Privacy Policy

TESORA AI PRIVACY POLICY

Tesora AI Inc. (the "Company," "we," "us," or "our") is committed to maintaining robust privacy protections for its users. This Privacy Policy ("Privacy Policy") is designed to help you understand how we collect, use, disclose, and safeguard the information you provide to us, and to assist you in making informed decisions when using our Service.

For purposes of this Privacy Policy, "Site" refers to the Company's website, which can be accessed at tesora.ai. "Service" refers to the Company's products and services accessed via the Site, through which users can use AI agents for actuarial analysis, rating, ingestion, and audit workflows. The Service includes the Tesora Compute API (compute.tesora.ai) and the Tesora Compute add-in for Microsoft Excel, which are described in Section I.5. "You" refers to you, as a user of our Site or our Service, whether on your own behalf or on behalf of an organization you represent.

Tesora is primarily a business-to-business service. Where you use the Service under an agreement between your organization and the Company, that organization is the controller of the data it submits, and our handling of that data is governed by the terms of that agreement. To the extent of any conflict between this Privacy Policy and a signed agreement covering your use of the Service, the signed agreement controls.

By accessing our Site or our Service, you accept this Privacy Policy and our Terms of Use (found here: tesora.ai/terms), and you consent to our collection, storage, use, and disclosure of your information as described in this Privacy Policy.

I. INFORMATION WE COLLECT

We collect "Non-Personal Information" and "Personal Information." Non-Personal Information includes information that cannot reasonably be used to identify you, such as aggregated or de-identified usage data, general demographic information, referring and exit pages, platform types, and interaction counts. Personal Information includes your name, email address, company information, job title, and any other contact or account details you provide, which you submit to us through the registration process or in the course of using the Service.

Our Service also allows you and your organization to upload documents and connect external accounts. We refer to the content you and your organization submit to, or generate within, the Service as "Customer Content." Customer Content may include rate filings, rate manuals, loss runs, statements of value, actuarial memos, and similar materials, along with the outputs the Service derives from them. In connection with these features we may process: (1) the content and metadata of uploaded documents; (2) authentication tokens and account information for external services you choose to connect; and (3) data transmitted from those connected accounts to our platform at your direction. We treat Customer Content as confidential and use it only to provide and support the Service, as described in Section II and Section IV.

1. Information collected via technology

To activate the Service you do not need to submit any Personal Information other than your email address. To use the Service thereafter, you do need to submit further Personal Information, which may include your name, company information, billing details, documents you choose to upload, and credentials for any external accounts you choose to connect. In addition, to operate and improve the Service, we automatically collect information provided by your browser or by our software when you view or use the Service, such as the referring URL, the type of browser and device you use, the time and date of access, and other information that does not by itself identify you. We collect this information using cookies and similar technologies, which are small text files that include an anonymous unique identifier. On the public marketing Site, non-essential cookies load only in accordance with your consent choices, as described in Section IX. For example, we may use cookies to collect the following:

  • User preferences and settings
  • Login status and authentication tokens
  • Usage patterns and interaction data
  • Performance and analytics data

We may use both persistent and session cookies. Persistent cookies remain on your device after you close your session and until you delete them, while session cookies expire when you close your browser. For example, we store a persistent cookie to keep you signed in and to remember your preferences. You can control cookies through your browser settings and through the choices described in Section IX.

2. Information you provide by registering for an account

In addition to the information provided automatically by your browser, to become a user of the Service you or your organization will create an account. You can create a profile by registering with the Service, providing your email address, and setting authentication credentials, which may be managed through your organization's single sign-on provider. You will then be prompted to provide additional information, including your name, company information, and, where applicable, billing details. By registering, you authorize us to collect, store, and use this information in accordance with this Privacy Policy.

