Privacy Policy

ProponoAudit.com

Effective Date: May 3, 2026 · Last Updated: May 3, 2026

1. Introduction

Propono.AI ("Propono," "our," or "us") operates an Insurance Technology Suite providing agentic insurance workflow products and related services (the "Services"). We are committed to protecting the privacy and security of personal information entrusted to us by our customers, end users, and business partners.

This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information in connection with our Services. It also describes your rights and choices regarding your personal information.

2. Scope

This Policy applies to:

  • Visitors to our website(s)
  • Customers and prospective customers who interact with our sales, marketing, or support teams
  • End users of our platform, including insurance professionals and administrators who access the Services under a customer account
  • Business contacts and partners

This Policy does not apply to personal information that Propono processes on behalf of its customers as a data processor or service provider. In those cases, the customer's own privacy policy and our Data Processing Agreement govern the handling of that data.

3. Information We Collect

3.1 Information You Provide Directly

  • Account registration details (name, email address, job title, company name)
  • Billing and payment information (processed via PCI-compliant third-party payment processors; we do not store raw payment card data)
  • Communications you send us (support requests, sales inquiries, feedback)
  • Information submitted through forms, surveys, or onboarding flows

3.2 Information Collected Automatically

  • Log data (IP address, browser type, operating system, pages visited, timestamps)
  • Usage and activity data within the platform (features used, workflow actions, session duration)
  • Device identifiers and technical information
  • Cookies and similar tracking technologies (see Section 10)

3.3 Information from Third Parties

  • Identity and authentication data from single sign-on (SSO) providers you authorize
  • Business contact information from data enrichment or CRM integrations
  • Information provided by your employer or organization when they provision your account

3.4 Sensitive Information

Our Services may process insurance-related data that is sensitive in nature (e.g., policyholder information, claims data, audit records). Such data is handled under strict access controls and, where applicable, subject to a separate Data Processing Agreement with the relevant customer.

4. How We Use Your Information

We use personal information for the following purposes, each grounded in a lawful basis:

  • Service Delivery: To provision, operate, and support the Services you or your organization have contracted for.
  • Account Management: To create and manage user accounts, authenticate users, and enforce access controls.
  • Product Improvement: To analyze usage patterns, diagnose technical issues, and improve platform performance and features.
  • Communications: To send transactional communications (account notices, security alerts, support responses) and, where you have opted in, marketing and product updates.
  • Security and Fraud Prevention: To monitor for unauthorized access, investigate suspicious activity, and protect the integrity of our systems and data.
  • Legal and Compliance Obligations: To comply with applicable laws, regulations, and contractual requirements, including audit and recordkeeping obligations.
  • Business Operations: For invoicing, contract management, and internal reporting.

We do not sell personal information to third parties. We do not use personal information to make automated decisions that produce legal or similarly significant effects without appropriate human review.

5. How We Share Your Information

5.1 Service Providers and Subprocessors

We engage vetted third-party vendors to help deliver our Services (e.g., cloud hosting, analytics, customer support platforms, payment processing). These vendors are bound by contractual data protection obligations and are only permitted to process personal information as directed by Propono.

5.2 Customers and Administrators

If you access the Services through an employer or organization, certain account information and activity data may be visible to your organization's administrators.

5.3 Business Transfers

In connection with a merger, acquisition, asset sale, or reorganization, personal information may be transferred to the successor entity. We will provide notice and, where required, seek consent before such a transfer occurs.

5.4 Legal Requirements

We may disclose personal information when required by law, subpoena, court order, or regulatory authority, or when we believe in good faith that disclosure is necessary to protect rights, safety, or property.

5.5 With Your Consent

We may share personal information for other purposes when we have obtained your explicit consent.

6. Data Retention

We retain personal information for as long as necessary to fulfill the purposes described in this Policy, to perform our contractual obligations, and to comply with legal and regulatory requirements. Retention periods are determined based on:

  • The nature and sensitivity of the data
  • The purpose for which it was collected
  • Applicable legal, regulatory, and contractual retention requirements
  • Our legitimate business needs

When personal information is no longer required, we securely delete or anonymize it in accordance with our data retention and disposal procedures.

