Last Updated: December 10, 2025
This Data Processing Addendum ("DPA") is incorporated into and forms part of the Terms of Service or other written agreement ("Agreement") between Matrisk, Inc. ("Matrisk," "we," "us," or "our") and the entity or person agreeing to these terms ("Customer," "you," or "your") for the use of Matrisk's AI-powered insurance market intelligence platform (the "Service").
| Role | Party |
|---|---|
| Data Controller | Customer |
| Data Processor | Matrisk |
Matrisk processes DPA Data on your behalf and according to your documented instructions as set forth in this DPA and the Agreement.
Matrisk processes DPA Data solely for the purpose of providing, maintaining, and improving the Service, including:
| Category | Description |
|---|---|
| User Account Data | Email addresses and account credentials of Customer's authorized users |
| Customer Queries | Any Personal Data contained within search queries or prompts submitted by Customer to the Service |
| Usage Data | Information about how authorized users interact with the Service |
Note: The Service provides access to publicly available regulatory filings and insurance documents. This corpus of public records is not Customer Content and is not processed on Customer's behalf. Matrisk processes this public data as an independent controller under Matrisk's Privacy Policy. This DPA applies only to Personal Data contained in Customer Content, User Account Data, and Usage Data as described above.
Processing will continue for the duration of the Agreement. Upon termination or expiration of the Agreement, Matrisk will delete or return DPA Data in accordance with Section 14 of this DPA.
2.1 "CCPA" means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and any implementing regulations.
2.2 "Customer Content" means any data, documents, queries, or other content that Customer or its authorized users submit to the Service.
2.3 "Data Controller" means the entity that determines the purposes and means of Processing Personal Data.
2.4 "Data Processor" means the entity that Processes Personal Data on behalf of the Data Controller.
2.5 "Data Protection Law" means all applicable laws and regulations relating to the Processing of Personal Data, including the CCPA, GDPR, and US State Privacy Laws.
2.6 "Data Subject" means an identified or identifiable natural person whose Personal Data is Processed.
2.7 "DPA Data" means Customer Content or other Customer data that constitutes Personal Data.
2.8 "GDPR" means the General Data Protection Regulation (EU) 2016/679.
2.9 "Personal Data" means any information relating to an identified or identifiable natural person that is protected under applicable Data Protection Law.
2.10 "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, DPA Data.
2.11 "Processing" (and its derivatives) means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment, combination, restriction, erasure, or destruction.
2.12 "Subprocessor" means any third party engaged by Matrisk to Process DPA Data on behalf of Customer.
2.13 "US State Privacy Laws" means applicable state privacy laws including the Virginia Consumer Data Protection Act, Colorado Privacy Act, Connecticut Data Privacy Act, Utah Consumer Privacy Act, and other similar state privacy laws as they become effective.
3.1 Matrisk will Process DPA Data only in accordance with your documented instructions, which include the instructions set forth in this DPA and the Agreement. Processing outside the scope of your instructions requires your prior written consent, unless required by applicable law.
3.2 Matrisk will promptly notify you if, in our reasonable opinion, your instructions conflict with applicable Data Protection Law.
3.3 Matrisk will promptly inform you if we become aware that we cannot comply with your Processing instructions.
3.4 Matrisk will ensure that all personnel authorized to Process DPA Data are bound by appropriate confidentiality obligations.
3.5 Taking into account the nature of the Processing, Matrisk will assist you, at your expense and upon reasonable request, in responding to requests from Data Subjects to exercise their rights under applicable Data Protection Law.
4.1 Third-Party AI Providers. The Service uses third-party large language model providers to generate responses. Customer queries are sent to these providers solely to generate responses for the Customer. We contractually require these providers not to use Customer Data for model training.
4.2 Internal Quality and Safety. Matrisk may review limited samples of Customer Queries for the purposes of abuse detection, safety monitoring, and service quality assurance. Any such review is conducted under strict confidentiality obligations and access controls.
4.3 Aggregated Analytics. Matrisk may collect and use aggregated, de-identified usage statistics (such as query volumes, feature usage patterns, and performance metrics) that cannot reasonably be used to identify any individual or Customer. Such aggregated data is not considered DPA Data.
5.1 Authorization. You authorize Matrisk to engage Subprocessors to Process DPA Data. A current list of Subprocessors is available upon request.
5.2 Subprocessor Obligations. Matrisk will enter into written agreements with each Subprocessor that impose data protection obligations no less protective than those set forth in this DPA.
5.3 Notice of New Subprocessors. Matrisk will provide you with at least thirty (30) days' prior written notice before engaging a new Subprocessor. Such notice will include the Subprocessor's name, location, and the Processing activities to be performed.
5.4 Objection to New Subprocessors. You may object to a new Subprocessor by providing written notice to Matrisk within fifteen (15) days of receiving notice of the new Subprocessor. Your objection must include reasonable grounds related to data protection. The parties will work together in good faith to resolve any objection. If resolution is not possible within thirty (30) days of your objection, you may terminate the affected portion of the Service by providing written notice to Matrisk, and Matrisk will refund any prepaid fees for the terminated Service covering the period after the effective date of termination.
5.5 Liability. Matrisk remains liable for the acts and omissions of its Subprocessors to the same extent Matrisk would be liable if performing the services directly.
