customer, contact us directly. California residents have rights under the CCPA/CPRA including access, deletion, correction and non-discrimination; we do not sell or share personal information as those terms are defined.
Children
Doux is a business product and is not directed to anyone under 18.
Changes
We will post any change here and update the date above. Material changes affecting customers are notified in advance under the customer agreement.