Privacy Policy
01Introduction
Aiden Risk Inc. ("Aiden," "we," "us," or "our") is a Delaware corporation headquartered at 535 Mission St, 14th Floor, San Francisco, CA 94105. We are committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website, use our platform, or engage with our insurance brokerage services.
This policy applies to all information collected through our website (aidenrisk.com), our AI-powered commercial insurance platform, and any related services, sales, marketing, or events (collectively, the "Services").
By accessing or using our Services, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this policy, please do not access our Services.
02Information We Collect
Information You Provide
We collect personally identifiable information that you voluntarily provide to us when you register for an account, request a quote, submit an application, or otherwise contact us. This includes:
- Identity data — Full name, job title, company name, and date of birth
- Contact data — Email address, phone number, and mailing address
- Business data — Industry, revenue, employee count, years in operation, and prior coverage history
- Insurance data — Application details, claims history, loss runs, risk exposures, and policy preferences
- Financial data — Information necessary for policy underwriting, premium payment, and billing
- Communication data — Records of correspondence, support tickets, and feedback you send us
Information Collected Automatically
When you access our platform, we automatically collect certain technical and usage information:
| Data Type | Examples | Purpose |
|---|---|---|
| Device Information | Browser type, operating system, device identifiers | Platform optimization |
| Usage Data | Pages visited, features used, time on page, click paths | Service improvement |
| Log Data | IP address, timestamps, referring URLs, access times | Security & analytics |
| Cookie Data | Session tokens, preference settings, analytics identifiers | Authentication & personalization |
| Location Data | Approximate location inferred from IP address | Regulatory compliance & content localization |
Information from Third Parties
We may receive information about you from insurance carriers, third-party data providers, and public databases to supplement the information you provide, verify your identity, and assess risk in connection with insurance applications.
03How We Use Your Information
We use the information we collect for the following purposes:
- Providing Insurance Services — To process applications, generate quotes, bind coverage, issue certificates, manage renewals, and handle claims on your behalf as your insurance broker.
- AI-Powered Risk Analysis — To leverage our proprietary AI risk engine for coverage optimization, risk assessment, and policy recommendations tailored to your business.
- Communication — To respond to inquiries, send policy documents, provide renewal reminders, and deliver customer support.
- Account Management — To create and manage your account, authenticate your identity, and maintain your policy portfolio.
- Regulatory Compliance — To satisfy legal and regulatory obligations under state insurance laws across all 50 states and the District of Columbia.
- Platform Improvement — To analyze usage patterns, conduct research, and improve our platform, algorithms, and services.
- Marketing — To send you information about our services, industry insights, and educational content, subject to your communication preferences.
- Security — To detect, prevent, and respond to fraud, security incidents, and technical issues.
AI Transparency: When our AI systems process your data for risk analysis or coverage recommendations, no fully automated decisions are made regarding policy eligibility. All underwriting and binding decisions involve human review by licensed insurance professionals.
04Data Sharing & Disclosure
We do not sell your personal information. We may share your information with the following categories of recipients:
- Insurance Carriers & Underwriters — To obtain quotes, bind coverage, process endorsements, and manage claims.
- Service Providers — Third-party vendors who assist us in operating our platform, including cloud hosting (AWS, GCP), analytics (Google Analytics, Mixpanel), CRM (Salesforce, HubSpot), payment processing (Stripe), email delivery (SendGrid, Mailchimp), and other operational tools — all subject to contractual data protection obligations.
- Professional Advisors — Attorneys, accountants, auditors, and consultants as necessary for our business operations.
- Legal Requirements — When required by law, regulation, subpoena, court order, or governmental request.
- Business Transfers — In connection with a merger, acquisition, reorganization, or sale of assets.
- With Your Consent — When you direct us to share information with specific third parties.
We require all third parties to respect the security of your personal data and to treat it in accordance with applicable law.
05Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required or permitted by law.
- Active client data — Duration of client relationship plus seven (7) years following expiration or cancellation of the last active policy.
- Insurance records — Minimum of seven (7) years following policy expiration, per state insurance regulatory requirements.
- Claims-related data — Applicable statute of limitations period plus an additional reasonable period.
- Marketing data — Until you opt out or for up to three (3) years of account inactivity.