3. Information you provide through in-product support chat

Within the Actuarial Workbench we make a chat widget available so you can reach our support team without leaving your work. The widget is provided and hosted by Front (FrontApp, Inc.), which acts as our subprocessor for support communications. It appears only in the Actuarial Workbench when you are signed in; it does not appear on our public marketing Site.

When the widget loads, we provide it with your name and email address, together with a signature we generate on our servers that lets Front confirm the identity is one we vouched for rather than one typed into the chat form. We do this so that support conversations are attributed to the right person and so that no one can impersonate you in a support thread. The messages you send, and our replies, are stored by Front on our behalf as part of your support history, and are used to answer your questions, provide technical support, and improve the Service.

The widget sets its own cookies in your browser so that a conversation survives page loads. Those cookies are necessary for the support feature to work and are not analytics or advertising cookies. When you sign out, or navigate away from the Actuarial Workbench, we instruct the widget to shut down and clear that session, so a subsequent user of the same browser does not resume your conversation. Please do not enter Customer Content or sensitive personal information into the chat beyond what is needed to resolve your question.

4. Sources of information

We collect information directly from you, automatically through your use of the Service, and from your organization when it provisions your account or submits Customer Content. We may also receive information from service providers that help us operate the Service, such as our identity, hosting, analytics, support, and payment providers.

5. Tesora Compute API and Tesora Compute for Excel

The Compute API and the Tesora Compute add-in for Excel are part of the Service and are covered by this Privacy Policy. The add-in adds functions to Microsoft Excel that are called from a worksheet cell as =TESORA.NAME(...). These functions are evaluated by the Compute API rather than on your device.

When you enter or recalculate such a formula, the add-in transmits the arguments of that formula, meaning the cell values and ranges you pass to the function over an encrypted connection to the Compute API, which evaluates the formula and returns the result to the cell. This is the only workbook data the add-in sends. It does not read, collect, or transmit any other part of your workbook, any other open workbook, or any file on your device, and it does not modify your workbook other than by returning the results of the functions you call.

Formula arguments and the results computed from them are processed only to answer the call in which they are sent. We do not retain them after the call completes, do not use them to train models, and do not sell or share them. We do log operational metadata about calls: the time, the function invoked, the response status, and a rate-limiting identifier. That metadata exists to operate, secure, and rate-limit the service.

The Compute API may be used without an account. If you choose to sign in from the add-in in order to raise your rate limit, we process your account identifier and email address as described elsewhere in this Policy; authentication is handled by our identity provider, and the add-in stores the resulting access token locally in Microsoft Office storage on your device so that your formulas remain signed in. Signing out removes it. If you send us a report through our support page, we process what you write there, and the contact address you supply, in order to answer you.

II. HOW WE USE INFORMATION

We use the information we collect to: provide, operate, secure, and improve the Service; authenticate users and administer accounts; process Customer Content to generate the analyses and outputs you request; respond to your questions and provide technical support; communicate with you about the Service, including administrative and transactional messages; send marketing communications where permitted; detect, investigate, and prevent fraud, abuse, and security incidents; and comply with our legal obligations and enforce our agreements.

Where we rely on consent to process your information, you may withdraw that consent at any time. Where we process information on the basis of our legitimate interests, those interests are operating and improving the Service, securing our systems, and communicating with our users, balanced against your rights and expectations.

In general, we use Non-Personal Information to help us understand how the Service is used, to improve it, and to customize the user experience. We may aggregate or de-identify information so that it no longer reasonably identifies you, and we may use and disclose such aggregated or de-identified information for our legitimate business purposes. We do not attempt to re-identify de-identified information except to test that it cannot be re-identified.

III. HOW WE SHARE INFORMATION

We do not sell your Personal Information, and we do not share your Personal Information for cross-context behavioral advertising in exchange for monetary or other valuable consideration. We share Personal Information only as described below.