6.1 Matrisk will notify you without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting DPA Data.
6.2 Such notification will include, to the extent known:
6.3 Matrisk will cooperate with you and take reasonable steps to assist in the investigation, mitigation, and remediation of each Personal Data Breach.
6.4 Matrisk's notification of or response to a Personal Data Breach under this Section 6 will not be construed as an acknowledgment of any fault or liability with respect to the Personal Data Breach.
7.1 Upon your written request (no more than once annually), Matrisk will make available information necessary to demonstrate compliance with this DPA and applicable Data Protection Law.
7.2 Subject to reasonable confidentiality obligations, Matrisk will allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you, provided that:
7.3 Matrisk may satisfy audit requests by providing relevant third-party audit reports (such as SOC 2 Type II reports) or certifications.
8.1 Matrisk will implement and maintain appropriate technical and organizational measures designed to protect DPA Data against unauthorized or unlawful Processing and against accidental loss, destruction, damage, theft, alteration, or disclosure. These measures include:
8.2 Matrisk will ensure that personnel with access to DPA Data are subject to appropriate confidentiality obligations and have received appropriate training on data protection requirements.
8.3 Matrisk's security measures are subject to technical progress and development. Matrisk may update or modify its security measures from time to time, provided that such updates and modifications do not materially decrease the overall security of the Service.
To the extent Matrisk Processes DPA Data subject to US State Privacy Laws, Matrisk certifies that it:
9.1 Will Process DPA Data only for the specific purposes set forth in this DPA and as permitted under the Agreement.
9.2 Will not "sell" or "share" (as defined under the CCPA) DPA Data.
9.3 Will not retain, use, or disclose DPA Data for any purpose other than for the specific purpose of performing the Service, including retaining, using, or disclosing DPA Data for a commercial purpose other than providing the Service.
9.4 Will not retain, use, or disclose DPA Data outside of the direct business relationship between Matrisk and Customer.
9.5 Will not combine DPA Data with Personal Data received from or on behalf of another person or collected from Matrisk's own interaction with Data Subjects, except as permitted under applicable Data Protection Law.
9.6 Will not attempt to reidentify any deidentified data.
9.7 Will comply with applicable requirements of US State Privacy Laws and provide the same level of privacy protection as required by such laws.
9.8 Will notify you if Matrisk determines that it can no longer meet its obligations under US State Privacy Laws.
9.9 Grants you the right to take reasonable and appropriate steps to ensure that Matrisk uses DPA Data in a manner consistent with your obligations under applicable US State Privacy Laws.
9.10 Grants you the right to stop and remediate unauthorized use of DPA Data upon notice.
10.1 You represent and warrant that you have provided all necessary notices and obtained all necessary consents, permissions, and rights to provide DPA Data to Matrisk for Processing as contemplated by this DPA and the Agreement.
10.2 You are responsible for ensuring that your use of the Service and your instructions to Matrisk comply with applicable Data Protection Law.
10.3 You are responsible for implementing appropriate security measures for transmitting DPA Data to and from the Service.
10.4 You acknowledge that the Service is not designed for Processing special categories of Personal Data (e.g., data revealing racial or ethnic origin, political opinions, religious beliefs, health data, genetic or biometric data, or data concerning sex life or sexual orientation) unless expressly agreed in writing.
11.1 All DPA Data is Processed and stored exclusively within the United States. Matrisk does not transfer DPA Data outside of the United States.
11.2 Matrisk's Subprocessors are also required to Process and store DPA Data exclusively within the United States.
12.1 If Matrisk receives a request from a Data Subject to exercise rights under applicable Data Protection Law with respect to DPA Data, Matrisk will promptly notify you and will not respond to such request except to acknowledge receipt, unless legally required to do so.
12.2 Matrisk will provide reasonable assistance to you in responding to Data Subject requests, taking into account the nature of the Processing.
13.1 Upon your reasonable request, Matrisk will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, to the extent required under applicable Data Protection Law and taking into account the nature of the Processing and the information available to Matrisk.
14.1 If Matrisk is required by applicable law to Process DPA Data other than in accordance with your instructions, Matrisk will notify you of such requirement before Processing (unless prohibited by law from doing so) and will limit such Processing to the extent required by applicable law.
15.1 Upon termination or expiration of the Agreement, Matrisk will, at your election and within thirty (30) days of your written request:
15.2 Matrisk may retain DPA Data to the extent required by applicable law, provided that Matrisk maintains the confidentiality of such DPA Data and Processes it only as necessary for the purpose(s) specified in the applicable law.
15.3 In the absence of your written request, Matrisk will delete DPA Data within ninety (90) days following termination or expiration of the Agreement, except as required by applicable law.
16.1 Conflicts. In the event of any conflict between this DPA and the Agreement, this DPA will prevail with respect to the Processing of DPA Data.
16.2 Amendments. Matrisk may update this DPA to reflect changes required by applicable law or to address new regulatory guidance. For any other amendments that materially reduce the protections provided under this DPA, Matrisk will provide at least thirty (30) days' prior written notice. If you do not agree to such material changes, you may terminate the Agreement by providing written notice to Matrisk before the changes take effect.
16.3 Severability. If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions will remain in full force and effect.
16.4 Governing Law. This DPA is governed by the laws specified in the Agreement.
For questions about this DPA or to exercise your rights, please contact:
Email: privacy@matrisk.ai
This DPA is effective as of the date Customer accepts the Agreement or begins using the Service, whichever is earlier.