- Technical logs — Typically 12 months, unless required longer for security investigation.
06Security Measures
We implement technical and organizational security measures designed to protect your information, including:
- AES-256 encryption for data at rest
- TLS 1.3 encryption for all data in transit
- SOC 2 Type II certified infrastructure
- Regular penetration testing and vulnerability assessments
- Role-based access controls with principle of least privilege
- Multi-factor authentication for all internal systems
- Centralized audit logging with immutable retention
- Automated threat detection and incident response procedures
While no method is 100% secure, we continuously monitor and update our security practices. For more details, visit our Trust Center.
07Your Rights & Choices
Depending on your jurisdiction, you may have the following rights:
- Access — Request a copy of the personal data we hold about you.
- Correction — Request that we correct inaccurate or incomplete information.
- Deletion — Request that we delete your personal data, subject to legal retention requirements.
- Portability — Receive your data in a structured, machine-readable format.
- Restriction — Request that we limit how we use your data.
- Opt-Out of Marketing — Unsubscribe from marketing communications at any time.
To exercise any of these rights, please contact us at privacy@aidenrisk.com. We will respond within 45 days.
08California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the CCPA/CPRA:
- Right to Know — Request disclosure of categories and specific pieces of personal information collected.
- Right to Delete — Request deletion of personal information, subject to exceptions.
- Right to Correct — Request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing — We do not sell your personal information.
- Right to Non-Discrimination — We will not discriminate against you for exercising your rights.
Insurance Exception: Certain personal information collected in connection with insurance products is subject to the GLBA and California IIPPA, which may exempt such data from certain CCPA requirements.
09Children's Privacy
Our Services are not directed to individuals under 18. We do not knowingly collect personal information from children. Contact us at privacy@aidenrisk.com if you believe we have.
10Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy and updating the "Last Updated" date.
11Contact Us
If you have questions about this Privacy Policy:
Aiden Risk Inc.
Attn: Privacy Team
535 Mission St, 14th Floor
San Francisco, CA 94105
Email: privacy@aidenrisk.com
01Definitions
This Data Processing Agreement ("DPA") is entered into by and between the client identified in the applicable service agreement ("Controller" or "Client") and Aiden Risk Inc., a Delaware corporation ("Processor" or "Aiden"). This DPA supplements and forms part of the Master Service Agreement or Terms of Service (the "Agreement") between the parties.
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or destruction.
- "Sub-Processor" means any third party engaged by Processor to process Personal Data on behalf of Controller.
- "Data Breach" means any unauthorized access, acquisition, use, or disclosure of Personal Data.
- "Applicable Data Protection Law" means all applicable laws relating to data protection and privacy, including the CCPA/CPRA, state insurance data security laws, and the GLBA.
02Scope & Purpose of Processing
Processor shall process Personal Data only to the extent necessary to provide insurance brokerage, risk analysis, and related services.
| Element | Description |
|---|---|
| Subject Matter | Provision of AI-powered commercial insurance brokerage services |
| Duration | Term of the Agreement plus applicable retention period |
| Nature & Purpose | Insurance application processing, risk analysis, quote generation, policy binding, renewals, claims support, compliance reporting |
| Categories of Data | Identity, contact, business, insurance, financial, and communications data |
| Data Subjects | Client employees, officers, directors, authorized representatives, and beneficiaries |
03Obligations of the Processor
Processor shall:
- Process Personal Data only on documented instructions from the Controller.
- Ensure all personnel are bound by appropriate confidentiality obligations.
- Implement and maintain the security measures described in Section 04.
- Assist Controller in responding to data subject requests.
- Assist Controller in compliance with security, breach notification, and impact assessment obligations.
- Make available all information necessary to demonstrate compliance.
- Not process Personal Data for any purpose other than providing the Services.
04Data Security
Processor shall implement appropriate measures including:
- Encryption at rest (AES-256) and in transit (TLS 1.3)
- SOC 2 Type II certified infrastructure
- Multi-factor authentication and role-based access controls
- Regular vulnerability scanning and annual penetration testing
- Intrusion detection and prevention systems
- Centralized, immutable audit logging (12-month minimum)
- Quarterly employee security awareness training
- Documented incident response procedures tested annually
- Business continuity and disaster recovery plans
05Sub-Processors
Controller provides general written authorization for Processor to engage Sub-Processors with 30 days advance notice for additions or replacements.