Service providers and subprocessors. We share Personal Information and Customer Content with vendors that perform services for us, such as cloud hosting, identity and authentication, analytics, communications, customer support and messaging, and payment processing. These providers act as our subprocessors, may use the information only at our direction and for the purpose of providing services to us, and are bound by confidentiality and data protection obligations. A current list of subprocessors is available through our Trust Center, which you can reach from our tesora.ai/security page.

Within your organization. Where you use the Service under an organizational account, your administrators may access account information and Customer Content associated with your organization, and may control your access to the Service.

Legal and safety. We may share information with outside parties if we have a good-faith belief that access, use, preservation, or disclosure is reasonably necessary to comply with applicable law or a valid legal request; to enforce our Terms of Use, including investigation of potential violations; to address fraud, security, or technical concerns; or to protect against harm to the rights, property, or safety of the Company, our users, or the public, as required or permitted by law.

Business transfers. If we undergo a business transaction such as a merger, acquisition, or sale of all or a portion of our assets, your information may be among the assets transferred. Any acquirer will remain bound by the commitments made in this Privacy Policy unless and until it is amended, and we will provide notice of any material change to how your information is handled.

IV. ARTIFICIAL INTELLIGENCE AND AUTOMATED PROCESSING

The Service uses artificial intelligence and machine learning to analyze Customer Content and generate outputs. We want to be clear about how that works.

We do not train shared or foundation models on Customer Content. Your rate plans, filings, books, submissions, and other Customer Content are not used to train models that are shared across customers. Each customer's data is processed within a dedicated, isolated tenant, with no cross-tenant inference and no shared embeddings or vector stores.

Human oversight and accuracy. Outputs generated by AI may contain errors or omissions and are intended to support, not replace, the judgment of qualified professionals. You are responsible for reviewing outputs before relying on them, and AI outputs should not be treated as actuarial, legal, financial, or other professional advice. The Service is designed to preserve the provenance of the values it produces so that a human reviewer can trace each output back to its source.

Where we use third-party model providers to deliver AI features, we engage them as subprocessors under terms that prohibit them from using Customer Content to train their models. For more detail on our data posture, see our tesora.ai/security page.

V. DATA RETENTION

We retain Personal Information and Customer Content for as long as your account is active, as needed to provide the Service, and as required to meet our legal, tax, and regulatory obligations, resolve disputes, and enforce our agreements. Retention periods for organizational accounts are governed by the agreement between your organization and the Company. When information is no longer needed for these purposes, we delete it or de-identify it. Upon termination of an account, we delete or return Customer Content in accordance with the applicable agreement, subject to any residual copies retained in routine backups for a limited period and to any information we are required to keep by law.

Formula arguments and results sent to the Compute API, including those sent by the Tesora Compute add-in for Excel, are an exception: they are held only for as long as it takes to answer the call and are not retained afterwards. See Section I.5.

VI. INTERNATIONAL DATA TRANSFERS

The Company is based in the United States, and production data is stored in United States region infrastructure by default, with European data residency available on request. If you access the Service from outside the United States, you understand that your information may be transferred to, stored, and processed in the United States and other countries where we or our service providers operate. Where we transfer Personal Information originating in the European Economic Area, the United Kingdom, or Switzerland to a country that has not been recognized as providing an adequate level of protection, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, to protect that information.

VII. HOW WE PROTECT INFORMATION

We implement administrative, technical, and organizational measures designed to protect your information from unauthorized access, use, alteration, and destruction. These measures include encryption of data at rest using AES-256 and in transit using TLS 1.3, customer-scoped key management, per-tenant isolation, role-based access controls, single sign-on support, and a practice of keeping plaintext personal information out of our logs. We maintain a SOC 2 Type II program that is audited annually. Your account is also protected by your authentication credentials, and we urge you to keep those credentials confidential and to sign out after each session. No method of transmission or storage is completely secure, and while we work hard to protect your information, we cannot guarantee its absolute security. By using the Service, you acknowledge that you understand and accept these risks.

