Doux

Privacy Policy

Last updated 8 August 2026

Doux is software used by licensed insurance agencies to operate their own business. Almost all of the data we handle belongs to the agency and to the agency's clients — not to us. This policy explains what we do with it, and the short version is: we process it to provide the service, and nothing else.

Who we are

Doux ("Doux", "we", "us") provides agency automation software to commercial property and casualty insurance agencies in the United States. Contact: privacy@getdoux.com.

Our role

For the data inside an agency's account, the agency is the controller and Doux is a processor (a "service provider" under the CCPA/CPRA). We act on the agency's documented instructions. We do not decide what data an agency collects about its clients, and we do not use that data for our own purposes.

What we process

Credentials

Credentials for an agency's connected systems are encrypted with a key unique to that agency and are used only to perform actions the agency has authorised. They are never shared between agencies, never exposed to our staff in plain text, and never sent to a third-party model provider.

Artificial intelligence

Doux uses large language models to classify, extract and propose. Three commitments govern that use:

Why we process it

To provide the service the agency has contracted for; to secure it and prevent abuse; to meet legal obligations; and, using aggregated, de-identified information only, to improve the product. We do not sell personal information, and we do not share it for cross-context behavioural advertising.

Subprocessors

We use a small number of vendors for hosting, storage, authentication, model inference, error monitoring and payments. A current list, with each vendor's role and location, is available at privacy@getdoux.com and is provided to every customer before onboarding. Customers are notified before a new subprocessor is added.

Retention and deletion

We retain data for as long as the agency's account is active, and then for the period stated in the agency's agreement. On request or on termination we delete or return the agency's data, and we destroy the encryption keys protecting it. Records we are legally required to keep are retained for that period and no longer. An agency's own regulatory record-keeping obligations remain the agency's.

Where data is held

All customer data is stored and processed in the United States.

Security

Encryption in transit and at rest, per-agency key separation, least-privilege access, an append-only audit record, and independent security testing. Details are on our security page. Report a vulnerability to security@getdoux.com.

Your rights

If you are an insured or a contact of an agency using Doux, your relationship is with that agency — please direct requests to access, correct or delete your information to them, and we will assist them in responding. If you are a user at a Doux customer, contact us directly. California residents have rights under the CCPA/CPRA including access, deletion, correction and non-discrimination; we do not sell or share personal information as those terms are defined.

Children

Doux is a business product and is not directed to anyone under 18.

Changes

We will post any change here and update the date above. Material changes affecting customers are notified in advance under the customer agreement.

Contact

privacy@getdoux.com