Current Sub-Processors
| Sub-Processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud infrastructure & hosting | United States |
| Google Cloud Platform | Cloud infrastructure & AI/ML | United States |
| Salesforce | CRM | United States |
| HubSpot | Marketing automation & CRM | United States |
| Stripe | Payment processing | United States |
| SendGrid (Twilio) | Transactional email | United States |
| Mixpanel | Product analytics | United States |
| Google Analytics | Website analytics | United States |
06Data Subject Rights
Processor shall assist Controller in fulfilling obligations to respond to data subject requests. When Processor receives a request directly, it shall promptly redirect the individual to Controller.
07Data Breach Notification
In the event of a Data Breach, Processor shall:
- Notify Controller within 48 hours of becoming aware of the breach.
- Provide information on the nature, consequences, and measures taken.
- Cooperate in investigation, remediation, and mitigation.
- Not notify third parties without Controller's prior written consent (unless required by law).
08Data Transfers
Personal Data is stored and processed within the United States. Processor shall not transfer Personal Data outside the US without Controller's prior written consent.
09Audit Rights
Controller may verify compliance through SOC 2 reports, on-site audits (once per year, 30 days notice), and security questionnaires (15-day response).
10Term, Termination & Data Return
Upon termination, Processor shall return or delete all Personal Data within 90 days, except where regulatory retention requirements apply.
For questions about this DPA, contact us at legal@aidenrisk.com.
01Acceptance of Terms
These Terms of Service ("Terms") constitute a legally binding agreement between you and Aiden Risk Inc., a Delaware corporation ("Aiden"). By accessing or using our website, platform, or services (the "Services"), you agree to be bound by these Terms.
If you are entering into these Terms on behalf of a business, you represent that you have authority to bind that entity. You must be at least 18 years of age to use the Services.
02Description of Services
Aiden provides an AI-powered commercial insurance brokerage platform enabling businesses to obtain quotes, receive AI risk analysis, bind and manage policies, access certificates, and receive advisory services. Aiden acts as a licensed insurance broker — we do not underwrite or issue policies.
03User Accounts
When registering, you agree to provide accurate information, maintain confidentiality of credentials, notify us of unauthorized access, and accept responsibility for all account activity.
04Permitted Use & Restrictions
You agree not to: use the Services unlawfully; reverse engineer any part; copy or distribute content; use bots or scraping tools; interfere with system integrity; provide fraudulent information; resell access; or circumvent security measures.
05Insurance Brokerage Relationship
- Broker Role — Aiden acts as your broker, not as a carrier or underwriter.
- No Guarantee — We do not guarantee coverage acceptance or claims payment.
- Accuracy — You are responsible for providing accurate application information.
- Duty to Review — You must review all policy documents for accuracy.
- AI Recommendations — Our AI recommendations are informational tools, not insurance or legal advice.
06Intellectual Property
The Services and all Aiden IP are our exclusive property. You retain ownership of your Client Data and grant us a limited license to use it for providing the Services.
07Fees & Payment
See our Compensation Disclosure for details. Direct fees will be disclosed in advance. Late payments may incur 1.5% monthly interest.
08Disclaimers
THE SERVICES ARE PROVIDED "AS IS" WITHOUT WARRANTIES OF ANY KIND. AIDEN DOES NOT PROVIDE LEGAL, TAX, OR FINANCIAL ADVICE.
09Limitation of Liability
AIDEN'S TOTAL LIABILITY SHALL NOT EXCEED THE GREATER OF FEES PAID IN THE PRIOR 12 MONTHS OR $1,000. AIDEN IS NOT LIABLE FOR CARRIER ACTS OR OMISSIONS.
10Indemnification
You agree to indemnify Aiden from claims arising from your misuse, misrepresentation, or violation of these Terms or applicable law.
11Dispute Resolution
Mandatory Arbitration: Disputes shall be resolved by binding arbitration administered by the AAA in San Francisco, California. Class Action Waiver: All claims shall be resolved individually, not on a class basis.