7. Security

Propono maintains a formal information security program designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. Our security controls include:

  • Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent)
  • Role-based access controls and the principle of least privilege
  • Multi-factor authentication for system access
  • Continuous monitoring, logging, and alerting for security events
  • Vulnerability management and regular penetration testing
  • Employee security training and background screening
  • Incident response procedures with defined notification timelines
  • Third-party risk assessments for subprocessors

Propono pursues SOC 2 Type II compliance. Our SOC 2 report is available to customers and prospective customers under NDA upon request.

No security program can guarantee absolute security. In the event of a data breach affecting your personal information, we will notify affected parties as required by applicable law.

8. Data Subject Rights

Propono recognizes and supports the data subject rights available to individuals under applicable privacy laws, including the CCPA, GDPR, and similar state and international regulations.

8.1 Right to Access

You have the right to request a copy of all personal data we hold about you, including information about how it is used, who it is shared with, and how long it is retained.

8.2 Right to Deletion

You have the right to request that we delete your personal data (right to erasure). Deletion requests are subject to legal and contractual retention obligations that may require us to retain certain data for a defined period.

8.3 Right to Correction

You have the right to request that inaccurate or incomplete personal data we hold about you be corrected or updated.

8.4 Right to Opt Out / Object

You have the right to opt out of the sale or sharing of your personal data and to object to certain processing activities, including profiling and direct marketing. Propono does not sell personal data to third parties.

8.5 Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format, and to request that it be transmitted to another controller where technically feasible.

8.6 How to Submit a Rights Request

To exercise any of the rights above, please contact our privacy team:

We will acknowledge your request within 5 business days and respond substantively within 30 days, or within the timeframe required by applicable law. We may need to verify your identity before processing your request.

9. Additional Rights and Choices

Depending on your jurisdiction, you may have the following additional rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete personal information.
  • Deletion: Request deletion of your personal information, subject to legal and contractual retention obligations.
  • Portability: Request that your personal information be provided to you in a structured, machine-readable format.
  • Objection / Restriction: Object to or request restriction of certain processing activities.
  • Withdraw Consent: Where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of prior processing.
  • Marketing Opt-Out: Unsubscribe from marketing communications at any time via the unsubscribe link in any email or by contacting us directly.

To exercise any of these rights, please contact us at the address in Section 12. We will respond within the timeframe required by applicable law.

10. Cookies and Tracking Technologies

We use cookies and similar technologies to operate and improve our Services, remember your preferences, and analyze usage. You can control cookie settings through your browser or, where applicable, through our cookie preference center.

Types of cookies we use:

  • Strictly Necessary: Required for the platform to function. Cannot be disabled.
  • Functional: Enable enhanced features and personalization.
  • Analytics: Help us understand how users interact with the platform (e.g., pages visited, errors encountered).
  • Marketing: Used to deliver relevant communications (only where consent has been obtained).

11. International Data Transfers

Propono operates primarily in the United States. If you are located outside the United States, your personal information may be transferred to and processed in the U.S. or other countries. Where such transfers occur, we implement appropriate safeguards, such as Standard Contractual Clauses or other legally recognized transfer mechanisms, to ensure your information receives an adequate level of protection.

12. Contact Us

For privacy-related questions, requests, or complaints, please contact:

Propono.AI — Privacy Team

Email: contactus@proponoaudit.com

Mailing Address: 994 Forest Street, Reno NV 89509

If you are located in the European Economic Area or United Kingdom and believe your rights have not been respected, you have the right to lodge a complaint with your local data protection authority.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will post the updated Policy on our website with a revised "Last Updated" date. For material changes, we will provide additional notice (such as a banner notification or email) where required. Your continued use of the Services after the effective date of a revised Policy constitutes your acceptance of the changes.

This Privacy Policy is intended to satisfy the transparency and notice requirements associated with SOC 2 Trust Services Criteria, including CC2.2 (internal and external communication of objectives and responsibilities), CC6.1 (logical access controls), CC6.7 (data transmission and disposal), and CC9.2 (vendor and business partner management).