Trust · Privacy
Minimum-necessary data, explicit boundaries.
Insurf builds tools for coverage decisions. The privacy posture is designed around data minimization, contractual authorization, and separate handling for public demos, pilots, and any future PHI workflow.
Collection
What Insurf may collect.
- Contact details you provide when requesting a demo, support, or diligence materials.
- Account, role, and access metadata for authorized pilot users.
- Product usage, security, audit, and diagnostic logs needed to operate and protect the service.
- Documents or case records only when an authorized pilot workflow and contract permit them.
Use
How data is used.
- Service delivery
- Operate Inveto and Surely, route user actions, generate supported drafts, and maintain audit history.
- Security
- Monitor access, investigate abuse, verify controls, and maintain evidence for diligence and audits.
- Improvement
- Use de-identified or synthetic data only when permitted by contract and reviewed for the relevant privacy boundary.
- Retention
- Retain records for the period required by contract, compliance needs, security review, and legal obligations.
Limits
What this page does not do.
- It does not replace a customer BAA or order form.
- It does not authorize production PHI processing by itself.
- It does not claim Safe Harbor or Expert Determination for any specific dataset.
- It does not change the signed terms that govern a named customer pilot.