12Termination
You may close your account by contacting legal@aidenrisk.com. We may suspend or terminate access for breach with immediate notice, or for any reason with 30 days notice.
13General Provisions
Governed by California law. These Terms plus our Privacy Policy and DPA constitute the entire agreement. Severability, no-waiver, assignment restrictions, force majeure, and written notice provisions apply. Notices to legal@aidenrisk.com.
14Contact
Aiden Risk Inc.
Attn: Legal Department
535 Mission St, 14th Floor
San Francisco, CA 94105
Email: legal@aidenrisk.com
01Consent to Use Electronic Signatures
By clicking "I Agree," "Accept," "Sign," or similar action on our platform, you consent to the use of electronic signatures and electronic records in connection with your insurance brokerage relationship with Aiden Risk Inc. This consent applies to all transactions conducted through our platform.
02Scope of Electronic Records
Documents that may be provided, executed, and retained electronically include: insurance documents (applications, quotes, binders, policies, certificates), brokerage agreements, compliance documents, claims documents, account management records, and communications.
03Hardware & Software Requirements
| Requirement | Specification |
|---|---|
| Operating System | Windows 10+, macOS 11+, iOS 15+, Android 10+, or ChromeOS |
| Web Browser | Latest two major versions of Chrome, Firefox, Safari, or Edge |
| Internet | Broadband (minimum 1 Mbps) |
| Screen | 1024x768 (desktop) or 375x667 (mobile) |
| PDF Viewer | Adobe Acrobat Reader or equivalent |
| Valid account capable of receiving 10 MB attachments |
04How to Sign Electronically
You may sign by clicking a button, drawing your signature, typing your name, or applying a saved signature. Each signature is associated with a timestamp, IP address, and account identity.
05Withdrawing Consent
You may withdraw consent at any time by contacting legal@aidenrisk.com. Withdrawal does not affect prior signatures and may result in paper-based processing delays.
06Requesting Paper Copies
Contact legal@aidenrisk.com to request paper copies. Insurance documents are free; administrative documents may incur a reasonable fee.
07Updating Contact Information
Keep your email and contact information current via your account profile or by contacting legal@aidenrisk.com.
08Legal Effect & Enforceability
Under the ESIGN Act and state UETA laws, electronic signatures carry the same legal weight as handwritten signatures. Certain documents (wills, UCC documents, court orders) may be excluded.
09Record Retention
We recommend downloading copies of signed documents. Electronic copies remain in your account for the duration of your relationship and at least seven (7) years per regulatory requirements.
10Contact Us
Aiden Risk Inc.
535 Mission St, 14th Floor
San Francisco, CA 94105
Email: legal@aidenrisk.com
01What Are Cookies
Cookies are small text files stored on your device when you visit a website. We also use similar technologies such as pixel tags, local storage, and device fingerprinting (collectively "Cookies").
Cookies can be first-party (set by us) or third-party (set by partners). They can be session cookies (deleted when you close your browser) or persistent cookies (remaining until expiry or deletion).
02How We Use Cookies
- Essential Operations — Authentication, session management, security, load balancing.
- Preferences — Settings, language, display customizations.
- Analytics and Performance — Understanding visitor behavior and measuring effectiveness.
- Marketing — Delivering relevant content and measuring campaign effectiveness.
03Types of Cookies We Use
| Category | Purpose | Duration |
|---|---|---|
| Strictly Necessary | Authentication, session management, CSRF protection, security. Cannot be disabled. | Session to 1 year |
| Functional | Preferences, display settings, recently viewed items. | Up to 1 year |
| Analytics | Google Analytics and Mixpanel tracking for page views, user flows, performance. | Up to 2 years |
| Marketing | Marketing effectiveness, attribution, conversion measurement. No cross-site targeted ads. | Up to 1 year |
04Third-Party Cookies
| Provider | Purpose | Privacy Policy |
|---|---|---|
| Google Analytics | Website analytics | Google Privacy Policy |
| Mixpanel | Product analytics | Mixpanel Privacy Policy |
| HubSpot | Marketing analytics | HubSpot Privacy Policy |
| Stripe | Payment processing | Stripe Privacy Policy |
05Managing Your Cookie Preferences
- Cookie consent banner — Choose which optional cookies to accept when you first visit.
