COVU OS Lite Data Processing Addendum
This Data Processing Addendum (this "DPA") is part of the OS Lite Terms of Service (the "Terms") and applies automatically when the Agency accepts the Terms and submits or connects Agency Customer Data. It governs COVU's processing of personal information contained in Agency Customer Data ("Customer Personal Information"). If a signed data-processing agreement exists between the parties, it controls over this DPA.
1. Roles and Scope
The Agency is the business / controller of Customer Personal Information; COVU is the Agency's service provider / processor. For nonpublic personal information subject to the Gramm-Leach-Bliley Act or state insurance privacy law, COVU acts as the Agency's service provider and will not use or disclose that information except to carry out the purposes for which it was disclosed, as permitted by GLBA §502(e) and its implementing rules, or as required by law.
2. Instructions and Purpose Limitation
COVU will process Customer Personal Information only: (a) to provide, secure, support, administer, and improve OS Lite for the Agency; (b) per the Agency's documented instructions, including its in-product configurations and task submissions; and (c) as required by law (with notice to the Agency unless legally prohibited). COVU will inform the Agency if, in its opinion, an instruction violates applicable data-protection law.
3. CCPA Service-Provider Certifications
COVU certifies that it will not: sell Customer Personal Information or share it for cross-context behavioral advertising; retain, use, or disclose it outside the direct business relationship with the Agency or for any purpose other than the business purposes in Section 2; or combine it with personal information received from other sources except as permitted for service providers. COVU will provide the same level of privacy protection required of businesses, grant the Agency the rights to take reasonable and appropriate steps to ensure COVU's use is consistent with the Agency's obligations, notify the Agency if it can no longer meet its obligations, and permit the Agency to take reasonable steps to stop and remediate unauthorized use.
4. Confidentiality and Personnel
COVU limits access to Customer Personal Information to personnel and Service Network workers who need it for the purposes above and are bound by confidentiality obligations, applying least-privilege and role-based access.
5. Security and Incidents
COVU maintains the written security program in the Security Exhibit, appropriate to the nature of the data and risks. COVU will notify the Agency without undue delay after confirming unauthorized access to, acquisition of, or disclosure of Customer Personal Information (a "Security Incident") — where reasonably practicable, within seventy-two (72) hours of confirmation — with available information about the nature, affected data, likely consequences, and containment/remediation, and will reasonably cooperate with the Agency's legally required notifications. COVU will not notify the Agency's customers or regulators on the Agency's behalf without approval unless law requires it.
6. Subprocessors
The Agency provides general authorization for the subprocessors listed at /subprocessors. COVU will: bind each subprocessor to data-protection obligations materially consistent with this DPA; remain responsible for their processing; and give at least fifteen (15) days' notice (via the list and email to Agency administrators) before adding a material new subprocessor. If the Agency reasonably objects on data-protection grounds and no reasonable alternative exists, the Agency may terminate the affected service and COVU will honor the export and deletion terms below.
7. Rights Requests and Assistance
Taking into account the nature of the processing, COVU will: promptly forward to the Agency any consumer request it receives that concerns Customer Personal Information; assist the Agency with verified access, deletion, correction, and opt-out requests through available functionality or reasonable cooperation; and reasonably assist with the Agency's security assessments, regulator inquiries, and legally required impact or incident assessments relating to COVU's processing.
8. Government Demands
If COVU receives a subpoena, warrant, or other governmental demand for Customer Personal Information, it will (unless legally prohibited) promptly notify the Agency, disclose only what is legally required, and reasonably cooperate with lawful efforts to seek protective treatment.
9. International Access
COVU processes Customer Personal Information in the United States, using the subprocessor locations listed. Access by the Agency's own authorized users located outside the United States is the Agency's instruction and responsibility; COVU remains responsible for its own personnel and subprocessors.
10. Return, Export, and Deletion
During the term, the Agency may export available Agency Data through available functionality. Upon the Agency's written request or when the applicable service ends, COVU will return or delete Customer Personal Information from active systems within sixty (60) days, except for records retained under legal obligation, dispute preservation, or security needs, and protected backups that expire through ordinary rotation. Retained data remains protected under this DPA and is not used for any other purpose.
11. Audits and Assurance
On reasonable request (no more than once per year absent a Security Incident or legal requirement), COVU will provide available security documentation, third-party audit summaries or certifications it holds, or a completed reasonable security questionnaire. An on-site or independent audit is available only where required by law, following a material Security Incident, or where provided evidence is materially insufficient — during business hours, without access to other customers' data, under confidentiality, and at the Agency's expense unless the audit reveals a material COVU breach.
12. Sensitive-Data Boundaries
OS Lite is not intended for protected health information subject to HIPAA, payment-card data subject to PCI-DSS, or plaintext credentials, and the Agency will not submit them absent a separate written agreement (including a BAA where required) and approved controls.
13. Processing Details Schedule
| Item | Description |
|---|---|
| Subjects | The Agency's customers, policyholders, prospects, and their household/business contacts; Agency personnel |
| Categories | Identifiers and contact details; policy, coverage, claims-adjacent, and billing-related details; communications (email, notes, tasks); workflow metadata; AI inputs/outputs derived from the above |
| Sensitive data | Only as incidentally present in insurance records; the exclusions in Section 12 apply |
| Purposes | Providing OS Lite services at the Agency's direction (Section 2) |
| Duration | Term of the Agency's use plus the deletion window in Section 10 |
Change log
- v0.9-draft (July 16, 2026) — initial complete draft per the approved OS Lite Legal and Compliance Design (2026-07-15); pending counsel review.
- v1.0 (July 16, 2026) — published to production pending counsel validation; content unchanged from v0.9-draft.