VIII. YOUR PRIVACY RIGHTS

You have the right at any time to prevent us from contacting you for marketing purposes. When we send a promotional communication, you can opt out by following the unsubscribe instructions in the message or by updating your preferences in the Settings section of the Service. Even if you opt out of marketing, we may continue to send you administrative messages, such as updates to this Privacy Policy or notices about your account.

1. Rights under GDPR and UK data protection law

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the right, subject to certain conditions and exceptions, to: access the Personal Information we hold about you; request correction of inaccurate information; request erasure of your information; restrict or object to our processing; request a portable copy of information you provided to us; and withdraw consent where our processing is based on consent. Where your organization is the controller of the data at issue, we will refer your request to that organization and support it in responding. You also have the right to lodge a complaint with your local supervisory authority.

2. Rights under California law

If you are a California resident, the California Consumer Privacy Act, as amended, gives you the right to: know the categories and specific pieces of Personal Information we have collected about you and how we use and disclose it; request deletion of your Personal Information; request correction of inaccurate Personal Information; opt out of the sale or sharing of your Personal Information; and limit the use and disclosure of sensitive Personal Information. We will not discriminate against you for exercising any of these rights. As noted in Section III, we do not sell Personal Information for money. Where we use analytics and marketing technologies that may qualify as sharing under California law, you can opt out using the "Do Not Sell or Share My Personal Information" control described in Section IX.

3. How to exercise your rights

To exercise any of these rights, please contact us at privacy@tesora.ai. We will verify your request, respond within the time required by applicable law, and may ask for information reasonably necessary to confirm your identity. You may use an authorized agent to submit a request on your behalf where permitted by law.

IX. COOKIES AND YOUR CHOICES

On our public marketing Site, we present a consent banner that adapts to your region. If you are in the European Economic Area, the United Kingdom, or a similar jurisdiction, non-essential analytics and marketing cookies load only after you accept them, and you can decline without losing access to the Site. If you are in California or a similar jurisdiction, we provide a "Do Not Sell or Share My Personal Information" option that opts you out of analytics and marketing technologies that may share information with third parties. A persistent "Your Privacy Choices" link in the footer lets you reopen these controls and change your choice at any time. You can also manage cookies through your browser settings, though disabling certain cookies may affect how the Site functions.

These controls govern the public marketing Site. Inside the authenticated Service, the cookies we and our subprocessors set are those necessary to operate it, for example to keep you signed in and, as described in Section I.3, to keep a support-chat conversation open across page loads. Because they are necessary rather than optional, they are not covered by the consent banner. If you would rather not use the in-product chat, you can reach our support and privacy teams by email instead.

X. LINKS TO OTHER WEBSITES

As part of the Service, we may provide links to or integrations with other websites and applications. We are not responsible for the privacy practices of those third parties or the content they provide. This Privacy Policy applies solely to information collected by us through the Site and the Service. When you access a third-party website or application, that party's privacy policy governs your use of it. We encourage you to read the privacy statements of any third-party services before using them.

XI. CHILDREN'S PRIVACY

The Site and the Service are intended for business use by adults and are not directed to anyone under the age of 18. We do not knowingly collect Personal Information from anyone under 18. If we learn that we have collected Personal Information from someone under 18, we will delete that information as soon as reasonably possible. If you believe we have collected such information, please contact us at privacy@tesora.ai.

XII. CHANGES TO THIS PRIVACY POLICY

We reserve the right to change this Privacy Policy at any time. We will notify you of material changes by sending a notice to the primary email address associated with your account or by placing a prominent notice on the Site. Material changes take effect 30 days following such notice. Non-material changes or clarifications take effect immediately. Please check the Site and this page periodically for updates.

XIII. CONTACT US

If you have any questions about this Privacy Policy or our privacy practices, please contact us at privacy@tesora.ai, or by mail at:

Tesora AI Inc. 1111B S Governors Ave, STE 28328 Dover, Delaware 19904