- Browser settings — Block or delete cookies through your browser. May impair functionality.
- Opt-out links — Install the Google Analytics Opt-Out Add-on.
Disabling strictly necessary cookies may prevent you from logging in or using core features.
06Do Not Track Signals
We do not currently respond to DNT signals but limit tracking to the purposes described in this policy.
07Changes to This Policy
We may update this Cookie Policy from time to time. Material changes will reset your cookie preferences.
08Contact Us
Aiden Risk Inc.
535 Mission St, 14th Floor
San Francisco, CA 94105
Email: privacy@aidenrisk.com
01Our Role as Your Broker
Aiden Risk Inc. is a licensed insurance broker operating across all 50 states and the District of Columbia. We act on your behalf to identify, recommend, and place commercial insurance coverage. We are not an insurance carrier or underwriter.
02Overview of Compensation
- Commissions — Paid by insurance carriers when we place or renew a policy
- Direct Brokerage Fees — Fees for specific services, disclosed in advance
- Platform & Technology Fees — Subscription or access fees for our AI-powered platform
- Contingent Compensation — Performance-based compensation from carriers
03Commissions from Insurance Carriers
Commissions are typically 5–20% of the policy premium, built into the premium you pay. Rates vary by carrier and line of business. Our recommendations are based on coverage quality, not commission rates.
04Direct Brokerage Fees
May include brokerage service fees, policy service fees, and consulting fees. All disclosed in writing before incurred.
05Platform & Technology Fees
May be structured as monthly/annual subscriptions, per-transaction fees, or tiered pricing. Independent of premiums and commissions.
06Contingent Compensation & Volume Bonuses
Based on volume, profitability, or growth metrics. Paid by carriers, not by you.
Our fiduciary duty is to you. We recommend coverage based on your needs, not on compensation we may receive.
07How Compensation May Affect Recommendations
We mitigate conflicts through a multi-carrier approach, AI-driven analysis on objective criteria, disclosure upon request, and a best interest standard.
08Your Right to Information
You may request a detailed breakdown of compensation for any specific policy. Contact legal@aidenrisk.com or your account representative.
09Contact Us
Aiden Risk Inc.
535 Mission St, 14th Floor
San Francisco, CA 94105
Email: legal@aidenrisk.com
01Our Commitment
Aiden Risk Inc. is committed to ensuring that our website and AI-powered insurance platform are accessible to all users, including people with disabilities.
02Conformance Standard
We target WCAG 2.1, Level AA conformance across four principles: Perceivable, Operable, Understandable, and Robust. We also comply with the ADA Title III, California's Unruh Civil Rights Act, and Section 508.
03Measures We Take
- Accessibility in development — Built into our design system and workflow from the start.
- Automated testing — Part of our CI pipeline.
- Manual testing — Regular audits with screen readers and keyboard navigation.
- Third-party audits — Independent consultants conduct periodic WCAG audits.
- Staff training — Design and engineering teams receive accessibility training.
- Feedback integration — User feedback incorporated into our product roadmap.
04Assistive Technologies Supported
| Technology | Platforms |
|---|---|
| JAWS | Windows + Chrome, Edge |
| NVDA | Windows + Chrome, Firefox |
| VoiceOver | macOS + Safari; iOS + Safari |
| TalkBack | Android + Chrome |
| Dragon NaturallySpeaking | Windows (voice navigation) |
| Keyboard-only navigation | All platforms |
| Browser zoom (up to 200%) | All modern browsers |
05Known Limitations
- Third-party content — Carrier-provided PDFs may not be fully accessible. We provide alternatives when possible.
- Data visualizations — Some interactive charts have limited accessibility; tabular alternatives are provided.
- Legacy documents — Older uploads may not meet all WCAG criteria.
06Feedback & Accommodation Requests
Aiden Risk Inc.
Attn: Accessibility Team
535 Mission St, 14th Floor
San Francisco, CA 94105
Email: accessibility@aidenrisk.com
Response times: Acknowledgment within 2 business days, alternative access within 5 business days, remediation within 30 days.
07Enforcement & Complaints
You may file complaints with the U.S. Department of Justice or the California DFEH.
This Accessibility Statement was last reviewed on February 19, 2026.